Operational privacy notice
Privacy Policy
Last updated: July 29, 2026
1. Scope and roles
PilumReach provides software used by workspace operators to manage business contacts and communications. The workspace operator normally decides why customer data is processed and who may access it. The deployed PilumReach operator processes platform data to provide, secure and support the service.
2. Data processed
Depending on enabled features, the service may process account and authentication details, workspace membership, business contact and company records, conversation content and attachments, provider account identifiers, consent and suppression records, deals and tasks, support records, billing evidence, API and webhook logs, audit events and technical security metadata.
3. Purposes
Data is used to authenticate users, isolate workspaces, deliver configured communications, maintain customer records, run approved workflows and broadcasts, process billing and credits, detect abuse, preserve audit evidence, support users and meet deletion, retention or legal-hold obligations.
4. Providers and subprocessors
Connected messaging, email, SMS, billing, hosting, storage, anti-bot, telemetry and malware-scanning providers process only the data needed for their configured function. Workspace operators are responsible for choosing lawful providers, configuring credentials and reviewing each provider’s terms and privacy practices.
5. Retention and deletion
Operational records follow configured retention schedules. Financial evidence may be retained longer where required. Workspace and account deletion use controlled queues and grace periods; legal holds can pause destructive retention. Backups and provider-side records may follow separate retention periods.
6. Security
The product uses workspace-scoped authorization, database row-level read controls, RPC-governed mutations, encrypted provider credentials, private media storage, signed webhooks, rate limits, durable worker leases and audit logging. No security measure eliminates all risk, and deployment controls must be tested in the target environment.
7. International transfers
Hosting and connected providers may process data in more than one country. The operator is responsible for selecting appropriate regions, contractual safeguards and transfer mechanisms for its users and customers.
8. Individual rights and requests
Requests to access, correct, export, restrict or erase customer data should first be directed to the relevant workspace operator. Account holders can use available profile, export and deletion workflows or contact the service operator for assistance. Identity and legal-basis checks may be required.
9. Cookies and technical storage
The application uses essential browser storage and session technologies for authentication, workspace context, security and preferences. Additional analytics or advertising technologies must not be enabled without an appropriate notice and consent mechanism.
10. Contact and changes
Privacy questions may be sent to privacy@pilumreach.ai. Material policy changes should be dated and communicated by the deployed service operator.