All policies

Legal

Privacy Policy

BEEVELOPE

PRIVACY POLICY

Effective Date: 5 September 2026

PART I

INTRODUCTION, SCOPE, DEFINITIONS AND APPLICABILITY

1. Introduction

1.1Welcome to the Privacy Policy (”Privacy Policy”) of BEEVELOPE (”Company”, “we”, “our”, or “us”).

We are committed to protecting the privacy, confidentiality and security of Personal Data entrusted to us by our Customers, Users, business partners and other individuals who interact with our AI-powered outbound sales automation platform, websites, mobile applications, application programming interfaces (APIs), integrations and related services (collectively, the “Platform”).

1.2This Privacy Policy explains how we collect, use, store, disclose, transfer, retain and otherwise process Personal Data when you access or use the Platform or otherwise interact with us.

1.3We recognise that privacy is a fundamental component of trust and are committed to processing Personal Data responsibly, transparently and in accordance with Applicable Privacy Laws.

2. Scope of this Privacy Policy

This Privacy Policy applies to the Processing of Personal Data relating to:

(a) visitors to our website;

(b) registered Users of the Platform;

(c) Customers;

(d) prospective Customers;

(e) authorised representatives of Customers;

(f) business contacts;

(g) subscribers to newsletters and communications;

(h) participants in demonstrations, webinars or events;

(i) individuals interacting with our support services;

(j) individuals whose Personal Data is Processed through the Platform by our Customers; and

(k) any other individual whose Personal Data is Processed in connection with the Services.

3. Applicability

This Privacy Policy applies whenever Personal Data is Processed by or on behalf of the Company in connection with the Services, regardless of the country from which the Platform is accessed.

Nothing contained herein limits any rights or obligations arising under mandatory Applicable Privacy Laws.

4. Relationship with Other Documents

This Privacy Policy should be read together with, and forms part of, the Company’s broader legal framework, including:

(a) Terms of Service;

(b) Cookie Policy;

(c) AI Services and Responsible AI Policy, etc.;

(d) any Enterprise Agreement or Order Form executed between the Company and the Customer.

Where the Company Processes Personal Data on behalf of a Customer as a Processor or Service Provider, the applicable Data Processing Agreement shall prevail in relation to such Processing to the extent of any inconsistency.

5. Privacy Principles

The Company endeavours to Process Personal Data in accordance with the following principles:

(a) lawfulness, fairness and transparency;

(b) purpose limitation;

(c) data minimisation;

(d) accuracy;

(e) storage limitation;

(f) integrity and confidentiality;

(g) accountability; and

(h) privacy by design and by default, where appropriate.

These principles shall be applied to the extent required under Applicable Privacy Laws.

6. Definitions

For the purposes of this Privacy Policy:

“Applicable Privacy Laws” means all laws, regulations and legally binding requirements relating to privacy, data protection or the Processing of Personal Data applicable to the Company or the Customer, including, where applicable, the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, the Digital Personal Data Protection Act, 2023 (India), the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other applicable privacy legislation.

“Customer” means any legal entity or individual subscribing to or using the Services.

“Personal Data” means any information relating to an identified or identifiable natural person, or any equivalent term such as “Personal Information” under Applicable Privacy Laws.

“Processing” means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, transmission, alignment, restriction, deletion or destruction.

“Data Subject” means an identified or identifiable individual whose Personal Data is Processed.

“User” means any individual authorised by a Customer to access or use the Platform.

“Services” means the Company’s software-as-a-service platform, AI-powered features, APIs, integrations, websites, applications and related services.

Capitalised terms not defined herein shall have the meanings assigned to them in the Terms of Service.

7. Roles of the Parties

Depending upon the nature of the Services provided:

(a) the Company may act as a Data Controller (or equivalent) where it determines the purposes and means of Processing Personal Data for its own business operations, such as account administration, billing, fraud prevention, security, legal compliance and customer relationship management; and

(b) the Company may act as a Data Processor, Service Provider or equivalent where it Processes Personal Data solely on behalf of and under the instructions of a Customer in connection with the Services.

The applicable role shall be determined based on the relevant Processing activity and Applicable Privacy Laws.

8. Commitment to Responsible Artificial Intelligence

The Platform incorporates artificial intelligence technologies to assist Users in creating content, automating workflows, analysing communications and improving business efficiency.

The Company is committed to the responsible deployment of AI technologies and seeks to ensure that AI-enabled Processing is conducted in accordance with Applicable Privacy Laws, appropriate governance measures and commercially reasonable safeguards.

AI-generated outputs should be reviewed by Users before being relied upon or communicated to third parties.

9. Acceptance of this Privacy Policy

By accessing or using the Platform, creating an Account, or otherwise interacting with the Company, you acknowledge that you have read and understood this Privacy Policy.

Where consent is required under Applicable Privacy Laws for specific Processing activities, such consent shall be obtained separately and may be withdrawn where permitted by law.

10. Contact Information

Questions, requests or concerns relating to this Privacy Policy or the Company’s Processing of Personal Data may be directed through the contact details published on the Platform or otherwise made available by the Company.

Where required by Applicable Privacy Laws, the Company may designate a Data Protection Officer, privacy representative or other authorised contact person, whose details shall be made available through the Platform or the Privacy Policy.

Part I establishes the legal foundation of the Privacy Policy. Part II should then move into “Categories of Personal Data We Collect and Sources of Collection,” explaining exactly what information the platform collects, from whom, and by what means. This structure is consistent with the expectations of GDPR, UK GDPR, DPDP Act, CCPA/CPRA and enterprise SaaS privacy notices.

Certainly. Below is Part II of your Global Privacy Policy, drafted specifically for your AI-powered outbound sales automation platform. This Part focuses on what Personal Data is collected, how it is collected, and the lawful basis for collection, while remaining consistent with GDPR, UK GDPR, India’s DPDP Act, CCPA/CPRA and other major privacy frameworks.

PART II

PERSONAL DATA WE COLLECT, SOURCES OF COLLECTION AND LAWFUL BASIS OF PROCESSING

11. PERSONAL DATA WE COLLECT

Depending on how you use Beevelope, we may collect and process the following categories of Personal Data:

11.1 Account and Authentication Information:

Your name, username, email address, password hash, account verification status, account status, last-login information and relevant account creation or modification timestamps.

11.2 Organisation and Profile Information:

Information relating to your organisation or business, including company name, business description, website, business address, telephone number, logo, brand colours and other brand or profile information that you choose to provide.

11.3 Contacts and CRM Information:

Information relating to contacts that you upload, import or otherwise process through the Platform, which may include names, email addresses, job titles, departments, seniority, company information, telephone numbers, LinkedIn or other professional/social profile URLs, location, time zone and other contact or enrichment information.

11.4 Email and Campaign Information:

Information relating to email campaigns and communications created, configured or processed through the Platform, including sender information, recipient information, campaign content, subject lines, sequences, follow-ups, delivery-related information, engagement information, replies and related campaign analytics.

11.5 AI-Generated and AI-Derived Information:

Where you use our AI-enabled features, we may process prompts, instructions, campaign or contact information submitted for AI processing, AI-generated outputs, and AI-derived or enrichment information relating to contacts, including inferred roles, buying signals, scores and other sales-prioritisation information.

11.6 Uploaded Materials:

Materials that you upload to the Platform, including documents, logos, brand assets, presentation materials and other files, together with generated outputs such as decks or other content generated through the Services.

11.7 Integration and Authentication Information:

Where you connect third-party services, we may process the information and credentials necessary to establish and maintain the requested integration, including applicable API credentials, tokens and account identifiers. The scope of such information depends upon the third-party service and the permissions you grant.

11.8 Email Account Information:

Where you connect your own SMTP/IMAP mailbox, we may process the relevant sender account information, credentials or tokens, email metadata and inbound replies necessary to provide the requested functionality. Credentials and secrets are stored using applicable encryption controls.

11.9 Payment and Subscription Information:

Payment processing is provided through Stripe. Email Marketer does not store payment-card numbers, PANs or equivalent card credentials. We may receive and retain limited payment-related information such as Stripe customer identifiers, subscription identifiers, price or plan identifiers, billing-period information and credit-transaction information.

11.10 Usage, Technical and Security Information:

We may process information relating to your use of the Platform, including IP address, device or browser information, timestamps, authentication and session information, usage information, security-related information and technical logs necessary to operate, secure and troubleshoot the Services.

11.11 Customer Support Information:

Support Information is collected when users or customers contact us for assistance. Support is handled via a monitored email inbox (support@beevelope.com); we do not currently use a third-party helpdesk/ticketing platform (no Zendesk / Intercom / Freshdesk). The mailbox is hosted on Microsoft 365 which is the relevant subprocessor for support communications. Support records typically include the individual's name, email address and the content of their query/correspondence.

11.12 Information from Third-Party Integrations:

Where you voluntarily connect third-party services, information may be received from those services in accordance with the permissions and authorisations you provide. The relevant third-party provider may separately process such information under its own terms and privacy policy.

11.13 Information You Choose to Provide:

We may process any other information that you voluntarily submit to or through the Platform where such processing is necessary to provide the Services or respond to your requests.

11.14 Information We Do Not Intentionally Collect:

We do not intentionally require or seek to collect sensitive or special-category Personal Data through the Platform. You should not submit such information unless the relevant functionality and applicable legal and contractual requirements expressly permit its Processing.

11.15 Accuracy of Information:

You are responsible for ensuring that Personal Data and other information submitted through your account is accurate, lawful and appropriate for use with the Services.

11.16 Categories of Personal Data We Collect

Depending upon your interaction with the Platform, the Company may collect, generate or otherwise Process the following categories of Personal Data.

11.16.1 Account and Registration Information

We may collect:

(a) full name;

(b) business email address;

(c) telephone number;

(d) company name;

(e) job title;

(f) business address;

(g) username;

(h) password or authentication credentials (stored in encrypted or hashed form where applicable);

(i) profile photograph, where voluntarily provided; and

(j) other account registration information.

11.16.2 Organisation Information

Where the Platform is used by businesses or enterprises, we may Process:

(a) organisation name;

(b) registered address;

(c) tax identification details;

(d) billing contact information;

(e) authorised representatives;

(f) subscription information; and

(g) account administrators.

11.16.3 Contact and CRM Data

Where uploaded or synchronised by the Customer, the Platform may Process:

(a) names of business contacts;

(b) business email addresses;

(c) business telephone numbers;

(d) company names;

(e) job titles;

(f) CRM records;

(g) customer notes;

(h) communication preferences; and

(i) other contact information provided by the Customer.

The Customer remains responsible for ensuring that such information has been lawfully collected and may lawfully be Processed through the Platform.

11.16.4 Email Communications

Where Customers connect email accounts to the Platform, the Company may Process:

(a) sender information;

(b) recipient information;

(c) subject lines;

(d) email content;

(e) timestamps;

(f) attachments;

(g) conversation history;

(h) delivery status;

(i) reply status; and

(j) metadata associated with email communications.

Such Processing is undertaken solely to provide the Services requested by the Customer and in accordance with the Terms of Service and Data Processing Agreement.

11.16.5 AI Inputs

The Platform may Process prompts, instructions, uploaded documents, campaign information, templates, messages and other information submitted by Users to AI-powered features.

11.16.6 AI Outputs

The Platform may generate and temporarily store AI-generated content, including:

(a) email drafts;

(b) summaries;

(c) recommendations;

(d) workflow suggestions;

(e) campaign content;

(f) classifications;

(g) analytics; and

(h) other AI-generated outputs.

11.16.7 Usage Information

We may automatically collect information regarding the use of the Platform, including:

(a) login history;

(b) session duration;

(c) pages viewed;

(d) features accessed;

(e) workflow activity;

(f) campaign statistics;

(g) AI usage metrics;

(h) API usage;

(i) interaction logs; and

(j) other operational information.

11.16.8 Device and Technical Information

We may collect technical information such as:

(a) IP address;

(b) browser type;

(c) browser version;

(d) operating system;

(e) device identifiers;

(f) language settings;

(g) time zone;

(h) network information;

(i) log files; and

(j) diagnostic information.

11.16.9 Cookies and Similar Technologies

The Marketing Website may use:

(a) cookies;

(b) session cookies;

(c) persistent cookies;

(d) pixels;

(e) local storage;

(f) web beacons; and

(g) similar technologies,

as further described in the Company’s Cookie Policy.

11.16.10 Customer Support Information

Where Users contact our support team, we may Process:

(a) support requests;

(b) correspondence;

(c) screenshots;

(d) diagnostic files;

(e) recordings of support sessions where applicable; and

(f) information voluntarily provided during support interactions.

11.16.11 Marketing Information

Not currently applicable but will update for the future marketing activity and the same will be notified as at present do not presently operate any newsletter, marketing-email, webinar or event programme, and we use no external marketing tools.

12. Sources of Personal Data

The Company may obtain Personal Data from one or more of the following sources:

(a) directly from the Customer;

(b) directly from Users;

(c) through authorised representatives;

(d) through Customer-uploaded information;

(e) through integrated third-party applications;

(f) through APIs;

(g) from connected email providers;

(h) from CRM integrations;

(i) through cookies and similar technologies;

(j) through publicly available business information where permitted by Applicable Laws;

(k) through Customer support interactions; and

(l) from service providers acting on the Company’s behalf.

13. Lawful Basis for Processing

Where required under Applicable Privacy Laws, the Company Processes Personal Data on one or more of the following lawful bases:

(a) performance of a contract;

(b) compliance with legal obligations;

(c) legitimate business interests;

(d) consent, where required;

(e) protection of vital interests where applicable; and

(f) any other lawful basis recognized under Applicable Privacy Laws.

The lawful basis applicable to a particular Processing activity will depend upon the nature of the Services, the relationship with the individual and the applicable legal framework.

14. Sensitive Personal Data

The Platform is designed primarily for business communications and is not intended to collect or Process Sensitive Personal Data unless expressly required for a specific lawful purpose.

Customers and Users should not upload or otherwise submit Sensitive Personal Data through the Platform unless:

(a) such Processing is necessary for the intended Services;

(b) all legally required notices and consents have been obtained; and

(c) such Processing complies with Applicable Privacy Laws.

Where Sensitive Personal Data is Processed, the Company shall apply appropriate safeguards consistent with Applicable Privacy Laws.

15. Children’s Data

The Services are intended for use by businesses and individuals who have reached the minimum age required to enter into legally binding agreements under Applicable Laws.

The Company does not knowingly collect Personal Data directly from children through the Platform.

If the Company becomes aware that Personal Data relating to a child has been collected in violation of Applicable Laws, it shall take commercially reasonable steps to delete or otherwise address such information in accordance with Applicable Privacy Laws.

16. Accuracy of Personal Data

The Company relies upon Customers and Users to provide accurate, complete and up-to-date information.

Customers remain responsible for ensuring the accuracy and lawfulness of Personal Data uploaded to or synchronised with the Platform.

17. Data Minimisation

The Company endeavours to collect and Process only such Personal Data as is reasonably necessary to provide the Services, comply with Applicable Laws, protect the security of the Platform and fulfil legitimate business purposes.

PART III

HOW WE USE PERSONAL DATA (PURPOSES OF PROCESSING)

18. General Principles

18.1The Company Processes Personal Data only where such Processing is necessary for the provision of the Services, compliance with Applicable Laws, protection of legitimate business interests, performance of contractual obligations, or where otherwise permitted under Applicable Privacy Laws.

18.2The Company shall Process Personal Data solely for legitimate, specified and lawful purposes and shall not Process Personal Data in a manner incompatible with those purposes unless otherwise authorised by Applicable Laws or the Data Subject.

19. Provision of Services

The Company may Process Personal Data for the purpose of:

(a) creating and administering User Accounts;

(b) authenticating Users;

(c) providing access to the Platform;

(d) delivering subscribed Services;

(e) enabling workspace administration;

(f) facilitating collaboration among authorised Users;

(g) maintaining Customer configurations; and

(h) fulfilling contractual obligations under the Terms of Service.

20. AI-Powered Features

The Company may Process Personal Data to provide AI-powered functionality, including:

(a) generating email drafts;

(b) preparing campaign content;

(c) creating personalised communication suggestions;

(d) analysing campaign performance;

(e) generating summaries;

(f) assisting workflow automation;

(g) producing business insights;

(h) generating recommendations; and

(i) supporting other AI-enabled Services offered through the Platform.

AI-generated outputs are intended to assist Users and should be reviewed before being relied upon for business, legal or commercial decisions.

21. Communication Services

Personal Data may be Processed to:

(a) send transactional communications;

(b) deliver service notifications;

(c) facilitate Customer communications;

(d) support email integrations;

(e) manage outbound campaigns initiated by the Customer;

(f) respond to enquiries;

(g) provide technical support; and

(h) communicate important updates regarding the Services.

22. Customer Support

The Company may Process Personal Data to:

(a) investigate reported issues;

(b) respond to support requests;

(c) diagnose technical problems;

(d) provide troubleshooting assistance;

(e) improve customer experience; and

(f) maintain records of support interactions.

23. Platform Administration

Personal Data may be Processed to:

(a) administer subscriptions;

(b) process billing and payments;

(c) manage invoices;

(d) verify account ownership;

(e) administer user permissions;

(f) maintain account security; and

(g) manage contractual relationships.

24. Analytics and Service Improvement

The Company may Process Personal Data to:

(a) analyse Platform usage;

(b) understand feature adoption;

(c) improve user experience;

(d) optimise workflows;

(e) enhance AI performance;

(f) identify usability issues;

(g) measure operational performance; and

(h) develop new products and services.

Where reasonably practicable, the Company may use aggregated, anonymised or de-identified information for analytics and research purposes.

25. Security and Fraud Prevention

The Company may Process Personal Data to:

(a) detect fraudulent activities;

(b) investigate suspected misuse of the Platform;

(c) prevent unauthorised access;

(d) protect Customer Accounts;

(e) monitor system security;

(f) identify cybersecurity threats;

(g) investigate Security Incidents; and

(h) maintain the integrity, confidentiality and availability of the Services.

26. Compliance with Legal Obligations

The Company may Process Personal Data where necessary to:

(a) comply with Applicable Laws;

(b) respond to lawful requests from governmental authorities;

(c) comply with judicial orders;

(d) satisfy regulatory obligations;

(e) establish, exercise or defend legal claims;

(f) enforce contractual rights; and

(g) comply with tax, accounting and financial reporting obligations.

27. Marketing and Business Communications

Subject to Applicable Privacy Laws, the Company may Process Personal Data to:

(a) send newsletters;

(b) announce new features;

(c) provide product updates;

(d) invite Users to webinars or events;

(e) distribute educational materials;

(f) conduct surveys; and

(g) communicate promotional offers.

Where required by Applicable Privacy Laws, such communications shall be sent only with the individual’s consent or another lawful basis.

Recipients may opt out of marketing communications at any time using the unsubscribe mechanism provided or by contacting the Company.

28. Research and Development

The Company may Process Personal Data for research, testing and product development purposes to:

(a) improve existing Services;

(b) develop new functionality;

(c) enhance Platform performance;

(d) improve AI capabilities;

(e) evaluate system reliability; and

(f) conduct internal business analysis.

Where feasible and appropriate, such activities shall utilise aggregated or de-identified information.

29. Business Operations

Personal Data may be Processed for legitimate business operations, including:

(a) financial management;

(b) internal reporting;

(c) auditing;

(d) corporate governance;

(e) mergers, acquisitions or restructuring;

(f) insurance purposes;

(g) risk management; and

(h) business continuity planning.

Where Personal Data is transferred as part of a corporate transaction, the Company shall take reasonable steps to ensure continued protection of such information in accordance with Applicable Privacy Laws.

30. Enforcement of Rights

The Company may Process Personal Data where necessary to:

(a) enforce the Terms of Service;

(b) investigate breaches of contractual obligations;

(c) protect the Company’s legal rights;

(d) protect the rights of Customers and Users;

(e) resolve disputes;

(f) recover unpaid amounts; and

(g) prevent unlawful or harmful activities.

31. Automated Processing

Certain Services may utilise automated technologies, including artificial intelligence and machine learning, to facilitate business workflows, improve efficiency and generate recommendations.

Where Applicable Privacy Laws grant individuals rights relating to automated decision-making, the Company shall provide such rights in accordance with those laws.

The Platform is designed to support business decision-making and does not intentionally make solely automated decisions producing legal or similarly significant effects on individuals unless expressly disclosed and permitted by Applicable Laws.

32. Purpose Limitation

The Company shall not Process Personal Data for purposes materially different from those described in this Privacy Policy unless:

(a) the individual has been informed where required;

(b) an appropriate lawful basis exists;

(c) the Processing is required by Applicable Laws; or

(d) another lawful basis under Applicable Privacy Laws permits such Processing.

33. Changes in Processing Purposes

Where the Company intends to Process Personal Data for a new purpose that is materially different from the purposes described in this Privacy Policy, the Company shall update this Privacy Policy or otherwise provide appropriate notice where required by Applicable Privacy Laws.

PART IV

SHARING, DISCLOSURE AND INTERNATIONAL TRANSFERS OF PERSONAL DATA

34. General Principles

34.1The Company does not sell Personal Data except where such activity is expressly disclosed, authorised by the applicable Customer or Data Subject, or otherwise permitted under Applicable Privacy Laws.

34.2The Company shares Personal Data only where necessary for providing the Services, complying with Applicable Laws, protecting legitimate business interests or with the consent of the Data Subject where required.

34.3All disclosures of Personal Data shall be subject to appropriate contractual, technical and organisational safeguards consistent with Applicable Privacy Laws.

35. Sharing Within the Company

The Company may share Personal Data with its Affiliates, subsidiaries or entities under common control where reasonably necessary for:

(a) account administration;

(b) customer relationship management;

(c) billing and finance;

(d) customer support;

(e) information security;

(f) legal compliance;

(g) internal auditing;

(h) product development; and

(i) other legitimate business operations.

Such entities shall Process Personal Data in accordance with this Privacy Policy and Applicable Privacy Laws.

36. Service Providers and Subprocessors

The Company may disclose Personal Data to carefully selected third-party service providers and authorised Subprocessors that assist in providing the Services.

Such providers may include those offering:

(a) cloud hosting;

(b) data storage;

(c) artificial intelligence services;

(d) email infrastructure;

(e) authentication and identity management;

(f) payment processing;

(g) customer support platforms;

(h) monitoring and logging services;

(i) analytics;

(j) security and fraud prevention;

(k) backup and disaster recovery;

(l) communication services; and

(m) other technology services reasonably necessary for the operation of the Platform.

The Company shall use commercially reasonable efforts to ensure that such providers are contractually bound to protect Personal Data in accordance with Applicable Privacy Laws.

37. Customer-Authorised Integrations

Where the Customer elects to connect the Platform with third-party applications or services, the Company may disclose Personal Data solely to facilitate the requested integration.

Such disclosures shall occur only:

(a) under the Customer’s instructions;

(b) in accordance with the Customer’s configuration; or

(c) as otherwise authorised by the Customer.

The Company is not responsible for the privacy practices of independent third-party services selected by the Customer.

38. Business Communications

Where necessary to provide the Services, the Platform may Process and transmit Personal Data through integrated communication providers, including email, messaging or collaboration services authorised by the Customer.

Such Processing is performed solely to facilitate communications initiated or approved by the Customer.

39. Legal and Regulatory Disclosures

The Company may disclose Personal Data where reasonably necessary to:

(a) comply with Applicable Laws;

(b) comply with judicial orders;

(c) comply with lawful governmental requests;

(d) comply with regulatory investigations;

(e) establish, exercise or defend legal claims;

(f) enforce the Terms of Service;

(g) investigate suspected unlawful activity;

(h) protect the safety, rights or property of the Company, Customers or third parties; or

(i) prevent fraud, cybercrime or other unlawful conduct.

Where legally permissible, the Company may notify the affected Customer before disclosing Personal Data in response to a compulsory legal request.

40. Corporate Transactions

In connection with any merger, acquisition, corporate restructuring, financing, sale of assets, insolvency proceeding or other business transaction, Personal Data may be disclosed to prospective or actual purchasers, investors, lenders, advisers or other participants in the transaction.

Any recipient shall be required to protect Personal Data in accordance with Applicable Privacy Laws and appropriate confidentiality obligations.

41. Professional Advisers

The Company may disclose Personal Data to its professional advisers where reasonably necessary, including:

(a) legal counsel;

(b) auditors;

(c) accountants;

(d) insurers;

(e) compliance consultants; and

(f) other professional advisers engaged to support the Company’s business operations.

Such disclosures shall be limited to the extent reasonably necessary for the relevant professional services.

42. Business Partners

Where the Customer requests or authorises participation in joint offerings, integrations or partner programmes, the Company may disclose relevant Personal Data to participating business partners solely for the purpose of providing the requested services.

Any such partner shall be responsible for its own processing activities in accordance with its applicable privacy obligations.

43. Aggregated and De-Identified Information

The Company may create, use and disclose aggregated, anonymised or de-identified information that does not reasonably identify any individual.

Such information may be used for:

(a) analytics;

(b) research;

(c) statistical reporting;

(d) product improvement;

(e) benchmarking;

(f) business intelligence; and

(g) other lawful business purposes.

Where information has been irreversibly anonymised, it shall no longer be treated as Personal Data under this Privacy Policy.

44. Where Your Data Is Stored And International Data Transfers

44.1 Cloud Infrastructure.

Email Marketer uses Microsoft Azure as its primary cloud infrastructure provider. Depending upon the functionality used, Customer Data may be stored and processed through Azure services including Azure App Service, Azure Static Web Apps, Azure Database for PostgreSQL and Azure Blob Storage.

44.2 Primary Hosting Region.

At launch, the Platform will operate using a single primary production region:

Primary Production Region: United States

The Company may change or expand the infrastructure locations used to provide, secure or maintain the Services, subject to applicable legal requirements and the Company’s contractual obligations.

44.3 Data Storage.

Customer Data may be stored in the Platform’s primary database and storage infrastructure, including Azure Database for PostgreSQL and Azure Blob Storage, as applicable to the Services. Uploaded materials, logos and generated decks may be stored in Azure Blob Storage.

44.4 International Processing.

Depending on the Services and integrations used, Customer Data may be processed outside the country in which you are located. In particular, certain AI-enabled functionality may involve processing through third-party AI providers, including OpenAI and Anthropic, where Company-controlled credentials are used.

44.5 AI Provider Locations.

The Company’s current production configuration may use OpenAI and Anthropic endpoints located in the United States. Accordingly, use of applicable AI functionality may involve transfer or processing of relevant Customer Data in the United States.

44.6 No Regional Data Residency at Launch.

Email Marketer does not currently offer customer-selectable regional data residency at launch. Customers should therefore not assume that Customer Data will remain exclusively within their country or geographic region.

44.7 Future Regional Residency.

The Company may introduce regional data-residency or geographically restricted hosting options in the future, including as part of Enterprise offerings. Availability, applicable regions and associated terms will be communicated separately where such functionality is introduced.

44.8 International Transfer Safeguards.

Where Personal Data is transferred internationally and Applicable Data Protection Laws require a lawful transfer mechanism, the Company shall implement an appropriate mechanism, which may include an adequacy decision, Standard Contractual Clauses, the UK International Data Transfer Addendum or another legally recognised transfer mechanism, as applicable.

44.9 Customer Responsibility for Third-Party Integrations.

Where you choose to connect third-party services using your own credentials or accounts, those third parties may independently process or transfer information in accordance with their own terms and privacy policies. The Company does not control the data-processing practices or geographic locations of such third parties.

44.10 Data Location Changes.

The Company may modify its hosting, storage or processing infrastructure from time to time for operational, security, scalability or service-continuity purposes. Where such changes materially affect applicable data-protection obligations, the Company will take such measures as are required by Applicable Data Protection Laws.

45. Data Residency

Depending upon the Services purchased and the applicable Subscription Plan, the Company may offer in future options regarding the geographic location in which certain Customer Data is hosted or stored, whereas at present the architecture is single region.

Any such commitments shall be governed by the applicable Enterprise Agreement or Order Form.

46. Public Information

The Company may publish or disclose information that has been made publicly available by the Customer or the Data Subject, provided that such use complies with Applicable Laws and does not exceed the scope of the original public disclosure.

47. No Sale or Sharing for Cross-Context Behavioural Advertising

Except where expressly disclosed and permitted by Applicable Privacy Laws, the Company does not sell Personal Data or share Personal Data for cross-context behavioural advertising as those terms may be defined under applicable privacy legislation.

Should the Company’s practices change in the future, this Privacy Policy shall be updated accordingly, and any rights afforded to individuals under Applicable Privacy Laws shall be respected.

48. Safeguards for Disclosures

Before disclosing Personal Data to third parties, the Company shall implement commercially reasonable safeguards, which may include:

(a) confidentiality agreements;

(b) data processing agreements;

(c) contractual privacy obligations;

(d) technical security measures;

(e) access controls;

(f) encryption where appropriate; and

(g) periodic review of service providers where commercially reasonable.

PART V

RETENTION, SECURITY, CONFIDENTIALITY AND PROTECTION OF PERSONAL DATA

49. Commitment to Protect Personal Data

49.1The Company is committed to maintaining the confidentiality, integrity, availability and resilience of Personal Data Processed in connection with the Services.

49.2The Company shall implement and maintain commercially reasonable administrative, technical and organisational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access or other unlawful Processing.

49.3The Company’s security programme shall be reviewed periodically and enhanced where reasonably necessary to address evolving cybersecurity threats, technological developments, regulatory requirements and industry best practices.

50. Information Security Measures

The Company maintains an information security programme appropriate to the nature, scope and complexity of the Services.

Such programme may include, where appropriate:

(a) encryption of Personal Data during transmission using industry-standard protocols;

(b) encryption of Personal Data at rest where commercially and technically appropriate;

(c) role-based access controls;

(d) multi-factor authentication for privileged administrative accounts where appropriate;

(e) secure authentication and identity management;

(f) network segmentation and firewall protection;

(g) vulnerability management and security patching;

(h) audit logging and security monitoring;

(i) secure software development practices;

(j) business continuity and disaster recovery procedures; and

(k) periodic review and improvement of security controls.

Nothing in this Privacy Policy shall be interpreted as guaranteeing absolute security, as no method of electronic transmission or storage can be entirely secure.

51. Confidentiality

51.1Access to Personal Data shall be restricted to personnel, contractors and authorised Subprocessors who require such access for legitimate business purposes or to perform contractual obligations.

51.2Individuals authorised to Process Personal Data shall be subject to appropriate confidentiality obligations and shall access Personal Data only to the extent necessary for the performance of their duties.

51.3The Company shall use commercially reasonable efforts to ensure that authorised Subprocessors are contractually required to maintain appropriate standards of confidentiality and data protection.

52. Privacy by Design and by Default

The Company endeavours, where appropriate and reasonably practicable, to incorporate privacy and data protection considerations into the design, development and operation of the Platform.

Such measures may include:

(a) data minimisation;

(b) least privilege access principles;

(c) appropriate retention controls;

(d) secure default configurations;

(e) privacy impact assessments where appropriate;

(f) periodic review of Processing activities; and

(g) implementation of technical safeguards proportionate to identified risks.

53. Data Retention

53.1The Company shall retain Personal Data only for so long as reasonably necessary to:

(a) provide the Services;

(b) fulfil contractual obligations;

(c) comply with Applicable Laws;

(d) resolve disputes;

(e) enforce legal rights;

(f) comply with lawful governmental requests; or

(g) satisfy legitimate business and operational requirements.

53.2Retention periods may vary depending upon:

(a) the nature of the Personal Data;

(b) the purpose of Processing;

(c) contractual obligations;

(d) legal and regulatory requirements;

(e) applicable limitation periods; and

(f) operational requirements.

54. Deletion and Anonymisation

Upon expiration of the applicable retention period, or upon lawful request where applicable, the Company shall, subject to Applicable Laws:

(a) securely delete Personal Data;

(b) return Personal Data to the Customer where contractually agreed;

(c) anonymise or de-identify Personal Data where appropriate; or

(d) retain Personal Data only where continued retention is required by Applicable Laws, regulatory obligations, fraud prevention, security purposes or the establishment, exercise or defence of legal claims.

Backup copies may continue to exist until deleted in accordance with the Company’s backup retention procedures.

55. Security Incident Management

The Company maintains procedures designed to detect, investigate, contain, mitigate and remediate Security Incidents affecting the Platform.

Where required by Applicable Laws or contractual obligations, the Company shall notify affected Customers of confirmed Security Incidents involving Customer Personal Data without undue delay.

Further details regarding incident management are contained in Schedule L – Security Incident Response and Vulnerability Disclosure Policy.

56. International Security Standards

The Company endeavours to maintain an information security programme aligned with recognised industry practices appropriate to the Services.

The Company may adopt internationally recognised security frameworks, standards or certifications from time to time where appropriate for its business operations.

Nothing contained herein shall constitute a representation that the Company maintains any specific certification unless expressly stated.

57. Customer Security Responsibilities

Customers and Users remain responsible for implementing appropriate security measures within their own organisations, including:

(a) protecting account credentials;

(b) enabling multi-factor authentication where available;

(c) maintaining secure endpoint devices;

(d) safeguarding API credentials and access tokens;

(e) restricting access to authorised Users;

(f) promptly reporting suspected Security Incidents; and

(g) ensuring that Personal Data uploaded to the Platform has been lawfully collected and may lawfully be Processed.

The Company shall not be responsible for Security Incidents primarily resulting from the Customer’s failure to implement reasonable security measures.

58. Continuous Improvement

The Company may modify or enhance its security measures, technologies, operational procedures and privacy safeguards from time to time to:

(a) improve the security of the Platform;

(b) respond to emerging cybersecurity threats;

(c) comply with Applicable Laws;

(d) implement technological advancements;

(e) improve operational resilience; and

(f) support new Services and Platform functionality.

Such improvements shall not materially diminish the overall level of protection afforded to Personal Data without a legitimate legal, operational or commercial justification.

59. Cross-Reference to Security Documentation

This Privacy Policy provides a general overview of the Company’s approach to protecting Personal Data and other security documents of the company may be referred for cross reference.

PART VI

PRIVACY RIGHTS OF DATA SUBJECTS

61. General Principles

61.1 The Company recognises that individuals may have certain rights regarding their Personal Data under Applicable Privacy Laws.

61.2 The availability, scope and manner of exercising such rights may vary depending upon:

(a) the jurisdiction of the Data Subject;

(b) the applicable privacy legislation;

(c) the Company’s role as Controller or Processor; and

(d) the nature of the Processing activity.

61.3Where the Company acts solely as a Processor on behalf of a Customer, requests relating to Customer-controlled Personal Data may be referred to the relevant Customer unless Applicable Laws require otherwise.

62. Right of Access

Where provided under Applicable Privacy Laws, Data Subjects may request confirmation as to whether the Company Processes their Personal Data.

Where such right exists, the Data Subject may also request access to:

(a) categories of Personal Data Processed;

(b) purposes of Processing;

(c) categories of recipients;

(d) retention periods;

(e) sources of Personal Data, where applicable;

(f) information regarding international transfers; and

(g) other information required by Applicable Privacy Laws.

63. Right to Rectification

Where permitted by Applicable Privacy Laws, a Data Subject may request correction or updating of inaccurate, incomplete or outdated Personal Data.

The Company may require reasonable verification before making requested corrections.

64. Right to Erasure

Subject to Applicable Privacy Laws, individuals may request deletion of Personal Data where:

(a) the information is no longer required for the purposes for which it was collected;

(b) consent has been withdrawn where Processing is based solely upon consent;

(c) Processing is unlawful;

(d) deletion is required by Applicable Laws; or

(e) another lawful ground for erasure exists.

The Company may refuse deletion where continued retention is required by law, necessary for legal claims, fraud prevention, security, contractual obligations or other legitimate purposes recognised under Applicable Privacy Laws.

65. Right to Restriction of Processing

Where recognised under Applicable Privacy Laws, individuals may request restriction of Processing under circumstances including:

(a) disputed accuracy;

(b) unlawful Processing where restriction is preferred over deletion;

(c) pending legal claims;

(d) pending verification of an objection; or

(e) other circumstances recognised by Applicable Privacy Laws.

66. Right to Data Portability

Where Applicable Privacy Laws provide such right, the Company shall, where technically feasible, provide Personal Data in a structured, commonly used and machine-readable format or facilitate its transfer to another service provider where requested by the Data Subject.

This right applies only where required by Applicable Privacy Laws and subject to technical feasibility.

67. Right to Object

Where Applicable Privacy Laws permit, individuals may object to Processing based upon:

(a) legitimate interests;

(b) direct marketing;

(c) profiling associated with direct marketing; or

(d) other legally recognised grounds.

The Company shall consider such objections in accordance with Applicable Privacy Laws.

68. Withdrawal of Consent

Where Processing is based upon consent, individuals may withdraw such consent at any time.

Withdrawal of consent shall not affect the lawfulness of Processing undertaken prior to the withdrawal.

Certain Services may become unavailable where Processing depends upon the withdrawn consent.

69. Automated Decision-Making

The Platform utilises artificial intelligence and automated technologies to assist Users in creating content, generating recommendations, automating workflows and improving operational efficiency.

The Company does not intentionally make decisions based solely on automated Processing that produce legal or similarly significant effects on individuals unless:

(a) expressly disclosed;

(b) authorised by Applicable Laws; or

(c) supported by appropriate safeguards.

Where Applicable Privacy Laws provide rights relating to automated decision-making, the Company shall honour such rights.

70. Marketing Preferences

Individuals may opt out of receiving marketing communications from the Company by:

(a) using the unsubscribe mechanism included in communications;

(b) updating communication preferences within the Platform where available; or

(c) contacting the Company directly.

Operational, transactional and security-related communications may continue where necessary for the provision of the Services.

71. Exercising Privacy Rights

Privacy requests may be submitted through the contact details provided in this Privacy Policy or through other mechanisms made available by the Company.

The Company may require reasonable information necessary to verify the identity and authority of the requesting individual before responding.

Fraudulent, excessive or manifestly unfounded requests may be declined or subject to reasonable limitations where permitted by Applicable Privacy Laws.

72. Response to Requests

The Company shall acknowledge and respond to privacy requests within the timeframes prescribed by Applicable Privacy Laws.

Where additional time is reasonably required due to complexity or volume, the Company may extend the response period where permitted by Applicable Privacy Laws and shall notify the requesting individual accordingly.

73. Complaints

Individuals who believe that the Company has not complied with Applicable Privacy Laws may contact the Company using the contact information provided in this Privacy Policy.

Where applicable, individuals may also have the right to lodge a complaint with the relevant supervisory authority, data protection authority or other competent regulator in their jurisdiction.Nothing in this Privacy Policy limits any statutory rights available under Applicable Privacy Laws.

74. Verification of Identity

Before acting upon a privacy request, the Company may request information reasonably necessary to verify:

(a) the identity of the requesting individual;

(b) authority to act on behalf of another person;

(c) ownership of the relevant account; or

(d) any other information reasonably necessary to prevent unauthorised disclosure of Personal Data.

75. No Discrimination

The Company shall not unlawfully discriminate against any individual for exercising privacy rights provided under Applicable Privacy Laws.

However, the Company may be unable to provide certain Services where Personal Data necessary for providing those Services is deleted or where consent essential for such Processing has been withdrawn.

PART VII

INTERNATIONAL DATA TRANSFERS, CROSS-BORDER PROCESSING AND DATA LOCALISATION

60. Global Nature of the Services

60.1The Company operates an international software-as-a-service platform and, accordingly, Personal Data may be collected, stored, processed, transmitted or otherwise made accessible in multiple jurisdictions where the Company, its Affiliates or authorised Subprocessors operate.

60.2By using the Services, the Customer acknowledges that Personal Data may be transferred across international borders in accordance with this Privacy Policy, the Terms of Service and Applicable Privacy Laws.

61. Cross-Border Transfers of Personal Data

The Company may transfer Personal Data to countries outside the jurisdiction in which the Personal Data was originally collected where such transfer is reasonably necessary for:

(a) providing the Services;

(b) operating the Platform;

(c) cloud hosting;

(d) customer support;

(e) disaster recovery;

(f) system monitoring;

(g) artificial intelligence processing;

(h) authorised integrations;

(i) payment processing; and

(j) other legitimate business purposes.

62. Transfer Safeguards

Where Applicable Privacy Laws require safeguards for international transfers, the Company shall implement appropriate measures, which may include:

(a) Standard Contractual Clauses approved by competent authorities;

(b) adequacy decisions or recognised adequacy mechanisms;

(c) legally recognised contractual safeguards;

(d) binding corporate rules where applicable;

(e) certification mechanisms approved under Applicable Privacy Laws; or

(f) any other lawful transfer mechanism recognised by Applicable Privacy Laws.

The Company shall periodically review such safeguards to ensure continued compliance with evolving legal requirements.

63. Processing in Multiple Jurisdictions

The Customer acknowledges that Personal Data may be Processed by the Company or its authorised Subprocessors in jurisdictions that may have privacy laws different from those of the Customer’s country of residence.

Where such Processing occurs, the Company shall use commercially reasonable efforts to ensure that Personal Data continues to receive an appropriate level of protection consistent with Applicable Privacy Laws.

64. Data Localisation

Where Applicable Laws require Personal Data to be stored, processed or retained within a particular jurisdiction, or where the Parties have agreed upon specific data residency commitments under an Enterprise Agreement or Order Form, the Company shall use commercially reasonable efforts to comply with such requirements.

Nothing in this Privacy Policy shall be interpreted as guaranteeing data localisation unless expressly agreed in writing or required by Applicable Laws.

65. Subprocessors Located Internationally

The Company may engage authorised Subprocessors located in various jurisdictions.

Before permitting a Subprocessor to Process Personal Data, the Company shall use commercially reasonable efforts to ensure that such Subprocessor:

(a) is contractually bound by appropriate confidentiality obligations;

(b) implements reasonable technical and organisational security measures;

(c) Processes Personal Data only for authorised purposes;

(d) complies with Applicable Privacy Laws applicable to its Processing activities; and

(e) provides an appropriate level of protection for Personal Data.

66. Regional Privacy Compliance

The Company endeavours to Process Personal Data in accordance with the privacy requirements applicable to the jurisdictions in which it operates, including, where applicable:

(a) the General Data Protection Regulation (EU);

(b) the United Kingdom General Data Protection Regulation;

(c) the Digital Personal Data Protection Act, 2023 (India);

(d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act;

(e) other applicable U.S. federal or state privacy laws;

(f) Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA);

(g) Australia’s Privacy Act 1988;

(h) Singapore’s Personal Data Protection Act;

(i) Brazil’s Lei Geral de Proteção de Dados (LGPD); and

(j) other applicable privacy and data protection laws.

References to specific legislation are intended to illustrate the Company’s commitment to compliance and shall apply only where such legislation is applicable to the relevant Processing activity.

67. International Customer Responsibilities

Customers using the Platform across multiple jurisdictions remain responsible for ensuring that:

(a) Personal Data has been lawfully collected;

(b) appropriate privacy notices have been provided;

(c) necessary consents or other lawful bases exist;

(d) applicable cross-border transfer requirements have been satisfied where required by law; and

(e) their use of the Services complies with Applicable Privacy Laws.

The Company does not provide legal advice regarding the Customer’s independent compliance obligations.

68. Government Access Requests

Where the Company receives a legally binding request from a governmental authority, regulatory body or court seeking disclosure of Personal Data, the Company may disclose such Personal Data where required by Applicable Laws.

Where legally permitted and reasonably practicable, the Company shall use commercially reasonable efforts to notify the affected Customer before making such disclosure.

Nothing in this Privacy Policy shall require the Company to challenge or refuse a lawful governmental request where doing so would violate Applicable Laws or binding legal obligations.

69. Updates to International Transfer Practices

The Company may modify its international transfer mechanisms, Subprocessor arrangements or data hosting practices where reasonably necessary to:

(a) comply with changes in Applicable Laws;

(b) implement new regulatory guidance;

(c) improve security;

(d) enhance operational efficiency;

(e) introduce new infrastructure providers; or

(f) support additional Services.

Material changes affecting international transfers shall be reflected in this Privacy Policy or otherwise communicated where required by Applicable Privacy Laws.

70. Commitment to International Privacy Standards

The Company is committed to maintaining privacy practices designed to support the responsible and lawful international movement of Personal Data while respecting the rights of individuals and the legal requirements of the jurisdictions in which it operates.

Where conflicts arise between this Privacy Policy and mandatory provisions of Applicable Privacy Laws, the mandatory legal requirements shall prevail to the extent of the inconsistency.

PART VIII

COOKIES, TRACKING TECHNOLOGIES, ANALYTICS AND ONLINE IDENTIFIERS

71. Use of Cookies and Similar Technologies

71.1The Application sets no cookies but uses browser local/session storage + a fonts CDN. The marketing website is where cookies apply (analytics, consent banner), once built — governed by the standalone Cookie Policy.

71.2The Company’s marketing website may use cookies and similar technologies, which are addressed separately in the Cookies Policy and the Cookies Policy may be placed by the Company or by authorised third-party service providers acting on the Company’s behalf in accordance with this Privacy Policy, the Cookie Policy and Applicable Privacy Laws.

71.3Where required by Applicable Privacy Laws, the Company shall obtain consent before placing non-essential cookies or similar technologies on a User’s device.

72. Categories of Cookies

The Marketing Website may use the following categories of cookies and similar technologies:

(a) Strictly Necessary Cookies

These cookies are essential for the operation, security and administration of the Marketing Platform and cannot ordinarily be disabled without affecting core functionality.

They may be used for:

* user authentication;

* session management;

* security;

* fraud prevention;

* load balancing; and

* network management.

(b) Functional Cookies

These cookies enable the marketing website to remember User preferences and provide enhanced functionality, including:

* language preferences;

* regional settings;

* accessibility preferences;

* dashboard customisation; and

* user interface preferences.

(c) Performance and Analytics Cookies

These cookies help the Company understand how Users interact with the marketing website and may be used to collect information regarding:

* page visits;

* feature usage;

* navigation patterns;

* session duration;

* error reporting;

* performance metrics; and

* overall marketing website optimisation.

Where reasonably practicable, analytics information shall be aggregated or de-identified.

(d) Security Cookies

Security cookies assist the Company in:

* detecting suspicious activities;

* preventing unauthorised access;

* identifying fraudulent activity;

* protecting User Accounts; and

* maintaining marketing website integrity.

(e) Preference Cookies

Preference cookies enable the marketing website to retain User-selected settings to improve convenience and consistency across future visits.

73. Analytics

The Company may use internal or third-party analytics services to understand marketing website usage, improve functionality and enhance the overall user experience.

Analytics information may include:

(a) browser information;

(b) operating system;

(c) device identifiers;

(d) IP address;

(e) session duration;

(f) page interactions;

(g) feature usage;

(h) performance metrics;

(i) error reports; and

(j) diagnostic information.

Where appropriate, the Company shall use measures designed to reduce the identification of individual Users.

74. Online Identifiers

The Platform may Process online identifiers including:

(a) IP addresses;

(b) browser identifiers;

(c) device identifiers;

(d) authentication tokens;

(e) session identifiers;

(f) API identifiers;

(g) network information; and

(h) similar technical identifiers necessary for providing and securing the Services.

Such Processing shall be carried out only for lawful purposes consistent with this Privacy Policy.

75. Third-Party Technologies

The Platform may incorporate services provided by authorised third parties for purposes including:

(a) analytics;

(b) authentication;

(c) payment processing;

(d) cloud hosting;

(e) customer support;

(f) communications;

(g) security monitoring;

(h) content delivery; and

(i) other operational services.

The Company’s use of such services shall remain subject to appropriate contractual safeguards and Applicable Privacy Laws.

The Company is not responsible for the independent privacy practices of third-party websites or services that are not controlled by the Company.

76. Managing Cookie Preferences

Users may manage cookie preferences through:

(a) the Company’s cookie consent management tool where available;

(b) browser settings;

(c) device settings; or

(d) other mechanisms provided by the Company.

Disabling certain cookies may affect the availability, functionality or performance of the Platform.

77. Do Not Track Signals

Some internet browsers transmit “Do Not Track” (“DNT”) signals.

Because no universally accepted standard currently exists for recognising or responding to DNT signals, the Company may not respond to such signals unless required by Applicable Laws.

Where Applicable Privacy Laws require specific treatment of browser privacy signals, the Company shall comply with such requirements.

78. Cookie Policy

The Company’s standalone Cookie Policy forms an integral part of this Privacy Policy and provides additional information regarding:

(a) categories of cookies;

(b) purposes of cookies;

(c) retention periods;

(d) consent mechanisms;

(e) third-party cookies;

(f) browser controls; and

(g) Users’ choices regarding cookies.

In the event of any inconsistency concerning cookies, the standalone Cookie Policy shall prevail to the extent of the inconsistency.

79. Updates to Tracking Technologies

The Company may introduce, modify or discontinue cookies, analytics technologies or similar tracking mechanisms where reasonably necessary to:

(a) improve the Services;

(b) enhance security;

(c) comply with Applicable Laws;

(d) support new Platform functionality;

(e) improve performance; or

(f) address operational requirements.

Material changes shall be reflected in this Privacy Policy or the Cookie Policy where required by Applicable Privacy Laws.

PART IX

PRIVACY REQUESTS, COMPLAINTS, REGULATORY COOPERATION AND ENFORCEMENT

80. Submission of Privacy Requests

80.1Individuals may submit requests relating to their Personal Data using the contact details published in this Privacy Policy or through any privacy request mechanism made available by the Company.

80.2Privacy requests may include requests concerning:

(a) access to Personal Data;

(b) correction of Personal Data;

(c) deletion of Personal Data;

(d) restriction of Processing;

(e) objection to Processing;

(f) withdrawal of consent;

(g) data portability; and

(h) any other rights recognised under Applicable Privacy Laws.

81. Verification of Identity

81.1Before responding to a privacy request, the Company may require information reasonably necessary to verify:

(a) the identity of the requesting individual;

(b) authority to act on behalf of another person;

(c) ownership of the relevant account; or

(d) any other information reasonably necessary to prevent unauthorised disclosure of Personal Data.

81.2Where identity cannot reasonably be verified, the Company may decline the request or request additional information before taking action.

82. Response to Requests

82.1The Company shall acknowledge and respond to valid privacy requests within the time periods prescribed by Applicable Privacy Laws.

82.2Where permitted by Applicable Privacy Laws, the Company may extend the response period where:

(a) the request is unusually complex;

(b) multiple requests have been received;

(c) additional verification is required; or

(d) circumstances reasonably justify an extension.

Where an extension is permitted, the Company shall notify the requesting individual accordingly.

83. Limitations on Requests

The Company may decline or limit a request where permitted by Applicable Privacy Laws, including where:

(a) the request is manifestly unfounded;

(b) the request is excessive or repetitive;

(c) compliance would adversely affect the rights or freedoms of another individual;

(d) compliance would violate Applicable Laws;

(e) legal privilege applies;

(f) information must be retained to establish, exercise or defend legal claims;

(g) disclosure would compromise Platform security; or

(h) another lawful exemption applies.

84. Requests Relating to Customer Data

84.1Where the Company Processes Personal Data solely on behalf of a Customer, the Customer ordinarily acts as the Data Controller or equivalent decision-maker.

84.2Accordingly, where the Company receives a request relating to Personal Data controlled by a Customer, the Company may:

(a) redirect the request to the relevant Customer;

(b) notify the Customer of the request; or

(c) assist the Customer in responding, as required under the applicable Data Processing Agreement and Applicable Privacy Laws.

85. Complaints

85.1Individuals who believe that the Company has not complied with this Privacy Policy or Applicable Privacy Laws are encouraged to contact the Company so that concerns may be investigated and addressed.

85.2The Company shall review complaints in good faith and use commercially reasonable efforts to respond within a reasonable period, subject to Applicable Privacy Laws.

86. Regulatory Authorities

Where Applicable Privacy Laws provide such rights, individuals may lodge complaints with the competent supervisory authority, privacy regulator or other governmental authority having jurisdiction.

Nothing contained in this Privacy Policy limits any statutory rights available under Applicable Privacy Laws.

87. Regulatory Cooperation

The Company may cooperate with competent governmental authorities, supervisory authorities, courts and regulators where required by Applicable Laws.

Where legally permitted, the Company shall use commercially reasonable efforts to notify the affected Customer or individual before disclosing Personal Data pursuant to a compulsory legal request.

Nothing in this Privacy Policy requires the Company to challenge or refuse a lawful governmental request where doing so would violate Applicable Laws or binding legal obligations.

88. Recordkeeping

The Company may maintain records relating to:

(a) privacy requests;

(b) complaints;

(c) investigations;

(d) regulatory communications;

(e) responses provided;

(f) verification activities; and

(g) compliance measures,

for the purposes of demonstrating compliance with Applicable Privacy Laws, resolving disputes and maintaining appropriate governance records.

Such records shall be retained only for as long as reasonably necessary in accordance with the Company’s retention practices and Applicable Privacy Laws.

89. Non-Retaliation

The Company shall not unlawfully discriminate or retaliate against any individual solely because that individual has exercised privacy rights available under Applicable Privacy Laws.

However, the Company may be unable to continue providing certain Services where Personal Data essential for those Services has been deleted or where consent necessary for Processing has been withdrawn.

90. Good Faith Cooperation

The Company and its Customers shall cooperate in good faith to facilitate compliance with Applicable Privacy Laws, including by providing reasonable assistance in responding to privacy requests, regulatory enquiries and lawful investigations where appropriate.

Such cooperation shall remain subject to confidentiality obligations, legal privilege, security considerations and applicable contractual arrangements.

PART X

CHILDREN’S PRIVACY, THIRD-PARTY SERVICES, CHANGES TO THIS PRIVACY POLICY AND CONTACT INFORMATION

91. Children’s Privacy

91.1The Platform is designed and intended for use by businesses, organisations and individuals who are legally capable of entering into binding agreements under Applicable Laws.

91.2The Company does not knowingly collect Personal Data directly from children or knowingly permit children to create Accounts unless expressly authorised by Applicable Laws and appropriate parental or legal guardian consent has been obtained where required.

91.3If the Company becomes aware that Personal Data relating to a child has been collected in violation of Applicable Privacy Laws, the Company shall take commercially reasonable steps to investigate the matter and, where appropriate, delete or otherwise address such Personal Data in accordance with Applicable Laws.

91.4Parents, legal guardians or other authorised representatives who believe that a child has provided Personal Data through the Platform may contact the Company using the contact details provided in this Privacy Policy.

92. Third-Party Websites and Services

92.1The Platform may contain links to or integrate with third-party websites, applications, platforms, APIs or services that are not owned or controlled by the Company.

92.2The Company is not responsible for the privacy practices, security measures or content of independent third-party services.

92.3Users are encouraged to review the privacy policies and terms applicable to any third-party services before providing Personal Data or authorising integrations.

92.4The inclusion of a link or integration does not constitute an endorsement or representation by the Company regarding any third-party service.

93. Third-Party Authentication and Integrations

Where the Customer chooses to authenticate or connect the Platform using third-party identity providers, email providers, CRM systems or other integrations, Personal Data may be exchanged with such providers solely for the purpose of enabling the requested functionality.

Such Processing shall remain subject to the Customer’s configuration, this Privacy Policy and Applicable Privacy Laws.

94. Changes to this Privacy Policy

94.1The Company may amend this Privacy Policy from time to time to reflect:

(a) changes in Applicable Laws;

(b) regulatory guidance;

(c) technological developments;

(d) new Platform features;

(e) changes in business operations;

(f) improvements to privacy practices; or

(g) other legitimate operational requirements.

94.2The revised Privacy Policy shall become effective on the date specified within the updated version unless otherwise required by Applicable Privacy Laws.

94.3Where required by Applicable Privacy Laws, the Company shall provide reasonable notice of material changes through appropriate communication channels, which may include:

(a) the Platform;

(b) email notifications;

(c) customer dashboards; or

(d) other electronic communications.

94.4Continued use of the Services following the effective date of an updated Privacy Policy constitutes acknowledgement of the revised Privacy Policy to the extent permitted by Applicable Laws.

95. Contact Information

Questions, requests or concerns relating to this Privacy Policy or the Processing of Personal Data may be directed to the Company using the contact details published on the Platform.

Where applicable, communications may relate to:

(a) privacy requests;

(b) Data Subject rights;

(c) complaints;

(d) security concerns;

(e) international data transfers;

(f) regulatory enquiries; or

(g) any matter relating to this Privacy Policy.

Where required by Applicable Privacy Laws, the Company shall identify its designated Data Protection Officer, privacy contact or authorised representative through the Platform or other appropriate communication channels.

96. Governing Privacy Standards

The Company endeavours to conduct its privacy programme in accordance with recognised international privacy principles and Applicable Privacy Laws.

Nothing contained in this Privacy Policy shall limit or exclude any rights granted to individuals under mandatory provisions of Applicable Privacy Laws.

Where mandatory legal requirements conflict with this Privacy Policy, the mandatory legal requirements shall prevail to the extent of the inconsistency.

97. Language

This Privacy Policy is prepared in the English language.

If the Privacy Policy is translated into another language for convenience, the English version shall prevail in the event of any inconsistency unless mandatory Applicable Laws require otherwise.

98. Severability

If any provision of this Privacy Policy is determined by a court or competent authority to be invalid, illegal or unenforceable, the remaining provisions shall continue in full force and effect to the maximum extent permitted by Applicable Laws.

99. Survival

Those provisions of this Privacy Policy that by their nature are intended to survive termination of the Services, including provisions relating to confidentiality, data retention, legal compliance, dispute resolution, limitation of liability and the protection of Personal Data, shall continue in effect to the extent necessary to fulfil their intended purpose.

100. Effective Date

This Privacy Policy shall become effective on the date published by the Company and shall remain in force until replaced by a revised version.

The Company shall maintain the most current version of this Privacy Policy on the Platform or make it otherwise available to Customers and Users.

PART XI

JURISDICTION-SPECIFIC PRIVACY NOTICES

101. General Application

101.1This Privacy Policy is intended to apply globally. However, certain jurisdictions grant additional rights or impose additional obligations relating to the Processing of Personal Data.

101.2Where Applicable Privacy Laws provide greater protection than this Privacy Policy, the mandatory provisions of those laws shall prevail to the extent of any inconsistency.

101.3Nothing contained in this Part limits any rights available to Data Subjects under Applicable Privacy Laws.

102. European Economic Area (EEA)

Where the General Data Protection Regulation (Regulation (EU) 2016/679) applies:

(a) the Company shall Process Personal Data only on an appropriate lawful basis;

(b) Data Subjects may exercise the rights available under the GDPR, including rights of access, rectification, erasure, restriction, portability and objection;

(c) international transfers shall be undertaken only using lawful transfer mechanisms recognised under the GDPR;

(d) appropriate technical and organisational measures shall be implemented to protect Personal Data; and

(e) Data Subjects may lodge complaints with the competent supervisory authority.

103. United Kingdom

Where the UK General Data Protection Regulation and the Data Protection Act 2018 apply:

(a) references in this Privacy Policy to the GDPR shall be interpreted as references to the UK GDPR where appropriate;

(b) Personal Data shall be Processed in accordance with applicable UK privacy legislation;

(c) international transfers shall comply with applicable UK transfer requirements; and

(d) Data Subjects may exercise their rights before the Information Commissioner’s Office or any successor authority where applicable.

104. India

Where the Digital Personal Data Protection Act, 2023 and applicable rules apply:

(a) Personal Data shall be Processed for lawful purposes;

(b) reasonable security safeguards shall be maintained;

(c) Data Principals may exercise the rights provided under applicable Indian privacy laws;

(d) consent shall be obtained where required;

(e) withdrawal of consent shall be respected where legally applicable; and

(f) grievances shall be handled through the Company’s designated grievance redressal mechanism.

Where required by applicable Indian law, the Company shall designate an appropriate Grievance Officer and publish the relevant contact details.

105. California

Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), applies, California residents may have rights including:

(a) the right to know;

(b) the right to access;

(c) the right to delete;

(d) the right to correct inaccurate Personal Information;

(e) the right to limit the use of Sensitive Personal Information where applicable;

(f) the right to opt out of the sale or sharing of Personal Information where applicable; and

(g) the right not to be unlawfully discriminated against for exercising statutory privacy rights.

The Company does not sell Personal Information or share Personal Information for cross-context behavioural advertising except as expressly disclosed and permitted by Applicable Laws.

106. Other United States Jurisdictions

Residents of certain U.S. states may have privacy rights under applicable state privacy legislation.

Where such laws apply, the Company shall honour applicable rights, including rights relating to:

(a) access;

(b) correction;

(c) deletion;

(d) portability;

(e) appeals; and

(f) opt-out rights,

to the extent required by Applicable Laws.

107. Canada

Where Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) or applicable provincial privacy legislation applies:

(a) Personal Information shall be collected, used and disclosed only for appropriate purposes;

(b) appropriate safeguards shall be implemented;

(c) individuals may request access to and correction of their Personal Information; and

(d) complaints may be submitted to the appropriate privacy authority where applicable.

108. Australia

Where Australia’s Privacy Act 1988 applies:

(a) Personal Information shall be handled in accordance with the Australian Privacy Principles;

(b) reasonable security measures shall be maintained;

(c) individuals may request access to and correction of Personal Information; and

(d) complaints may be submitted to the Office of the Australian Information Commissioner where applicable.

109. Brazil

Where Brazil’s Lei Geral de Proteção de Dados (LGPD) applies:

(a) Personal Data shall be Processed only on lawful grounds recognised by the LGPD;

(b) Data Subjects shall be afforded applicable statutory rights;

(c) international transfers shall comply with Brazilian legal requirements; and

(d) the Company shall cooperate with the competent Brazilian supervisory authority where required.

110. Singapore and Other Asia-Pacific Jurisdictions

Where applicable privacy legislation in Singapore or other Asia-Pacific jurisdictions applies, the Company shall Process Personal Data in accordance with the applicable legal requirements governing:

(a) consent;

(b) notification;

(c) purpose limitation;

(d) security safeguards;

(e) retention; and

(f) cross-border transfers.

111. Future Privacy Legislation

The Company recognises that privacy laws continue to evolve globally.

Accordingly, the Company may update this Privacy Policy to reflect:

(a) newly enacted privacy legislation;

(b) amendments to existing laws;

(c) regulatory guidance;

(d) judicial decisions;

(e) technological developments; or

(f) changes in business operations.

Such updates shall become effective in accordance with Part X of this Privacy Policy.

112. Interpretation

References to specific privacy legislation in this Privacy Policy are intended solely to identify legal frameworks that may apply to the Company’s Processing activities.

Such references shall not be interpreted as an admission that every referenced law applies in every circumstance or jurisdiction.

The applicability of any privacy law shall depend upon the facts of the relevant Processing activity and the requirements of Applicable Laws.

PART XII

FINAL PROVISIONS

113. Interpretation

113.1 This Privacy Policy shall be interpreted in a manner consistent with:

(a) the Terms of Service;

(b) the Cookie Policy;

(c) the AI Services and Responsible AI Policy; and

(d) all other documents incorporated by reference.

113.2 Capitalised terms not defined in this Privacy Policy shall have the meanings assigned to them in the Terms of Service.

113.3Headings are inserted for convenience only and shall not affect the interpretation of this Privacy Policy.

114. Order of Precedence

In the event of any inconsistency relating to the Processing of Personal Data, the following order of precedence shall apply, unless otherwise required by Applicable Privacy Laws:

(a) mandatory provisions of Applicable Privacy Laws;

(b) the Data Processing Agreement (where applicable);

(c) this Privacy Policy;

(d) the Terms of Service;

(e) other applicable schedules, policies or enterprise agreements.

Nothing contained herein shall reduce any statutory rights available under Applicable Privacy Laws.

115. Entire Privacy Policy

This Privacy Policy constitutes the Company’s complete privacy notice governing the collection, use, disclosure, storage, transfer and other Processing of Personal Data in connection with the Services.

It supersedes all previous privacy notices, privacy statements or similar documents relating to the same subject matter.

116. No Waiver

Failure by the Company to enforce any provision of this Privacy Policy shall not constitute a waiver of any right or remedy available to the Company.

Any waiver shall be effective only if made in writing by an authorised representative of the Company.

117. Severability

If any provision of this Privacy Policy is held to be invalid, illegal or unenforceable by a court or competent authority, such provision shall be interpreted, modified or severed to the minimum extent necessary.

The remaining provisions shall continue in full force and effect.

118. Assignment

The Company may assign or transfer its rights and obligations under this Privacy Policy in connection with a merger, acquisition, corporate restructuring, sale of assets or other lawful business transaction, provided that the successor entity continues to Process Personal Data in accordance with Applicable Privacy Laws.

This Privacy Policy does not grant any individual the right to assign statutory privacy rights.

119. Survival

The provisions relating to:

(a) confidentiality;

(b) data retention;

(c) information security;

(d) legal compliance;

(e) dispute resolution;

(f) limitation of liability;

(g) regulatory cooperation; and

(h) protection of Personal Data,

shall survive termination of the Services for so long as necessary to fulfil their intended purpose or comply with Applicable Laws.

120. Contact Information

Questions, concerns or requests relating to this Privacy Policy may be directed to the Company using the contact details published on the Platform. Where required by Applicable Privacy Laws, the Company shall publish the contact details of its:

(a) Privacy Team;

(b) Data Protection Officer;

(c) Grievance Officer;

(d) EU Representative; or

(e) any other legally required privacy contact.

The Company shall use commercially reasonable efforts to respond to communications within the timeframes prescribed by Applicable Privacy Laws.

121. Effective Date

This Privacy Policy shall become effective on the date specified by the Company and shall remain in effect until replaced by an updated version.

The most current version shall be made available through the Platform or the Company’s official website.

122. Acceptance

By accessing or using the Services, or by otherwise providing Personal Data to the Company, the Customer and each User acknowledge that they have read and understood this Privacy Policy.

Where consent is required under Applicable Privacy Laws for specific Processing activities, such consent shall be obtained separately and may be withdrawn in accordance with Applicable Privacy Laws.

ANNEXURE A

Categories of Personal Data

The Company may Process the following categories of Personal Data, depending on the Services used:

Account / User: email, username, full name, bcrypt password hash, active/verified flags, last login, created/updated timestamps

Organisation / Company: company name, description, website, physical address, phone; brand logo, brand colours, brand book

Contact / Prospect (processed on behalf of customers): email, first/last/full name, job title, department, seniority; company name/website/industry/size/revenue; phone, LinkedIn URL, Twitter URL; city/state/country/timezone

AI research & enrichment (about the contact): AI research data, company news, person insights, structured enrichment (person, company, buying signals, champion score, decision-authority/buying-role, communication prefs, competitive intel), provider/model used, enrichment timestamps

Engagement: emails sent/opened/clicked/replied counts + last-activity timestamps; lead score; lead status; tags; segments; email status (active/bounced/unsubscribed/complained); unsubscribe date; bounce count; import source

Email content: outbound subject + body; inbound reply subject + body + sentiment + intent + urgency; message/tracking ids

Technical: IP address + user-agent + timestamps on opens/clicks; JWT tokens (in browser localStorage)

Payment: Stripe customer id, subscription id, plan/price ids, billing-period dates, credit balances & transactions (NO card data)

Integration credentials (the user's own, encrypted): ~40 API keys/tokens/webhooks for enrichment, CRM, calendar, comms, SMS, storage, analytics, LLM — all Fernet-encrypted at rest

ANNEXURE B

Categories of Recipient

Recipient categoryActual provider(s)Status
Cloud infrastructureMicrosoft AzureLive
AI service providersOpenAI, Anthropic (Company key)Live
Payment processorsStripe (identifiers only; no card data)Live
Email infrastructureCustomer's own SMTP/IMAP mailbox (sending/receiving); support inbox hostLive (customer-directed)
Customer support providersEmail host for support@beevelope.com [Google Workspace / M365 — confirm]Confirm
Analytics providersNone currently (PostHog planned)Planned
Security service providersError monitoring [Sentry — confirm if live]; otherwise Azure-inheritedConfirm
Identity management providersIn-house authentication today; customer SSO identity providers once SSO shipsN/A now / future
Authorised subprocessorsAzure, OpenAI, Anthropic, Stripe (Company); enrichment/CRM/calendar/comms (customer-directed)Live
Affiliates[Confirm if any group affiliates process data]Confirm
Professional advisersLegal, accounting, auditors (as needed)As needed
Regulatory / courts / governmentWhere legally requiredAs needed
Other (customer-authorised)Customer-directed integrations (enrichment, CRM, calendar, comms, SMS, storage) via the customer's own credentialsLive

The listed categories are appropriate. Company-operated recipients are Azure, OpenAI, Anthropic and Stripe (plus the support email host and, if live, error monitoring). All other integrations are customer-directed (engaged via the customer's own credentials). We do not use analytics providers today (PostHog planned). No data is sold or shared for advertising.

ANNEXURE C

General Data Retention Principles

Personal Data shall generally be retained only for as long as reasonably necessary to:

* provide the Services;

* comply with legal obligations;

* resolve disputes;

* protect the rights of the Company, Customers and Users;

* enforce contractual obligations;

* maintain security;

* prevent fraud; or

* satisfy legitimate business requirements.

Retention periods may vary depending upon the category of Personal Data and Applicable Privacy Laws.

ANNEXURE D

International Transfer Mechanisms

Where Personal Data is transferred internationally, the Company may rely upon one or more lawful transfer mechanisms recognised under Applicable Privacy Laws, including:

* Adequacy Decisions

* Standard Contractual Clauses (SCCs)

* UK International Data Transfer Addendum

* Binding Corporate Rules (where applicable)

* Approved Codes of Conduct or Certification Mechanisms (where available)

* Contractual safeguards with authorised Subprocessors

* Other legally recognised transfer mechanisms