Privacy
Privacy notice
This notice explains what personal data OutboundFix handles, why we handle it, who receives it, and what rights you may have. It applies to visitors to this website, customers and their authorized users, and people whose business details appear on public websites that our customers ask us to analyze. OutboundFix is a B2B commercial decision tool offered for business and professional use.
Effective: 2026-09-21.
Source-backed B2B legal baseline. This page is based on the product’s current behavior and authoritative public legal sources. It is not a claim of lawyer approval or universal compliance. Any item marked “Release verification required” is a concrete provider, production, operational or product fact that must still be verified before publication.
Who is responsible for your data
The data controller is Vesanto Consulting.
Registered address: Lapinlahdenkatu 16, 00180 Helsinki, Finland.
How to contact us about your data: use the Privacy Choices page, which records your request for review by a person, or write to [email protected].
What personal data we handle
- Account data: your work email address when you create a free workspace, your workspace identifier, your plan and your usage.
- Enquiries and requests: your name, work email, company, website and message when you contact us, and the details you give in a privacy request.
- Orders: your name, email address and company details for paid services, plus payment confirmation from our payment provider. Card details are entered on the payment provider’s page and are not received or stored by OutboundFix.
- Workspace content: the domains you submit, the policy you write, the decisions and evidence produced, your feedback comments and your questions to the AI Agent.
- Prospect and public business data: publicly available information about businesses and, incidentally, the names, job titles and business contact details of individuals published on their public pages.
- Technical data: your IP address, which is passed to our bot check when you complete it, and browser information that your browser sends to our servers. The page you came from and campaign parameters in a link are recorded with your requests and workspace activity, to see which pages lead to sign ups and enquiries.
- In your browser: a workspace key that keeps you signed in on this browser, and your privacy preferences. These are necessary for the site to work and are not used for advertising.
Where the data comes from
From you, when you sign up, submit domains, write a policy, give feedback, ask a question, place an order or contact us. From publicly available company websites, when a customer asks us to analyze a company. From business data providers and public sources, when we identify companies and business contacts to tell about OutboundFix. From your browser and our servers, for technical data.
Where the GDPR applies and we obtain your personal data indirectly for our own outreach, we provide the information required by Article 14 no later than our first communication with you. Public availability is the source of the data, not an automatic exemption from transparency.
Why we use it, and on what legal basis
- Provide the product (create your workspace, produce decisions, research, policy, feedback and AI Agent answers): performance of a contract with you.
- Take payment and keep records: performance of a contract and compliance with legal obligations, such as tax and accounting.
- Security, fraud and abuse prevention, and keeping the service reliable: our legitimate interests.
- Understand and improve the product, including which pages lead to sign ups: our legitimate interests, using first-party measurement only.
- Tell relevant businesses about OutboundFix using business contact details: our legitimate interests, with an easy way to object.
- Answer enquiries and privacy requests: our legitimate interests and compliance with legal obligations.
- Where a law requires consent, we ask for it, and you can withdraw it at any time.
Where EU, EEA or UK data protection law applies to our processing of your data, we rely on the legal bases above. Where those laws do not apply to you, we still handle your data for the purposes above and in accordance with this notice.
Where we rely on legitimate interests under Article 6(1)(f) GDPR, we document the interest, whether the processing is necessary for it, and the balance against the individual’s interests, rights and freedoms. If you object to processing for our direct marketing, we stop using your personal data for that direct-marketing purpose.
How long we keep it
We keep personal data only as long as we need it for the purpose it was collected for, and we run an automated retention job to enforce this.
- Prospect research content — the raw page content gathered when we evaluate a business is deleted 90 days from the date we collected it. Structural evidence metadata (source, reliability score) is kept for decision audit purposes.
- Evaluation records — the full chain of commercial decisions, claims, and policy snapshots for an evaluated business is deleted 24 months after we last evaluated that business.
- Workspace and account data — kept while your workspace exists; deleted within 30 days of workspace or account deletion.
- Privacy requests — a record of any privacy right request you submit is kept for 3 years after the case is closed so we can show how we handled it, then deleted.
- Suppression and objection records — if you object to direct-marketing contact, we retain only a one-way hash of your email address (not the address itself) to continue honouring the objection. No additional data is stored alongside it.
- Accounting and payment records — orders and payment events are retained for at least 6 years from the end of the relevant financial year as required by Finnish accounting law. These records are excluded from the automated retention job.
- Provider logs — log retention by our hosting and tool providers is governed by each provider's own policy; verified periods are documented in our internal provider register.
Who receives it
We use service providers who process data for us. They include:
- Infrastructure and database hosting for the application and its data.
- Web hosting and bot protection for this website, which sees your IP address when you complete the verification challenge.
- Payment providers for paid services.
- AI model providers, which receive bounded evidence and question text to help produce explanations. They do not decide verdicts.
- Workflow and email sending tools, and a business data provider, used when we contact businesses about OutboundFix.
We may also disclose data where the law requires it, or to protect our rights or the safety of others. Based on how the product works today, OutboundFix does not sell personal information and does not share it for cross-context behavioral advertising, and this website loads no advertising trackers. If this changes, we will update this notice first. See Do Not Sell or Share My Personal Information.
This is a factual description of our current business model, not a statement that every disclosure has the same legal classification in every jurisdiction. Service-provider disclosures are described according to the applicable role and agreement.
Transfers outside your country
Some of our providers may process data in other countries, including outside the European Economic Area and the United Kingdom. Where a law requires a safeguard for such a transfer, we will use one that it recognizes.
How we protect it
Connections use HTTPS. Workspace data is scoped to your workspace, in the application and in the database functions it calls. Database access uses narrow, least-privilege roles, and the application role cannot read or change tables directly. Secrets are kept on the server, not in your browser. Sign-up and public forms are protected by a bot check, and some requests are rate limited. No system is perfectly secure, and we will tell you and the relevant authority about a breach where the law requires it.
Your rights
Depending on where you are and which privacy law applies to our processing of your data, you may have rights to:
- Access: ask for a copy of your personal data and how it is used.
- Correction: ask us to fix data that is wrong or incomplete.
- Deletion: ask us to delete your data, subject to what we must keep by law.
- Objection: object to processing based on our legitimate interests, including being contacted about OutboundFix. Where you object to direct marketing, we will stop.
- Portability: where the law provides it, receive the data you gave us in a common, machine-readable format.
- Withdraw consent: where we rely on consent, withdraw it at any time. This does not affect what we did before.
- Complain: you can complain to the data protection or privacy authority in the country where you live or work, or where you think a problem happened.
These rights may be subject to conditions and exceptions under the applicable law. Use Privacy Choices to make a request. A person reads each request and confirms it is you before acting, so nobody can obtain or delete your data by pretending to be you. We aim to answer within the time the applicable law requires.
EU and EEA
Where the GDPR applies, you have rights of access, rectification, erasure, restriction of processing, data portability, and objection. You may also have the right not to be subject to a solely automated decision that significantly affects you. You may complain to the Finnish supervisory authority or, where applicable, to the authority in the EU member state where you live, work, or where the alleged infringement occurred.
United Kingdom
Where the UK GDPR applies, equivalent rights apply under UK data protection law. You may complain to the Information Commissioner’s Office (ICO).
California and other US states
If a US state privacy law applies to our processing of your personal information, you may have additional rights under that law. For California, applicable rights may include the right to know, delete, correct, opt out of sale or sharing of personal information, and the right to non-discrimination for exercising your rights. The full California controls are labeled “Do Not Sell or Share My Personal Information” on the Privacy Choices page and footer.
California privacy rights are shown conditionally because statutory coverage depends on the applicable business and processing thresholds. We monitor those thresholds and do not represent that California law applies to every visitor or every OutboundFix processing activity.
For GDPR matters involving our establishment in Finland, you may contact the Finnish Data Protection Ombudsman. Depending on the circumstances, you may also have the right to complain to another competent supervisory authority in the EU or EEA country where you live, work or consider an infringement occurred.
Automated processing and AI assisted decision support
OutboundFix produces a PASS, RESEARCH MORE or KILL result about a company for a customer. The result comes from a rule-based decision engine that applies the customer’s own policy to recorded evidence. AI does not set a verdict, and it cannot change a policy, start research or send messages: a person confirms any change. AI models can help gather and summarize evidence and explain a result, and the AI Agent reads a workspace and proposes next steps. These results are about businesses and are used by our customers to prioritize their own work. Customers can give feedback on any result, and a person can ask us about how their data was used.
Article 22 GDPR concerns decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect that individual. OutboundFix’s product verdict is a company-level prioritization output. OutboundFix does not itself use that verdict to make a solely automated decision about an individual that produces legal or similarly significant effects. If the product later gains that kind of individual-level decision authority, this notice and the safeguards will be reassessed before the change is enabled.
Prospect and publicly available business data
When a customer submits a company domain, we read a small, fixed number of publicly available pages of that company’s official website, without signing in, and keep what is relevant as evidence in that customer’s workspace. This can include names and roles published on those pages; email addresses and phone numbers are removed from the page text before it becomes decision evidence. We use it to produce that customer’s decision. Text on a website is treated as data to be described. It is never treated as an instruction. Evidence is not shared between different customers’ workspaces. If you appear in this kind of data and want to exercise a right, use Privacy Choices.
Where Vesanto Consulting is the controller and Article 14 GDPR applies to personal data obtained indirectly, we provide the required information within the statutory period and, when we use the data to contact the person, no later than the first communication. We do not assume that information being publicly available removes that transparency duty. Where a customer is the controller and OutboundFix processes the evidence only on that customer’s documented instructions, the customer remains responsible for its controller transparency duties and OutboundFix assists as required by the applicable DPA.
Changes to this notice
When we change how we handle personal data, we update this notice and its effective date before the change takes effect. For a material change that affects an existing paid customer, we also provide direct notice by an available account or business contact channel before the change where reasonably practicable. A change required urgently for law, security or abuse prevention may take effect sooner.