DraftDraft template — not legal advice; review with counsel before launch.

Privacy Policy

Last updated: 20 July 2026

1. Overview

This Privacy Policy explains how Outrepped ("we", "us") collects, uses, shares, retains, and protects personal data when you use the Outrepped application and related services (the "Service"). For customers in the EEA/UK, Outrepped acts as a data controller for account and usage data, and as a data processor for the workspace content you manage in the Service.

2. Information we collect

  • Account information — your name, email address, password (stored only as a secure hash), workspace, and role.
  • Workspace content — the contacts, companies, deals, messages, notes, tasks, and related records you or your team create or import.
  • Usage and device data — log data such as IP address, browser type, timestamps, and feature usage, used to operate and secure the Service.
  • Cookies — see our Cookies Policy. We use only strictly-necessary cookies by default.

3. Data from connected accounts (Google and Microsoft)

If you choose to connect a Google or Microsoft account, you grant access through that provider's consent screen. We request only the access needed for the features you use, and you can revoke it at any time from your provider's security settings or by disconnecting the integration in Outrepped.

What we access. Depending on the features you enable, this may include: your basic profile and email address (to identify your account); the ability to read and send email on your behalf and read message metadata (to show your conversations in Outrepped and send outreach you initiate); and calendar access (to show availability and schedule meetings you request).

How we use it. Connected-account data is used solely to provide the features you asked for — sending and syncing your communications, displaying your inbox and threads, and scheduling. We do not use it for advertising, and we do not sell it.

Retention and deletion. We retain connected-account data only as long as the integration is connected and for as long as needed to provide the Service. When you disconnect an integration or delete your account, the associated access tokens and synced connected-account data are deleted, subject to limited backup and legal-retention windows described below.

Google API Services User Data Policy. Outrepped's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not transfer or use Google user data for serving advertisements, and we do not allow humans to read this data unless we have your consent for specific messages, it is necessary for security or to comply with applicable law, or the data has been aggregated and anonymised.

Microsoft data. Where you connect a Microsoft account, we handle data received through Microsoft Graph on the same limited basis: only to provide the features you enable, never for advertising, and never sold.

4. How we use information

  • to provide, maintain, and secure the Service;
  • to authenticate you and manage your workspace and team;
  • to send transactional messages (for example, email verification and password reset);
  • to provide support and respond to your requests;
  • to detect, prevent, and address abuse, fraud, or security issues;
  • to comply with legal obligations.

5. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we process personal data on the bases of performance of a contract (to provide the Service), our legitimate interests (to secure and improve the Service), consent (where required, such as non-essential cookies), and compliance with legal obligations.

6. How we share information

We do not sell personal data. We share it only with service providers (subprocessors) who host and support the Service under contractual confidentiality and data-protection obligations, when required by law or to protect rights and safety, or in connection with a business transfer. A list of subprocessors will be maintained and made available before launch.

7. Data retention

We retain personal data for as long as your account is active or as needed to provide the Service, and thereafter only as required to comply with legal obligations, resolve disputes, and enforce agreements. Backups are retained on a rolling basis and cycle out over time.

8. Your rights and data deletion

Depending on your location, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can disconnect integrations and request account deletion, after which we delete or anonymise your personal data subject to the retention limits above. To exercise these rights, contact us at privacy@outrepped.com.

9. International transfers

Personal data may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.

10. Security

We use administrative, technical, and organisational measures designed to protect personal data, including encryption in transit, hashed credentials, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children

The Service is not directed to children and is not intended for anyone under the age required to form a binding contract in their jurisdiction.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice. The "last updated" date above reflects the latest revision.

13. Contact

For privacy questions or to exercise your rights, contact privacy@outrepped.com. The data controller's legal identity and address will be finalised with counsel before launch.