Outiy

Privacy Policy

How Webdior Solutions Private Limited collects, uses and protects personal data when you use Outiy, visit our website, or appear in the business contact information our customers search.

Last updated 15 September 2026

Contents

1. Who we are and what this policy covers

Outiy (https://outiy.com) is a sales prospecting and outreach platform provided by Webdior Solutions Private Limited, a private limited company incorporated in India with its registered office at New Delhi, India (full registered address to be confirmed) ("Outiy", "we", "us", "our").

This policy explains what personal data we handle, why, on what legal basis, who we share it with, how long we keep it, and the rights you have. It applies to three groups of people:

  • Customers and users — people who create an account, belong to an organisation that uses the product, or buy a plan.
  • Website visitors — people who browse our marketing site, pricing, help centre or status page.
  • Business contacts — professionals whose business contact details appear in the Outiy index, or who receive emails our customers send using Outiy.

If you are a business contact and want to know what we hold about you, or want to be removed, you can go straight to section 12. You do not need an account.

We have written this policy in plain language. Where a term has a specific legal meaning — "controller", "processor", "personal data" — it has the meaning given in the EU General Data Protection Regulation (GDPR) and the UK GDPR.

2. When we are a controller and when we are a processor

Data protection law treats an organisation differently depending on whether it decides why and how personal data is used (a controller) or uses it on someone else’s behalf and instructions (a processor). We are both, for different data:

DataOur roleWho you should contact first
Account, billing, support and security data about our customers and usersControllerUs, at privacy@outiy.com
Website visitor dataControllerUs, at privacy@outiy.com
The Outiy index of business contact information that we compileControllerUs, at privacy@outiy.com
Data a customer puts into their own workspace — leads they import or save, lists, notes, email content, campaign activity, replies, connected mailbox and calendar dataProcessor, acting for the customerThe customer who contacted you. We will help them, and forward anything sent to us.

When we act as a processor, our customers are responsible for having a lawful basis for their own use of the data and for their outreach. Our Data Processing Agreement governs that relationship.

3. The short version

  • We only compile business contact information — work roles, work email addresses, company phone numbers and company facts — and we try hard not to collect anything else.
  • Every person in our index can see what we hold, correct it or have it removed. Removal is permanent: we keep a one-way hash of the address so it is never collected again or emailed through our platform.
  • Every email sent through our platform carries an unsubscribe link that works instantly, and the sender’s identity and postal address.
  • We never sell customers’ own data, never use it for advertising, and never use it — or mailbox, calendar or email content — to train AI models.
  • When a customer connects a mailbox, we read only replies and bounces to emails sent through us. When they connect a calendar, we store only meetings that include one of their leads.
  • Our browser extension works in the customer’s own browser and their own LinkedIn session. We never see a LinkedIn password, and what it saves goes only into that customer’s own workspace.
  • Our website uses no advertising or analytics cookies.

4. What we collect and where it comes from

4.1 Account and organisation information. Your name, work email address, password (stored only as a salted hash), two-factor authentication settings, profile preferences (language, theme, time zone), the organisations and workspaces you belong to and your role in them. If you sign in with Google or Microsoft single sign-on, we receive your name, email address and a unique account identifier from that provider.

4.2 Billing information. Company name, billing address, country, tax identifiers such as a VAT or GST number, the plan and add-ons you buy, invoices and payment status. Card and bank details are entered directly with our payment processor, Razorpay; we never see or store full card numbers. Charges are made by Webdior Solutions Private Limited and appear on statements as WEBDIOR SOLUTIONS PRIVATE LIMITED.

4.3 Usage, device and security information. IP address, browser and device type, pages and features used, timestamps, error reports, sign-in events, and an audit log of significant actions (for example, inviting a teammate, changing a role, exporting data). We use this to run, secure and improve the service.

4.4 Content customers add. Leads a customer imports or saves, lists, tags, notes, email templates and campaigns, deals and pipeline stages, the business profile in the AI Context Center, knowledge-base text used by Smart AI Reply, and files uploaded for import. We process this as a processor.

4.5 Connected mailboxes. A customer may connect a Gmail or Google Workspace mailbox (with an app password) or a Microsoft 365 or Outlook.com mailbox (with Microsoft sign-in). We use that connection to:

  • send emails the customer has written or approved, from their own address;
  • read message headers to recognise replies, automatic replies and bounces to emails sent through us; and
  • download and store the body only of those replies and bounces.

We do not read, store or index other messages in the mailbox. Credentials and message bodies are encrypted at rest; message bodies are decrypted only when a user opens the conversation. Credentials are never shown to our staff and are deleted when the mailbox is disconnected.

4.6 Connected calendars. A user may connect a Google Calendar or Microsoft 365 calendar with read-only access. We read events to find meetings that include one of the workspace’s leads. For those meetings only, we store the title, start and end time, organiser and attendee email addresses, their responses, the location and the video-call link. Every other event is examined in memory during a sync and immediately discarded. We cannot create, change or delete anything in your calendar. Disconnecting deletes our access token.

Google user data. Outiy’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail and Google Calendar data only to provide the features described above, never for advertising, never to train generalised AI models, and we do not allow humans to read it except with the user’s explicit consent, for security purposes, or where required by law.

4.7 The browser extension. A customer may install our browser extension. It runs in their own browser, in their own LinkedIn session, and we never receive or store their LinkedIn password. When they save someone, the extension sends us what that LinkedIn page was already showing them — name, headline, location, current and past roles, the company page it links to, and an email address or phone number only where the member has published it in their contact panel and the customer has opened it. That information is stored in that customer’s workspace, where we act as a processor on their instructions. It is not added to our own business contact index and no other customer sees it. We also record each action the extension takes on LinkedIn — an invitation, a message, a profile visit — with the person who took it, so the daily limits can be enforced and the customer can answer for what was sent from their account.

When a customer saves someone this way, they decide who to save and why: for that data they are the controller and we are their processor, and it is their responsibility to give the notice their law requires. We are the controller only for the record of extension activity described above.

4.8 Email engagement. If a customer turns on tracking for a campaign, emails include a small image and redirecting links that record when a message is opened or a link is clicked, together with the IP address and user agent of that request. We label opens that come from privacy proxies and security scanners so they are not counted as human opens. Unsubscribes, replies, bounces and spam complaints are recorded against the recipient so they are honoured in every future campaign.

4.9 The Outiy business contact index. We compile information about businesses and the professionals who work for them, so that customers can find relevant people to contact about their work. The index may contain:

CategoryExamples
Professional identityName, job title, seniority, department
Work contact detailsWork email address and its verification status, business telephone number
Employer informationCompany name, website, industry, size range, founding year, registered company number
Business locationCity, region and country of the business or role
Public professional presenceAddresses of public business profiles, company social media pages, podcast or video channels
Company signalsTechnologies a company’s own website uses; roles a company advertises on its own careers page

This information comes from:

  • Public websites — company websites and their contact, team and careers pages, read by our crawler, which identifies itself as OutiyBot/1.0 (+https://outiy.com/bot) and respects robots.txt;
  • Public registers and directories — for example national company registries and business directories;
  • Public business listings — map and local business listings;
  • Public media feeds — podcast feeds and public channel pages where a host or owner has published business contact details;
  • Licensed data providers — business data companies that supply professional information under contract and warrant that they may lawfully do so;
  • Public profile pages — logged-out, publicly visible business profiles, collected only through contracted vendors. These sources are switched off for people in the EU and UK;
  • Email verification — whether an address exists and accepts mail, checked without sending an email; and
  • Our customers — where business contact details they import are added to or used to correct the index.

We do not intentionally collect, and take steps to exclude: special category data (such as health, religion, political opinions or sexual orientation), home addresses, personal photographs, private social media content, information about children, or inferences about sensitive characteristics. If we find such data, we delete it.

4.10 Support and communications. Messages you send us, support tickets, chat transcripts with our support assistant, call notes, and survey responses.

4.11 Website visitors. Standard server logs (IP address, browser, pages requested, referrer, time) kept for security and reliability. See our Cookie Policy.

5. How we use personal data, and our legal basis

Under the GDPR and UK GDPR we must have a legal basis for each use. The table below sets out our main purposes.

PurposeData usedLegal basis (GDPR Article 6)
Create and run your account; provide the features you useAccount, billing, usage, contentContract (6(1)(b))
Take payment, issue invoices, keep accounting recordsBillingContract; legal obligation (6(1)(c))
Keep the service secure; prevent fraud, abuse and spamAccount, usage, security logs, email engagementLegitimate interests (6(1)(f)); legal obligation
Enforce sending limits, suppression lists and country rulesContent, engagement, suppression dataLegitimate interests; legal obligation
Run the browser extension: save the people a customer chooses, and keep to the daily limitsContent the customer saves, extension activityContract (6(1)(b)); legitimate interests in keeping accounts within safe limits
Provide customer supportAccount, support, usageContract; legitimate interests
Improve and develop the product, using aggregated or de-identified usage statisticsUsageLegitimate interests
Send service messages (security alerts, billing notices, changes to terms)AccountContract; legal obligation
Send product news and offers to customersAccountLegitimate interests, or consent where the law requires it. You can opt out at any time.
Compile the Outiy index and make business contact information available to customers for B2B prospectingBusiness contact indexLegitimate interests — see section 6
Respond to data subject requests and maintain the global suppression listRequest details, hashed email addressLegal obligation; legitimate interests
Comply with law, respond to lawful requests, establish or defend legal claimsAny relevant dataLegal obligation; legitimate interests

6. Our legitimate interests in the business contact index

We rely on legitimate interests to compile the index and make it available to customers. Businesses have a genuine interest in finding and contacting other businesses that may need their products or services, and professionals regularly publish their work contact details for exactly that reason. We have carried out a legitimate interests assessment and apply these safeguards so that the balance is fair to the people in the index:

  • Business information only. We limit the index to professional information connected with a person’s work.
  • Transparency. This policy is public, and emails sent to people in the EU and UK include a short notice that their business details came from publicly available sources, with a link to a privacy notice, as Article 14 GDPR requires.
  • Easy, permanent opt-out. Anyone can have their data removed. We keep a salted one-way hash of their email address on a platform-wide suppression list so it cannot be collected again or used to send email through our platform.
  • Accuracy. Email addresses are verified before customers can send to them, and addresses taken from public profiles cannot be emailed until verification confirms them.
  • Instant unsubscribe. Every email includes a working unsubscribe link and one-click unsubscribe headers that customers cannot remove, honoured within seconds.
  • Country rules. Before every send, our platform applies country-specific rules — for example, in countries that require prior consent for marketing email, a send is blocked unless the customer records a lawful basis.
  • No profiling with legal effects. Scores such as “fit” and “intent” only help a salesperson prioritise; they are never used to make decisions with legal or similarly significant effects on anyone.

You may object to this processing at any time. Because it is linked to direct marketing, your objection is absolute: we will stop. Contact privacy@outiy.com.

7. Artificial intelligence features

Outiy uses large language models to help customers write and translate emails, draft replies, read their own website to build a business profile, and answer support questions. The models are provided by Anthropic, OpenAI and Google through their business APIs.

  • We send a model only the information needed for the task — for example, a lead’s name, company and role when drafting an email to that lead.
  • Under our agreements with these providers, data sent through their APIs is not used to train their models.
  • We keep a record of AI requests and responses for 90 days to investigate errors and abuse, then delete it.
  • AI output can be wrong. The product shows drafts to a person before they are sent, unless a customer deliberately turns on automatic replies, which only send when strict conditions are met.
  • We do not use customers’ content, mailbox data or calendar data to train AI models of our own.

8. Who we share personal data with

  • Service providers (sub-processors) who host our infrastructure, process payments, verify email addresses, supply data or provide AI models, under contracts that require confidentiality and security. The current list is on our Sub-processors page.
  • Customers. Customers who search the Outiy index receive business contact information about the people they find. We never tell customers which specific source a piece of information came from; we tell only the person it is about, if they ask.
  • Integrations a customer turns on, such as a CRM, Slack, Microsoft Teams or an automation platform. Data goes only where the customer directs it.
  • Professional advisers such as lawyers, auditors and insurers, under confidentiality obligations.
  • Authorities when we are legally required to, or where necessary to protect the rights, safety or property of our users, the public or us. We push back on requests that are not legally valid.
  • A buyer or successor if we are involved in a merger, acquisition or sale of assets, subject to this policy.

We do not sell customers’ personal data. Making business contact information in the index available to customers may count as “selling” or “sharing” personal data under some US state laws; see section 13 for how to opt out.

9. International transfers

Webdior Solutions Private Limited is based in India, and our infrastructure and some service providers are located in the United States, the European Economic Area and other countries. These countries may not have data protection laws equivalent to those where you live.

When we transfer personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, we use appropriate safeguards, including:

  • the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914);
  • the UK International Data Transfer Addendum to those clauses;
  • the equivalent Swiss arrangements; and
  • the EU–US and UK–US data transfer frameworks, where a US provider is certified.

We assess the laws of the destination country and apply supplementary measures such as encryption where needed. You can request a copy of the relevant safeguards from privacy@outiy.com. Enterprise customers can choose to have their workspace data hosted in the EU.

10. How long we keep personal data

DataHow long
Account and workspace dataFor as long as the account is open. After an organisation is deleted, it is purged within 30 days.
Billing records and invoicesAs long as tax and company law requires, currently up to eight years.
Pages fetched while building the index30 days
Business contact index factsUntil they are no longer considered current, plus 12 months — or until removal is requested
Hashed addresses on the global suppression listPermanently, so a removal request keeps working
Email reply bodies from connected mailboxes180 days; the fact that a reply happened is kept for reporting
Meetings found in connected calendarsFor as long as the workspace exists, or until deleted by the customer
AI requests and responses90 days
Email open and click events24 months, then kept only as aggregated counts
Audit logs2 years (Enterprise customers may configure up to 7)
Support tickets and chat transcripts3 years after the ticket is closed
Backups35 days on a rolling basis
Website server logs30 days

We may keep data longer where required by law or to establish, exercise or defend legal claims.

11. How we protect personal data

  • Encryption in transit (TLS) everywhere, and encryption at rest for our databases and storage.
  • Mailbox credentials, calendar tokens, integration keys and email reply bodies are individually encrypted with AES-256-GCM envelope encryption and bound to their record, so a copied value cannot be decrypted elsewhere.
  • Database-level row security separates every organisation’s data, and automated tests check that one organisation can never read another’s.
  • Two-factor authentication, single sign-on, SCIM provisioning, custom roles and IP allowlists for customers who need them.
  • Our staff tools show aggregate information only. Viewing a customer’s account for support requires a written reason, is time-limited, is read-only by default, and is recorded in that customer’s own audit log.
  • Least-privilege access, secret management, dependency and vulnerability scanning, and regular security testing.

No system is perfectly secure. If a personal data breach affects you, we will notify the relevant supervisory authority within 72 hours where required, and tell affected customers and individuals without undue delay. Report security issues to security@outiy.com.

12. Your rights

If you are in the EEA, the UK or Switzerland — and in many other places — you have the right to:

  • Access the personal data we hold about you and receive a copy, including, for the business contact index, the categories of source it came from;
  • Correct data that is inaccurate or incomplete;
  • Erase your data;
  • Restrict our use of your data while a concern is resolved;
  • Object to our use of your data based on legitimate interests — including, at any time and without giving a reason, to direct marketing;
  • Port data you gave us, in a machine-readable format;
  • Withdraw consent where we rely on it, without affecting earlier processing; and
  • Complain to a supervisory authority — in the EU, the authority where you live or work; in the UK, the Information Commissioner’s Office (ico.org.uk).

How to make a request.

  1. Use our privacy request page to see, erase or object to the data we hold about an address, or email privacy@outiy.com from the address the request concerns.
  2. We confirm you control that address by sending a link to it, so we never give your data to someone else.
  3. We respond within one month. For complex requests we may extend this by up to two further months and will tell you why.

Requests are free unless they are clearly unfounded or excessive.

If you are in the business contact index and ask us to remove you, we delete your record from the index, add a salted hash of your email address to our global suppression list so you are never collected again or emailed through our platform, and mark any copies customers have saved as suppressed. Customers who saved your details are controllers of their own copies; we tell them about your request so they can respond to it too.

If a customer’s workspace holds your data — for example, because they imported you from their own records — we are that customer’s processor. You can contact them directly; if you contact us, we will pass your request on and help them respond.

13. Additional information for US residents

Residents of California and other US states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas and Oregon) have rights to know what personal information we collect, use, disclose and “sell” or “share”; to access and delete it; to correct inaccuracies; and to opt out of its sale or sharing and of targeted advertising. We will not discriminate against you for exercising these rights.

Category of personal informationCollected in the last 12 monthsDisclosed to
Identifiers (name, email, IP address, account ID)YesService providers; customers (business contact index only)
Professional or employment informationYesService providers; customers (business contact index only)
Commercial information (plans, purchases)YesService providers (payments)
Internet or network activity (usage, email engagement)YesService providers; the customer who sent the email
Inferences (fit and intent scores for sales prioritisation)YesCustomers
Sensitive personal informationNo, other than account passwords, which are stored only as a hash—

We do not use or disclose sensitive personal information for purposes that require a right to limit. To exercise any right, including opting out of the sale or sharing of business contact information in the index, email privacy@outiy.com with the subject "Do Not Sell or Share". An authorised agent may make a request for you with your signed permission. Our website does not sell or share visitor data, so a Global Privacy Control signal from your browser needs no further action; to opt out of the index, use the email above.

We do not knowingly sell or share the personal information of consumers under 16.

14. Additional information for Australian residents

We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). You can ask to access or correct your personal information, or complain about how we have handled it, by contacting privacy@outiy.com. We will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

15. Children

Our services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal data from children, and we exclude profiles that indicate the person is under 18. If you believe we hold data about a child, contact us and we will delete it.

16. Marketing from us

We may send customers and people who signed up on our website news about Outiy. Every such email has an unsubscribe link. You can also email privacy@outiy.com. Service messages about your account, security or billing are not marketing and will still be sent.

17. Changes to this policy

We update this policy when our practices or the law change. The date at the top shows when it last changed. If a change is significant, we will notify customers by email or in the product at least 30 days before it takes effect.

18. Contact us

ControllerWebdior Solutions Private Limited, New Delhi, India (full registered address to be confirmed)
Company identification numberto be confirmed
Privacy enquiries and requestsprivacy@outiy.com
Data protection contactour privacy team at privacy@outiy.com
EU representative (GDPR Article 27)to be confirmed
UK representative (UK GDPR Article 27)to be confirmed
Security reportssecurity@outiy.com