Skip to content
All policies

Data Processing Addendum

Last updated 4 July 2026

This addendum covers the personal data outr processes on your behalf when you run outreach: the leads you target and the replies they send. It meets the requirements of Article 28 of the GDPR, the equivalent UK GDPR provisions, and other data protection laws where they apply. It is part of your agreement with outr, and if it ever conflicts with the rest of that agreement on a data protection point, this addendum wins.

1. The two roles we play

outr is an AI agent that builds and runs B2B cold email. It sources leads to your criteria, drafts an email sequence, sets up the sending inboxes and domains, and, only after you approve, launches sending and tracks replies. Nothing goes to anyone until you review the campaign and click Approve and launch.

There are two kinds of personal data here, and our legal role is different for each. We are straight with you about both.

Your account data. The personal data of you and your team: account, billing, business profile, agent chats, and usage records. For this we are the controller, and our Privacy Policy explains how we handle it. This addendum does not change that.

Lead and reply data. The personal data of the prospects you target, and the replies they send back. You decide who to contact and why, so you are the controller. For most of what we do with that data, we act as your processor and follow your instructions. This addendum governs that processing.

One honest point (worth reading)

Roles under the GDPR follow what a party actually does, not the label a contract puts on it. Because we choose and run the tool that finds the leads, run that search on your instruction, provide the AI that drafts the copy, and run the shared sending setup, a regulator or court could decide we are a controller, or joint controller, for parts of the lead lifecycle, especially finding the leads and any use of data to improve outr. So:

  • for processing we do on your instructions (storing lead data, drafting copy to your brief, sending on your approval, routing replies, reporting engagement), we are your processor, and Sections 3 to 12 apply to us as processor;
  • for processing where we might be found to be a controller or joint controller (lead acquisition through our lead-sourcing provider, and any product-improvement use), each party is responsible for its own obligations, and Section 13 applies; and
  • nothing here makes you solely liable for our own processing, and nothing shifts to you the obligations the law puts on us as processor or possible controller. Each of us follows the data protection law that applies to our own role.

Your instructions

Your instructions to us as processor are: the agreement, this addendum, and how you actually use outr (the criteria you set, the leads and copy you approve, and your in-product settings). Any extra instruction has to be agreed in writing. If we think an instruction breaks the GDPR or other data protection law, we will tell you.

The approval gate

You alone decide who gets contacted and what is said. outr sources leads to your criteria and drafts copy for you, but every campaign starts as a draft, and nothing sends until you review it and click Approve and launch. We run your approved instructions; we do not pick the audience or the content on our own. That is simply how outr works.

2. What the processing covers

The full Article 28(3) particulars are in Annex I. In short: we process lead and reply personal data to run the outreach service for you; we do it for as long as the agreement lasts, plus the retention and deletion periods in Section 10 and our Data Retention Schedule; and the work is lead sourcing, storage, AI-assisted drafting, sending on your approval, and reply handling. The types of personal data and the categories of people are listed in Annex I.

3. We process only on your instructions

We process lead and reply personal data only on your documented instructions, including for any international transfer, unless a law we are subject to requires otherwise. If a law does require it, we will tell you before we process, unless that law bans us from telling you on important public-interest grounds.

We do not use lead or reply data for our own purposes, except a use we have disclosed to you that fits our role. Any use of data to improve outr is covered in Section 13, and we do not treat it as something you are solely responsible for.

4. Confidentiality

Everyone we let near this data is bound to keep it confidential, either by agreement or by law. Access is limited to the people who need it to run, support, or secure outr.

5. Security (Article 32)

We put appropriate technical and organizational measures in place to keep the data secure at a level that fits the risk, taking into account the state of the art, the cost, the nature of the processing, and the risk to people.

The measures are described in Annex II and in our Security Statement, which is part of this addendum by reference. They include keeping each customer's data isolated with row-level security, encryption in transit and at rest, restricting sensitive writes to service-role access, secret management, constant-time comparison of automation secrets, verifying webhook signatures, rate limiting, and spend controls. We can update the measures over time as long as security is not materially weakened.

You are responsible for keeping your own login safe and for choosing settings that suit how you use outr.

6. Sub-processors

General permission. You give us general written permission to use sub-processors to process lead and reply personal data so we can run outr. The ones in place at the effective date are listed in Annex III, with more detail in our Sub-processor List.

Flow-down. When we bring in a sub-processor, we put it under a written contract with data protection obligations that are, in substance, at least as protective as this addendum, in particular the duty to apply appropriate technical and organizational measures. If a sub-processor fails to meet its obligations, we stay fully liable to you for what it does.

Changes and objection. We will give you at least thirty (30) days' notice before we add or swap a sub-processor that handles lead and reply data, by updating the Sub-processor List and, if you have subscribed to notifications, by telling you. You can object on reasonable data protection grounds within that window. If you object, we will work with you in good faith to sort it out; if we cannot, your only remedy is to end the affected part of the service under the agreement.

7. Helping with data-subject requests

Taking into account the nature of the processing, we help you meet your duty to respond to people exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection), as far as we reasonably can.

If someone (including a lead or a recipient) sends a request straight to us about data we process for you, we will promptly tell you and will not answer it ourselves except on your instructions, unless the law requires us to act, or unless we have to answer in our own right as a possible controller for lead acquisition (see Section 13).

Self-serve tools for lead-level and reply-level requests are not built into outr yet, so for now our team handles this work by hand under our internal privacy-request procedure. We will do it within a reasonable time that fits the response deadlines that apply to you.

8. Helping with Articles 32 to 36

Taking into account how the processing works and what we know, we help you meet your obligations under Articles 32 to 36 of the GDPR: security of processing, notifying a personal data breach, telling data subjects about a breach, data protection impact assessments, and prior consultation with a supervisory authority.

9. Data breach notification

We tell you without undue delay once we become aware of a personal data breach affecting lead or reply data we process for you.

Our notice will set out, as far as we know it and as we learn more, the nature of the breach, the categories and rough number of people and records affected, the likely consequences, and what we have done or plan to do about it. We will cooperate with you and take reasonable steps to contain and fix it.

Telling you about a breach, or responding to one, is not us admitting fault or liability.

10. Deletion or return when we are done

When the agreement ends, we delete or return the lead and reply personal data we processed for you, whichever you choose, and delete any copies, unless a law requires us to keep it.

How deletion actually works. You can delete your account any time from account settings. Deleting it pauses all campaigns, detaches and releases your inboxes, cancels subscriptions, and then deletes your authentication record, which cascades to your profile, subscriptions, business context, agent memory, campaigns, leads, agent tasks, credit ledger, sending-account records, inbox messages, email accounts, usage events, and chat messages. Deletion is logged and permanent. Our Data Retention Schedule and Privacy Policy describe this in more detail.

What survives, and residual copies. A few operational and security records that do not identify you (for example audit-log entries, error logs, automated-job records, aggregate business snapshots, and inbox-health snapshots), plus inbox-scrub ledger rows with the account link removed, are kept as set out in the Data Retention Schedule. On top of that, our email-sending provider keeps its own record of campaigns and lead lists on its side after we delete ours; you may need to ask that provider to delete it separately, and we will help you. Data can also sit in routine backups for a limited time before it is overwritten, as the Data Retention Schedule explains.

11. Audits and information

We give you the information you need to show we are meeting our Article 28 and addendum obligations, and we allow for and contribute to audits, including inspections, run by you or an auditor you appoint.

To protect our systems and other customers' data, audits come with reasonable conditions: reasonable prior notice, no more than once in any twelve-month period unless a supervisory authority requires it or a material breach happens, during normal business hours, without unreasonable disruption, and under confidentiality. We can meet an audit request by giving you our current security documentation, sub-processor agreements, and any third-party certifications or reports we hold.

Each side covers its own audit costs, except that you reimburse our reasonable costs for help that goes beyond handing over standard documentation.

12. Your promises as controller

For lead and reply personal data, you promise and undertake that:

  • you act as a controller and have decided the purpose and means of the outreach, including who is contacted and what is said;
  • you have a valid lawful basis under Article 6 of the GDPR (or the equivalent under the UK GDPR or other law that applies) for the processing you instruct, and you hold any consent needed under the GDPR, the ePrivacy rules, or applicable national law;
  • you give us, and instruct us to process, only personal data you obtained lawfully and are entitled to process, and you do not instruct outreach to consumers, to purchased or rented lists, or in breach of anti-spam or electronic-marketing law (for example the US CAN-SPAM Act, Canada's Anti-Spam Legislation (CASL), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and Member-State ePrivacy rules), and you follow every law that applies to you and to your recipients wherever they are;
  • when we source leads, we are carrying out your instruction to find contacts matching the criteria you set for your own approved campaign, and you confirm you have a lawful basis and the right to contact that audience;
  • you give data subjects any transparency information they are owed and you honor opt-outs and objections;
  • your instructions to us comply with applicable data protection law; and
  • you will indemnify us for third-party claims arising from your breach of this Section, on the terms of the agreement, understanding (per Section 13.4) that an indemnity settles things between you and us and is not a defense against a regulator or a data subject who comes after us directly.

13. Independent or joint controllership, and who is responsible

For processing where we might be found to be a controller or joint controller (lead acquisition through our lead-sourcing provider, and any product-improvement use), each party is responsible for the obligations that apply to it in that role, including giving any required transparency information and answering data-subject requests aimed at it.

We will cooperate in good faith to give effect to people's rights and to respond to supervisory authorities on any processing we jointly determine.

This addendum does not try to settle by contract a role that the law assigns by conduct. Where the law treats a party as a controller for a given operation, that party's obligations apply regardless of the labels used here.

Any indemnity in the agreement or this addendum is about who recovers from whom between you and us. It does not limit, exclude, or transfer the direct legal liability either party owes to a supervisory authority or to a data subject.

14. International transfers

Several of our sub-processors sit outside the European Economic Area, including in the United States. When personal data goes to a country without an adequacy decision, we make the transfer under appropriate safeguards: the Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914), or another valid mechanism such as certification under the EU-US Data Privacy Framework where it applies, plus any extra measures needed. For transfers under the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies.

Where the Standard Contractual Clauses apply between us, they are part of this addendum by reference; the module that fits our roles applies, and the details needed to complete them come from Annexes I to III. For onward transfers to sub-processors, we make sure an equivalent mechanism is in place with each one.

The transfer mechanism for each sub-processor, and the region where it processes data, are in our Sub-processor List.

15. Liability and how this fits the agreement

Each party's liability under this addendum is subject to the limits and exclusions in the agreement, and any reference to a party's liability means its total liability across the agreement and this addendum together.

That does not limit either party's liability where the law does not allow it, including liability that cannot be limited under the GDPR or toward a data subject, and liability for a party's own fraud, willful misconduct, or gross negligence.

Nothing here relieves either party of its own obligations and liabilities under the GDPR toward data subjects and supervisory authorities.

16. General

This addendum takes effect on the effective date and lasts as long as we process lead and reply personal data for you.

It is governed by the same law as the agreement: the laws of the European Union and of the country where outr is based, without its conflict-of-law rules. If you are a consumer, you also keep the protection of the mandatory laws where you live. This is subject to any different requirement of the Standard Contractual Clauses where they apply.

If any part of this addendum is held invalid or unenforceable, the rest still stands, and the invalid part is replaced by a valid one that comes closest to its intent.

Questions about this addendum: support@tryoutr.io.

Annex I: Details of processing

A. Subject-matter. Running outr: sourcing, storing, AI-assisted drafting, approval-gated sending, and reply handling of B2B cold-email outreach on your instructions.

B. Duration. The term of the agreement, then deletion or return under Section 10 and the Data Retention Schedule.

C. Nature and purpose. Collecting or sourcing lead records to your criteria; storing them; generating draft email sequences, follow-ups, and reply drafts with an AI model; setting up and configuring sending inboxes and domains; sending campaigns only after you approve; routing and storing replies; and reporting engagement stats.

D. Types of personal data.

  • Lead and recipient contact data: business email address, first name, last name, full name, job title, company name, LinkedIn profile URL, and country.
  • Lead metadata: status, score, source (manual, sourced, or CSV), and the sourcing-run identifier.
  • Reply content: the subject, body, and preview of a prospect's reply, a derived category (for example interested, meeting, question, or not-now), read and answered timestamps, and the full reply payload we receive from our email-sending provider.
  • Campaign content that may contain personal data: campaign name, audience description, and the draft and sent sequence copy.

E. Categories of data subjects.

  • The prospects and business contacts you choose to target through outr.
  • The people who reply to your campaigns.

F. Controller and processor. You are the controller. outr is the processor, subject to the honest role caveat in Sections 1 and 13 for lead acquisition and product-improvement processing.

Your own account data (account, billing, business profile, agent chats, and usage) is processed by outr as a controller under our Privacy Policy and is not covered by this Annex.

Annex II: Technical and organizational security measures

These are in summary; the fuller, current description is in our Security Statement, which is part of this addendum by reference.

  • Isolation and access control. Each customer's database records are isolated with row-level security; sensitive writes go only through restricted service-role access; client write access to ownership and billing fields is revoked.
  • Encryption. Encryption in transit over HTTPS, and encryption at rest through our managed database and hosting provider.
  • Secret management. Secrets live in environment configuration, never in source code; automation and webhook secrets are compared in constant time; email-sending webhook signatures are verified.
  • Application security. Open-redirect protection on the authentication callback; rate limiting on signup, lead-count preview, and agent dispatch; spend kill-switches on paid lead sourcing.
  • Authentication. Passwords are hashed and stored by our authentication provider, not in application tables.
  • Sub-processor assurances. Our sub-processors add their own encryption and, where they hold them, industry certifications.
  • Organizational measures. Confidentiality commitments for our people; least-privilege access; audit logging of sensitive and money-moving actions.

We do not promise absolute security. Security is shared: you are responsible for keeping your login safe and setting up your use of outr sensibly.

Annex III: Sub-processors

We use the sub-processors listed in our Sub-processor List to process lead and reply personal data so we can run outr. They are described here by category. A current list of the specific providers is available on request at support@tryoutr.io. As at the effective date, they cover these functions:

#Function
1Our hosting and database provider (database hosting)
2Our authentication provider (account sign-in and password hashing)
3Our payment processor (payments and subscriptions)
4Our email-sending provider (inbox management, sending, and reply routing)
5Our lead-sourcing provider (finding leads to your criteria)
6Our lead-count provider (free lead-count preview, no scrape)
7Our fallback lead-count provider (free lead-count preview, no scrape)
8Our AI provider (generating copy, follow-ups, reply drafts, and answers)
9Our inbox and domain provisioning provider
10Our domain registrar (domain registration and DNS)
11Our transactional email provider
12Our error-monitoring provider (optional)
13Our hosting provider (application hosting, deployment, and cron execution)

The purpose, data categories, processing region, and transfer mechanism for each sub-processor are in our Sub-processor List, which is kept current and forms part of this Annex. A current list of the specific providers behind each function is available on request at support@tryoutr.io. Changes are notified under Section 6.

Questions about this addendum: support@tryoutr.io.

Questions about this page? Email support@tryoutr.io.