Privacy Policy

Last updated: 30 July 2026

This policy explains how Keplent (“Keplent”, “we”) handles personal data when you visit keplent.com, join the waitlist, or use the Keplent platform. It is written to meet the EU General Data Protection Regulation (GDPR).

1. Who is responsible for your data

The controller is Keplent, [REGISTERED ADDRESS], [COUNTRY OF INCORPORATION]. For anything to do with privacy — a question, a request, or a complaint — write to support@keplent.com and it reaches the person accountable for it here.

Two different roles. For data about our own visitors, waitlist subscribers and account holders we are the controller — this policy describes that. For the content our customers put into their workspace — their lead lists, prospects, campaign records and client data — we act as a processor on the customer’s instructions, under our Data Processing Agreement. If you were contacted by an agency using Keplent, that agency is the controller; see section 10 below.

2. What we collect

CategoryWhat it includesWhere it comes from
Waitlist dataThe email address you submit on the home pageYou
Account dataName, username, email address, password (stored hashed by our backend), organisation and roleYou, or the colleague who invited you
Workspace contentLeads, contacts, campaigns, sequences, automations, uploaded assets, reports and messages created in your workspaceYou and the sources you connect
Connected accountsTokens and the mail data we are authorised to read or send when you connect an inbox or a third-party toolYou, via the provider’s consent screen
Support and communicationsEmails, onboarding calls and product feedbackYou
Technical dataIP address, browser and device information, and server logs generated when you use the ServiceAutomatically

We do not ask for special categories of data (health, beliefs, and so on) and ask you not to load them into the workspace.

3. Why we use it, and on what legal basis

PurposeLegal basis
Providing the Service, hosting your workspace and running the features you usePerformance of a contract (Art. 6(1)(b))
Creating and administering your account, and supporting youPerformance of a contract
Keeping you on the waitlist and telling you when access opensConsent (Art. 6(1)(a)) — withdraw it any time by replying to any of those emails
Keeping the Service secure, preventing abuse, debugging and maintaining logsLegitimate interests (Art. 6(1)(f)) in a secure, working product
Improving the product, and understanding which features are usedLegitimate interests
Sending service messages about changes, incidents or your subscriptionPerformance of a contract
Meeting accounting, tax and other legal obligationsLegal obligation (Art. 6(1)(c))

We do not sell personal data, and we do not use your workspace content to train general-purpose AI models.

4. Automated processing and AI

Keplent uses automated systems to research prospects, enrich records, score them against a profile you describe, draft outreach copy and summarise results. These produce suggestions for you to review and change. They do not make decisions producing legal or similarly significant effects about you within the meaning of Art. 22 GDPR, and a person on your team decides what is actually sent.

5. Who we share it with

We share personal data only with service providers who process it on our behalf under written contracts, and only as far as they need it to do their job. The current list — what each one does, where it is, and the safeguard relied on — is published at keplent.com/subprocessors.

We may also disclose data:

  • to a provider you choose to connect, at your instruction — for example when you send a lead to your CRM;
  • to professional advisers, auditors or insurers where necessary;
  • to public authorities where the law requires it, after checking the request is valid;
  • to a buyer or successor if the business is sold or reorganised, with notice to you.

6. International transfers

Our production infrastructure runs in [HOSTING REGION]. Where a processor is outside the European Economic Area, the transfer relies on an adequacy decision or on the European Commission’s Standard Contractual Clauses with supplementary measures where needed. The mechanism used for each processor is shown on the Subprocessors page, and you can request a copy of the clauses at support@keplent.com.

7. How long we keep it

  • Account data: for as long as the account is open, and up to 12 months afterwards so it can be restored if you come back.
  • Workspace content: for as long as the account is open. On termination we delete or return it in line with the DPA — export first if you need it.
  • Waitlist emails: until access opens or you ask us to remove you, whichever is sooner.
  • Authentication tokens for connected accounts: until you disconnect the account or revoke access at the provider.
  • Technical and security logs: normally up to 12 months.
  • Invoices and accounting records: for the period required by tax law, typically 6 to 10 years.

8. Security

Access to the platform runs over HTTPS. Session tokens are stored in cookies marked httpOnly, so page scripts cannot read them, and secure in production. Passwords are hashed by our backend and never stored in readable form. Access to production data is limited to the staff who need it. No system is perfectly secure, so if a breach affects your data we will notify you and the supervisory authority as the GDPR requires.

9. Your rights

Under the GDPR you can ask us to:

  • confirm what personal data we hold about you and give you a copy (access);
  • correct data that is wrong or incomplete (rectification);
  • delete it (erasure), where we have no overriding reason to keep it;
  • restrict or object to processing based on our legitimate interests;
  • give you your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting processing already carried out.

Write to support@keplent.com. We answer within one month and may ask you to confirm your identity first. If you are unhappy with the outcome you can complain to [SUPERVISORY AUTHORITY], or to the authority where you live or work.

If your data sits in a customer’s workspace, we will pass your request to that customer, who is the controller and answers it. See the next section.

10. If you were contacted by an agency using Keplent

Keplent helps agencies find and contact business prospects. If you received an email or a call from an agency using our platform, your details will have been compiled from public professional sources — company websites, professional networks, public business directories — or from licensed data partners, and every record carries its source. Typically that means your name, job title, employer, business email address and public professional profile.

The agency that contacted you is the controller of that data, and decides why and how it is used. We process it for them as a processor. Your rights — access, correction, erasure, objection — are exercised against that agency, and their contact details will be in the message you received.

If you cannot reach them, or you want your details removed from the sources we use, write to support@keplent.com and we will pass the request to the relevant customer and act on our own records. Say “do not contact” and we will honour it across the data we hold.

11. Google user data

When you connect a Gmail account, Google asks you to authorise specific permissions before anything is shared with us. Keplent’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

  • We use Gmail data only to provide features you asked for — sending and tracking outreach from your own inbox.
  • We do not transfer it to anyone except as needed to provide those features, for security, or where the law requires it.
  • We do not use it for advertising, and we do not allow humans to read it except with your explicit consent, for security or to comply with the law.
  • You can revoke our access at any time from your Google Account permissions page or by disconnecting the inbox in Keplent.

12. Cookies

We set only strictly necessary cookies, and there is no analytics or advertising tracking on this site. The full list is on the Cookie Policy page.

13. Children

The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, write to support@keplent.com and we will delete it.

14. Changes to this policy

We update this policy when our processing changes. The date at the top always reflects the current version, and we will give notice by email or in the app before a material change takes effect.