Privacy Policy
Last updated: 10 August 2026
1. Who we are
Algeist (the "Service") is operated by a UK-based provider. This policy explains what personal data we process, why, and your rights. It applies to the Service at algeist.com and the managed outreach services we provide.
2. Roles
For the outreach data processed on your behalf (leads, their messages and profiles), you are the controller and Algeist is the processor, acting on your documented instructions under a data-processing schedule. For your account data (email, name, billing), Algeist is the controller.
3. What we collect and why
| Data | Purpose | Lawful basis |
|---|---|---|
| Account details (email, name, company) | Providing the Service, authentication, billing | Performance of contract |
| Billing details via Stripe | Subscriptions, trials, invoices | Performance of contract / legal obligation |
| LinkedIn session data (encrypted) | Running outreach from your account | Performance of contract (session only - passwords are never stored) |
| Lead data you import or we source for you | Campaign delivery, analytics | Your legitimate interest in B2B outreach (documented LIA); you warrant rights to the data |
| Usage events and send logs | Delivering the Service, flywheel analytics, abuse prevention | Legitimate interests |
4. Subprocessors
We use the following processors to deliver the Service: LLM providers (OpenRouter/OpenAI-class - messages processed for personalization), Resend (transactional email), Stripe (billing), Dokploy hosting infrastructure (Postgres, Redis), and email-lookup providers (when enabled). We update this list as providers change.
5. Security
Sessions are encrypted at rest (AES-256-GCM); traffic is TLS-encrypted; each account is isolated. We never store your LinkedIn password - credentials are used once to establish a session and discarded. Access to production data is restricted and audited.
6. Retention
Account data is kept while your account is active. Lead and outreach data is retained for 24 months after contract end, then deleted unless law requires longer. Opt-out and consent records are retained for compliance. You can request erasure at any time - we honour it within 30 days (opt-outs within 24 hours).
7. Your rights
Under UK GDPR / EU GDPR you have rights to access, rectification, erasure, restriction, portability and objection. To exercise them, email the contact below. You may also lodge a complaint with the ICO (UK) or your local supervisory authority.
8. Cookies
We use a single httpOnly session cookie for authentication and strictly necessary cookies. We do not run advertising trackers.
9. Contact
Privacy questions: privacy@algeist.com. This policy may be updated; material changes will be notified on the Service.