Privacy Policy

Last updated: 2026-10-04

This policy explains how Outbly (“we”) processes personal data when you use Outbly: the website, the application and related services. It complements our Terms of Service (/legal/terms), our Data Processing Agreement (/legal/dpa) and our Cookie Policy (/legal/cookies).

1.Who we are

Outbly operates Outbly. Data protection contact: privacy@outbly.com.

For any question about this policy or to exercise your rights, write to this address.

2.Controller and processor roles

We act as controller for: our customers' and their users' accounts, authentication, billing, support, security and fraud prevention, technical logs, aggregated usage statistics and our service emails.

For prospect data that customers upload, import, sync or have enriched with Outbly (contacts, companies, emails, replies, notes, CRM data, campaigns), the customer is the controller and Outbly acts as processor on the customer's documented instructions. Our Data Processing Agreement (DPA) governs this processing.

When the customer sends us prospect data or asks us to use a data provider, the customer remains responsible for the lawfulness of the collection, the source of the data, the legal basis, informing individuals and respecting their rights.

3.Data we process

  • Account data: name, email address, password hash, language, organization and role.
  • Billing data: plan, subscription status and invoices (card details are handled by Stripe and never stored by us).
  • Usage and security data: security and audit logs, credit usage, IP address and user agent of sessions.
  • Customer content: prospect data, messages, replies, notes and CRM data you add or connect.
  • Mailbox connection data: OAuth tokens or SMTP credentials, encrypted at rest.
  • Support and testimonial messages you send us.

4.Sources of data

We receive data: from you directly (sign-up, entry, settings); imported by the customer (files, API, browser extension); synced from its connected tools (mailbox, CRM, calendar); collected automatically when the service is used; supplied by a prospecting data provider enabled on the platform; generated or enriched by an AI service; derived from replies received on the customer's connected mailboxes.

Where prospect data is collected indirectly, the customer is responsible for informing the individuals concerned and documenting the source and legal basis of the processing.

5.Purposes and legal bases

  • Creating and managing the account, providing the service: performance of a contract.
  • Billing and accounting: contract and legal obligation.
  • Service emails (verification, password reset, invitations): contract.
  • Product emails (weekly digest, activation help): legitimate interest in helping users get value from the service; they can be turned off in notification preferences or via the unsubscribe link.
  • Support: contract or legitimate interest.
  • Security, fraud prevention, incident diagnosis, audit logs: legitimate interest in protecting the service and its users; it does not override your rights disproportionately.
  • AI features, at your request: contract.

B2B outreach run by customers is their responsibility: each customer, as controller, must choose and document its legal basis (generally legitimate interest, with a documented assessment), comply with applicable electronic-marketing rules, inform prospects and honor objections.

6.Recipients and sub-processors

Depending on the features enabled, we use:

  • Hosting and databases (application servers, PostgreSQL, Redis): IONOS SE (data center in Germany).
  • Service emails: Resend (Ireland region, European Union).
  • Stripe: payments and billing.
  • AI providers (depending on the configured routing): OpenAI, Anthropic, Google (Gemini) and OpenRouter, plus the model providers OpenRouter forwards the request to.
  • Web search for AI research: Serper and/or Google Custom Search.
  • Prospecting data providers: Apollo, Prospeo, Clay, Apify or a custom provider.
  • Email address verification: ZeroBounce and/or NeverBounce.
  • Notifications and SMS, if enabled: Slack, Twilio.

Tools the customer connects itself (Google, Microsoft, its SMTP provider, CRM, calendar) are chosen by the customer. The detailed list of sub-processors is in our DPA (/legal/dpa); it gives countries and transfer safeguards: [to be completed before publication].

7.International transfers

Some providers may be located outside the European Economic Area or access data from abroad, notably some AI or data providers. These transfers are covered by an adequacy decision, standard contractual clauses or another recognized mechanism, supplemented where necessary by technical and organizational measures. The list of providers and applicable mechanisms is in our DPA.

8.Retention

  • User account: for the life of the account. You can delete it at any time from Settings → Privacy & data.
  • Customer content: as long as the customer keeps it in its workspace; deleting the organization erases its data and cancels the subscription.
  • Sessions: 30 days, then automatically purged. Verification tokens: deleted once used or expired.
  • Invoices and accounting records: period required by accounting law (in France, 10 years).
  • Suppression list: as long as the organization exists, so the person is not contacted again.
  • Security, audit and technical logs (API, webhooks, system): 12 months, then automatically purged. Proof of DPA signature is kept for the duration of the contract.
  • Backups: database copies are kept for at most 30 days, then deleted automatically.
  • Data sent to an AI or data provider: per that provider's terms.

9.Artificial intelligence

Depending on the features enabled, we use AI services to generate, summarize, personalize or classify text. Data sent may include text provided by the customer, selected prospect information and the related instructions.

We do not use customer data to train our own models. Generated content may contain errors: AI-generated emails require human approval by default, and the customer remains responsible for checking and sending them.

10.Profiling and automated decisions

The service can compute a prospect score, classify leads, classify replies, recommend actions or automatically stop sequences (reply, unsubscribe, bounce). These features help the customer decide; they do not produce legal or similarly significant effects on a person. The customer remains responsible for final decisions.

11.Cookies and trackers

Outbly uses strictly necessary cookies (session, language, sign-in security, remembering your choice). We use no advertising cookies. Only with your consent, we may measure the audience of the public site with Google Analytics (Google Ireland Limited; transfers outside the European Union are possible). No audience measurement is done inside the signed-in application. You can refuse or withdraw your consent at any time. Details and durations: Cookie Policy (/legal/cookies).

12.If one of our customers contacted you

If you received an outreach email sent with Outbly, the sender is the controller of your data and must identify itself in its message. Every email contains an unsubscribe link: it immediately stops all future sends from that sender, and sends already scheduled are blocked before they go out.

Your address is then added to the sender's suppression list, which keeps only the address, reason, source and date to avoid contacting you again. This information is not used for any commercial purpose. We cannot delete it permanently without risking contacting you again.

You can also write to support@outbly.com or privacy@outbly.com: we will forward your request to the customer concerned and, where applicable, add your address to its suppression list.

13.Your rights and how to exercise them

Subject to applicable law, you have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing relies on it.

To exercise your rights, write to privacy@outbly.com or, if you have an account, use Settings → Privacy & data (export and deletion). We may ask you to prove your identity. We reply within one month of a complete request, extendable by two months for a complex request, with prior notice. The reply is free in principle.

If your request concerns prospect data processed on behalf of a customer, we forward it to that customer, who remains the controller. You may also lodge a complaint with the CNIL (cnil.fr) or your supervisory authority.

14.Whether providing data is mandatory

Account data is needed to create and use an account; without it we cannot provide the service. Other information is optional.

15.Minors

The service is intended for professionals. We do not knowingly collect personal data of minors. If you believe a minor has sent us data, write to privacy@outbly.com.

16.Security and data breaches

We use: encryption in transit (TLS); encryption at rest of credentials, secrets and connection tokens (AES-256-GCM); hashed passwords (bcrypt); hashed session tokens; role-based access control; rate limiting; audit logs. Other data benefits from the protections of the hosting infrastructure.

In case of a data breach likely to result in a high risk to your rights, we will inform you as provided by law. When we act as processor, we inform the customer concerned within the time set in our DPA, so it can meet its own notification obligations.

17.Changes

We may change this policy; the date of the last update is shown at the top of the page, and we will inform users of any significant change.

18.Contact

Privacy requests: privacy@outbly.com. General support: support@outbly.com.

Privacy Policy · Outbly