Privacy policy
Reading translation. The French version is the contractual reference. Version française
Version du 28 septembre 2026, en vigueur le 28 septembre 2026.
Sommaire10 parties
This policy explains what personal data Outsendr processes, why, for how long, and how you can exercise your rights.
At a glance
- When you select a currency, the website remembers it in a functional cookie. It does not measure its audience or load resources from another website.
- The waiting list stores your email address and the plan you selected, and nothing else.
- We act on behalf of our customers when processing the prospects they import.
Who is responsible
SAS LHOMME DEVELOPMENT AND INNOVATION, 5 rue Saint-Thomas, 30000 Nîmes, France, which publishes Outsendr, is the controller for the processing described here, except for processing carried out on behalf of customers (see “Our customers’ prospects”).
For questions about your personal data, contact Thomas Lhomme at [email protected]. No data protection officer has been appointed.
The website
- Currency. If you choose EUR, USD or GBP, the website stores your choice for one year in the functional
outsendr_devisecookie so that it can show subsequent prices in that currency. It is not used to track your browsing. There is no audience measurement or pixel, and no font or resource loaded from another website. - Light or dark theme. If you change the theme, your choice is kept in your browser’s local storage. It is never sent to the server, and you can clear it in your browser settings.
- Connection. To deliver pages to you, the server receives your connection’s IP address. The website does not record it, except as a fingerprint for the waiting list as described below.
The waiting list
Data. Your email address, the plan you chose if any, and the registration date. No email is sent when you join the list.
Purpose. To tell you when Outsendr opens and offer you the plan you selected.
Legal basis. Your consent, given when you sign up to be contacted at launch. This contact also prepares a possible subscription at your request. You can withdraw consent at any time by writing to [email protected].
Retention. Your address is kept until Outsendr opens, then for no more than twelve months if you do not create an account. It is deleted on request.
Protection against abuse. The form accepts at most 5 requests per connection per day. To count them, the website keeps a fingerprint of the IP address, calculated with a secret key, which cannot be used to recover the address. The plain IP address is never recorded. Legal basis: our legitimate interest in protecting the form.
Our customers
SAS LHOMME DEVELOPMENT AND INNOVATION is the controller for its customers’ accounts and their users’ accounts.
Sign in with Google, GitHub or Microsoft
From Settings › Security, you can link a Google, GitHub or Microsoft account to an existing Outsendr account. You can then use that provider to sign in. Matching email addresses alone never link accounts automatically, and this sign-in option does not create a Outsendr account.
Data requested. For Google, we request only the openid and email permissions. We do not request access to your Google profile name or photo. For Microsoft, we request openid, email and profile. For GitHub, we request user:email to obtain the verified primary address. When you sign in with Google, we receive an identity token and check the stable identifier of your Google account, your email address and whether it is verified. We store only the provider name, its stable identifier, the email address received, whether that address is verified, the date the account was linked and the date of the last sign-in with that provider. The address is used to display and verify the link; it does not automatically replace your Outsendr account address.
Use, sharing and access. We use this data only to verify your identity, find the link to your Outsendr account, open a session and secure sign-in. It is stored by our technical hosting provider, identified under “Subprocessors and transfers”, and is not disclosed to other customers or advertising partners. The Google token is used during the exchange and is not stored in the database. Sign in with Google does not request access to Gmail, messages, contacts or Google Drive, and it does not allow us to send email from your Google mailbox. If you separately connect a sending mailbox to Outsendr, that is a different process with separate permissions.
Retention and choice. Linked identity data is stored for as long as that identity remains linked to your account. You can unlink it in Settings › Security after confirming your identity; the linked identity data is then deleted. The signed, script-inaccessible cookie used for the temporary round trip to the provider lasts ten minutes and is cleared at the end of sign-in. Sign-in events in the security logs follow the retention period in the table below. The legal basis for linking and signing in is performance of the contract; for security checks and logs it is our legitimate interest in protecting accounts. You can also exercise your rights using the address under “Your rights”.
| Processing | Data | Legal basis | Retention |
|---|---|---|---|
| Account and use of the service | Name, professional email address, organisation, SIREN or VAT number, settings | Performance of the contract | Term of the contract, then five years (limitation period) |
| Service emails | Account address, subject and content of the email (notifications, account security) | Performance of the contract | Content deleted when the link it contains expires, or otherwise after thirty days |
| Billing | Organisation billing data | Legal obligation | Ten years (accounting obligation) |
| Security and logs | Sign-ins; API calls without bodies or IP addresses; actions within the organisation | Legitimate interest: securing the service | Sign-ins: at most twelve months; API calls: thirty days; actions: from thirty days to two years depending on the plan |
| Proof of accepted documents | User, date, IP address, document version and fingerprint of the accepted wording | Legitimate interest: proving agreement | Term of the contract, then five years |
| Abuse prevention | Reports and addresses of complainants | Legitimate interest: protecting recipients and the service | As long as necessary to avoid contacting the person again |
Service emails are sent from a dedicated sending mailbox of SAS LHOMME DEVELOPMENT AND INNOVATION through its email host’s server. They contain no tracking pixel or tracking link. Payments are collected by the payment provider identified at checkout and on the invoice. That provider receives billing data, never prospect data.
The optional warm-up network has its own rules: see its terms, article 8.
Our customers’ prospects
When a customer imports prospects and writes to them using Outsendr, the customer is the controller and SAS LHOMME DEVELOPMENT AND INNOVATION acts as processor, under the data processing agreement.
- Have you received an email from one of our customers? Contact the company that wrote to you. The unsubscribe link at the bottom of each message stops further sends immediately.
- If you write to us, we forward your request to that customer within three working days.
- Opens and clicks. A campaign email contains a small image which, by default, serves only our sending engine: it records the date of the first open to slow down and then stop follow-ups to people who do not respond, without statistics or exports. The customer can see each recipient’s opens only if it declares that it obtained their consent. Link clicks are tracked by default unless the customer disables this. No IP address is recorded.
- Retention. The periods chosen by the customer, within their plan’s limits: sending events from 7 days to 2 years; prospects and messages for at most 3 years after the last contact originating from the prospect; the suppression register throughout the contract. Mailbox content unrelated to a thread is not kept.
- At the end of the contract, the customer can export its data for at least thirty days; the data is then deleted.
Artificial intelligence
Outsendr uses artificial intelligence models provided by Anthropic PBC (United States) for three purposes:
- The infrastructure adviser, presented as an assistant, receives users’ questions and the status of their domains and mailboxes, never prospect data. Entered email addresses are masked before sending. The conversation log is kept for twelve months.
- Checking uploaded declarations: the document and the customer’s declaration, never contacts from its lists.
- Classifying replies, off by default and enabled only by the customer: Prospect reply text before the quoted message, limited to 2 000 characters, excluding headers, attachments and email addresses, only if the customer enables classification.
This data is processed in the United States under the DPA of Anthropic PBC, which incorporates the European Commission’s standard contractual clauses. Anthropic PBC may not use it to train its models.
Subprocessors and transfers
- Railway Corporation (United States): Hosting of the application, background processing and PostgreSQL database. EU West region (Amsterdam, Netherlands); operational access from the United States. Safeguards: European Commission standard contractual clauses included in Railway's DPA (https://railway.com/legal/dpa); EU–US Data Privacy Framework when Railway is certified under it.
- Anthropic PBC (United States): Optional classification of minimised excerpts of prospect replies when the controller enables this feature. United States; transfer outside the European Union. Safeguards: Anthropic's DPA, incorporated into its Commercial Terms, includes the European Commission's standard contractual clauses, module 3 (processor to processor) (https://www.anthropic.com/legal/data-processing-addendum).
The full list is published on the subprocessors page. Any addition is announced 30 days in advance. No data is sold or rented.
Security
Connected mailbox secrets are encrypted. Connections to the console, API and webhooks use TLS. Our staff’s access to data is restricted and logged. Details are in Annex 2 of the data processing agreement.
Your rights
You may request access to, correction or deletion of your data, restriction of processing or data portability. You may object to processing based on our legitimate interest and withdraw consent at any time.
Write to Thomas Lhomme at [email protected]. We respond within one month.
If you believe your rights have not been respected, you may complain to the French data protection authority, CNIL: www.cnil.fr.