Data Protection & Trust

Privacy Policy

ExiReach is committed to protecting customer data, lead confidentiality, and upholding global privacy standards.

Last Updated: August 13, 2026Version 2.5

1. Privacy Commitment & Overview

At ExiReach ("ExiReach", "We", "Us", or "Our"), transparency and data privacy are foundational principles. This Privacy Policy describes how we collect, store, process, protect, and handle personal and business data when you use our web platform, APIs, email outreach tools, and AI sales services.

We adhere to international data privacy standards including the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and applicable email communication regulations.

2. Information We Collect

We collect information in three main categories:

A. Account & Billing Information

Name, work email address, company name and password hashes. We never see or store your card details. ExiReach is invoiced directly by bank transfer under a services agreement — no card is taken through this site and no payment processor holds card data on our behalf. See Section 6.

B. CRM & Lead Outreach Data

B2B prospect contact details uploaded by you (names, work emails, job titles, LinkedIn profile URLs, company attributes), email campaign content, sequence schedules, and lead status history.

C. Connected Inbox & Telemetry Data

OAuth authorization tokens for email providers (Google Workspace / Microsoft 365), sent/received outreach email metrics, open/click event logs, IP addresses, browser types, and error diagnostic logs.

3. How We Use Information

  • Service Execution: Operating email outreach automation, CRM sequence tracking, and lead pipeline management.
  • AI Personalization: Generating tailored draft messages, subject lines, and reply classification for your sales reps.
  • Security & Deliverability: Monitoring inbox health, SPF/DKIM verification, preventing spam or abuse, and managing opt-out blacklists.
  • Product Analytics: Improving system performance, feature usability, and technical troubleshooting.

4. OAuth & Connected Email Inboxes

When you connect your email accounts via Google OAuth or Microsoft 365 OAuth:

Google Limited Use Compliance

ExiReach's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use your Google workspace data to train AI/ML models.

  • OAuth tokens are stored encrypted using AES-256 GCM encryption.
  • You can revoke ExiReach email access at any time directly through your email provider settings or workspace account page.

5. AI & Tenant Data Isolation

ExiReach enforces strict multi-tenant data architecture boundaries. Your CRM database, prospect records, and outbound email messaging are strictly isolated per tenant.

  • We do NOT sell customer data or prospect records to data brokers or third parties.
  • We do NOT share lead lists across different workspace accounts.
  • LLM requests are processed zero-retention where supported by enterprise AI API infrastructure.

6. Data Sharing & Subprocessors

We do not sell personal data. We share it only with vetted third parties essential to providing the service:

  • Resend (transactional email). Sends account email on our behalf — verification links, password resets, workspace invitations and service notifications. It processes the recipient address and message content as our processor. Resend does not carry outreach campaigns, which are sent through your own connected mailbox.
  • Cloud Infrastructure Providers: Managed hosting, database and CDN services.
  • Email & OAuth Infrastructure: Google Cloud Platform and Microsoft Graph APIs, used only to send and read mail on inboxes you have explicitly connected.
  • Amazon Web Services (AI inference). The only AI provider we use. Through Amazon Bedrock it drafts and classifies outreach content, runs the marketing agent, and performs web search during content research. Inference runs in Stockholm, Sweden and web search in Ireland — both inside the EEA, so prompt content does not leave it. Prompts are scoped to a single workspace and are not used to train public foundation models. The authors of the open models we run receive nothing; Amazon operates them on our behalf.
  • MillionVerifier (email deliverability). Checks whether an address can receive mail, immediately before we send to it. It receives the email address alone — no name, company, or campaign detail — and we use the answer only to avoid sending to a mailbox that does not exist. It is operated by GBD Software as a Service Private Limited Company from Hungary (EEA).
  • Hetzner (hosting). Runs the platform and its database in Helsinki, Finland, with backups held in Falkenstein, Germany. Both are inside the EEA.
  • Expo (mobile push notifications).Delivers notifications to our customers’ own mobile devices, relaying onward to Apple and Google. Push notifications carry only a category heading such as “New reply” and an internal reference — never a prospect’s name, email address, or the content of their message. The full detail is fetched from our own servers in Finland when the app is opened.
  • Cloudflare (bot protection).Provides the Turnstile check on our website chat widget. It receives the visitor’s IP address when that check runs, and does not receive anything typed into the chat.
  • Legal Requirements: Disclosures strictly required to satisfy law enforcement warrants, court orders, or legal process.

7. Data Security & Retention

We implement industry-standard administrative, physical, and technical safeguards:

  • TLS 1.3 encryption in transit and AES-256 encryption for data at rest.
  • Role-based access control (RBAC) and mandatory JWT token authentication.
  • Data retention: Customer data is retained for the duration of your engagement and for 30 days after account closure so that you can export it, after which it is permanently deleted from production systems. You may request immediate deletion at any time.

8. Your Rights & Data Subject Requests

Depending on your location (e.g. EU/EEA, UK, California), you possess specific legal rights regarding your personal data:

  • Right of Access & Portability: Request export of your account and prospect data.
  • Right to Rectification: Correct inaccurate or incomplete information.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of customer or lead records.
  • Opt-Out Rights: Opt out of marketing communications or non-essential data processing.

To submit a Data Subject Request (DSAR), please contact [email protected]. Where we process data on a client's instructions as their processor, we will forward the request to that client and support them in answering it.

9. Prospect Data & People You Contact

This section is for people who receive outreach sent through ExiReach, rather than for our own customers. If you were contacted by a business using our platform and want your details removed, this is the section you need.

Who is responsible for your data

The ExiReach customer who contacted you is the data controller — they decide who to contact and what to say. Exicube App Solutions (OPC) Private Limited acts as a data processor on their instructions. We will always act on a removal request ourselves, and will also pass it to the relevant customer.

Where the information comes from

Business contact details are compiled from sources that are already public: a company's own website, public business directories and mapping listings, and public search-engine results. We do not log in to any social network to collect data, we do not purchase contact lists, and we do not attempt to obtain personal, non-business contact details.

A business using ExiReach can also upload contacts it already holds. When it does, it must state at the point of upload how it obtained them — that they are its own customers, that they gave their details to that business directly, or that they were found published online — and we record that statement against the person who made it. Bought or rented lists are refused and cannot be uploaded. If you were contacted because a business uploaded your details, the removal routes below work in exactly the same way.

Legal basis

Where the GDPR or UK GDPR applies, processing of business contact data for B2B outreach is carried out on the basis of legitimate interests (Article 6(1)(f)) — specifically, the interest of a business in contacting another business about a relevant commercial offering. That basis is conditional on your rights, which is why the objection route below is unconditional and takes effect immediately.

Whether the message is tracked

Outreach sent as part of a sequence usually carries an invisible image that records when the message was opened, and its links are rewritten so that clicks are recorded too. It is used to decide whether to follow up, and it is why a message you never opened may be followed by another. The sender chooses whether to use it; when it is in use, the footer of the message you received says so. The unsubscribe link is deliberately excluded from click tracking, so exercising your opt-out is never recorded as a click, and opting out stops both.

How to stop being contacted

  • Use the unsubscribe link in any message you received. Every email sent through ExiReach carries a one-click unsubscribe (RFC 8058) and a link in the body. This suppresses you immediately and permanently.
  • Reply with the word unsubscribe — replies are scanned for opt-out intent and the sequence is stopped.
  • Email [email protected] to request erasure across all workspaces on the platform, not just the sender who contacted you.

You also have the right of access, rectification, erasure, restriction, and objection to processing in respect of this data, and the right to lodge a complaint with your local supervisory authority. Suppression records are retained after erasure for the sole purpose of ensuring you are not contacted again.

10. Website Visitors: Contact Form & Live Chat

Sections 2 to 9 describe data we handle on behalf of our clients, where we act as a processor. This section is different. When you use the contact form or the live chat on this website, Exicube App Solutions (OPC) Private Limited is the controller of the information you give us.

What we collect. The contact form asks for your email address and your message; your name, phone number and a subject line are optional. The chat widget asks for your name and email address before starting a conversation, and records the messages you send and any files you attach. In both cases our server also sees the IP address the request arrives from, which is used to rate-limit abuse of the form.

What we do with it. We use it to answer you, and to prepare a quote where you have asked for one. We run our own sales through the product we sell, so your enquiry is recorded in ExiReach's own workspace: a contact record with your message attached, a follow-up task for a member of our team, and an entry on our sales pipeline so your enquiry is not forgotten. A copy is emailed to [email protected]. It is never shared with our clients, added to an outreach campaign you did not ask to be part of, or sold.

How long we keep it. We keep your enquiry while we are dealing with it and afterwards as our record of the conversation. Live-chat transcripts are deleted automatically after 365 days. You can ask us to delete either sooner than that, at any time, and we will — see Section 8.

Who else is involved.Neither the form nor the chat widget is a third-party service: both are served from our own infrastructure. Nor are our page statistics, described in Section 11 — they are collected by software we run ourselves, on our own servers, and this site carries no advertising trackers and no third-party analytics. The only external party is the transactional email provider that delivers the notification to us, named in Section 6.

11. Cookies & Tracking Technologies

ExiReach uses essential cookies and session tokens to maintain user authentication, secure sessions, and preserve theme preferences (light/dark mode). We do not use intrusive cross-site ad tracking cookies.

Tracking inside outreach email is a separate thing from cookies, and it is described where it belongs — in Section 9, which is written for the people who receive that mail rather than for our customers. In short: a sequence message can carry an open pixel and rewritten links, the sender decides whether it does, and the footer of the message says so when it does.

Page statistics on our public pages. Our home, contact, privacy and terms pages count visits using Umami, analytics software we host ourselves on the same servers as the rest of the service — no data about your visit is sent to a third party. It sets no cookiesand stores nothing on your device. It records the page visited, the site that referred you, your country, and your browser and device type. It does not store your IP address or build a profile that follows you between visits: a visitor is identified only by a one-way hash that includes a secret which changes daily, so the same person returning tomorrow cannot be linked to today. Because nothing is stored on or read from your device and no profile is created, this needs no consent banner. The signed-in application — every dashboard and workspace page — carries no page analytics at all.

12. International Data Transfers

ExiReach is operated from India by Exicube App Solutions (OPC) Private Limited, and is hosted in data centres operated by our infrastructure providers in the European Union. Using the service therefore involves transferring personal data across borders.

Since 16 August 2026, hosting itself no longer takes personal data out of the EEA: the platform and its database run in Finland, and backups are held in Germany. AI inference is also inside the EEA — prompt content is processed in Stockholm, Sweden and web search runs in Ireland, as described in Section 6. The transfers that do remain are our US-based provider of transactional email — platform messages such as password resets and team invitations, never your outreach campaigns, which send from your own mailbox and domain — together with administrative access by our own personnel in India. For those, and for any other transfer out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical measures (encryption in transit and at rest, and access controls described in Section 7). A Data Processing Addendum incorporating those clauses is available on request from [email protected].

Invoicing is handled directly by Exicube App Solutions (OPC) Private Limited in India; no billing data is passed to a third-party merchant of record.

13. Privacy Contact & Data Controller

For questions, concerns, or data protection enquiries, contact us at:

Exicube App Solutions (OPC) Private Limited

3, Sreenagar, Madhyamgram

Kolkata - 700129, West Bengal, India

CIN: U74999WB2017OPC223198

Email: [email protected]

If you are in the EEA or the UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.