Privacy Policy

Last updated 30 September 2026

This policy explains what personal data OutreachAuto processes when you visit outreachauto.com, run the homepage demo or use the service, why we process it, who receives it and which rights you have.

Who is responsible for your data

The controller of personal data described in this policy is the operator of outreachauto.com, whose company details are shown in the image below. You can reach us about any privacy matter at [email protected].

Company details
Company details

What data we collect

We collect only what the site and the service need to work, to stay secure and to bill you correctly.

  • Account data: your name, business email address, password hash, workspace name, role and plan.
  • Billing data: billing name, billing address, tax number where you provide one, plan, invoices and payment status. Full card numbers are handled by the payment processor and never stored by OutreachAuto.
  • Demo inputs: the website address, the offer description and the ideal customer description you enter on the homepage, plus the output generated from them.
  • Usage data: pages and features you use, timestamps, IP address, browser type, device type and error logs.
  • Support data: the content of messages you send to [email protected].
  • Connected inbox data: when you connect your own inboxes, the connection settings and authorisation tokens needed to send and read campaign mail on your behalf.

Cookies

OutreachAuto uses only cookies that are strictly necessary: a session cookie that keeps you logged in, a security token that protects forms against cross site request forgery, and a cookie that remembers your consent choices. We do not use advertising cookies. Because these cookies are necessary for the service, they do not require consent, and they expire when your session ends or shortly after.

Creating and running your account and workspaces

Data
Account data, connected inbox data
Legal basis under GDPR
Performance of a contract, Article 6(1)(b)

Running the homepage demo and showing your result

Data
Demo inputs
Legal basis under GDPR
Performance of a contract at your request, Article 6(1)(b)

Billing, invoices and tax records

Data
Billing data
Legal basis under GDPR
Legal obligation, Article 6(1)(c), and contract

Security, fraud and abuse prevention

Data
Usage data
Legal basis under GDPR
Legitimate interest in protecting the service, Article 6(1)(f)

Improving features and fixing errors

Data
Usage data in aggregated form
Legal basis under GDPR
Legitimate interest, Article 6(1)(f)

Transactional emails such as sign-in codes and receipts

Data
Account data
Legal basis under GDPR
Performance of a contract, Article 6(1)(b)

Answering support requests

Data
Support data
Legal basis under GDPR
Contract or legitimate interest, Article 6(1)(b) and (f)

We do not sell personal data and we do not use it for automated decisions that produce legal effects for you.

Your data versus your campaign data

For your account, billing and usage data, OutreachAuto acts as controller. For the prospect and contact data you import or build in the service, and for the content of your campaigns, you are the controller and OutreachAuto acts as your processor. That processing follows your instructions and the Data Processing Agreement. You are responsible for having a lawful basis to contact your prospects; see our cold email compliance page for how the product supports this.

Data about prospects

When you build a prospect list, OutreachAuto reads public company websites and public business signals and combines them with the contacts you import. It processes business contact data only, never special categories of data. Every campaign email carries an unsubscribe link and header, and an opt-out goes to one suppression list for the whole account. A prospect who wants their data removed can write to [email protected] and we pass the request to the responsible customer and delete it from the suppression process where the law allows.

Who receives your data

We share personal data only with service providers that help us run OutreachAuto, under written agreements that bind them to confidentiality and security. We name them by category.

  • A hosting provider in the European Union that stores the application and its databases.
  • An email delivery provider that sends transactional mail such as sign-in codes and receipts.
  • A payment processor that handles subscriptions, card payments and invoices.
  • An AI model provider that generates offer analysis, account briefs and email drafts from the inputs you give.
  • A network and security provider that protects the site against attacks and delivers it quickly.

We also disclose data where the law requires it, for example to a court or a tax authority.

International transfers

Some providers process data outside the European Economic Area. Where that happens, transfers are covered by the standard contractual clauses approved by the European Commission, or by an adequacy decision, together with additional safeguards such as encryption in transit and at rest. You can request a copy of the relevant safeguards at [email protected].

How long we keep data

  • Demo runs made without an account are kept for 7 days and then deleted.
  • Account and workspace data is kept while your subscription is active and deleted within 30 days after you close your account, unless you export it first.
  • Billing records are kept for the period required by tax and accounting law.
  • Security logs are kept for up to 12 months.
  • Suppression entries are kept as long as needed to honour the opt-out.

Your rights

Under GDPR you have the right to:

  • access the personal data we hold about you,
  • have inaccurate data rectified,
  • have your data erased,
  • restrict processing,
  • receive your data in a portable format,
  • object to processing based on legitimate interest,
  • withdraw consent at any time where processing is based on consent.

To use any of these rights, write to [email protected]. We answer within one month. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, work or where the alleged infringement took place.

How we protect data

Data is encrypted in transit and at rest, access is limited by roles, connected inbox tokens are stored encrypted, and administrative access is logged. Read more on the outbound data security page.

Changes to this policy

We update this policy when the service or the law changes. The date at the top shows the latest version. If a change matters to how we use your data, we tell account holders by email before it takes effect.

Contact

Questions about privacy go to [email protected]. You can also read our Terms of Service or use the contact page.

See pricing