1.Who We Are
AutomateYourOutreach.com is operated by two affiliated entities, depending on where you or your business is located:
| If you are located in | Your data controller is |
|---|---|
| The United States | G1 Group International LLC, a Wyoming limited liability company, registered at 30 N Gould St Ste N, Sheridan, WY 82801, USA |
| The EU/EEA, UK, or anywhere else outside the United States | G1 Equity Ltd., a company registered in Cyprus at Efesou 9, 5280 Paralimni, Cyprus |
Wherever this policy says "we", "us", or "our", it refers to whichever of the two entities above is your data controller, based on your location as a client or, where applicable, the client relationship through which you were contacted. If you are unsure which entity applies to you, contact us using the details in Section 18 and we will confirm.
This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in connection with our website and our services, in accordance with Regulation (EU) 2016/679 (the "GDPR") and equivalent UK data protection law, and, for our US entity, applicable US state privacy laws.
2.Scope and Our Two Roles
Because of how our service works, we act in two different capacities under the GDPR, and this policy addresses both:
- As a data controller: for personal data of website visitors, prospective clients who contact us, and our clients' own account and billing data. We decide the purposes and means of processing this data.
- As a data processor: for personal data of the individuals our clients ask us to contact on LinkedIn ("prospects"). Here, our client is the data controller, and we process this data strictly on their documented instructions under a data processing agreement.
Sections 3 to 5 and 9 to 11 below apply primarily to our role as controller. Section 6 explains our role as processor and what that means for prospect data.
3.Personal Data We Collect
3.1 Website visitors
- IP address, browser type, device information, and general location (country or city level)
- Pages visited, referring URLs, and time spent on the site, collected via analytics tools
- Cookie identifiers, see Section 13
3.2 Prospective and existing clients
- Name, business email address, company name, job title, and phone number if provided
- Information shared during kickoff calls: ideal customer profile (ICP), campaign goals, and messaging preferences
- LinkedIn account access credentials or authorized session tokens, used solely to operate campaigns on the client's behalf
- Billing details, processed by our payment provider; we do not store full card numbers
- Support and email correspondence
3.3 Prospects contacted through client campaigns (processed as processor)
- Publicly available LinkedIn profile information: name, job title, employer, and profile URL
- Connection status, message and reply content, and engagement timestamps
- No special categories of data (Article 9 GDPR) are intentionally collected or targeted
4.Why and How We Use It
| Purpose | Data used |
|---|---|
| Operating and improving our website | Visitor and cookie data |
| Responding to inquiries and providing support | Contact and correspondence data |
| Onboarding and delivering the outreach service | Client account data, LinkedIn access, campaign inputs |
| Running outreach campaigns on a client's behalf | Prospect data, as instructed by the client |
| Billing and accounting | Billing and transaction data |
| Legal and regulatory compliance | Client and billing records |
| Marketing communications, only with consent or an existing client relationship | Contact data |
5.Legal Bases for Processing
Under Article 6(1) GDPR, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): to onboard clients, run campaigns, and deliver the service they purchased.
- Legitimate interests (Art. 6(1)(f)): to operate and secure our website, respond to inquiries, and, where we act as controller, to maintain business records. We have assessed that these interests are not overridden by data subjects' rights and freedoms.
- Consent (Art. 6(1)(a)): for non-essential cookies and any marketing communications sent to individuals who are not existing clients.
- Legal obligation (Art. 6(1)(c)): to retain invoices and accounting records as required by applicable tax law.
Where we process prospect data as a processor on a client's behalf, the client, as controller, is responsible for identifying and documenting their own legal basis, typically legitimate interest for B2B outreach under Article 6(1)(f) and Recital 47. We support clients with the safeguards described in Section 6, but the legal basis assessment itself is the client's responsibility.
6.When We Act as a Processor
When we run outreach campaigns for a client, that client is the data controller for the prospect data involved, and we process it solely as their processor, under a written data processing agreement (DPA) that reflects the requirements of Article 28 GDPR. In that agreement:
- We process prospect data only on the client's documented instructions
- We apply appropriate technical and organizational security measures (see Section 10)
- We do not use prospect data for our own purposes, including our own marketing
- We assist the client in responding to data subject requests concerning prospects, and in fulfilling their Article 33/34 breach notification obligations where relevant
- We only engage sub-processors listed in Section 7 with the client's general authorization, and we remain responsible for those sub-processors' compliance
- We delete or return prospect data at the end of the engagement, as instructed by the client
7.Who We Share Data With
We share personal data only with the following categories of recipients, and never sell personal data:
- Hosting and infrastructure providers, to operate our website and store campaign data securely
- Payment processors, to handle billing on our behalf
- Email and communication tools, to correspond with clients and prospects
- Analytics providers, for aggregated website usage insights
- Professional advisors (accountants, lawyers), where necessary for our legitimate business operations
- Authorities, where disclosure is required by law or to protect our legal rights
All third-party processors are bound by written data processing agreements consistent with Article 28 GDPR.
8.International Data Transfers
Where G1 Equity Ltd. (our EU entity) engages service providers located outside the EU/EEA, including in the United States, we ensure an adequate level of protection through one or more of the following safeguards:
- An adequacy decision by the European Commission for the destination country
- The recipient's certification under the EU-U.S. Data Privacy Framework, where applicable
- The European Commission's Standard Contractual Clauses (SCCs), together with a transfer impact assessment where required
Where G1 Outreach LLC (our US entity) processes personal data of individuals located in the EU/EEA on behalf of a US-based client, as described in the warning box in Section 1, the same safeguards apply to that specific processing, and data may in addition be transferred to G1 Equity Ltd. or its sub-processors under the same protections.
You may request further information about the specific safeguards applied to a given transfer by contacting us using the details in Section 18.
9.How Long We Keep Data
| Data category | Retention period |
|---|---|
| Website analytics and cookie data | Up to 14 months |
| Client account and campaign data | Duration of the engagement, plus up to 3 years for legitimate business and legal purposes |
| LinkedIn access credentials or session tokens | Deleted within 30 days of service termination |
| Prospect data processed on a client's behalf | Deleted or returned at the end of the engagement, per the client's instructions and the data processing agreement |
| Invoices and accounting records | As required by applicable tax law, typically 6 to 7 years |
| Email correspondence | Up to 3 years from the last exchange |
When a retention period expires, data is securely deleted or anonymized so it can no longer be linked to an identifiable individual.
10.Security Measures
We apply technical and organizational measures appropriate to the risk, in line with Article 32 GDPR, including:
- Encryption of data in transit via TLS/SSL
- Access to personal data restricted to personnel who need it to perform their role
- Secure handling of LinkedIn credentials, never stored in plain text where technically avoidable
- Regular review of our processing activities and vendor security practices
- Written confidentiality obligations for anyone with access to client or prospect data
No system is completely secure. If you become aware of a security concern relating to your data, please contact us immediately using the details in Section 18.
11.Your Rights Under the GDPR
If you are located in the EU/EEA (and, in equivalent form, the UK), you have the following rights regarding your personal data, subject to certain legal exceptions:
- Right of access (Art. 15): obtain confirmation of whether we process your data, and a copy of it.
- Right to rectification (Art. 16): have inaccurate or incomplete data corrected.
- Right to erasure (Art. 17): request deletion of your data in certain circumstances.
- Right to restriction of processing (Art. 18): limit how we use your data in certain circumstances.
- Right to data portability (Art. 20): receive data you provided to us in a structured, machine-readable format, or have it transferred directly to another controller, where technically feasible.
- Right to object (Art. 21): object to processing based on legitimate interests, including profiling, on grounds relating to your particular situation.
- Right to withdraw consent (Art. 7(3)): withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint (Art. 77): with your local supervisory authority. See Section 18 for details.
To exercise any of these rights, contact us using the details in Section 18. We will respond within one month, extendable by two further months for complex requests, as permitted under Article 12(3). We may need to verify your identity before processing your request.
12.Rights of LinkedIn Prospects
If you have been contacted through one of our clients' LinkedIn outreach campaigns, our client is the data controller responsible for your data, and we act only as their processor. You can exercise your GDPR rights, including the right to object to further contact at any time, at no cost, by:
- Replying "unsubscribe" or a similar request directly on LinkedIn, which we honor promptly, or
- Contacting the company that reached out to you directly, or
- Contacting us at the address in Section 18, and we will forward your request to the relevant client without delay and support them in responding.
Under Article 21(2) and (3) GDPR, you have an absolute right to object to processing for direct marketing purposes, including profiling related to such marketing, and processing will stop as soon as reasonably possible after such an objection.
13.Cookies
Our website uses cookies and similar technologies. Strictly necessary cookies are used without consent, as permitted under the ePrivacy rules implementing Article 5(3) of Directive 2002/58/EC. All other cookies, such as analytics or preference cookies, are set only with your prior consent, collected through a cookie banner, and you may withdraw that consent at any time through your browser settings or our cookie preferences tool.
14.Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects concerning you, or similarly significantly affects you, within the meaning of Article 22 GDPR. Outreach messaging is configured by our team based on criteria agreed with the client, not generated through automated profiling of individual prospects.
15.Children's Data
Our website and services are directed at business professionals and are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
16.Data Breaches
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by Article 33 GDPR, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34.
17.Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, our services, or legal requirements. Material changes will be reflected by an updated "Last updated" date at the top of this page, and, where appropriate, communicated directly to clients by email.
18.Contact and Complaints
For any question, request, or concern about this Privacy Policy or our data practices, contact our data protection contact. Please specify whether you are contacting us as a US-based or an EU/international client or prospect, so we can route your request to the correct entity.
G1 Equity Ltd. — EU / international clients and prospects
Email: info@g-1.group
Registered address: Efesou 9, 5280 Paralimni, Cyprus
G1 Group International LLC — US-based clients and prospects
Email: info@g-1.group
Registered address: 30 N Gould St Ste N, Sheridan, WY 82801, USA
We aim to acknowledge privacy inquiries within 5 business days and to resolve requests within one month, as required by Article 12(3) GDPR.
If G1 Equity Ltd. is your data controller, our lead supervisory authority is the Office of the Commissioner for Personal Data Protection, Cyprus. You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence or place of work. A full list of EU supervisory authorities is available from the European Data Protection Board.