GDPR & Data Protection
Last updated: September 21, 2026
1. Our commitment
Outbound Suite pro is committed to helping customers meet their obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR and other privacy laws. This page explains the roles we play, our security measures, and the commitments that support your compliance.
2. Roles: controller and processor
- Controller — for the personal data of our own customers and website visitors (account, billing, support and usage data), we act as the data controller and determine the purposes and means of processing, as described in our Privacy Policy.
- Processor — for the contact data you upload or collect (leads and newsletter subscribers), you are the controller and we act as a processor, handling that data only on your documented instructions to provide the Service.
3. Data Processing Agreement (DPA)
Our processing of your contact data is governed by a Data Processing Agreement that incorporates the GDPR Article 28 requirements. It covers: processing only on your instructions; confidentiality; security measures; use of sub-processors; assistance with data-subject requests and breach notification; and deletion/return of data at the end of the engagement. A signed DPA is available on request through our contact form.
4. Data subject rights
Under the GDPR, individuals have rights of access, rectification, erasure, restriction, portability and objection, plus the right not to be subject to automated decision-making. We provide tooling to help you honour these rights for the contacts you store (for example, deleting a lead or honouring an unsubscribe), and we respond to requests directed at us as controller within the statutory timeframes.
5. Sub-processors
We engage the following categories of sub-processors to deliver the Service:
- Payment processing — Stripe (card and subscription data).
- Hosting and infrastructure — our cloud and database providers.
- Email delivery — the SMTP providers you configure yourself (you control this relationship).
- DNS / SSL and CDN — providers such as Cloudflare where enabled.
We maintain a current list of sub-processors and will notify you of material additions.
6. International transfers
Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, to keep the transfer lawful.
7. Security measures
- Encryption in transit (TLS) and encryption at rest for sensitive fields.
- Passwords stored as salted hashes; SMTP credentials encrypted with an application key.
- Strict tenant isolation — your data is always scoped to your workspace server-side.
- Access controls, audit logging of privileged actions, and monitoring for abuse and security events.
8. Retention and deletion
Contact data is stored for as long as your workspace holds it and is deleted when you delete it or close your account. Suppression records are retained as required to honour opt-outs and protect deliverability. See our Privacy Policy for full retention details.
9. Breach notification
We will notify affected customers without undue delay upon becoming aware of a personal-data breach that is likely to result in a risk to individuals, as required by applicable law.
10. Contact and DPO
For data-protection questions, subject-access requests or to request a DPA, contact us through our contact form. EU/UK individuals may also contact their local supervisory authority.