Version 1
OutreachEU platform privacy policy
Last updated: [DATE]
1. Controller
QARYA S.r.l. [to verify: registered office, VAT no., privacy@[DOMAIN]] ("OutreachEU", "we") is the controller for data of users who register on the platform. For contact data uploaded by customers, OutreachEU acts as a processor (Art. 28 GDPR) under the DPA accepted by the customer.
2. Data we process
- Account data: email, password (stored only as a hash by the authentication service), workspace membership and role.
- Workspace data: legal name, VAT number, country, address, privacy contact email, customer privacy notice URL.
- Activity log: administrative actions (e.g. inviting a member, launching a campaign) with date and author. The log never contains email open events.
- Technical data: technical session cookies required to sign in. We use no third-party analytics, advertising or tracking tools.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service and managing the account | Contract (Art. 6.1.b) |
| Security, abuse and spam prevention | Legitimate interest (Art. 6.1.f) |
| Tax and accounting obligations | Legal obligation (Art. 6.1.c) |
4. Retention
Account data: for the contract term and up to [N] months after closure. Activity log: [N] months. Tax records: 10 years.
5. Recipients
Providers acting as sub-processors, listed on the "Sub-processors" page.
6. Transfers outside the EU
Data is hosted in the European Union ([REGION TO BE CONFIRMED]). Any transfer only takes place with Art. 44-49 GDPR safeguards (adequacy decision or Standard Contractual Clauses).
7. Your rights
You may request access, rectification, erasure, restriction, portability and object to processing by writing to privacy@[DOMAIN]. You may lodge a complaint with your supervisory authority (in Italy: Garante per la protezione dei dati personali).