Privacy Policy
Effective date: 12 May 2026
Last updated: 2 June 2026
Data controller: Kardania (FZC), a UAE Free Zone Company ("Kardania", "we", "us", "our")
Contact: [email protected]
This Privacy Policy explains what personal data Kardania collects when you use the Loop application, the Connect public-profile service, the Kardania mobile application, and related services (collectively, the "Services"), how we use that data, who we share it with, how long we keep it, and the rights you have over it.
By using the Services you agree to the practices described in this Policy. If you do not agree, do not use the Services.
This Policy is written in plain English so you understand what happens with your data. Where defined legal terms apply (for example under the UAE Personal Data Protection Law — Federal Decree-Law No. 45 of 2021, the "UAE PDPL"), we have aligned our practices accordingly.
1. Who We Are
Kardania (FZC) is a UAE Free Zone Company that operates the Loop CRM platform, the Connect public-profile service, and a companion mobile application. For the purposes of UAE PDPL and similar laws, Kardania acts as the data controller for the personal data described in this Policy, except where we expressly note that we act as a data processor on behalf of an Enterprise Account customer (see Section 2.2).
You can reach us at:
- Email: [email protected] (also our designated contact for privacy questions and data-subject requests)
- Company: Kardania (FZC), United Arab Emirates
2. Scope of This Policy
2.1 What this Policy covers
This Policy covers personal data we process in connection with:
- the Loop web application (loop.kardania.com),
- the Connect public-profile service (connect.kardania.com and individual published profile URLs),
- the Kardania Mobile App for iOS and Android,
- the marketing website at kardania.com,
- any direct communication with us (email, support requests).
2.2 Controller versus processor
There are two distinct relationships in our Services:
- When you are an end user of Connect, or an individual registering for a Loop free trial or buying a subscription directly: we are the data controller of your personal data. This Policy describes how we use that data.
- When you are a Team Member of an Enterprise Account (i.e., your employer subscribes to Loop and added you): the Enterprise Account customer is the data controller of the data your employer uploads, and we act as a data processor on their behalf. The Enterprise Account customer has its own privacy policy that governs how they collect and use your data; you should refer to that policy for questions about their practices. We process that data only as instructed by the Enterprise Account customer in accordance with our Terms of Service.
For your own account-level data (your login, your profile, your activity within the application), we are the controller in either case.
2.3 What this Policy does not cover
- Third-party services you choose to integrate with (Zoho CRM, Microsoft Entra ID, etc.) — those services have their own privacy policies, which govern their handling of your data.
- The Apple App Store and Google Play, which independently process payment data and account data when you purchase Connect Premium — see Apple's and Google's respective privacy policies.
- Third-party websites or apps that link to or from the Services.
3. Personal Data We Collect
The categories of personal data we collect depend on which Service you use.
3.1 Loop (Enterprise SaaS)
Account and profile data
- Your full name, email address, mobile phone number (optional), work phone number (optional), profile photo (optional).
- Your password (stored only as a one-way BCrypt hash — we never store or have access to the plaintext password).
- Your role within the Enterprise Account (Account Owner, Account Admin, Brand Manager, Branch Manager, Team Member).
- Your assigned brand and branch.
- Your preferred language (English or Arabic).
- A history of sessions (sign-in time, IP address, user agent of the device, session-family identifier).
Content you upload or create
- Customer and contact records (names, email addresses, phone numbers, company affiliations, addresses, notes).
- Brand and branch details (name, location, contact information, branding assets).
- Activities, notes, tasks, and form submissions you create.
- Images, documents, and files you upload (avatars, business cards, branch media, attachments).
- Integration data (when you connect Zoho CRM or Microsoft Entra ID, we store your authorization tokens, encrypted at rest — see Section 7).
- Campaign workspaces: campaign details and settings, landing-page content, files you upload to a campaign, and messages you post in a campaign's team chat ("Team Space").
Campaign landing-page visitor data (for visitors to your public campaign pages)
- When someone visits a published campaign landing page, we record limited visitor data: IP address, country and city (derived from the IP address), browser user-agent, the referrer, which page elements they interacted with (for example call-to-action clicks), and the time of the visit. This data is aggregated into campaign analytics shown to the campaign's team.
- If a visitor submits a linked data-capture form, the submission (the fields you configured) is stored under your Enterprise Account.
Usage and operational data
- API request logs (path, status code, duration, timestamp) used for rate limiting and performance monitoring.
- Audit log entries describing significant administrative actions you take (creating users, changing billing, deleting records, etc.) — retained indefinitely for compliance reasons.
- Application-error reports from your browser and our servers, including stack traces. Where these contain identifiers, we hash email addresses and phone numbers in the logs to limit exposure.
Billing data (when you subscribe)
- Customer name, billing address, tax identifier (if you provide one).
- The last four digits of your credit-card number and the card type. We do not store full card numbers or CVCs. Tokenized card data is held by our payment processor, Stripe.
- Invoice history, payment status, and Stripe customer identifier.
3.2 Connect (public profile + Mobile App)
Account data
- Your full name, email address, mobile phone number (optional), profile photo.
- Your password hash (BCrypt) if you registered with email and password; for users who registered with Sign in with Apple or Sign in with Google, we store only the relevant provider identifier and no password.
- Your preferred language.
Profile content
- Public profile fields you choose to publish: bio, job title, company, social links, contact methods, theme, custom domain (Connect Premium).
- Files you upload to the profile (avatar, cover image, business-card image, gallery).
- Profile-visit settings (e.g. whether to count anonymous visits, whether to capture form submissions).
Visitor data (for visitors to your public Connect profile)
- When someone visits your Connect profile, we record limited visitor data: IP address, country and city (derived from the IP address), browser user-agent string, the page or referrer they came from, and the time of the visit. This data is shown to you (the profile owner) on your dashboard and is used to compute the "Profile Visits Map" feature.
- Visitors are not personally identified unless they choose to submit a contact form on your profile. Form submissions (name, email, message, etc., as configured by you) are stored under your account.
Mobile App data
- Device platform (iOS or Android), operating system version, application version.
- Push-notification tokens, if you opt in to receive notifications.
- In-app purchase receipts and entitlement state when you purchase Connect Premium: the Apple Original Transaction ID or the Google Purchase Token, the product purchased, the renewal status, and timestamps. We do not have access to your payment card.
- Cached profile data on the device (cleared when you sign out).
3.3 Common to all Services
Communications you send us
- The content of support emails, in-app feedback, and any correspondence with us.
Marketing-website analytics
- Standard server logs from kardania.com (IP, user agent, page requested, timestamp).
4. AI Features
When you use the Business Card Scan feature or AI Insights, we send the relevant content (image or text) to OpenAI, L.L.C. for processing. The content sent is limited to what the feature needs to produce the result:
- For Business Card Scan: the image of the business card, plus instructions telling the AI to extract the name, email, phone, company, and similar standard fields.
- For AI Insights: structured customer/contact data (name, company, role, notes) and instructions to summarize.
Under our enterprise agreement with OpenAI, OpenAI does not use submitted content to train its general-purpose models and retains the content only briefly for abuse-monitoring before deleting it. AI outputs are returned to your account and stored under your Enterprise Account.
You may avoid AI processing by simply not using the AI features.
5. Legal Bases for Processing
Under UAE PDPL and equivalent laws, we process your personal data on one or more of the following legal bases:
| Activity | Legal basis |
|---|---|
| Creating and operating your account, providing the Services as you have configured them | Performance of a contract with you (or, for Team Members, performance of our contract with your employer) |
| Processing payments and tax reporting | Performance of a contract, legal obligation |
| Sending service emails (welcome, billing, renewal, password reset, security alerts) | Performance of a contract, legitimate interest in providing a usable Service |
| Sending marketing emails about new features or offers | Consent (you can opt out at any time using the unsubscribe link or in account settings) |
| Security monitoring, fraud prevention, and abuse detection (login throttling, anomaly detection) | Legitimate interest in protecting the Services and our users |
| AI-feature processing (when you use the feature) | Performance of a contract (you requested the feature) |
| Storing integration tokens (Zoho, Entra ID) | Consent (you authorized the integration) |
| Visitor analytics on public Connect profiles | Legitimate interest of the profile owner in understanding their audience; data is limited and shown only to that owner |
| Visitor analytics on public campaign landing pages | Legitimate interest of the Enterprise Account in measuring campaign performance; data is limited and shown only to the campaign's team |
| Compliance with UAE law (audit logs, retaining transaction records) | Legal obligation |
Where consent is the basis, you can withdraw it at any time, but doing so does not affect processing already carried out, and may mean a feature stops working.
6. How We Use Personal Data
We use the personal data described above for the following purposes:
- Provide the Services — create and operate your account, store your content, deliver the features you use, provide customer support.
- Bill you and manage subscriptions — process payments, send invoices and receipts, manage upgrades, downgrades, renewals, and cancellations.
- Communicate with you — send service emails (welcome, billing, security alerts, deletion reminders, etc.), respond to support requests, and (with your consent) send marketing.
- Operate and improve the Services — diagnose technical issues, monitor performance, prevent abuse, and develop new features.
- Enforce our agreements and protect rights — comply with our Terms of Service, enforce our policies, defend ourselves against legal claims, and protect the rights, safety, and property of Kardania and others.
- Comply with law — meet our tax, audit, anti-money-laundering, and other regulatory obligations.
We do not:
- sell your personal data to anyone;
- use your User Content to train our own machine-learning models;
- use the content of your communications with customers for advertising;
- share your personal data with third parties for their own marketing.
7. Sharing Personal Data with Third Parties — Subprocessors
We use a small set of carefully vetted third-party service providers ("subprocessors") to operate the Services. These providers process personal data only as instructed by us, only for the purposes listed below, and under contractual obligations consistent with this Policy.
| Subprocessor | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Infrastructure hosting (compute, storage, database), Key Management Service for encryption, Simple Email Service for transactional email, Secrets Manager for runtime configuration secrets, S3 for backups | Frankfurt, Ireland (EU regions) |
| Stripe, Inc. | Payment processing for Loop subscriptions, card tokenization, invoice generation, payment-retry logic | Global (Stripe processes EU data in the EU) |
| OpenAI, L.L.C. | AI processing for Business Card Scan and AI Insights | United States |
| Cloudflare, Inc. | Content-delivery network, DDoS protection, DNS, and bot-detection (CAPTCHA) at our public endpoints | Global edge network |
| Apple Inc. | App Store distribution of the Mobile App, in-app-purchase processing for Connect Premium, App Store Server Notifications for subscription lifecycle events | Global |
| Google LLC | Google Play distribution of the Mobile App, in-app-purchase processing for Connect Premium, Real-Time Developer Notifications for subscription lifecycle events, Sign in with Google | Global |
| Microsoft Corporation | Microsoft Entra ID single sign-on (only if you choose to integrate Entra in Loop) | Global (Microsoft offers EU data residency) |
| Zoho Corporation | Zoho CRM integration (only if you choose to enable it) | Global (region depends on your Zoho account) |
If we add a new subprocessor, we will update this list, and where required by UAE PDPL we will notify Account Owners with at least 30 days' advance notice.
Other limited disclosures
We may also disclose personal data:
- Within your Enterprise Account — your content and activity are visible to other users of the same Enterprise Account in accordance with the role-based access controls configured by your Account Admin.
- To law enforcement and government authorities — when required by valid legal process or court order from a jurisdiction we operate in, and when we believe in good faith that disclosure is necessary to comply with the law, to protect against fraud, or to protect the safety of our users or the public. We will challenge requests we consider overbroad or unlawful.
- In connection with a business transaction — if Kardania is involved in a merger, acquisition, asset sale, or bankruptcy, your personal data may be transferred to the successor entity, subject to the same protections as in this Policy.
- With your consent — for any other purpose disclosed to you at the time we ask for your consent.
IP geolocation data
To show account owners the approximate country and city of visitors to their public Connect pages, we estimate location from the visitor's IP address using a locally-hosted copy of the MaxMind GeoLite2 database. These lookups run entirely on our own servers — no visitor IP address or other personal data is sent to MaxMind. The estimate is approximate (city-level at best) and is not used to identify individuals.
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
8. International Transfers of Personal Data
Some of our subprocessors process personal data outside the UAE, including in the European Union, the United Kingdom, the United States, and other jurisdictions. When personal data is transferred internationally, we rely on appropriate legal mechanisms to protect it, including:
- the adequacy decisions issued by the UAE Data Office where available,
- Standard Contractual Clauses approved by the UAE Data Office or the European Commission (where the receiving party processes EU-resident data),
- the receiving party's certification under recognized frameworks (such as the EU-US Data Privacy Framework, where applicable),
- explicit consent from you for specific transfers, where required.
By using the Services, you understand that your personal data may be processed outside the UAE in accordance with this Policy.
9. Data Retention
We retain personal data only for as long as we need it to provide the Services, to comply with our legal obligations, and to resolve disputes. Specific retention rules:
| Data category | Retention |
|---|---|
| Active account data (profile, content, integrations) | While the account is active |
| Cancelled / unpaid Loop accounts (locked) | Until the Account Owner deletes the account or 12 months of continuous lockout, whichever is sooner |
| Deleted accounts | Cooldown for 14 days, then hard-deleted; after hard-deletion only a minimal audit record remains (see below) |
| Data export ZIP archives | The download link is valid for 7 days; after expiry, the file is permanently deleted from our storage |
| Connect content archived on plan downgrade (profiles, contacts, connectors over the free-tier limit) | Archived for 30 days, then permanently deleted; restored automatically if you re-subscribe within the window |
| Refresh tokens (session credentials) | Valid for 30 days; expired tokens are kept for 7 days for forensic purposes, then deleted |
| API request and performance logs | 30 days |
| Email-delivery logs (open/bounce/complaint events from SES) | 90 days |
| Audit logs of significant administrative actions | Indefinitely, for legal-compliance and dispute-resolution reasons (these logs do not contain message content or customer-record content) |
| Application-error reports (with PII hashed) | 90 days |
| Billing records (invoices, payment history) | At least 5 years to meet UAE tax and accounting requirements |
| Marketing-website server logs | 30 days |
If you delete your account, the hard-deletion process at the end of the 14-day cooldown removes your data from our active systems. Backups may retain a copy for up to 30 additional days, after which they are rotated out. Audit-log entries that mention your account survive deletion (for the reasons above), but they reference your account by identifier and do not contain User Content.
10. How We Protect Personal Data
We apply technical and organizational security measures aligned with industry good practice, including:
In transit
- All connections to the Services use HTTPS with TLS 1.2 or later.
- HTTP Strict Transport Security (HSTS) is enabled with a long max-age.
At rest
- Customer integration secrets (Zoho tokens, Entra credentials) are encrypted with a per-tenant Data Encryption Key, which is itself wrapped by an AWS Key Management Service ("KMS") Customer Managed Key (envelope encryption).
- Passwords are stored only as one-way BCrypt hashes; we do not have access to the plaintext.
Application-level
- Strong content-security-policy headers, HSTS, X-Frame-Options, and other browser-protection headers are enforced on all our endpoints.
- We rate-limit authentication endpoints, scrub personal identifiers (email, phone) from server logs by hashing them, and apply least-privilege access controls to our infrastructure.
- Container hardening: backend services run as a non-privileged user with a read-only filesystem, dropped capabilities, and resource limits.
- Refresh tokens are rotated on every use, with reuse detection that immediately revokes the whole session family on tampering.
Operationally
- Production systems are accessed through SSH-key authentication; passwords are not permitted.
- Runtime secrets (database credentials, API keys, signing keys) live in AWS Secrets Manager and are hydrated to a memory-only tmpfs at boot; they never touch disk on application servers.
- Production data is backed up multiple times per day, with periodic restore drills.
No security system is impenetrable. We work hard to protect your data, but we cannot guarantee it will never be compromised. If a personal-data breach affecting your rights occurs, we will notify the UAE Data Office and affected users in accordance with applicable law (see Section 14).
11. Cookies and Similar Technologies
We use only the minimum cookies and similar technologies needed to operate the Services. We do not use third-party analytics cookies, advertising cookies, or cross-site tracking cookies.
| Cookie / Token | Purpose | Duration |
|---|---|---|
__Host-loop_auth | Loop authentication (short-lived access token, http-only, secure) | 60 minutes |
__Host-loop_refresh | Loop session refresh (http-only, secure, scoped to /api/auth) | Up to 30 days (or session-only if "Remember Me" is unchecked) |
__Host-loopadmin_auth | Admin-panel authentication | 60 minutes |
__Host-loopadmin_refresh | Admin-panel session refresh | 30 days |
| Cloudflare bot-protection tokens | DDoS protection and CAPTCHA verification at public endpoints | Short-lived per Cloudflare's behavior |
Cookies marked "http-only" cannot be read by JavaScript in your browser, providing protection against cross-site scripting attacks.
On the Mobile App, similar functionality is provided by secure on-device token storage rather than cookies.
You can clear cookies in your browser at any time. Clearing the authentication cookies will sign you out of the Services.
12. Your Rights Over Your Personal Data
Under UAE PDPL and equivalent laws, you have several rights over the personal data we hold about you. These rights are:
12.1 Right of access
You can ask what personal data we hold about you and how we use it. Much of this is visible in the application itself (your profile, your settings, your subscription status, the audit log of your own actions). For a comprehensive view, request a data export (see below).
12.2 Right of rectification
You can correct or update inaccurate or incomplete personal data. Most fields are editable directly in the application's settings. For fields you cannot edit yourself (such as email address for some authentication providers), contact [email protected].
12.3 Right of erasure (deletion)
You can request deletion of your account at any time. The Account Owner of an Enterprise Account can initiate deletion from the "Delete Account" page. Individual users on Connect can delete their account from their Mobile App settings. After a 14-day cooldown (during which you can change your mind), all your personal data is permanently deleted. See our Terms of Service for the full deletion process.
Note: data we are required to retain by law (such as billing records for tax purposes) is kept for the required period and then deleted.
12.4 Right to data portability
You can request a copy of the personal data you have given us in a structured, commonly-used, machine-readable format. The Account Owner of an Enterprise Account can request a data export from the "Delete Account" page or by emailing [email protected]. We provide the export as a ZIP archive of CSV files plus a structured JSON summary, delivered via a download link valid for 7 days.
12.5 Right to restrict processing
You can ask us to limit how we use your personal data in certain circumstances — for example, if you believe the data is inaccurate or if you have objected to processing (see below). Email [email protected].
12.6 Right to object
You can object to our processing of your personal data where it is based on legitimate interest (for example, security monitoring). Where the objection is well-founded, we will stop or limit the processing.
12.7 Right to withdraw consent
Where we process data based on your consent (such as for marketing emails or integrations you authorized), you can withdraw that consent at any time:
- Marketing emails: click the unsubscribe link in any marketing message, or adjust your preferences in account settings.
- Integrations (Zoho, Entra ID): revoke the integration from the Integrations area in Loop. We will delete the stored credentials.
- AI features: simply stop using them.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal, and may mean a feature no longer works for you.
12.8 Right not to be subject to automated decisions
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. The AI features provide informational suggestions, not automated decisions.
12.9 How to exercise your rights
To exercise any of the above rights, email [email protected] from the email address associated with your account. We will respond within 30 days (extendable to 60 days where the request is complex), and we may ask you to verify your identity before fulfilling the request.
If we cannot fulfill a request (for example because the data is no longer held, or because fulfillment would compromise the rights of others), we will explain why.
12.10 Right to lodge a complaint
If you believe we have not handled your personal data in accordance with the law, you have the right to file a complaint with the UAE Data Office, the supervisory authority for UAE PDPL.
We would appreciate the chance to address your concern directly before you do — please contact [email protected] first.
13. Children's Privacy
The Services are not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, please contact [email protected] and we will take steps to delete the data.
14. Personal Data Breach Notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights, we will:
- notify the UAE Data Office without undue delay, and where feasible, within 72 hours of becoming aware of the breach;
- notify you directly without undue delay where the breach is likely to result in a high risk to your rights.
The notification will describe (to the extent known) the nature of the breach, the categories of data affected, the likely consequences, and the measures we have taken or propose to take.
We maintain an internal incident-response process to ensure rapid containment, investigation, and notification.
15. Marketing Communications
If you opt in to receive marketing emails, we may send you product updates, feature announcements, and similar communications. Every marketing email contains an "Unsubscribe" link that lets you opt out with one click. You can also turn off marketing in your account settings.
We do not share your email address with third parties for their own marketing.
We may send transactional and service emails (account confirmations, password resets, billing notices, security alerts, deletion reminders, etc.) regardless of your marketing preferences, because they are necessary for the operation of your account.
16. Third-Party Links
The Services may contain links to third-party websites or applications. We are not responsible for the content, privacy practices, or operation of those third parties. We encourage you to review the privacy policies of any third-party site you visit through a link from the Services.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our service offerings, or applicable law. When we update it:
- We will revise the "Last updated" date at the top of this document.
- For material changes — those that significantly affect how we process your personal data — we will notify Account Owners and Account Admins by email at least 30 days before the changes take effect, where reasonably practicable.
- For non-material changes (clarifications, new subprocessors of the same category, fixing typos), we may make them without prior notice.
- Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
We maintain prior versions of this Policy internally and will provide them on reasonable request.
18. Specific Notes for UAE Residents
This Policy is designed to be consistent with the requirements of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) ("UAE PDPL") and its implementing regulations.
For UAE residents, references in this Policy to "personal data," "data controller," "data processor," "processing," and similar terms have the meanings given in UAE PDPL. References to "lawful bases" and the list of rights in Section 12 are aligned with the rights granted by UAE PDPL.
The supervisory authority for UAE PDPL is the UAE Data Office.
19. Specific Notes for Non-UAE Residents
If you are located outside the UAE and use the Services, your personal data will be transferred to and processed in the UAE and the locations of our subprocessors listed in Section 7. By using the Services, you understand and consent to this transfer.
For residents of the European Union and the United Kingdom, we rely on appropriate safeguards (typically Standard Contractual Clauses) for transfers out of the EU/UK. Email [email protected] for the specific safeguards applicable to your data.
20. Contact
For any privacy-related question, concern, or request:
Kardania (FZC)
Email: [email protected]
We aim to respond to all privacy-related inquiries within 5 business days, and to substantive data-subject requests within the timeline set by applicable law (typically 30 days).
Thank you for trusting Kardania with your personal data. We take that trust seriously.