Privacy Policy
Last updated: 30 July 2026
This policy explains how Keplent (“Keplent”, “we”) handles personal data when you visit keplent.com, join the waitlist, or use the Keplent platform. It is written to meet the EU General Data Protection Regulation (GDPR).
1. Who is responsible for your data
The controller is Keplent, [REGISTERED ADDRESS], [COUNTRY OF INCORPORATION]. For anything to do with privacy — a question, a request, or a complaint — write to support@keplent.com and it reaches the person accountable for it here.
Two different roles. For data about our own visitors, waitlist subscribers and account holders we are the controller — this policy describes that. For the content our customers put into their workspace — their lead lists, prospects, campaign records and client data — we act as a processor on the customer’s instructions, under our Data Processing Agreement. If you were contacted by an agency using Keplent, that agency is the controller; see section 10 below.
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Waitlist data | The email address you submit on the home page | You |
| Account data | Name, username, email address, password (stored hashed by our backend), organisation and role | You, or the colleague who invited you |
| Workspace content | Leads, contacts, campaigns, sequences, automations, uploaded assets, reports and messages created in your workspace | You and the sources you connect |
| Connected accounts | Tokens and the mail data we are authorised to read or send when you connect an inbox or a third-party tool | You, via the provider’s consent screen |
| Support and communications | Emails, onboarding calls and product feedback | You |
| Technical data | IP address, browser and device information, and server logs generated when you use the Service | Automatically |
We do not ask for special categories of data (health, beliefs, and so on) and ask you not to load them into the workspace.
3. Why we use it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the Service, hosting your workspace and running the features you use | Performance of a contract (Art. 6(1)(b)) |
| Creating and administering your account, and supporting you | Performance of a contract |
| Keeping you on the waitlist and telling you when access opens | Consent (Art. 6(1)(a)) — withdraw it any time by replying to any of those emails |
| Keeping the Service secure, preventing abuse, debugging and maintaining logs | Legitimate interests (Art. 6(1)(f)) in a secure, working product |
| Improving the product, and understanding which features are used | Legitimate interests |
| Sending service messages about changes, incidents or your subscription | Performance of a contract |
| Meeting accounting, tax and other legal obligations | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data, and we do not use your workspace content to train general-purpose AI models.
4. Automated processing and AI
Keplent uses automated systems to research prospects, enrich records, score them against a profile you describe, draft outreach copy and summarise results. These produce suggestions for you to review and change. They do not make decisions producing legal or similarly significant effects about you within the meaning of Art. 22 GDPR, and a person on your team decides what is actually sent.
5. Who we share it with
We share personal data only with service providers who process it on our behalf under written contracts, and only as far as they need it to do their job. The current list — what each one does, where it is, and the safeguard relied on — is published at keplent.com/subprocessors.
We may also disclose data:
- to a provider you choose to connect, at your instruction — for example when you send a lead to your CRM;
- to professional advisers, auditors or insurers where necessary;
- to public authorities where the law requires it, after checking the request is valid;
- to a buyer or successor if the business is sold or reorganised, with notice to you.
6. International transfers
Our production infrastructure runs in [HOSTING REGION]. Where a processor is outside the European Economic Area, the transfer relies on an adequacy decision or on the European Commission’s Standard Contractual Clauses with supplementary measures where needed. The mechanism used for each processor is shown on the Subprocessors page, and you can request a copy of the clauses at support@keplent.com.
7. How long we keep it
- Account data: for as long as the account is open, and up to 12 months afterwards so it can be restored if you come back.
- Workspace content: for as long as the account is open. On termination we delete or return it in line with the DPA — export first if you need it.
- Waitlist emails: until access opens or you ask us to remove you, whichever is sooner.
- Authentication tokens for connected accounts: until you disconnect the account or revoke access at the provider.
- Technical and security logs: normally up to 12 months.
- Invoices and accounting records: for the period required by tax law, typically 6 to 10 years.
8. Security
Access to the platform runs over HTTPS. Session tokens are stored in cookies marked httpOnly, so page scripts cannot read them, and secure in production. Passwords are hashed by our backend and never stored in readable form. Access to production data is limited to the staff who need it. No system is perfectly secure, so if a breach affects your data we will notify you and the supervisory authority as the GDPR requires.
9. Your rights
Under the GDPR you can ask us to:
- confirm what personal data we hold about you and give you a copy (access);
- correct data that is wrong or incomplete (rectification);
- delete it (erasure), where we have no overriding reason to keep it;
- restrict or object to processing based on our legitimate interests;
- give you your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out.
Write to support@keplent.com. We answer within one month and may ask you to confirm your identity first. If you are unhappy with the outcome you can complain to [SUPERVISORY AUTHORITY], or to the authority where you live or work.
If your data sits in a customer’s workspace, we will pass your request to that customer, who is the controller and answers it. See the next section.
10. If you were contacted by an agency using Keplent
Keplent helps agencies find and contact business prospects. If you received an email or a call from an agency using our platform, your details will have been compiled from public professional sources — company websites, professional networks, public business directories — or from licensed data partners, and every record carries its source. Typically that means your name, job title, employer, business email address and public professional profile.
The agency that contacted you is the controller of that data, and decides why and how it is used. We process it for them as a processor. Your rights — access, correction, erasure, objection — are exercised against that agency, and their contact details will be in the message you received.
If you cannot reach them, or you want your details removed from the sources we use, write to support@keplent.com and we will pass the request to the relevant customer and act on our own records. Say “do not contact” and we will honour it across the data we hold.
11. Google user data
When you connect a Gmail account, Google asks you to authorise specific permissions before anything is shared with us. Keplent’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
- We use Gmail data only to provide features you asked for — sending and tracking outreach from your own inbox.
- We do not transfer it to anyone except as needed to provide those features, for security, or where the law requires it.
- We do not use it for advertising, and we do not allow humans to read it except with your explicit consent, for security or to comply with the law.
- You can revoke our access at any time from your Google Account permissions page or by disconnecting the inbox in Keplent.
12. Cookies
We set only strictly necessary cookies, and there is no analytics or advertising tracking on this site. The full list is on the Cookie Policy page.
13. Children
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, write to support@keplent.com and we will delete it.
14. Changes to this policy
We update this policy when our processing changes. The date at the top always reflects the current version, and we will give notice by email or in the app before a material change takes effect.