1. Privacy Commitment & Overview
At ExiReach ("ExiReach", "We", "Us", or "Our"), transparency and data privacy are foundational principles. This Privacy Policy describes how we collect, store, process, protect, and handle personal and business data when you use our web platform, APIs, email outreach tools, and AI sales services.
We adhere to international data privacy standards including the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and applicable email communication regulations.
2. Information We Collect
We collect information in three main categories:
A. Account & Billing Information
Name, work email address, company name and password hashes. We never see or store your card details. ExiReach is invoiced directly by bank transfer under a services agreement — no card is taken through this site and no payment processor holds card data on our behalf. See Section 6.
B. CRM & Lead Outreach Data
B2B prospect contact details uploaded by you (names, work emails, job titles, LinkedIn profile URLs, company attributes), email campaign content, sequence schedules, and lead status history.
C. Connected Inbox & Telemetry Data
OAuth authorization tokens for email providers (Google Workspace / Microsoft 365), sent/received outreach email metrics, open/click event logs, IP addresses, browser types, and error diagnostic logs.
3. How We Use Information
- Service Execution: Operating email outreach automation, CRM sequence tracking, and lead pipeline management.
- AI Personalization: Generating tailored draft messages, subject lines, and reply classification for your sales reps.
- Security & Deliverability: Monitoring inbox health, SPF/DKIM verification, preventing spam or abuse, and managing opt-out blacklists.
- Product Analytics: Improving system performance, feature usability, and technical troubleshooting.
4. OAuth & Connected Email Inboxes
When you connect your email accounts via Google OAuth or Microsoft 365 OAuth:
Google Limited Use Compliance
ExiReach's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use your Google workspace data to train AI/ML models.
- OAuth tokens are stored encrypted using AES-256 GCM encryption.
- You can revoke ExiReach email access at any time directly through your email provider settings or workspace account page.
5. AI & Tenant Data Isolation
ExiReach enforces strict multi-tenant data architecture boundaries. Your CRM database, prospect records, and outbound email messaging are strictly isolated per tenant.
- We do NOT sell customer data or prospect records to data brokers or third parties.
- We do NOT share lead lists across different workspace accounts.
- LLM requests are processed zero-retention where supported by enterprise AI API infrastructure.
7. Data Security & Retention
We implement industry-standard administrative, physical, and technical safeguards:
- TLS 1.3 encryption in transit and AES-256 encryption for data at rest.
- Role-based access control (RBAC) and mandatory JWT token authentication.
- Data retention: Customer data is retained for the duration of your engagement and for 30 days after account closure so that you can export it, after which it is permanently deleted from production systems. You may request immediate deletion at any time.
8. Your Rights & Data Subject Requests
Depending on your location (e.g. EU/EEA, UK, California), you possess specific legal rights regarding your personal data:
- Right of Access & Portability: Request export of your account and prospect data.
- Right to Rectification: Correct inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of customer or lead records.
- Opt-Out Rights: Opt out of marketing communications or non-essential data processing.
To submit a Data Subject Request (DSAR), please contact [email protected]. Where we process data on a client's instructions as their processor, we will forward the request to that client and support them in answering it.
9. Prospect Data & People You Contact
This section is for people who receive outreach sent through ExiReach, rather than for our own customers. If you were contacted by a business using our platform and want your details removed, this is the section you need.
Who is responsible for your data
The ExiReach customer who contacted you is the data controller — they decide who to contact and what to say. Exicube App Solutions (OPC) Private Limited acts as a data processor on their instructions. We will always act on a removal request ourselves, and will also pass it to the relevant customer.
Where the information comes from
Business contact details are compiled from sources that are already public: a company's own website, public business directories and mapping listings, and public search-engine results. We do not log in to any social network to collect data, we do not purchase contact lists, and we do not attempt to obtain personal, non-business contact details.
A business using ExiReach can also upload contacts it already holds. When it does, it must state at the point of upload how it obtained them — that they are its own customers, that they gave their details to that business directly, or that they were found published online — and we record that statement against the person who made it. Bought or rented lists are refused and cannot be uploaded. If you were contacted because a business uploaded your details, the removal routes below work in exactly the same way.
Legal basis
Where the GDPR or UK GDPR applies, processing of business contact data for B2B outreach is carried out on the basis of legitimate interests (Article 6(1)(f)) — specifically, the interest of a business in contacting another business about a relevant commercial offering. That basis is conditional on your rights, which is why the objection route below is unconditional and takes effect immediately.
Whether the message is tracked
Outreach sent as part of a sequence usually carries an invisible image that records when the message was opened, and its links are rewritten so that clicks are recorded too. It is used to decide whether to follow up, and it is why a message you never opened may be followed by another. The sender chooses whether to use it; when it is in use, the footer of the message you received says so. The unsubscribe link is deliberately excluded from click tracking, so exercising your opt-out is never recorded as a click, and opting out stops both.
How to stop being contacted
- Use the unsubscribe link in any message you received. Every email sent through ExiReach carries a one-click unsubscribe (RFC 8058) and a link in the body. This suppresses you immediately and permanently.
- Reply with the word unsubscribe — replies are scanned for opt-out intent and the sequence is stopped.
- Email [email protected] to request erasure across all workspaces on the platform, not just the sender who contacted you.
You also have the right of access, rectification, erasure, restriction, and objection to processing in respect of this data, and the right to lodge a complaint with your local supervisory authority. Suppression records are retained after erasure for the sole purpose of ensuring you are not contacted again.
10. Website Visitors: Contact Form & Live Chat
Sections 2 to 9 describe data we handle on behalf of our clients, where we act as a processor. This section is different. When you use the contact form or the live chat on this website, Exicube App Solutions (OPC) Private Limited is the controller of the information you give us.
What we collect. The contact form asks for your email address and your message; your name, phone number and a subject line are optional. The chat widget asks for your name and email address before starting a conversation, and records the messages you send and any files you attach. In both cases our server also sees the IP address the request arrives from, which is used to rate-limit abuse of the form.
What we do with it. We use it to answer you, and to prepare a quote where you have asked for one. We run our own sales through the product we sell, so your enquiry is recorded in ExiReach's own workspace: a contact record with your message attached, a follow-up task for a member of our team, and an entry on our sales pipeline so your enquiry is not forgotten. A copy is emailed to [email protected]. It is never shared with our clients, added to an outreach campaign you did not ask to be part of, or sold.
How long we keep it. We keep your enquiry while we are dealing with it and afterwards as our record of the conversation. Live-chat transcripts are deleted automatically after 365 days. You can ask us to delete either sooner than that, at any time, and we will — see Section 8.
Who else is involved.Neither the form nor the chat widget is a third-party service: both are served from our own infrastructure. Nor are our page statistics, described in Section 11 — they are collected by software we run ourselves, on our own servers, and this site carries no advertising trackers and no third-party analytics. The only external party is the transactional email provider that delivers the notification to us, named in Section 6.
12. International Data Transfers
ExiReach is operated from India by Exicube App Solutions (OPC) Private Limited, and is hosted in data centres operated by our infrastructure providers in the European Union. Using the service therefore involves transferring personal data across borders.
Since 16 August 2026, hosting itself no longer takes personal data out of the EEA: the platform and its database run in Finland, and backups are held in Germany. AI inference is also inside the EEA — prompt content is processed in Stockholm, Sweden and web search runs in Ireland, as described in Section 6. The transfers that do remain are our US-based provider of transactional email — platform messages such as password resets and team invitations, never your outreach campaigns, which send from your own mailbox and domain — together with administrative access by our own personnel in India. For those, and for any other transfer out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical measures (encryption in transit and at rest, and access controls described in Section 7). A Data Processing Addendum incorporating those clauses is available on request from [email protected].
Invoicing is handled directly by Exicube App Solutions (OPC) Private Limited in India; no billing data is passed to a third-party merchant of record.
13. Privacy Contact & Data Controller
For questions, concerns, or data protection enquiries, contact us at:
Exicube App Solutions (OPC) Private Limited
3, Sreenagar, Madhyamgram
Kolkata - 700129, West Bengal, India
CIN: U74999WB2017OPC223198
Email: [email protected]
If you are in the EEA or the UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

