Privacy Policy
What we collect, why, on what legal basis, and what you can do about it. Written to describe what this website actually does rather than every theoretical possibility.
1. Controller
The controller responsible for the processing of personal data in connection with this website is:
- Controller
- Loki Solutions CWD LLC
- Address
- SHAMS Business Center, Sharjah Media City Free Zone
P.O. Box 839, Sharjah, United Arab Emirates - Licence number
- 2538433
- office@lokipartner.com
- Telephone
- +971 58 544 2351
For any question about this policy or about your personal data, write to the email address above with "Data protection" in the subject line.
2. Scope and applicable law
This policy covers the website at lokipartner.com and direct communication with us by email, telephone or through the enquiry form.
We are established in the United Arab Emirates and process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Because we offer our services to businesses located in the European Union, the EU General Data Protection Regulation (GDPR) also applies to the relevant processing under its Article 3(2), and we apply GDPR standards to it. Where this policy refers to legal bases and rights, it refers to those under the GDPR.
Personal data that we process on behalf of a client as part of a delivery engagement is covered by section 8, not by the sections about this website.
3. When you visit this website
This website is hosted on Cloudflare Pages. When your browser requests a page, the hosting infrastructure automatically processes technical data that is necessary to deliver the page and to protect the service:
- the IP address of the requesting device
- date and time of the request
- the page or file requested and the amount of data transferred
- HTTP status code and request method
- the referring page, where your browser transmits one
- browser type and version, and operating system
Purpose: delivering the website, ensuring stability and availability, and detecting and defending against attacks and abuse.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is operating a functioning, secure website. We do not use this data to identify individual visitors and do not combine it with other data sources.
Retention: log and security data is retained only for as long as necessary for the purposes above, and is deleted or anonymised thereafter. Our hosting provider applies short, standard retention periods to this data.
4. Cookies, analytics and tracking
This website sets no cookies and uses no local or session storage for tracking purposes. It runs no web analytics — no Google Analytics, no comparable product, first-party or otherwise. It contains no advertising or remarketing pixels from Google, Meta, LinkedIn or any other platform. No content is embedded from third-party servers: fonts, styles, scripts and images are all served from our own domain.
Because no non-essential information is stored on or read from your device, no cookie consent banner is required and none is shown.
Cloudflare may set a strictly necessary security cookie in specific circumstances — for example if a request is challenged by its bot-protection systems. Where such a cookie is used, it serves exclusively to protect the website against automated abuse and is technically necessary for that purpose.
If we introduce analytics or advertising technologies in future, we will update this policy and, where required, obtain your consent before any such technology is loaded.
5. Enquiry form and contact by email or telephone
If you use the enquiry form, we process the information you enter: name, company, work email address, and optionally telephone number, topic, team size and the free-text description of your situation. Technical metadata about the submission — the page it came from and the time of submission — is transmitted with it.
If the form's server-side delivery endpoint is not configured, the form instead opens a pre-filled message in your own email application. In that case nothing is transmitted to us until you actively send the email yourself.
If you contact us directly by email or telephone, we process the contact details and the content of your message.
Purposes: responding to your enquiry, preparing and conducting an initial consultation, and — where a business relationship follows — taking pre-contractual steps and performing the contract.
Legal bases: Article 6(1)(b) GDPR for enquiries relating to a potential or existing contract; Article 6(1)(f) GDPR for general communication, based on our legitimate interest in responding to enquiries directed at us; and Article 6(1)(a) GDPR where you have separately given consent, for example for marketing communication. Consent can be withdrawn at any time with effect for the future.
Provision: providing your data is voluntary. Without at least a name and an email address, however, we cannot reply to you.
Retention: enquiry data is deleted once your request has been dealt with conclusively and no legal retention obligation applies. Correspondence connected to a contract is retained for the duration of the business relationship and for the applicable statutory retention periods thereafter, after which it is deleted.
6. Recipients and processors
We do not sell personal data and do not pass it to third parties for their own advertising purposes. Personal data is disclosed only to service providers who process it on our behalf under a data processing agreement, and only to the extent necessary. The categories of recipient relevant to this website are:
| Category | Purpose | Data involved |
|---|---|---|
| Hosting & CDN Cloudflare, Inc. | Delivering the website, TLS encryption, protection against attacks and abuse | Technical access and security data as described in section 3 |
| Email service | Receiving, sending and storing business correspondence | Contact details and message content |
| Form delivery & CRM | Where configured, routing an enquiry from the website into our own systems and documenting the resulting business contact | The details submitted in the enquiry form |
| Telephony | Inbound and outbound business calls | Telephone number and connection data |
| Professional advisers & authorities | Legal, tax and accounting obligations, or where disclosure is legally required | Only what is necessary in the individual case |
We can name the specific providers currently engaged for each of these categories on request.
7. International transfers
We are established in the United Arab Emirates, and our service providers may process data in the United States or in other countries outside the European Economic Area. The United Arab Emirates and the United States are not covered by a general EU adequacy decision within the meaning of Article 45 GDPR.
Where personal data of individuals in the European Economic Area is transferred to us or to our processors outside it, we rely on appropriate safeguards under Article 46 GDPR — in particular the European Commission's Standard Contractual Clauses, accompanied by a transfer impact assessment and, where indicated, supplementary technical and organisational measures. Where a specific processor is certified under the EU–US Data Privacy Framework, we may rely on that mechanism for transfers to that processor.
You may request a copy of the relevant safeguards from us using the contact details in section 1.
8. Data processed on behalf of clients
When we deliver a project — implementing a CRM, building automation, developing an AI system, or running acquisition campaigns — we may access personal data held in our client's systems, such as data about their customers, prospects, candidates or employees.
In that context our client is the controller and we act as a processor within the meaning of Article 28 GDPR. Such processing takes place exclusively on our client's documented instructions and under a written data processing agreement concluded before access is granted, which sets out the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, the technical and organisational measures, the rules on engaging sub-processors, and the arrangements for deletion or return at the end of the engagement.
Wherever possible we work inside our client's own systems and tenancies rather than creating separate copies of their data. If you are a customer, candidate or employee of one of our clients and wish to exercise your rights in relation to that data, please contact that company directly as the controller; we will support them in responding.
9. Automated decision-making
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you, within the meaning of Article 22 GDPR, in connection with this website or with enquiries submitted through it. We do not profile visitors to this website.
10. Your rights
Subject to the conditions in the GDPR, you have the following rights in relation to your personal data:
- Access (Article 15) — confirmation of whether we process data about you, and a copy of that data
- Rectification (Article 16) — correction of inaccurate data and completion of incomplete data
- Erasure (Article 17) — deletion where one of the grounds set out in the GDPR applies
- Restriction (Article 18) — restriction of processing in the circumstances provided for
- Data portability (Article 20) — receipt of the data you provided in a structured, commonly used, machine-readable format
- Objection (Article 21) — objection at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f). Where we process personal data for direct marketing, you may object at any time and without giving reasons, and we will stop that processing
- Withdrawal of consent (Article 7(3)) — where processing is based on consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of processing carried out beforehand
To exercise any of these rights, write to office@lokipartner.com. We respond without undue delay and in any event within one month of receipt, and we may ask for information reasonably necessary to confirm your identity before acting.
Right to lodge a complaint. If you are in the European Economic Area, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. In Germany, the competent authority is the data protection supervisory authority of the relevant federal state. Individuals in the United Arab Emirates may address the competent UAE authority.
11. Representative in the European Union
We have assessed our obligation to designate a representative in the European Union under Article 27 GDPR. Our processing of data relating to individuals in the European Union in connection with this website is occasional, limited to business contact details voluntarily provided in the course of business enquiries, does not involve special categories of data or data relating to criminal convictions on a large scale, and is unlikely to result in a risk to the rights and freedoms of natural persons — with the result that the exemption in Article 27(2)(a) GDPR applies. Should the nature or scale of our processing change, we will designate a representative and publish their details here.
12. Security
We apply appropriate technical and organisational measures under Article 32 GDPR to protect personal data against unauthorised access, loss and misuse. These include transport encryption via TLS for all traffic to this website, multi-factor authentication on all business systems, individually named accounts with least-privilege access rather than shared logins, credential management through a password manager, encryption of data at rest with our providers, and regular review of access rights. No transmission over the internet can be guaranteed completely secure, but we design our systems to minimise both the likelihood and the impact of a breach.
13. Children
Our services are directed exclusively at businesses. This website is not intended for children, and we do not knowingly collect personal data relating to children. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Changes to this policy
We update this policy when our processing changes or when legal requirements make it necessary. The version published here is always the current one, and the date of the last update is shown below. Where a change materially affects existing clients, we notify them directly.
15. Contact
For any question regarding this privacy policy or the processing of your personal data, contact us at office@lokipartner.com or by post at the address given in section 1. Company details are set out in the imprint.
Last updated: 4 August 2026