Privacy Policy
SDRCloud, Inc. · a Delaware corporation
Last Updated: 8th July 2026
Website: sdrcloud.ai | Contact: privacy@sdrcloud.ai
About This Privacy Policy
This Privacy Policy explains how SDRCloud, Inc. ("SDRCloud," "we," "us," or "our") collects, uses, discloses, protects, and otherwise processes personal information in connection with SDRCloud.ai, our websites, software platform, applications, dashboards, integrations, AI-assisted workflows, customer accounts, support channels, billing processes, email synchronization features, website tracking tools, and related services (collectively, the "Platform").
This Privacy Policy is designed to work together with our Terms of Service, Data Processing Addendum, Cookie Policy, Order Forms, and any other agreement between SDRCloud and a customer.
If you are a customer of SDRCloud, this Privacy Policy explains how we process information about your account, users, billing, usage, and relationship with us.
If your personal information is included in data that one of our customers uploads to, connects to, or processes through SDRCloud, we generally process that information on behalf of that customer as a service provider, contractor, or processor. In that case, the customer is primarily responsible for deciding why and how your information is processed, and you should contact that customer directly to exercise privacy rights relating to that data.
We take a conservative approach to privacy. SDRCloud does not sell Customer Personal Data. SDRCloud does not share Customer Personal Data for cross-context behavioral advertising. SDRCloud does not use customer data to train foundation AI models shared across customers. SDRCloud does not attempt to identify natural persons solely from IP addresses.
1. Important Summary
This summary is provided for convenience. The full Privacy Policy controls.
What SDRCloud Is
SDRCloud is a software platform for AI-assisted sales development workflows. Customers use SDRCloud to configure AI-assisted outbound workflows, process prospect and customer records, generate personalized content, operate campaign workflows, connect customer-authorized inboxes, create landing pages or videos, and review reporting.
SDRCloud is not a data broker, lead broker, managed sales agency, legal advisor, or compliance advisor.
Our Role
For most data that customers upload, connect, or process through the Platform, SDRCloud acts as a processor, service provider, or contractor on behalf of the customer.
For information we collect for our own business operations, including website analytics, account administration, billing, security, fraud prevention, communications, compliance, and product operations, SDRCloud may act as an independent controller or business.
Customer Responsibility
Customers are responsible for the data they provide to SDRCloud, the lawful basis for their outreach, their prospect lists, their email compliance, their cookie and tracking notices, their opt-out handling, their suppression lists, and their own privacy obligations.
No IP Deanonymization
SDRCloud does not identify natural persons solely from IP addresses.
SDRCloud does not reverse engineer, enrich, or deanonymize individual visitors based solely on IP address information.
Where our Platform provides website visitor, engagement, or account-level analytics, that functionality is intended to support business-level, account-level, firmographic, or engagement insights, not to identify individual natural persons from IP addresses alone.
No Cross-Tenant AI Training
SDRCloud does not use Customer Personal Data to train foundation AI models shared across customers.
SDRCloud does not use one customer's Client Data to train models for another customer.
Customer-specific AI configuration, learning, optimization, and account-level processing are intended to remain customer-specific within the customer's SDRCloud environment.
Email Synchronization
If a customer connects an inbox, SDRCloud may process email data through email synchronization providers such as Nylas. This may include email metadata, message bodies, sender and recipient information, attachments, threads, labels, and related mailbox information as necessary to provide Platform functionality.
No Sale or Sharing
SDRCloud does not sell Customer Personal Data.
SDRCloud does not share Customer Personal Data for cross-context behavioral advertising.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal information we process in connection with:
- •SDRCloud.ai;
- •our public website;
- •customer accounts;
- •the SDRCloud Platform;
- •AI-assisted campaign workflows;
- •customer-authorized email and inbox integrations;
- •customer-authorized CRM, calendar, marketing, payment, and communication integrations;
- •customer support;
- •billing and payments;
- •sales, marketing, and business communications;
- •cookies, analytics, pixels, and similar technologies on our website;
- •security, fraud prevention, abuse prevention, and compliance.
This Privacy Policy does not apply to third-party websites, services, applications, or integrations that we do not control. Those third parties may have their own privacy policies and terms.
3. Relationship to the Terms of Service
Capitalized terms not defined in this Privacy Policy have the meanings given in the Terms of Service.
This Privacy Policy is aligned with the Terms of Service. In particular:
- •Customer owns Client Data.
- •Customer is responsible for lawful basis, notices, consent, outreach compliance, suppression, and opt-out handling.
- •SDRCloud processes Customer Personal Data as a processor, service provider, or contractor where applicable.
- •SDRCloud does not provide legal or compliance advice.
- •SDRCloud does not guarantee deliverability, replies, meetings, revenue, or legal compliance from customer campaigns.
- •SDRCloud may use subprocessors to provide the Platform.
- •SDRCloud may suspend or restrict use where needed to prevent abuse, spam, unlawful activity, security risk, platform risk, provider risk, or legal risk.
4. Definitions
For purposes of this Privacy Policy:
"Account Data" means information relating to a customer account, including account owner details, Authorized Users, login details, business contact information, settings, subscriptions, billing status, and support interactions.
"Authorized User" means an individual authorized by a customer to access or use the Platform.
"Client Data" means data, content, prospect records, customer records, CRM data, campaign data, email data, message content, contact lists, uploaded files, prompts, inputs, outputs, settings, and related information submitted to or processed through the Platform by or on behalf of a customer.
"Customer" means the person or entity that has entered into an agreement with SDRCloud to use the Platform.
"Customer Personal Data" means Client Data that constitutes personal data, personal information, personally identifiable information, or similar regulated data under applicable privacy laws.
"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an individual or household, as defined by applicable law.
"Platform Usage Data" means technical, operational, interaction, event, diagnostic, and performance information generated through use of the Platform.
"Processor" includes equivalent concepts under applicable law, including "service provider" and "contractor" under California privacy law.
"Subprocessor" means a third party engaged by SDRCloud to process Customer Personal Data on behalf of SDRCloud in connection with the Platform.
5. The Categories of Personal Information We Collect
Depending on how you interact with SDRCloud, we may collect the following categories of personal information.
5.1 Account and Registration Information
We may collect:
- •name;
- •business email address;
- •business phone number;
- •company name;
- •job title;
- •username;
- •password or authentication credential information;
- •account settings;
- •role and permission information;
- •workspace or organization details;
- •subscription plan information.
5.2 Billing and Payment Information
We may collect or process:
- •billing name;
- •billing email;
- •billing address;
- •company billing information;
- •tax information;
- •invoice details;
- •subscription status;
- •payment status;
- •payment method tokens;
- •transaction history.
Payments may be processed by third-party payment processors such as Stripe. SDRCloud does not intentionally store full payment card numbers where payment processing is handled by a third-party payment processor.
5.3 Customer-Provided Client Data
Customers may submit, upload, connect, or generate Client Data through the Platform, including:
- •prospect records;
- •customer records;
- •lead records;
- •CRM data;
- •business contact information;
- •company information;
- •job titles;
- •business email addresses;
- •business phone numbers;
- •campaign lists;
- •segmentation data;
- •targeting data;
- •sales notes;
- •message history;
- •campaign settings;
- •uploaded files;
- •prompts;
- •AI inputs;
- •AI outputs;
- •landing page content;
- •video content;
- •high-value offer materials;
- •reporting data.
Customer is responsible for ensuring that it has the right to provide this data to SDRCloud.
5.4 Email and Inbox Synchronization Data
If a customer authorizes an inbox or email account connection, SDRCloud may process email data through providers such as Nylas.
This may include:
- •email metadata;
- •sender details;
- •recipient details;
- •subject lines;
- •timestamps;
- •message bodies;
- •attachments;
- •email threads;
- •labels;
- •folders;
- •mailbox state;
- •reply signals;
- •engagement signals;
- •calendar or contact metadata where enabled;
- •account connection status;
- •OAuth tokens or authorization data.
We process this data to provide inbox synchronization, sending, reply detection, campaign workflows, routing, reporting, and related Platform functionality.
5.5 Integration Data
Customers may connect third-party systems to SDRCloud, including CRMs, email providers, calendar systems, payment tools, marketing platforms, and other applications.
Depending on the integration, we may process:
- •account identifiers;
- •API tokens;
- •OAuth authorization data;
- •CRM fields;
- •campaign data;
- •calendar metadata;
- •contact records;
- •email records;
- •event logs;
- •sync status;
- •integration configuration data.
5.6 Platform Usage Data
We may collect information about how Authorized Users use the Platform, including:
- •login events;
- •pages viewed;
- •features used;
- •buttons clicked;
- •workflow actions;
- •campaign configuration events;
- •credit consumption;
- •agent activity;
- •processing events;
- •error messages;
- •diagnostic logs;
- •performance data;
- •session data;
- •device and browser information;
- •IP address;
- •approximate location derived from IP address;
- •security and audit logs.
5.7 Website and Cookie Data
When you visit our website, we may collect:
- •IP address;
- •browser type;
- •device type;
- •operating system;
- •referring URL;
- •pages visited;
- •time spent on pages;
- •cookie identifiers;
- •analytics identifiers;
- •preference settings;
- •interaction events;
- •consent status.
Our Cookie Policy provides more detail about cookies and similar technologies.
5.8 Support, Sales, and Communications Data
If you contact us, request a demo, communicate with sales, submit a support request, or otherwise interact with us, we may collect:
- •name;
- •email address;
- •company;
- •job title;
- •phone number;
- •message content;
- •meeting notes;
- •support tickets;
- •call recordings where disclosed;
- •chat transcripts;
- •feedback;
- •preferences;
- •business needs;
- •communications history.
5.9 Security and Compliance Data
We may collect and process information for security, abuse prevention, legal compliance, audit, and enforcement, including:
- •IP addresses;
- •login attempts;
- •authentication events;
- •access logs;
- •device identifiers;
- •fraud signals;
- •abuse reports;
- •bounce, complaint, and unsubscribe indicators;
- •provider enforcement signals;
- •spam indicators;
- •security incident data;
- •audit logs;
- •legal request records.
6. Sensitive Personal Information
The Platform is designed primarily for business-to-business sales development workflows.
Customers must not upload or process sensitive personal information through the Platform unless expressly authorized by SDRCloud in writing and legally permitted.
Sensitive personal information may include:
- •government identification numbers;
- •financial account numbers;
- •payment card data, except through approved payment processors;
- •health information;
- •biometric data;
- •genetic data;
- •precise geolocation;
- •children's data;
- •criminal history;
- •racial or ethnic origin;
- •political opinions;
- •religious or philosophical beliefs;
- •trade union membership;
- •sexual orientation or sex life information;
- •immigration status;
- •passwords, private keys, or authentication secrets.
If Customer submits sensitive personal information without authorization, Customer remains responsible for that submission and any related legal obligations.
7. How We Collect Personal Information
We collect personal information from several sources.
7.1 Directly from You
We collect information when you:
- •create an account;
- •subscribe to the Platform;
- •complete forms;
- •request a demo;
- •contact sales;
- •contact support;
- •configure the Platform;
- •upload data;
- •connect integrations;
- •authorize inbox access;
- •submit feedback;
- •pay invoices;
- •communicate with us.
7.2 From Customers
Customers may submit personal information about Authorized Users, prospects, leads, customers, website visitors, email recipients, and business contacts.
7.3 From Integrations
We may receive information from customer-authorized integrations, including email providers, CRMs, payment processors, cloud services, calendar systems, messaging systems, analytics platforms, and other connected services.
7.4 From Cookies and Similar Technologies
We may collect website and Platform usage information through cookies, pixels, local storage, SDKs, analytics tools, and similar technologies.
7.5 From Third Parties
We may receive business contact, firmographic, enrichment, security, fraud prevention, marketing, or analytics information from third-party providers, where permitted by law.
8. How We Use Personal Information
We use personal information for the purposes described below.
8.1 To Provide the Platform
We use personal information to:
- •create and manage accounts;
- •authenticate users;
- •provide Platform functionality;
- •process Client Data;
- •generate AI-assisted Outputs;
- •operate AI agents and workflows;
- •connect inboxes and integrations;
- •sync email data;
- •send or prepare campaign communications as instructed by Customer;
- •generate landing pages, videos, reports, and other assets;
- •process credits;
- •provide dashboards and analytics;
- •store settings;
- •maintain customer workspaces.
8.2 To Support Customer-Configured Campaigns
When a customer configures a campaign, we process Client Data according to the customer's instructions.
This may include:
- •processing prospect records;
- •generating personalized content;
- •preparing outbound messages;
- •detecting replies;
- •updating campaign status;
- •scoring engagement;
- •reporting campaign performance;
- •syncing data with connected systems.
Customer remains responsible for campaign legality, lawful basis, message content, consent, opt-outs, suppression, targeting, and outreach compliance.
8.3 To Operate Email Synchronization
We process email and inbox data to:
- •connect authorized inboxes;
- •synchronize messages;
- •send authorized messages;
- •detect replies;
- •classify threads;
- •support campaign workflows;
- •update statuses;
- •route conversations;
- •provide reporting;
- •maintain audit trails;
- •troubleshoot inbox connections.
8.4 To Process Payments and Manage Subscriptions
We use billing and payment information to:
- •process payments;
- •manage subscriptions;
- •issue invoices;
- •calculate taxes;
- •process overages;
- •manage credits;
- •detect payment failures;
- •prevent fraud;
- •maintain financial records.
8.5 To Secure the Platform
We use personal information to:
- •authenticate users;
- •prevent unauthorized access;
- •monitor suspicious activity;
- •detect spam, phishing, abuse, fraud, or provider violations;
- •protect Platform integrity;
- •enforce rate limits and guardrails;
- •investigate incidents;
- •maintain logs;
- •protect customers, SDRCloud, and third parties.
8.6 To Improve and Maintain the Platform
We may use information to:
- •debug issues;
- •monitor performance;
- •improve usability;
- •develop features;
- •understand feature adoption;
- •improve documentation;
- •improve support;
- •optimize reliability;
- •reduce abuse;
- •measure aggregate usage.
We do not use Customer Personal Data to train foundation AI models shared across customers.
8.7 To Communicate
We may use contact information to:
- •respond to inquiries;
- •provide support;
- •send administrative notices;
- •send security notices;
- •send billing notices;
- •send product updates;
- •send policy updates;
- •send sales or marketing communications where permitted.
You may opt out of marketing emails, but we may still send transactional, security, legal, account, or service-related messages.
8.8 To Comply with Law and Enforce Rights
We may use personal information to:
- •comply with legal obligations;
- •respond to lawful requests;
- •enforce agreements;
- •protect rights and safety;
- •defend claims;
- •conduct audits;
- •maintain tax and accounting records;
- •prevent illegal activity.
9. Legal Bases for Processing
Where GDPR, UK GDPR, or similar laws apply, our legal bases may include:
9.1 Contract
We process personal information to provide the Platform, manage accounts, process payments, provide support, and perform agreements.
9.2 Legitimate Interests
We may process personal information for legitimate interests, including security, fraud prevention, abuse prevention, platform improvement, business communications, analytics, support, legal enforcement, and B2B marketing, where those interests are not overridden by individual rights.
9.2.1 Legitimate Interests for B2B Communications
Where Customers use SDRCloud to support business-to-business communications, Customers may rely upon legitimate interests where permitted under applicable law. SDRCloud does not determine whether legitimate interests is an appropriate lawful basis for any Customer activity. Customers remain solely responsible for assessing, documenting, maintaining, and defending any Legitimate Interest Assessment or equivalent lawful basis analysis required under applicable law.
9.3 Consent
We may rely on consent for certain cookies, marketing communications, optional features, or processing where legally required.
9.4 Legal Obligation
We may process personal information to comply with tax, accounting, legal, regulatory, court, law enforcement, or compliance obligations.
9.5 Customer Instructions
Where we act as processor, service provider, or contractor, we process Customer Personal Data on Customer's documented instructions.
10. Customer-Controlled Data and Customer Responsibility
Customers control the Client Data they submit to SDRCloud.
Customers are responsible for:
- •determining whether they have a lawful basis to process personal information;
- •providing required privacy notices;
- •obtaining consent where required;
- •conducting legitimate interest assessments where applicable;
- •honoring objections and opt-outs;
- •maintaining suppression lists;
- •ensuring contact data is accurate and lawfully obtained;
- •ensuring campaign targeting is lawful;
- •ensuring messages comply with applicable law;
- •responding to data subject and consumer rights requests;
- •complying with email, SMS, telemarketing, cookie, and privacy laws;
- •ensuring connected inboxes and integrations are authorized.
SDRCloud is not responsible for Customer's failure to comply with these obligations.
11. AI Processing
The Platform uses AI systems, machine learning systems, prompts, models, automation, rules, and workflow logic to provide Platform functionality.
AI processing may include:
- •generating emails;
- •generating landing page copy;
- •generating video scripts or content;
- •creating personalized messages;
- •summarizing records;
- •classifying replies;
- •scoring engagement;
- •suggesting campaign actions;
- •analyzing campaign context;
- •processing prompts and inputs;
- •producing Outputs.
Customer is responsible for reviewing AI-generated Outputs before use.
AI-generated Outputs may be inaccurate, incomplete, misleading, biased, non-compliant, or unsuitable for a particular use case.
SDRCloud does not make legal, compliance, employment, lending, housing, insurance, healthcare, government benefit, or other high-impact decisions.
Customers must not use the Platform for high-impact automated decisions unless expressly authorized by SDRCloud in writing and permitted by applicable law.
11.1 Automated Decision-Making
SDRCloud does not make decisions producing legal effects or similarly significant effects concerning individuals through solely automated processing. Any campaign recommendations, prioritizations, classifications, engagement scores, generated content, suggested actions, or workflow recommendations produced by the Platform are intended solely as decision-support functionality and remain subject to Customer review, approval, and control. Customers remain responsible for all decisions made using SDRCloud outputs.
12. No Cross-Tenant AI Training
SDRCloud does not use Customer Personal Data to train foundation AI models shared across customers.
SDRCloud does not use one customer's Client Data to train models for another customer.
Customer-specific AI configuration, optimization, learning, and account-level processing are intended to be containerized or customer-specific within the customer's SDRCloud environment.
We may use aggregated, anonymized, or de-identified operational data that does not identify Customer, Customer's prospects, Customer's customers, or natural persons to monitor, secure, operate, benchmark, and improve the Platform.
We may use feedback, prompts, usage patterns, diagnostics, and support information to troubleshoot, maintain, and improve Customer's own account and Platform functionality, subject to our confidentiality and data protection obligations.
13. Website Visitor Tracking and No IP Deanonymization
The Platform may include website tracking, analytics, attribution, engagement, and account-level reporting features.
SDRCloud does not attempt to identify natural persons solely from IP addresses.
SDRCloud does not reverse engineer, enrich, or deanonymize individual website visitors based solely on IP address information.
SDRCloud does not represent that it can identify every visitor to a website.
Where website tracking, attribution, or visitor analytics are used, the functionality is intended to support business-level, account-level, firmographic, or engagement insights.
Customers are responsible for:
- •disclosing their use of website tracking;
- •providing cookie notices;
- •obtaining consent where required;
- •honoring opt-outs;
- •configuring consent management tools;
- •maintaining privacy policies;
- •ensuring compliance with GDPR, UK GDPR, PECR, ePrivacy laws, CCPA/CPRA, CalOPPA, and other applicable laws.
Customers must not use SDRCloud to unlawfully identify, profile, target, or contact individuals based on website tracking data.
13.1 Enhanced No IP Deanonymization Commitments
SDRCloud does not purchase identity resolution services for the purpose of identifying natural persons solely from IP address information. SDRCloud does not sell visitor identity information. SDRCloud does not operate a consumer profiling business. SDRCloud does not operate a people-identification platform.
14. Cookies and Similar Technologies
We and our service providers may use cookies, pixels, local storage, SDKs, tags, scripts, and similar technologies.
These technologies may be used to:
- •operate our website;
- •authenticate users;
- •maintain sessions;
- •remember preferences;
- •secure accounts;
- •prevent fraud;
- •measure usage;
- •analyze website performance;
- •understand feature adoption;
- •support marketing;
- •manage consent preferences.
Where required by law, we will use a consent mechanism before deploying non-essential cookies on our own website.
Customers are responsible for consent mechanisms on their own websites where they deploy SDRCloud scripts, tracking, pixels, or similar technologies.
More detail is available in our Cookie Policy.
14.1 United Kingdom PECR Compliance
For visitors located in the United Kingdom, SDRCloud seeks to comply with the Privacy and Electronic Communications Regulations ("PECR"). Where required by PECR, SDRCloud will obtain consent before storing or accessing non-essential cookies, pixels, local storage technologies, analytics technologies, or similar technologies on a user's device, unless an applicable exemption applies. Customers remain responsible for PECR compliance on websites, landing pages, and digital properties they control.
15. How We Disclose Personal Information
We may disclose personal information as described below.
15.1 To Subprocessors and Service Providers
We may disclose personal information to vendors, subprocessors, contractors, and service providers who help us operate the Platform.
These may include providers of:
- •cloud hosting;
- •email synchronization;
- •email sending;
- •AI model functionality;
- •payment processing;
- •database services;
- •analytics;
- •monitoring;
- •security;
- •customer support;
- •communications;
- •logging;
- •error tracking;
- •infrastructure;
- •compliance tools.
15.2 To Customer-Authorized Integrations
If Customer connects an integration, we may disclose or transmit data to that integration according to Customer's configuration and authorization.
15.3 To Customers
Where we process personal information on behalf of a customer, we may disclose that information to the customer and its Authorized Users.
15.4 To Professional Advisors
We may disclose information to lawyers, auditors, accountants, insurers, bankers, consultants, and other professional advisors.
15.5 For Legal and Safety Reasons
We may disclose information if we believe disclosure is necessary to:
- •comply with law;
- •respond to lawful requests;
- •enforce agreements;
- •protect rights;
- •protect safety;
- •prevent fraud;
- •prevent abuse;
- •investigate security incidents;
- •respond to legal process;
- •protect SDRCloud, customers, users, or third parties.
15.6 Business Transfers
We may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction.
15.7 With Consent or Direction
We may disclose information with consent or at the direction of the relevant customer or individual.
16. Subprocessors
SDRCloud may use subprocessors to provide the Platform.
Current or anticipated subprocessors and infrastructure providers may include:
- •Google Cloud;
- •Nylas;
- •Resend;
- •Convex;
- •Stripe;
- •AI model providers used to provide Platform functionality;
- •security, analytics, monitoring, support, and infrastructure providers.
Subprocessors may process personal information only as necessary to provide services to SDRCloud, subject to appropriate contractual obligations.
Customers may request current subprocessor information by contacting privacy@sdrcloud.ai.
17. Nylas Email Synchronization
SDRCloud may use Nylas or similar providers to enable email synchronization and inbox connectivity.
When Customer authorizes an inbox connection, Customer authorizes SDRCloud and its email synchronization provider to access, sync, store, transmit, and process email data as necessary to provide the Platform.
This may include:
- •email metadata;
- •sender information;
- •recipient information;
- •subject lines;
- •timestamps;
- •message bodies;
- •attachments;
- •thread data;
- •labels;
- •folders;
- •reply signals;
- •mailbox state;
- •calendar or contact metadata where enabled.
Customers must ensure they have all required rights, permissions, notices, consents, and lawful bases for connecting inboxes and processing email data.
Customers may revoke inbox access through the Platform or the relevant provider settings. Revoking access may disable Platform functionality.
17.1 Google API Services Disclosure
Where Customer authorizes access to Google services through OAuth, Nylas, or similar authorization mechanisms, SDRCloud's use and transfer of information received from Google APIs will comply with applicable Google API Services User Data Policy requirements, including applicable Limited Use requirements. Information obtained through Google APIs will be used solely to provide and improve Platform functionality authorized by the Customer and will not be used for unauthorized advertising, profiling, or unrelated purposes.
18. Payment Processing
We may use Stripe or another payment processor to process payments.
Payment processors may collect and process payment information according to their own terms and privacy policies.
SDRCloud generally does not store full payment card numbers where payment processing is handled by a third-party payment processor.
We may store billing records, invoices, subscription information, payment status, tax information, and related financial records.
19. International Data Transfers
SDRCloud is based in the United States and may process personal information in the United States and other jurisdictions where we, our personnel, our affiliates, our vendors, or our subprocessors operate.
Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, we use appropriate transfer mechanisms, which may include Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful mechanisms.
Customers authorize SDRCloud and its subprocessors to process Customer Personal Data in the United States and other jurisdictions as described in the Terms of Service and Data Processing Addendum.
19.1 International Transfer Mechanisms
Where required by applicable law, transfers of Customer Personal Data from the European Economic Area, United Kingdom, or Switzerland shall be governed by the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or another legally recognized transfer mechanism adopted by SDRCloud.
20. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Retention periods depend on:
- •the type of information;
- •the purpose of processing;
- •customer instructions;
- •subscription status;
- •legal obligations;
- •audit needs;
- •tax and accounting requirements;
- •security needs;
- •dispute resolution;
- •enforcement needs;
- •backup and deletion cycles.
20.1 Client Data
Client Data is deleted upon cancellation or termination according to our standard deletion processes, subject to lawful retention exceptions.
Customers should export any data they wish to retain before cancellation or termination.
20.2 Account and Billing Records
We may retain account, billing, tax, invoice, payment, security, compliance, and audit records for as long as required for financial, legal, tax, audit, security, and compliance purposes, typically up to seven years or longer where legally required.
20.3 Backups
Backup copies may persist for a limited period until overwritten or deleted in the ordinary course.
20.4 Security Logs
Security logs may be retained as necessary to protect the Platform, investigate incidents, prevent abuse, and comply with legal obligations.
21. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, disclosure, alteration, and destruction.
Safeguards may include:
- •encryption in transit;
- •encryption at rest;
- •access controls;
- •least privilege controls;
- •authentication controls;
- •logging and monitoring;
- •security reviews;
- •vendor management;
- •infrastructure protections;
- •backup and recovery procedures;
- •incident response procedures.
No system is perfectly secure. We cannot guarantee absolute security.
Customers are responsible for securing their own accounts, credentials, devices, domains, inboxes, integrations, personnel access, and internal systems.
22. Your Privacy Rights
Depending on your location and applicable law, you may have rights regarding your personal information.
These rights may include:
- •access;
- •correction;
- •deletion;
- •portability;
- •restriction;
- •objection;
- •withdrawal of consent;
- •opt-out of marketing;
- •opt-out of sale or sharing;
- •limitation of sensitive personal information use;
- •non-discrimination for exercising rights.
To exercise rights relating to personal information SDRCloud controls, contact privacy@sdrcloud.ai.
If your information was provided to SDRCloud by one of our customers, we may direct your request to that customer. The customer is generally responsible for responding to rights requests relating to Customer Personal Data.
We may need to verify your identity before processing a request.
23. California Privacy Notice
This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies.
23.1 Categories of Personal Information Collected
In the preceding 12 months, we may have collected the following categories of personal information:
- •identifiers, such as name, email address, IP address, account identifiers, and online identifiers;
- •customer records information, such as billing information and business contact details;
- •commercial information, such as subscription details, invoices, transaction records, and service history;
- •internet or electronic network activity, such as usage data, log data, cookie data, and interaction data;
- •geolocation information, such as approximate location derived from IP address;
- •professional or employment-related information, such as job title, company, and business role;
- •inferences, such as engagement, usage, or campaign-related insights;
- •sensitive personal information, only where required for limited purposes such as account security, payment processing through providers, or where Customer submits such information despite restrictions.
23.2 Sources
We may collect personal information from:
- •you;
- •Customers;
- •Authorized Users;
- •integrations;
- •inbox connections;
- •cookies and similar technologies;
- •service providers;
- •business partners;
- •public or commercially available sources;
- •security and fraud prevention providers.
23.3 Purposes
We collect, use, and disclose personal information for the purposes described in this Privacy Policy, including:
- •providing the Platform;
- •account management;
- •billing;
- •support;
- •security;
- •fraud prevention;
- •abuse prevention;
- •analytics;
- •communications;
- •compliance;
- •legal obligations;
- •business operations.
23.4 Categories of Personal Information Disclosed
We may disclose the categories listed above to:
- •service providers;
- •contractors;
- •subprocessors;
- •payment processors;
- •cloud hosting providers;
- •email synchronization providers;
- •AI model providers;
- •analytics providers;
- •security providers;
- •professional advisors;
- •legal authorities where required;
- •business transfer counterparties.
23.5 No Sale or Sharing
SDRCloud does not sell Customer Personal Data.
SDRCloud does not share Customer Personal Data for cross-context behavioral advertising.
If our practices change, we will update this Privacy Policy and provide any legally required rights or notices.
23.5.1 Service Provider and Contractor Processing
For purposes of the California Consumer Privacy Act, as amended by the California Privacy Rights Act, SDRCloud processes Customer Personal Data as a service provider and contractor. SDRCloud processes Customer Personal Data solely for the limited and specified business purposes of providing, operating, maintaining, supporting, securing, and improving the Platform; account administration, authentication, billing, and subscription management; customer-authorized email synchronization, inbox connectivity, workflow execution, and reporting; AI-assisted content generation and campaign processing performed pursuant to Customer instructions; fraud prevention, abuse prevention, security monitoring, and incident response; and legal compliance, auditing, recordkeeping, and enforcement of contractual rights. SDRCloud does not retain, use, disclose, sell, share, or otherwise process Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law.
23.6 Sensitive Personal Information
SDRCloud does not use or disclose sensitive personal information for purposes that require a right to limit under California law, unless disclosed otherwise.
Customers are prohibited from uploading sensitive personal information unless expressly authorized and legally permitted.
23.7 California Rights
California residents may have the right to:
- •know what personal information we collect, use, disclose, sell, or share;
- •access personal information;
- •delete personal information;
- •correct inaccurate personal information;
- •opt out of sale or sharing;
- •limit use and disclosure of sensitive personal information where applicable;
- •not be discriminated against for exercising privacy rights.
To exercise rights, contact privacy@sdrcloud.ai.
If your information is processed by SDRCloud on behalf of a Customer, we may direct your request to that Customer.
23.8 Authorized Agents
California residents may designate an authorized agent to submit a privacy request. We may require proof of authorization and verification of identity.
23.9 Global Privacy Controls
Where legally required and technically feasible for our own website, we will honor recognized browser-based opt-out preference signals for applicable processing.
Customers are responsible for honoring applicable opt-out preference signals on their own websites where they deploy SDRCloud technologies.
24. UK and European Privacy Rights
If GDPR, UK GDPR, or similar laws apply, individuals may have rights to:
- •access personal data;
- •correct inaccurate personal data;
- •delete personal data;
- •restrict processing;
- •object to processing;
- •receive data portability;
- •withdraw consent;
- •lodge a complaint with a supervisory authority.
Where SDRCloud acts as a processor, we process personal data on behalf of the Customer. Requests relating to Customer Personal Data should generally be directed to the relevant Customer.
Where SDRCloud acts as controller, you may contact privacy@sdrcloud.ai.
Individuals in the United Kingdom may also contact the UK Information Commissioner's Office. Individuals in the EEA may contact their local data protection authority.
25. Marketing Communications
We may send marketing communications to business contacts where permitted by law.
You may opt out of marketing emails by using the unsubscribe link or contacting us.
Even if you opt out of marketing, we may still send non-marketing communications, including security notices, account notices, billing notices, legal notices, service updates, and transactional messages.
Customers are responsible for their own marketing and outbound communications sent or prepared through the Platform.
26. Customer Outreach and Email Compliance
Customers may use the Platform to support outbound communications.
Customers are solely responsible for ensuring that their outreach complies with applicable laws, including CAN-SPAM, TCPA, CASL, GDPR, UK GDPR, PECR, CCPA/CPRA, and similar laws.
Customers are responsible for:
- •lawful basis;
- •consent where required;
- •accurate sender information;
- •non-deceptive subject lines;
- •opt-out mechanisms;
- •honoring unsubscribe requests;
- •maintaining suppression lists;
- •avoiding unlawful spam;
- •complying with email provider terms;
- •complying with SMS and telemarketing laws where applicable.
SDRCloud may provide tools to assist with compliance, but Customer remains responsible for final compliance.
27. Children's Privacy
The Platform is not intended for children.
Customers must not use the Platform to collect or process personal information about children.
We do not knowingly collect personal information from children through our website or Platform.
If you believe a child has provided personal information to us, contact privacy@sdrcloud.ai.
28. Do Not Track
Some browsers provide "Do Not Track" signals. There is no uniform industry standard for responding to these signals.
Where required by law, we will honor applicable opt-out preference signals. Otherwise, we may not respond to Do Not Track signals.
29. De-Identified, Aggregated, and Anonymized Data
We may process de-identified, aggregated, or anonymized data for business purposes, including analytics, benchmarking, security, performance monitoring, product improvement, and reporting.
Where we maintain de-identified data, we will take reasonable measures designed to prevent re-identification and will not attempt to re-identify the data except as permitted by law, such as to test de-identification processes.
30. Data Broker Statement
SDRCloud is not a data broker in the ordinary operation of the Platform.
SDRCloud provides software that customers use to process their own Client Data and customer-authorized integrations.
SDRCloud does not sell Customer Personal Data.
SDRCloud does not share Customer Personal Data for cross-context behavioral advertising.
31. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
When we make material changes, we will provide notice through the website, Platform, email, or other reasonable means.
The updated Privacy Policy is effective as of the "Last Updated" date unless otherwise stated.
Continued use of the Platform after an updated Privacy Policy becomes effective means that the updated Privacy Policy applies.
32. Contact Us
For privacy questions or requests, contact:
SDRCloud, Inc.
Attn: Privacy
[Insert Address]
Email: privacy@sdrcloud.ai
For legal notices, contact: legal@sdrcloud.ai
Schedule A: Platform Privacy Commitments
SDRCloud makes the following commitments for the Platform:
- •SDRCloud does not sell Customer Personal Data.
- •SDRCloud does not share Customer Personal Data for cross-context behavioral advertising.
- •SDRCloud does not use Customer Personal Data to train foundation AI models shared across customers.
- •SDRCloud does not use one customer's Client Data to train models for another customer.
- •SDRCloud does not identify natural persons solely from IP addresses.
- •SDRCloud does not reverse engineer, enrich, or deanonymize individual website visitors based solely on IP address information.
- •SDRCloud processes Customer Personal Data as a processor, service provider, or contractor where applicable.
- •SDRCloud uses subprocessors to provide the Platform.
- •SDRCloud may process email data through Nylas or similar email synchronization providers where Customer authorizes inbox access.
- •SDRCloud deletes Client Data after cancellation or termination according to standard deletion processes, subject to lawful retention exceptions.
Schedule B: Customer Privacy Responsibilities
Customers are responsible for:
- •lawful basis for processing;
- •lawful basis for outreach;
- •consent where required;
- •privacy notices;
- •cookie notices;
- •website consent mechanisms;
- •email compliance;
- •SMS compliance;
- •opt-out handling;
- •suppression lists;
- •data accuracy;
- •data minimization;
- •privacy rights responses;
- •connected inbox authorization;
- •CRM and integration authorization;
- •end-client authorization where Customer acts for another party;
- •compliance with GDPR, UK GDPR, PECR, CCPA/CPRA, CAN-SPAM, TCPA, CASL, and similar laws.
Schedule C: Processing Details
Subject Matter
Provision of SDRCloud's AI-assisted sales development software platform.
Duration
The subscription term plus any period required for deletion, backup retention, audit, legal compliance, security, dispute resolution, or enforcement.
Nature and Purpose
Hosting, storing, syncing, transmitting, analyzing, generating, organizing, securing, supporting, reporting, and deleting data as necessary to provide the Platform.
Categories of Data
Business contact information, prospect records, customer records, CRM data, campaign data, email data, inbox data, message content, website activity data, usage data, account data, billing data, and support data.
Categories of Data Subjects
Customer personnel, Authorized Users, prospects, leads, customers, business contacts, email recipients, website visitors, and individuals whose information is submitted by Customer.
Subprocessors
Google Cloud, Nylas, Resend, Convex, Stripe, AI model providers, and other support, security, analytics, hosting, monitoring, and infrastructure providers used to provide the Platform.
Privacy questions or requests? Contact privacy@sdrcloud.ai. For legal notices, contact legal@sdrcloud.ai.
© 2026 SDRCloud, Inc. All rights reserved.