Skip to content
Privacy

Your data, your rules.

Plain-language privacy policy. We collect what we need to run the platform, nothing more. We never sell your data. We delete on request inside 30 days.

Last updated:

TL;DR

  • We collect: account info you give us, the leads you upload, the messages you send/receive, the calls you make, and basic usage telemetry.
  • We use it to: run the platform, send you product updates, and improve the product. Never to train AI on your data.
  • We share it with: the third-party processors listed below — only the minimum required to deliver the feature you asked for.
  • We never sell your data. We never let advertisers see your leads, messages, calls or deal data.
  • You can export, correct, or delete it any time. Deletion completes within 30 days.

What we collect

Account data you provide: name, email, organisation name, billing details (handled by our payment processor), team-member emails, role.

Operational data you upload or generate: lead lists, sequences, mailbox credentials (encrypted at rest), carrier API keys, call recordings + transcripts, message bodies, notes, deal pipeline data, audio files for IVR + voicemail drops.

Usage telemetry: page views, feature usage, error reports, performance metrics. We use this to find bugs, prioritise the product roadmap, and measure which marketing campaigns bring people to Autocloz. The data you put into Autocloz — leads, messages, calls, deals — is never part of it.

Cookies: a strictly-necessary session cookie for auth, plus a remember-me token if you tick the box. We also run measurement tags — Microsoft Clarity, Google Analytics and the Meta pixel — which set their own cookies. They record which pages you view and whether you took an action such as signing up or booking a demo, so we can tell which campaigns and pages actually work. They never receive your leads, messages, calls or deal data. They run on our public marketing pages only — never inside the app you log in to, and never on a password-reset, invite, booking or shared-document link. Block them with any standard tracker blocker or by blocking third-party cookies; nothing on the site depends on them.

How we use it

  • To run the platform — store and serve your leads, sequences, mailboxes, calls, etc.
  • To send you product updates (email; you can unsubscribe with one click)
  • To send you transactional emails (password reset, billing receipts, security notifications) — these you cannot unsubscribe from
  • To improve the product (aggregate analytics; never individual-level shared)
  • To meet legal obligations (e.g., GST filing in India, tax records)

We do not use your data to train AI models — neither ours nor third-party providers'. We do not share your leads, messages, calls or deal data with advertisers. We do not sell it.

Prospecting data (people we have not met)

Autocloz operates a business directory that our customers search to find companies to contact. Most of it is company information, but some records name a person in a professional role. If you are in it, this section is your notice — you did not give us this data, so the law requires us to tell you where it came from and how to get out.

What is in it. Business records: company name, category, business address, business phone, website and, where the business published one, a general business email. Where a company publishes a team, about or leadership page, we may also hold a person’s name, job title, employer and the exact page URL we read it from.

Where it comes from. Business records come from the Overture Maps Foundation open dataset (CDLA-Permissive-2.0). Person records come from pages companies publish on their own websites, read by our crawler AutoclozBot, which obeys robots.txt. Some officer records come from public company registries.

What is deliberately NOT in it. We do not scrape LinkedIn or any site whose terms forbid it. We do not buy, use or resell breach data. We do not hold personal mobile numbers. We do not use Google Maps or Bing data.

Why we hold it. To let business users find other businesses to contact about their products — business-to-business prospecting, nothing else. We do not use it for advertising, profiling, credit decisions or any automated decision that produces a legal effect on you.

Our lawful basis. For the UK and EEA we rely on legitimate interests (UK GDPR / GDPR Art 6(1)(f)) in business-to-business outreach, balanced against your rights — which is why the data is limited to a professional role at a company, never special-category data, and why the objection route below is one step. In India we rely on the publicly-available-data provision of the DPDP Act 2023 for information a person or their employer published themselves. Where neither basis holds, the record does not belong in the corpus and we will remove it.

Who we are to you. For this directory Autocloz is the data controller, not a processor acting for a customer. Requests come to us directly and we answer them ourselves.

How long. A record is kept while the source page still publishes it. Three things end that: the page drops the person and we see it on a re-read; the record is not re-observed at all within 12 months, after which it is deleted automatically; or you ask us to remove it, which we honour immediately.

Getting out — one step. Use autocloz.com/privacy/remove or email [email protected] with the name, company or domain. You do not need an account and you do not have to give a reason. We remove the record and add it to a do-not-contact list so our customers cannot send to it. You also have the right to access what we hold, correct it, and complain to your supervisory authority — the ICO in the UK, your national DPA in the EEA, or the Data Protection Board in India.

Blocking the crawler entirely. Add this to your site’s robots.txt and AutoclozBot will not read any page on it:

User-agent: AutoclozBot
Disallow: /

Third-party processors

These vendors process customer data on our behalf — strictly limited to what's needed to deliver the feature.

  • AWS (Amazon Web Services) — hosting, storage, backups (Mumbai by default; EU on request)
  • Stripe / Razorpay — payment processing
  • Telnyx / DIDLogic / FreJun — voice carriers (your choice; we proxy your credentials)
  • Twilio / MessageBird / Vonage — SMS and WhatsApp delivery (your choice)
  • Google / Microsoft — OAuth + IMAP for connected mailboxes
  • Unipile / PhantomBuster — LinkedIn provider (your choice)
  • OpenAI / Anthropic / Groq / ElevenLabs / Deepgram — LLM + voice AI (with zero-retention enabled where supported)
  • Cloudflare / Sentry — DNS, error monitoring
  • Mailgun / SendGrid — transactional emails (password reset, etc.)
  • Microsoft Clarity / Google Analytics / Meta — website analytics and advertising measurement on our public marketing pages. Unlike the vendors above these are not pure processors: Meta in particular acts as an independent controller for the pixel data it receives. They see marketing page URLs and conversion events (e.g. a signup completing) — never the contents of your workspace, and they are not loaded on authenticated app pages.

AI providers

When you use AI replies, AI voice agents, or AI summaries, the relevant content is sent to the configured LLM/voice provider for inference. We enable zero-retention mode on every API call where the provider supports it (OpenAI data_retention=none, Anthropic enterprise zero-retention).

You can bring your own API key per workspace. When you do, the provider becomes your sub-processor (not ours) and the data path goes directly from Autocloz to your account.

Retention

  • Active workspaces — kept indefinitely while you remain a customer
  • Cancelled workspaces — soft-deleted immediately on cancellation; hard-deleted after 30 days unless you explicitly request earlier deletion
  • Audit log — 12 months on Pro, 24 on Business, 7 years on Enterprise (regulatory requirement)
  • Backups — retained 30 days then permanently deleted
  • Voice recordings — retained per the workspace's recording_retention_days setting (default 90 days)
  • Marketing analytics — aggregated only; personal identifiers stripped after 13 months

Your rights

Depending on where you live (GDPR, India DPDP, CCPA, etc.) you have the right to:

  • Access — request a copy of all the data we hold about you
  • Correct — fix inaccuracies (most fields editable directly in the product)
  • Delete — we honour deletion within 30 days; some data must be retained for tax/audit reasons (we'll tell you what)
  • Port — export your data in standard formats (CSV, JSON)
  • Object — opt out of marketing emails with one click; opt out of usage analytics in Settings → Privacy
  • Withdraw consent — for AI features, marketing, or any specific processing

Email [email protected] to exercise any of these rights. We respond within 5 business days and complete the action within 30 days.

International transfers

Your data is stored in our primary AWS region (Mumbai, ap-south-1 by default). EU customers can request EU data residency (eu-west-1) at signup or via support.

For transfers outside India / the EU (e.g., when AI providers are US-hosted), we rely on Standard Contractual Clauses (SCCs) and the receiving party's own GDPR / DPDP compliance posture.

Children's data

Autocloz is a B2B platform. We do not knowingly collect data from anyone under 18. If you discover that a child has provided us data, email [email protected] and we'll delete it.

Changes to this policy

When we change this policy materially, we'll email every workspace Owner at least 30 days in advance. Non-material changes (typo fixes, clarifications) take effect on publication and the "Last updated" stamp at the top reflects the date.

Contact us

Privacy questions: [email protected]
Security incidents: [email protected]
Everything else: [email protected]

Data Protection Officer (for GDPR / DPDP requests): [email protected].

Free to start

Your data, handled with care.

A free-forever CRM with tenant isolation, encryption and role-based access built in. Unlimited users, no card required.