1.Who We Are

AutomateYourOutreach.com is operated by two affiliated entities, depending on where you or your business is located:

If you are located inYour data controller is
The United States G1 Group International LLC, a Wyoming limited liability company, registered at 30 N Gould St Ste N, Sheridan, WY 82801, USA
The EU/EEA, UK, or anywhere else outside the United States G1 Equity Ltd., a company registered in Cyprus at Efesou 9, 5280 Paralimni, Cyprus

Wherever this policy says "we", "us", or "our", it refers to whichever of the two entities above is your data controller, based on your location as a client or, where applicable, the client relationship through which you were contacted. If you are unsure which entity applies to you, contact us using the details in Section 18 and we will confirm.

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in connection with our website and our services, in accordance with Regulation (EU) 2016/679 (the "GDPR") and equivalent UK data protection law, and, for our US entity, applicable US state privacy laws.

Important nuance on the two-entity split: Assigning US-based clients to the Wyoming LLC does not automatically remove GDPR from the picture. GDPR applies based on where the individual whose data is processed is located, not where the paying client is based. If a US client instructs us, through the LLC, to run LinkedIn outreach targeting prospects located in the EU/EEA, that processing still falls within GDPR's territorial scope under Article 3(2), regardless of which entity carries it out. In that scenario, the Wyoming LLC would likely need to appoint an EU representative under Article 27 for those specific campaigns, and should apply the same safeguards described in this policy. Confirm with counsel how client contracts should route prospect targeting so each entity's GDPR exposure stays clear.

2.Scope and Our Two Roles

Because of how our service works, we act in two different capacities under the GDPR, and this policy addresses both:

  • As a data controller: for personal data of website visitors, prospective clients who contact us, and our clients' own account and billing data. We decide the purposes and means of processing this data.
  • As a data processor: for personal data of the individuals our clients ask us to contact on LinkedIn ("prospects"). Here, our client is the data controller, and we process this data strictly on their documented instructions under a data processing agreement.

Sections 3 to 5 and 9 to 11 below apply primarily to our role as controller. Section 6 explains our role as processor and what that means for prospect data.

3.Personal Data We Collect

3.1 Website visitors

  • IP address, browser type, device information, and general location (country or city level)
  • Pages visited, referring URLs, and time spent on the site, collected via analytics tools
  • Cookie identifiers, see Section 13

3.2 Prospective and existing clients

  • Name, business email address, company name, job title, and phone number if provided
  • Information shared during kickoff calls: ideal customer profile (ICP), campaign goals, and messaging preferences
  • LinkedIn account access credentials or authorized session tokens, used solely to operate campaigns on the client's behalf
  • Billing details, processed by our payment provider; we do not store full card numbers
  • Support and email correspondence

3.3 Prospects contacted through client campaigns (processed as processor)

  • Publicly available LinkedIn profile information: name, job title, employer, and profile URL
  • Connection status, message and reply content, and engagement timestamps
  • No special categories of data (Article 9 GDPR) are intentionally collected or targeted

4.Why and How We Use It

PurposeData used
Operating and improving our websiteVisitor and cookie data
Responding to inquiries and providing supportContact and correspondence data
Onboarding and delivering the outreach serviceClient account data, LinkedIn access, campaign inputs
Running outreach campaigns on a client's behalfProspect data, as instructed by the client
Billing and accountingBilling and transaction data
Legal and regulatory complianceClient and billing records
Marketing communications, only with consent or an existing client relationshipContact data

5.Legal Bases for Processing

Under Article 6(1) GDPR, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)): to onboard clients, run campaigns, and deliver the service they purchased.
  • Legitimate interests (Art. 6(1)(f)): to operate and secure our website, respond to inquiries, and, where we act as controller, to maintain business records. We have assessed that these interests are not overridden by data subjects' rights and freedoms.
  • Consent (Art. 6(1)(a)): for non-essential cookies and any marketing communications sent to individuals who are not existing clients.
  • Legal obligation (Art. 6(1)(c)): to retain invoices and accounting records as required by applicable tax law.

Where we process prospect data as a processor on a client's behalf, the client, as controller, is responsible for identifying and documenting their own legal basis, typically legitimate interest for B2B outreach under Article 6(1)(f) and Recital 47. We support clients with the safeguards described in Section 6, but the legal basis assessment itself is the client's responsibility.

6.When We Act as a Processor

When we run outreach campaigns for a client, that client is the data controller for the prospect data involved, and we process it solely as their processor, under a written data processing agreement (DPA) that reflects the requirements of Article 28 GDPR. In that agreement:

  • We process prospect data only on the client's documented instructions
  • We apply appropriate technical and organizational security measures (see Section 10)
  • We do not use prospect data for our own purposes, including our own marketing
  • We assist the client in responding to data subject requests concerning prospects, and in fulfilling their Article 33/34 breach notification obligations where relevant
  • We only engage sub-processors listed in Section 7 with the client's general authorization, and we remain responsible for those sub-processors' compliance
  • We delete or return prospect data at the end of the engagement, as instructed by the client
If you are a client, our standard Data Processing Agreement reflects these terms in full and should be countersigned alongside your service agreement before any campaign involving personal data begins.

7.Who We Share Data With

We share personal data only with the following categories of recipients, and never sell personal data:

  • Hosting and infrastructure providers, to operate our website and store campaign data securely
  • Payment processors, to handle billing on our behalf
  • Email and communication tools, to correspond with clients and prospects
  • Analytics providers, for aggregated website usage insights
  • Professional advisors (accountants, lawyers), where necessary for our legitimate business operations
  • Authorities, where disclosure is required by law or to protect our legal rights

All third-party processors are bound by written data processing agreements consistent with Article 28 GDPR.

8.International Data Transfers

Where G1 Equity Ltd. (our EU entity) engages service providers located outside the EU/EEA, including in the United States, we ensure an adequate level of protection through one or more of the following safeguards:

  • An adequacy decision by the European Commission for the destination country
  • The recipient's certification under the EU-U.S. Data Privacy Framework, where applicable
  • The European Commission's Standard Contractual Clauses (SCCs), together with a transfer impact assessment where required

Where G1 Outreach LLC (our US entity) processes personal data of individuals located in the EU/EEA on behalf of a US-based client, as described in the warning box in Section 1, the same safeguards apply to that specific processing, and data may in addition be transferred to G1 Equity Ltd. or its sub-processors under the same protections.

You may request further information about the specific safeguards applied to a given transfer by contacting us using the details in Section 18.

9.How Long We Keep Data

Data categoryRetention period
Website analytics and cookie dataUp to 14 months
Client account and campaign dataDuration of the engagement, plus up to 3 years for legitimate business and legal purposes
LinkedIn access credentials or session tokensDeleted within 30 days of service termination
Prospect data processed on a client's behalfDeleted or returned at the end of the engagement, per the client's instructions and the data processing agreement
Invoices and accounting recordsAs required by applicable tax law, typically 6 to 7 years
Email correspondenceUp to 3 years from the last exchange

When a retention period expires, data is securely deleted or anonymized so it can no longer be linked to an identifiable individual.

10.Security Measures

We apply technical and organizational measures appropriate to the risk, in line with Article 32 GDPR, including:

  • Encryption of data in transit via TLS/SSL
  • Access to personal data restricted to personnel who need it to perform their role
  • Secure handling of LinkedIn credentials, never stored in plain text where technically avoidable
  • Regular review of our processing activities and vendor security practices
  • Written confidentiality obligations for anyone with access to client or prospect data

No system is completely secure. If you become aware of a security concern relating to your data, please contact us immediately using the details in Section 18.

11.Your Rights Under the GDPR

If you are located in the EU/EEA (and, in equivalent form, the UK), you have the following rights regarding your personal data, subject to certain legal exceptions:

  • Right of access (Art. 15): obtain confirmation of whether we process your data, and a copy of it.
  • Right to rectification (Art. 16): have inaccurate or incomplete data corrected.
  • Right to erasure (Art. 17): request deletion of your data in certain circumstances.
  • Right to restriction of processing (Art. 18): limit how we use your data in certain circumstances.
  • Right to data portability (Art. 20): receive data you provided to us in a structured, machine-readable format, or have it transferred directly to another controller, where technically feasible.
  • Right to object (Art. 21): object to processing based on legitimate interests, including profiling, on grounds relating to your particular situation.
  • Right to withdraw consent (Art. 7(3)): withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint (Art. 77): with your local supervisory authority. See Section 18 for details.

To exercise any of these rights, contact us using the details in Section 18. We will respond within one month, extendable by two further months for complex requests, as permitted under Article 12(3). We may need to verify your identity before processing your request.

12.Rights of LinkedIn Prospects

If you have been contacted through one of our clients' LinkedIn outreach campaigns, our client is the data controller responsible for your data, and we act only as their processor. You can exercise your GDPR rights, including the right to object to further contact at any time, at no cost, by:

  • Replying "unsubscribe" or a similar request directly on LinkedIn, which we honor promptly, or
  • Contacting the company that reached out to you directly, or
  • Contacting us at the address in Section 18, and we will forward your request to the relevant client without delay and support them in responding.

Under Article 21(2) and (3) GDPR, you have an absolute right to object to processing for direct marketing purposes, including profiling related to such marketing, and processing will stop as soon as reasonably possible after such an objection.

13.Cookies

Our website uses cookies and similar technologies. Strictly necessary cookies are used without consent, as permitted under the ePrivacy rules implementing Article 5(3) of Directive 2002/58/EC. All other cookies, such as analytics or preference cookies, are set only with your prior consent, collected through a cookie banner, and you may withdraw that consent at any time through your browser settings or our cookie preferences tool.

14.Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects concerning you, or similarly significantly affects you, within the meaning of Article 22 GDPR. Outreach messaging is configured by our team based on criteria agreed with the client, not generated through automated profiling of individual prospects.

15.Children's Data

Our website and services are directed at business professionals and are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

16.Data Breaches

In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34.

17.Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, our services, or legal requirements. Material changes will be reflected by an updated "Last updated" date at the top of this page, and, where appropriate, communicated directly to clients by email.

18.Contact and Complaints

For any question, request, or concern about this Privacy Policy or our data practices, contact our data protection contact. Please specify whether you are contacting us as a US-based or an EU/international client or prospect, so we can route your request to the correct entity.

G1 Equity Ltd. — EU / international clients and prospects

Email: info@g-1.group

Registered address: Efesou 9, 5280 Paralimni, Cyprus

G1 Group International LLC — US-based clients and prospects

Email: info@g-1.group

Registered address: 30 N Gould St Ste N, Sheridan, WY 82801, USA

We aim to acknowledge privacy inquiries within 5 business days and to resolve requests within one month, as required by Article 12(3) GDPR.

If G1 Equity Ltd. is your data controller, our lead supervisory authority is the Office of the Commissioner for Personal Data Protection, Cyprus. You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence or place of work. A full list of EU supervisory authorities is available from the European Data Protection Board.

Legal disclaimer: This document is a template designed to reflect the core requirements of the GDPR based on the information provided about your business model. It is not a substitute for legal advice. Before publishing it, have it reviewed by a qualified data protection lawyer in your jurisdiction, particularly to confirm: the correct legal entity details, whether an EU representative under Article 27 is required, whether your processing of prospect data at scale triggers a mandatory Data Protection Officer under Article 37, and whether a Data Protection Impact Assessment (Article 35) is advisable given the volume of LinkedIn outreach you perform.