GGet-IT-Done ← Back to site

Privacy Policy

Last updated: 18 August 2026  ·  Effective: 18 August 2026

1. Who we are

This website (served at ccg-analytics.de) and the “Get-IT-Done” platform are operated by LB TEC (PTY) LTD (“we”, “us”, the responsible party / data controller). Smart AI Solutions (smartaisolutions.co.za) provides e-mail infrastructure to the platform and acts as an operator / processor on our instructions.

Our two roles

We act in two different capacities, and which one applies depends on whose information it is:

Where this policy says “your information” without qualification, it means information we hold as responsible party. If you are an employee or contact of one of our customers and want to know how they use your information, please contact them directly; we will help route the request if you are unsure who to ask.

2. Scope

This policy explains how we collect, use, share, and protect personal information across both of the following, and how we comply with the Protection of Personal Information Act, 2013 (POPIA) of South Africa, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act / CPRA (CCPA).

3. Information we collect

We collect what you give us, the minimum the website needs to function, and — within the platform — the content our customers choose to process through it.

Information you provide directly

Information collected automatically

Information processed inside the Get-IT-Done platform

Where a customer uses the platform, the following is processed on their instructions. We hold it as operator, not as responsible party (§1):

We do not intentionally collect special-category / sensitive information (e.g. health, biometric, or financial account data) through this website, and the platform is not intended for it. Please do not enter such information in free-text fields.

Artificial intelligence: we do not currently send personal information, message content, or customer data to any third-party AI or large-language-model provider — no such provider is connected to the platform. If we introduce an AI-assisted feature that does so, we will name the provider in the table in §6 and update this policy before that feature is switched on.

4. How and why we use your information (and our legal basis)

PurposeLegal basis (GDPR) / lawful processing (POPIA)
Schedule and confirm your booking; contact you about itConsent, and steps to enter/perform a contract at your request (GDPR Art. 6(1)(a)/(b); POPIA s11(1)(a)/(b))
Process your intake answers and prepare a proposalConsent / pre-contract steps (GDPR Art. 6(1)(a)/(b); POPIA s11)
Respond to enquiries and manage the sales relationshipLegitimate interests / consent (GDPR Art. 6(1)(a)/(f); POPIA s11(1)(a)/(f))
Keep the site secure and prevent abuseLegitimate interests / legal obligation (GDPR Art. 6(1)(c)/(f); POPIA s11(1)(c)/(f))
Provide the platform to a customer: host their contacts, boards and tasks, and operate their user accountsPerformance of our contract with the customer (GDPR Art. 6(1)(b); POPIA s11(1)(b)) — and, for the customer's own contacts, on the customer's instructions as operator
Send task and reminder messages over WhatsApp and e-mail on a customer's behalf, and receive replies back into their tasksOn the customer's documented instructions as operator (POPIA s20–21; GDPR Art. 28). The customer is responsible for having a lawful basis and opt-in for the people they message — see §5 of our Terms of Service

We do not use your information for automated decision-making that produces legal effects, and we do not sell your personal information (relevant to CCPA — see §9).

5. Cookies and tracking

We use only strictly-necessary first-party cookies (session and CSRF token). Because these are essential to provide the service you request, they do not require prior consent under GDPR/POPIA. We do not use analytics or advertising cookies and do not track you across other sites. If we add non-essential cookies in future, we will show a consent banner first.

6. Who we share information with

We share personal information with the service providers (“operators”/“processors”) needed to run the site and the platform, and we never sell it. Each provider is bound to process data only on our instructions. The table below is the complete list.

ProviderWhat they receiveWhere
Supabase (booking database)Booking details: name, e-mail, phone, topic, notes, appointment timeEuropean Union (Supabase on AWS)
Smart AI Solutions (e-mail / SMTP)Recipient address + message content for booking confirmations and intake reportsSouth Africa
Hostinger (web hosting)Anything processed on the server (site + CRM); server logsEuropean Union
Meta Platforms, Inc. and its affiliates — the WhatsApp Business Platform, which carries every WhatsApp message the platform sends or receivesRecipient and sender WhatsApp phone numbers, the content of each message, and message metadata (identifiers, timestamps, delivery and read status)Meta’s global processing infrastructure, including the United States
Unipile (WhatsApp connectivity provider — currently in use, being retired)The same WhatsApp phone numbers, message content and metadata, while it remains the transportEuropean Union

About WhatsApp: WhatsApp is operated by Meta. Any message the platform sends to, or receives from, a WhatsApp number necessarily passes through Meta’s systems and is subject to Meta’s own terms and privacy practices in addition to this policy. We cannot deliver a WhatsApp message without Meta receiving it. Meta is an independent controller for its own purposes as described in its terms; we do not control what it does with the data it holds about a WhatsApp user.

We may also disclose information where required by law, or to protect our rights, safety, or property.

7. International transfers

Our hosting and booking database are located in the European Union, and our e-mail infrastructure is in South Africa. Because we are a South African responsible party using EU-based processors, personal information is transferred out of South Africa to the EU/EEA. We rely on lawful transfer mechanisms for this — your consent, contractual necessity, and appropriate safeguards under POPIA section 72, supported by GDPR Standard Contractual Clauses in our processors’ terms.

WhatsApp messages travel further than the EU. Every WhatsApp message the platform sends or receives passes through Meta’s global infrastructure, which includes the United States — a destination without a South African adequacy finding and, for EU data subjects, outside the EEA. This transfer is unavoidable if WhatsApp is used at all: it is how the network works. We rely on the Standard Contractual Clauses and data-transfer terms incorporated into the Meta Platform Terms and the WhatsApp Business Terms, together with contractual necessity under POPIA section 72(1)(b), for this leg. While Unipile remains the transport, the same message data also passes through Unipile in the European Union. If you do not want your information sent through WhatsApp, ask us or your employer to use e-mail reminders instead — the platform supports e-mail and in-app reminders that do not involve Meta.

8. How long we keep your information

We keep personal information only as long as necessary for the purpose it was collected, then delete or anonymise it. Our retention periods are:

You can ask us to delete your information sooner — see §9.

9. Your rights

Depending on where you are, you have the following rights. To exercise any of them, contact our Information Officer (§1). We respond within the timeframes required by law and will not discriminate against you for exercising them.

Under POPIA (South Africa)

Under GDPR (EU/EEA)

Under CCPA/CPRA (California)

10. How we protect your information

No method of transmission or storage is completely secure; while we use appropriate safeguards, we cannot guarantee absolute security.

11. Children’s privacy

This website is intended for businesses and is not directed at children. We do not knowingly collect personal information from children (under 18 under POPIA; under 16 under GDPR unless a lower national age applies). If you believe a child has provided us information, contact us and we will delete it.

12. Contact us

For any privacy question or to exercise your rights, contact our Information Officer:

13. Changes to this policy

We may update this policy from time to time. We will post the revised version here with a new “Last updated” date and, for material changes, take reasonable steps to notify you.