Privacy Policy
How Webdior Solutions Private Limited collects, uses and protects personal data when you use Outiy, visit our website, or appear in the business contact information our customers search.
Last updated 15 September 2026
Contents
1. Who we are and what this policy covers
Outiy (https://outiy.com) is a sales prospecting and outreach platform provided by Webdior Solutions Private Limited, a private limited company incorporated in India with its registered office at New Delhi, India (full registered address to be confirmed) ("Outiy", "we", "us", "our").
This policy explains what personal data we handle, why, on what legal basis, who we share it with, how long we keep it, and the rights you have. It applies to three groups of people:
- Customers and users — people who create an account, belong to an organisation that uses the product, or buy a plan.
- Website visitors — people who browse our marketing site, pricing, help centre or status page.
- Business contacts — professionals whose business contact details appear in the Outiy index, or who receive emails our customers send using Outiy.
If you are a business contact and want to know what we hold about you, or want to be removed, you can go straight to section 12. You do not need an account.
2. When we are a controller and when we are a processor
Data protection law treats an organisation differently depending on whether it decides why and how personal data is used (a controller) or uses it on someone else’s behalf and instructions (a processor). We are both, for different data:
| Data | Our role | Who you should contact first |
|---|---|---|
| Account, billing, support and security data about our customers and users | Controller | Us, at privacy@outiy.com |
| Website visitor data | Controller | Us, at privacy@outiy.com |
| The Outiy index of business contact information that we compile | Controller | Us, at privacy@outiy.com |
| Data a customer puts into their own workspace — leads they import or save, lists, notes, email content, campaign activity, replies, connected mailbox and calendar data | Processor, acting for the customer | The customer who contacted you. We will help them, and forward anything sent to us. |
When we act as a processor, our customers are responsible for having a lawful basis for their own use of the data and for their outreach. Our Data Processing Agreement governs that relationship.
3. The short version
- We only compile business contact information — work roles, work email addresses, company phone numbers and company facts — and we try hard not to collect anything else.
- Every person in our index can see what we hold, correct it or have it removed. Removal is permanent: we keep a one-way hash of the address so it is never collected again or emailed through our platform.
- Every email sent through our platform carries an unsubscribe link that works instantly, and the sender’s identity and postal address.
- We never sell customers’ own data, never use it for advertising, and never use it — or mailbox, calendar or email content — to train AI models.
- When a customer connects a mailbox, we read only replies and bounces to emails sent through us. When they connect a calendar, we store only meetings that include one of their leads.
- Our browser extension works in the customer’s own browser and their own LinkedIn session. We never see a LinkedIn password, and what it saves goes only into that customer’s own workspace.
- Our website uses no advertising or analytics cookies.
4. What we collect and where it comes from
4.1 Account and organisation information. Your name, work email address, password (stored only as a salted hash), two-factor authentication settings, profile preferences (language, theme, time zone), the organisations and workspaces you belong to and your role in them. If you sign in with Google or Microsoft single sign-on, we receive your name, email address and a unique account identifier from that provider.
4.2 Billing information. Company name, billing address, country, tax identifiers such as a VAT or GST number, the plan and add-ons you buy, invoices and payment status. Card and bank details are entered directly with our payment processor, Razorpay; we never see or store full card numbers. Charges are made by Webdior Solutions Private Limited and appear on statements as WEBDIOR SOLUTIONS PRIVATE LIMITED.
4.3 Usage, device and security information. IP address, browser and device type, pages and features used, timestamps, error reports, sign-in events, and an audit log of significant actions (for example, inviting a teammate, changing a role, exporting data). We use this to run, secure and improve the service.
4.4 Content customers add. Leads a customer imports or saves, lists, tags, notes, email templates and campaigns, deals and pipeline stages, the business profile in the AI Context Center, knowledge-base text used by Smart AI Reply, and files uploaded for import. We process this as a processor.
4.5 Connected mailboxes. A customer may connect a Gmail or Google Workspace mailbox (with an app password) or a Microsoft 365 or Outlook.com mailbox (with Microsoft sign-in). We use that connection to:
- send emails the customer has written or approved, from their own address;
- read message headers to recognise replies, automatic replies and bounces to emails sent through us; and
- download and store the body only of those replies and bounces.
We do not read, store or index other messages in the mailbox. Credentials and message bodies are encrypted at rest; message bodies are decrypted only when a user opens the conversation. Credentials are never shown to our staff and are deleted when the mailbox is disconnected.
4.6 Connected calendars. A user may connect a Google Calendar or Microsoft 365 calendar with read-only access. We read events to find meetings that include one of the workspace’s leads. For those meetings only, we store the title, start and end time, organiser and attendee email addresses, their responses, the location and the video-call link. Every other event is examined in memory during a sync and immediately discarded. We cannot create, change or delete anything in your calendar. Disconnecting deletes our access token.
4.7 The browser extension. A customer may install our browser extension. It runs in their own browser, in their own LinkedIn session, and we never receive or store their LinkedIn password. When they save someone, the extension sends us what that LinkedIn page was already showing them — name, headline, location, current and past roles, the company page it links to, and an email address or phone number only where the member has published it in their contact panel and the customer has opened it. That information is stored in that customer’s workspace, where we act as a processor on their instructions. It is not added to our own business contact index and no other customer sees it. We also record each action the extension takes on LinkedIn — an invitation, a message, a profile visit — with the person who took it, so the daily limits can be enforced and the customer can answer for what was sent from their account.
When a customer saves someone this way, they decide who to save and why: for that data they are the controller and we are their processor, and it is their responsibility to give the notice their law requires. We are the controller only for the record of extension activity described above.
4.8 Email engagement. If a customer turns on tracking for a campaign, emails include a small image and redirecting links that record when a message is opened or a link is clicked, together with the IP address and user agent of that request. We label opens that come from privacy proxies and security scanners so they are not counted as human opens. Unsubscribes, replies, bounces and spam complaints are recorded against the recipient so they are honoured in every future campaign.
4.9 The Outiy business contact index. We compile information about businesses and the professionals who work for them, so that customers can find relevant people to contact about their work. The index may contain:
| Category | Examples |
|---|---|
| Professional identity | Name, job title, seniority, department |
| Work contact details | Work email address and its verification status, business telephone number |
| Employer information | Company name, website, industry, size range, founding year, registered company number |
| Business location | City, region and country of the business or role |
| Public professional presence | Addresses of public business profiles, company social media pages, podcast or video channels |
| Company signals | Technologies a company’s own website uses; roles a company advertises on its own careers page |
This information comes from:
- Public websites — company websites and their contact, team and careers pages, read by our crawler, which identifies itself as
OutiyBot/1.0 (+https://outiy.com/bot)and respects robots.txt; - Public registers and directories — for example national company registries and business directories;
- Public business listings — map and local business listings;
- Public media feeds — podcast feeds and public channel pages where a host or owner has published business contact details;
- Licensed data providers — business data companies that supply professional information under contract and warrant that they may lawfully do so;
- Public profile pages — logged-out, publicly visible business profiles, collected only through contracted vendors. These sources are switched off for people in the EU and UK;
- Email verification — whether an address exists and accepts mail, checked without sending an email; and
- Our customers — where business contact details they import are added to or used to correct the index.
We do not intentionally collect, and take steps to exclude: special category data (such as health, religion, political opinions or sexual orientation), home addresses, personal photographs, private social media content, information about children, or inferences about sensitive characteristics. If we find such data, we delete it.
4.10 Support and communications. Messages you send us, support tickets, chat transcripts with our support assistant, call notes, and survey responses.
4.11 Website visitors. Standard server logs (IP address, browser, pages requested, referrer, time) kept for security and reliability. See our Cookie Policy.
5. How we use personal data, and our legal basis
Under the GDPR and UK GDPR we must have a legal basis for each use. The table below sets out our main purposes.
| Purpose | Data used | Legal basis (GDPR Article 6) |
|---|---|---|
| Create and run your account; provide the features you use | Account, billing, usage, content | Contract (6(1)(b)) |
| Take payment, issue invoices, keep accounting records | Billing | Contract; legal obligation (6(1)(c)) |
| Keep the service secure; prevent fraud, abuse and spam | Account, usage, security logs, email engagement | Legitimate interests (6(1)(f)); legal obligation |
| Enforce sending limits, suppression lists and country rules | Content, engagement, suppression data | Legitimate interests; legal obligation |
| Run the browser extension: save the people a customer chooses, and keep to the daily limits | Content the customer saves, extension activity | Contract (6(1)(b)); legitimate interests in keeping accounts within safe limits |
| Provide customer support | Account, support, usage | Contract; legitimate interests |
| Improve and develop the product, using aggregated or de-identified usage statistics | Usage | Legitimate interests |
| Send service messages (security alerts, billing notices, changes to terms) | Account | Contract; legal obligation |
| Send product news and offers to customers | Account | Legitimate interests, or consent where the law requires it. You can opt out at any time. |
| Compile the Outiy index and make business contact information available to customers for B2B prospecting | Business contact index | Legitimate interests — see section 6 |
| Respond to data subject requests and maintain the global suppression list | Request details, hashed email address | Legal obligation; legitimate interests |
| Comply with law, respond to lawful requests, establish or defend legal claims | Any relevant data | Legal obligation; legitimate interests |
6. Our legitimate interests in the business contact index
We rely on legitimate interests to compile the index and make it available to customers. Businesses have a genuine interest in finding and contacting other businesses that may need their products or services, and professionals regularly publish their work contact details for exactly that reason. We have carried out a legitimate interests assessment and apply these safeguards so that the balance is fair to the people in the index:
- Business information only. We limit the index to professional information connected with a person’s work.
- Transparency. This policy is public, and emails sent to people in the EU and UK include a short notice that their business details came from publicly available sources, with a link to a privacy notice, as Article 14 GDPR requires.
- Easy, permanent opt-out. Anyone can have their data removed. We keep a salted one-way hash of their email address on a platform-wide suppression list so it cannot be collected again or used to send email through our platform.
- Accuracy. Email addresses are verified before customers can send to them, and addresses taken from public profiles cannot be emailed until verification confirms them.
- Instant unsubscribe. Every email includes a working unsubscribe link and one-click unsubscribe headers that customers cannot remove, honoured within seconds.
- Country rules. Before every send, our platform applies country-specific rules — for example, in countries that require prior consent for marketing email, a send is blocked unless the customer records a lawful basis.
- No profiling with legal effects. Scores such as “fit” and “intent” only help a salesperson prioritise; they are never used to make decisions with legal or similarly significant effects on anyone.
You may object to this processing at any time. Because it is linked to direct marketing, your objection is absolute: we will stop. Contact privacy@outiy.com.
7. Artificial intelligence features
Outiy uses large language models to help customers write and translate emails, draft replies, read their own website to build a business profile, and answer support questions. The models are provided by Anthropic, OpenAI and Google through their business APIs.
- We send a model only the information needed for the task — for example, a lead’s name, company and role when drafting an email to that lead.
- Under our agreements with these providers, data sent through their APIs is not used to train their models.
- We keep a record of AI requests and responses for 90 days to investigate errors and abuse, then delete it.
- AI output can be wrong. The product shows drafts to a person before they are sent, unless a customer deliberately turns on automatic replies, which only send when strict conditions are met.
- We do not use customers’ content, mailbox data or calendar data to train AI models of our own.
9. International transfers
Webdior Solutions Private Limited is based in India, and our infrastructure and some service providers are located in the United States, the European Economic Area and other countries. These countries may not have data protection laws equivalent to those where you live.
When we transfer personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, we use appropriate safeguards, including:
- the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914);
- the UK International Data Transfer Addendum to those clauses;
- the equivalent Swiss arrangements; and
- the EU–US and UK–US data transfer frameworks, where a US provider is certified.
We assess the laws of the destination country and apply supplementary measures such as encryption where needed. You can request a copy of the relevant safeguards from privacy@outiy.com. Enterprise customers can choose to have their workspace data hosted in the EU.
10. How long we keep personal data
| Data | How long |
|---|---|
| Account and workspace data | For as long as the account is open. After an organisation is deleted, it is purged within 30 days. |
| Billing records and invoices | As long as tax and company law requires, currently up to eight years. |
| Pages fetched while building the index | 30 days |
| Business contact index facts | Until they are no longer considered current, plus 12 months — or until removal is requested |
| Hashed addresses on the global suppression list | Permanently, so a removal request keeps working |
| Email reply bodies from connected mailboxes | 180 days; the fact that a reply happened is kept for reporting |
| Meetings found in connected calendars | For as long as the workspace exists, or until deleted by the customer |
| AI requests and responses | 90 days |
| Email open and click events | 24 months, then kept only as aggregated counts |
| Audit logs | 2 years (Enterprise customers may configure up to 7) |
| Support tickets and chat transcripts | 3 years after the ticket is closed |
| Backups | 35 days on a rolling basis |
| Website server logs | 30 days |
We may keep data longer where required by law or to establish, exercise or defend legal claims.
11. How we protect personal data
- Encryption in transit (TLS) everywhere, and encryption at rest for our databases and storage.
- Mailbox credentials, calendar tokens, integration keys and email reply bodies are individually encrypted with AES-256-GCM envelope encryption and bound to their record, so a copied value cannot be decrypted elsewhere.
- Database-level row security separates every organisation’s data, and automated tests check that one organisation can never read another’s.
- Two-factor authentication, single sign-on, SCIM provisioning, custom roles and IP allowlists for customers who need them.
- Our staff tools show aggregate information only. Viewing a customer’s account for support requires a written reason, is time-limited, is read-only by default, and is recorded in that customer’s own audit log.
- Least-privilege access, secret management, dependency and vulnerability scanning, and regular security testing.
No system is perfectly secure. If a personal data breach affects you, we will notify the relevant supervisory authority within 72 hours where required, and tell affected customers and individuals without undue delay. Report security issues to security@outiy.com.
12. Your rights
If you are in the EEA, the UK or Switzerland — and in many other places — you have the right to:
- Access the personal data we hold about you and receive a copy, including, for the business contact index, the categories of source it came from;
- Correct data that is inaccurate or incomplete;
- Erase your data;
- Restrict our use of your data while a concern is resolved;
- Object to our use of your data based on legitimate interests — including, at any time and without giving a reason, to direct marketing;
- Port data you gave us, in a machine-readable format;
- Withdraw consent where we rely on it, without affecting earlier processing; and
- Complain to a supervisory authority — in the EU, the authority where you live or work; in the UK, the Information Commissioner’s Office (ico.org.uk).
How to make a request.
- Use our privacy request page to see, erase or object to the data we hold about an address, or email privacy@outiy.com from the address the request concerns.
- We confirm you control that address by sending a link to it, so we never give your data to someone else.
- We respond within one month. For complex requests we may extend this by up to two further months and will tell you why.
Requests are free unless they are clearly unfounded or excessive.
If you are in the business contact index and ask us to remove you, we delete your record from the index, add a salted hash of your email address to our global suppression list so you are never collected again or emailed through our platform, and mark any copies customers have saved as suppressed. Customers who saved your details are controllers of their own copies; we tell them about your request so they can respond to it too.
If a customer’s workspace holds your data — for example, because they imported you from their own records — we are that customer’s processor. You can contact them directly; if you contact us, we will pass your request on and help them respond.
13. Additional information for US residents
Residents of California and other US states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas and Oregon) have rights to know what personal information we collect, use, disclose and “sell” or “share”; to access and delete it; to correct inaccuracies; and to opt out of its sale or sharing and of targeted advertising. We will not discriminate against you for exercising these rights.
| Category of personal information | Collected in the last 12 months | Disclosed to |
|---|---|---|
| Identifiers (name, email, IP address, account ID) | Yes | Service providers; customers (business contact index only) |
| Professional or employment information | Yes | Service providers; customers (business contact index only) |
| Commercial information (plans, purchases) | Yes | Service providers (payments) |
| Internet or network activity (usage, email engagement) | Yes | Service providers; the customer who sent the email |
| Inferences (fit and intent scores for sales prioritisation) | Yes | Customers |
| Sensitive personal information | No, other than account passwords, which are stored only as a hash | — |
We do not use or disclose sensitive personal information for purposes that require a right to limit. To exercise any right, including opting out of the sale or sharing of business contact information in the index, email privacy@outiy.com with the subject "Do Not Sell or Share". An authorised agent may make a request for you with your signed permission. Our website does not sell or share visitor data, so a Global Privacy Control signal from your browser needs no further action; to opt out of the index, use the email above.
We do not knowingly sell or share the personal information of consumers under 16.
14. Additional information for Australian residents
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). You can ask to access or correct your personal information, or complain about how we have handled it, by contacting privacy@outiy.com. We will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
15. Children
Our services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal data from children, and we exclude profiles that indicate the person is under 18. If you believe we hold data about a child, contact us and we will delete it.
16. Marketing from us
We may send customers and people who signed up on our website news about Outiy. Every such email has an unsubscribe link. You can also email privacy@outiy.com. Service messages about your account, security or billing are not marketing and will still be sent.
17. Changes to this policy
We update this policy when our practices or the law change. The date at the top shows when it last changed. If a change is significant, we will notify customers by email or in the product at least 30 days before it takes effect.
18. Contact us
| Controller | Webdior Solutions Private Limited, New Delhi, India (full registered address to be confirmed) |
| Company identification number | to be confirmed |
| Privacy enquiries and requests | privacy@outiy.com |
| Data protection contact | our privacy team at privacy@outiy.com |
| EU representative (GDPR Article 27) | to be confirmed |
| UK representative (UK GDPR Article 27) | to be confirmed |
| Security reports | security@outiy.com |