SmartReach emblemSmartReach AI
← Back to SmartReach

Privacy Policy

Last updated: September 16, 2026

SmartReach AI LLC (“SmartReach,” “Company,” “we,” “us,” or “our”) respects your privacy and is committed to responsible handling of personal information.

This Privacy Policy explains how SmartReach collects, receives, uses, processes, stores, analyzes, derives, discloses, and protects personal information in connection with:

  • smartreachai.com and other SmartReach websites;
  • the SmartReach AI platform;
  • SmartData;
  • SmartAgent;
  • SmartMail;
  • SmartLink;
  • SmartSonar;
  • Managed Outbound and full-service outreach;
  • SmartDesign website services;
  • SmartConvert;
  • CRM, automation, AI chat, voice, telephone, SMS, WhatsApp, email, appointment booking, analytics, website hosting, and related services;
  • our sales, support, marketing, and business operations; and
  • other products and services offered by SmartReach.

This Policy should be read together with our Terms and Conditions, Cookie Policy, and Data Processing Addendum (“DPA”), where applicable.

1. Who We Are

SmartReach AI LLC is a limited liability company organized under the laws of the State of Wyoming, United States.

Our website is:

https://www.smartreachai.com

Our platform may be accessed through:

https://app.smartreachai.com

For privacy inquiries:

privacy@smartreachai.com

For legal inquiries:

legal@smartreachai.com

2. Business Transfer

Effective June 1, 2026, certain business operations, customer relationships, software platforms, technology, intellectual property, data assets, and services previously operated by SSC International Ltd. were transferred to or are now operated by SmartReach AI LLC.

SmartReach AI LLC is responsible for processing personal information in connection with the SmartReach Services described in this Policy, except where SmartReach acts solely as a processor or service provider on behalf of a Client.

3. When This Privacy Policy Applies

This Policy may apply to information relating to:

  • Website visitors;
  • SmartReach customers;
  • SmartReach platform users;
  • potential customers;
  • business contacts;
  • people who request demos or information;
  • individuals who communicate with SmartReach;
  • business professionals contained in B2B research or intelligence data;
  • prospects included in outreach campaigns;
  • recipients of Managed Outbound communications;
  • SmartConvert users;
  • visitors interacting with SmartConvert-enabled websites;
  • people communicating through AI chat, SMS, WhatsApp, email, telephone, or voice tools;
  • people booking appointments through SmartConvert;
  • individuals contained in a Client’s CRM or customer database;
  • vendors, contractors, partners, and service providers; and
  • applicants for employment or contractor roles.

4. SmartReach’s Role

SmartReach may process personal information in different roles depending on the circumstances.

4.1 SmartReach as Controller or Business

SmartReach generally determines the purposes and means of processing when we collect information for our own business purposes.

Examples include:

  • visitors to SmartReach websites;
  • SmartReach customers and account holders;
  • billing information;
  • SmartReach sales prospects;
  • people communicating directly with SmartReach;
  • SmartReach marketing activities;
  • security and fraud prevention;
  • website analytics;
  • B2B business intelligence activities where SmartReach determines the purpose of processing; and
  • our own business administration.

In these situations, SmartReach generally acts as a controller, business, or equivalent role under applicable privacy law.

4.2 SmartReach as Processor or Service Provider

Clients may provide personal information to SmartReach through SmartConvert, Managed Outbound, SmartDesign, integrations, CRM systems, communications tools, or other Services.

Where SmartReach processes personal information solely on behalf of a Client and according to that Client’s instructions, the Client generally acts as controller or business and SmartReach acts as processor, service provider, or contractor.

This processing is governed by our DPA where applicable.

If your information was collected by one of our Clients through a SmartConvert-powered website, chatbot, form, CRM, telephone interaction, campaign, or other Client service, you may need to contact that Client directly to exercise your privacy rights.

SmartReach will assist Clients with valid privacy requests as required by law and our DPA.

5. Personal Information We May Collect

The information we collect depends on how you interact with SmartReach and which Services are used.

5.1 Identity and Contact Information

We may process:

  • first name;
  • last name;
  • business name;
  • job title;
  • department;
  • professional role;
  • work email address;
  • telephone number;
  • business address;
  • country;
  • state, region, or general location;
  • professional website;
  • social or professional profile information; and
  • other business contact details.

5.2 Account Information

We may process:

  • account identifier;
  • username;
  • authentication information;
  • account role;
  • permissions;
  • organization membership;
  • subscription information;
  • account settings;
  • preferences;
  • connected accounts;
  • integration information; and
  • login and security information.

Passwords are intended to be maintained using security measures appropriate to the applicable system.

5.3 Client and Commercial Information

We may process information relating to:

  • Services purchased;
  • subscription level;
  • contracts;
  • invoices;
  • transactions;
  • usage credits;
  • billing status;
  • support history;
  • order forms;
  • proposals;
  • customer preferences;
  • account activity; and
  • business relationship history.

5.4 Payment Information

Payments may be processed through third-party payment providers.

Depending on the payment method, we may receive:

  • payer name;
  • billing address;
  • transaction identifier;
  • payment status;
  • card type;
  • limited card information;
  • bank-related transaction information; and
  • other information necessary to process or reconcile payments.

SmartReach may not directly receive or store complete payment card numbers when payment information is collected directly by a payment processor.

5.5 Communications and Support Information

When you communicate with SmartReach, we may process:

  • emails;
  • chat messages;
  • support requests;
  • telephone communications;
  • meeting notes;
  • call summaries;
  • correspondence;
  • files or documents you provide;
  • feedback;
  • survey responses; and
  • information contained in your communications.

5.6 SmartConvert CRM Information

Depending on Client configuration, SmartConvert may process:

  • names;
  • email addresses;
  • telephone numbers;
  • company information;
  • lead source;
  • pipeline stage;
  • contact status;
  • tags;
  • notes;
  • tasks;
  • opportunities;
  • estimated deal values;
  • appointments;
  • customer history;
  • communication history;
  • forms;
  • survey responses;
  • custom fields;
  • workflow activity;
  • consent status;
  • opt-out status; and
  • other information entered into the CRM.

5.7 Chat and AI Assistant Information

When someone interacts with a SmartConvert AI assistant or chatbot, we may process:

  • chat messages;
  • questions;
  • responses;
  • timestamps;
  • conversation history;
  • contact information submitted during the conversation;
  • page or website context;
  • appointment requests;
  • product or service interests;
  • lead qualification information;
  • AI-generated summaries;
  • conversation classifications;
  • intent signals;
  • recommended actions; and
  • related metadata.

5.8 Telephone and Voice Information

Where SmartConvert telephone or voice functionality is used, we may process:

  • telephone numbers;
  • incoming and outgoing call information;
  • call date and time;
  • call duration;
  • routing information;
  • call outcome;
  • transcripts;
  • AI-generated summaries;
  • conversation classifications;
  • appointment information;
  • call metadata; and
  • audio recordings where recording is enabled.

Calls may be recorded or transcribed where the applicable Client has enabled those features.

Required notices or consent must be provided or obtained where applicable law requires them.

When SmartReach processes calls on behalf of a Client, the Client is responsible for determining whether recording or transcription is lawful and what notice or consent is required.

SmartReach does not represent that audio recordings are used to create biometric identifiers unless expressly disclosed for a specific feature.

5.9 SMS and WhatsApp Information

Where SMS, WhatsApp, or similar messaging features are used, we may process:

  • telephone number;
  • account or messaging identifier;
  • message content;
  • attachments;
  • timestamps;
  • delivery status;
  • read or interaction status where available;
  • opt-in information;
  • opt-out information;
  • workflow activity; and
  • related metadata.

5.10 Email Information

Our Services may process:

  • sender address;
  • recipient address;
  • subject line;
  • message content;
  • reply content;
  • send status;
  • delivery status;
  • bounce status;
  • unsubscribe status;
  • timestamps;
  • engagement information where permitted;
  • classification of responses;
  • email infrastructure information; and
  • campaign performance information.

5.11 Appointment and Calendar Information

SmartConvert and other Services may process:

  • requested appointment times;
  • scheduled date and time;
  • timezone;
  • meeting type;
  • calendar availability;
  • participant information;
  • calendar identifiers;
  • appointment status;
  • cancellations;
  • rescheduling information;
  • meeting links; and
  • appointment-related communications.

5.12 Website Visitor and Usage Information

When you visit a SmartReach website or a SmartConvert-enabled website, depending on configuration and consent requirements, we may process:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • language;
  • approximate geographic location;
  • referring website;
  • landing page;
  • pages viewed;
  • links clicked;
  • date and time of visits;
  • session information;
  • time spent on pages;
  • conversion events;
  • forms opened or submitted;
  • chatbot interactions;
  • booking activity;
  • website navigation;
  • traffic source;
  • cookie identifiers;
  • advertising identifiers; and
  • similar technical information.

5.13 Managed Outbound and B2B Prospect Information

SmartReach’s outreach, research, and intelligence Services may process professional or business-related information such as:

  • name;
  • company;
  • job title;
  • department;
  • seniority;
  • professional email address;
  • business telephone number;
  • company location;
  • company size;
  • industry;
  • company website;
  • professional profile URL;
  • professional profile information;
  • publicly available business information;
  • professional interests;
  • business events or signals;
  • campaign history;
  • outreach status;
  • reply information;
  • outcome classifications;
  • intent indicators;
  • engagement data;
  • campaign metadata; and
  • derived business intelligence.

Sources may include Clients, public business information, professional websites, company websites, publicly accessible professional information, licensed data providers, verification providers, enrichment providers, business directories, integrations, and other lawful sources.

5.14 Social and Professional Platform Information

Where a Service connects with or uses professional or social platforms, we may process information made available through authorized integrations, Client-provided access, licensed providers, or publicly available sources.

This may include:

  • profile information;
  • business name;
  • professional role;
  • profile URL;
  • business-related posts;
  • public engagement;
  • public business interests; and
  • communications processed as part of a Client-authorized campaign.

5.15 SmartDesign Information

For SmartDesign projects, we may process:

  • Client contact information;
  • company details;
  • branding materials;
  • logos;
  • website content;
  • photographs;
  • videos;
  • product information;
  • service descriptions;
  • testimonials;
  • employee or team information;
  • website credentials;
  • domain information;
  • hosting information;
  • integration credentials;
  • analytics information; and
  • materials supplied by the Client.

Clients are responsible for ensuring they have the right to provide personal information contained in website content and materials supplied to SmartReach.

5.16 Derived Information and Inferences

Our technology may generate information from other data, including:

  • lead scores;
  • intent classifications;
  • prospect classifications;
  • reply classifications;
  • sentiment or topic classifications;
  • predicted relevance;
  • recommended next actions;
  • engagement scores;
  • campaign performance indicators;
  • website intent signals;
  • customer journey information;
  • account-level signals;
  • AI summaries;
  • analytics;
  • benchmarks; and
  • similar derived information.

5.17 Sensitive Personal Information

SmartReach does not generally require sensitive personal information to provide standard B2B Services.

However, Clients or users may submit information through CRM records, chat conversations, telephone calls, forms, messages, or other communications that could be considered sensitive under applicable law.

Users and Clients should avoid providing sensitive information unless it is reasonably necessary.

Where sensitive information is processed, we use it only as permitted under applicable law and applicable contractual instructions.

6. Where We Obtain Personal Information

We may obtain personal information:

  • directly from you;
  • from a SmartReach Client;
  • from your employer or organization;
  • from authorized users;
  • through SmartReach websites;
  • through SmartConvert-enabled websites;
  • through forms;
  • through chat;
  • through email;
  • through telephone or voice communications;
  • through SMS or WhatsApp;
  • through appointment systems;
  • through CRM systems;
  • from integrations authorized by a Client;
  • from professional or business websites;
  • from publicly accessible sources;
  • from licensed B2B data providers;
  • from data enrichment providers;
  • from verification providers;
  • from business directories;
  • from professional databases;
  • from advertising or analytics providers;
  • from referral partners;
  • from service providers; and
  • from information generated through use of our Services.

When required by applicable law, SmartReach provides appropriate information regarding personal data obtained from third-party or public sources.

7. How We Use Personal Information

We may process personal information for the following purposes.

7.1 Providing the Services

We use information to:

  • create and manage accounts;
  • provide SmartReach products;
  • provide Managed Outbound;
  • operate SmartConvert;
  • provide SmartDesign;
  • process campaigns;
  • operate CRM functionality;
  • manage leads;
  • send communications;
  • schedule appointments;
  • operate telephone and messaging functions;
  • host websites;
  • provide analytics;
  • perform research;
  • provide integrations;
  • provide support; and
  • otherwise perform our contractual obligations.

7.2 Customer Support

We may use information to:

  • respond to questions;
  • investigate problems;
  • provide technical support;
  • troubleshoot;
  • process requests;
  • provide training;
  • manage Client relationships; and
  • improve customer service.

7.3 Sales and Marketing

Where permitted by law, we may use business contact information to:

  • respond to inquiries;
  • conduct B2B outreach;
  • market SmartReach products;
  • provide product information;
  • invite people to demonstrations or events;
  • follow up with business contacts;
  • personalize communications;
  • measure campaign performance; and
  • develop customer relationships.

Recipients may opt out of marketing communications as described below.

7.4 Managed Outbound

When providing outreach Services for Clients, we may process professional contact and campaign information to:

  • identify relevant business prospects;
  • verify contact information;
  • segment prospects;
  • research companies;
  • personalize communications;
  • send Client-authorized outreach;
  • manage replies;
  • maintain suppression lists;
  • book meetings;
  • classify outcomes;
  • update CRM systems;
  • measure campaign performance; and
  • improve campaign effectiveness.

7.5 SmartConvert

We may process information to:

  • manage customer relationships;
  • operate CRM records;
  • respond through AI assistants;
  • route inquiries;
  • automate follow-up;
  • send messages;
  • place or receive calls;
  • schedule appointments;
  • manage leads and opportunities;
  • provide analytics;
  • identify website activity;
  • personalize customer experiences;
  • trigger workflows; and
  • perform actions configured by the applicable Client.

7.6 Artificial Intelligence

We may use AI systems to:

  • generate communications;
  • summarize conversations;
  • classify replies;
  • analyze data;
  • detect intent;
  • assist with research;
  • answer questions;
  • recommend next actions;
  • support sales and customer service;
  • personalize communications;
  • improve workflows;
  • perform quality evaluation; and
  • provide features requested by Clients.

7.7 Analytics and Product Improvement

We may use information to:

  • measure product usage;
  • understand feature performance;
  • troubleshoot;
  • improve Services;
  • test new functionality;
  • measure campaigns;
  • develop analytics;
  • develop benchmarks;
  • evaluate models;
  • improve AI systems;
  • improve fraud detection;
  • analyze trends; and
  • understand customer needs.

7.8 Security and Fraud Prevention

We may process information to:

  • authenticate users;
  • detect unauthorized access;
  • prevent abuse;
  • investigate fraud;
  • protect accounts;
  • maintain network security;
  • enforce usage restrictions;
  • identify malicious activity; and
  • protect SmartReach, Clients, Users, and third parties.

7.9 Legal and Compliance Purposes

We may process information to:

  • comply with legal obligations;
  • respond to lawful requests;
  • enforce agreements;
  • establish or defend legal claims;
  • protect rights and property;
  • investigate misuse;
  • maintain required records;
  • respond to regulatory authorities; and
  • meet tax, accounting, corporate, and compliance obligations.

8. Legal Bases for Processing

Where GDPR, UK GDPR, or another law requires a lawful basis, SmartReach may rely on one or more of the following.

8.1 Contract

Processing may be necessary to perform a contract with you or take steps at your request before entering into a contract.

This may apply to:

  • account creation;
  • delivery of Services;
  • billing;
  • SmartDesign;
  • SmartConvert;
  • customer support;
  • subscriptions; and
  • other contractual services.

8.2 Legitimate Interests

We may process information where necessary for legitimate business interests and where those interests are not overridden by applicable individual rights.

These interests may include:

  • operating a B2B technology company;
  • providing and improving Services;
  • B2B sales and marketing;
  • business development;
  • researching business prospects;
  • network and information security;
  • fraud prevention;
  • measuring product usage;
  • improving customer experience;
  • protecting legal rights;
  • maintaining accurate business information; and
  • developing analytics and business intelligence.

8.3 Consent

Where required, we rely on consent.

Examples may include:

  • certain cookies;
  • certain electronic marketing;
  • recording calls where consent is legally required;
  • certain communications;
  • certain uses of sensitive information; and
  • other activities requiring consent.

Consent may be withdrawn as permitted by law.

8.4 Legal Obligation

We may process information where necessary to comply with legal obligations.

8.5 Other Lawful Bases

Where applicable law provides another lawful basis, SmartReach may rely on that basis.

9. Aggregated, De-Identified, and Derived Data

SmartReach may create:

  • aggregated information;
  • de-identified information;
  • anonymized information;
  • statistical information;
  • derived information;
  • campaign benchmarks;
  • model evaluation data;
  • performance data; and
  • other information that does not reasonably identify an individual.

We may use this information for:

  • analytics;
  • product development;
  • benchmarking;
  • research;
  • AI and machine-learning development;
  • model training and evaluation;
  • service improvement;
  • commercial analytics;
  • dataset development; and
  • other lawful business purposes.

SmartReach may license, disclose, or commercialize information that has been appropriately aggregated or de-identified so that it is not reasonably intended to identify an individual.

SmartReach uses measures designed to prevent externally licensed de-identified datasets from containing direct identifiers.

Externally licensed de-identified datasets are not intended to include direct personal identifiers such as personal names tied to an identifiable record, personal email addresses, telephone numbers, raw private messages, or identifiable Client campaign information unless legally permitted and separately authorized.

SmartReach does not attempt to re-identify information that has been de-identified except as permitted by law for purposes such as evaluating whether de-identification processes are effective.

10. AI Model Processing

SmartReach Services may use proprietary or third-party artificial intelligence systems.

Information submitted to AI-enabled features may be transmitted to AI technology providers acting as service providers or subprocessors.

The information processed depends on the feature being used and may include:

  • prompts;
  • chat messages;
  • emails;
  • business information;
  • CRM information;
  • prospect information;
  • call transcripts;
  • summaries;
  • website content;
  • documents; and
  • other information needed to produce the requested output.

SmartReach may use de-identified, aggregated, or derived data to evaluate, train, test, or improve its own models, systems, classifiers, prompts, algorithms, and Services.

Use of identifiable Client Data for AI processing remains subject to applicable agreements, our DPA, applicable law, and the purpose for which the information was provided.

11. Automated Processing and Profiling

SmartReach uses automated systems for activities that may include:

  • prospect scoring;
  • lead qualification;
  • reply classification;
  • intent detection;
  • prioritization;
  • personalization;
  • website visitor analysis;
  • workflow routing;
  • spam and fraud detection;
  • recommended next actions;
  • conversation analysis; and
  • campaign optimization.

SmartReach does not generally use solely automated processing, in its own capacity as controller, to make decisions that produce legal or similarly significant effects concerning individuals.

SmartConvert Clients may configure automated systems to:

  • send messages;
  • route leads;
  • schedule follow-up;
  • classify inquiries;
  • book appointments;
  • update CRM records; or
  • perform other workflow actions.

Where SmartReach acts as processor, the Client determines how those automated features are configured and used.

Where applicable law grants rights relating to certain automated decision-making or profiling, requests may be submitted using the contact details in this Policy.

12. Cookies and Tracking Technologies

SmartReach and its service providers may use:

  • cookies;
  • pixels;
  • tags;
  • local storage;
  • SDKs;
  • analytics technologies;
  • advertising technologies;
  • session technologies; and
  • similar tracking tools.

These technologies may be used for:

  • essential website functionality;
  • authentication;
  • security;
  • remembering settings;
  • analytics;
  • measuring website performance;
  • understanding traffic;
  • attribution;
  • conversion measurement;
  • personalization; and
  • advertising where permitted.

Where applicable law requires consent before using non-essential cookies or similar technologies, SmartReach will request consent.

Additional information is provided in our Cookie Policy and cookie preference tools.

13. Advertising and Analytics

We may use analytics and advertising providers to measure website usage, understand campaign effectiveness, and market SmartReach Services.

Depending on the technologies enabled and your choices, these providers may receive information such as:

  • IP address;
  • device information;
  • cookie identifiers;
  • pages viewed;
  • referring URLs;
  • interaction information;
  • advertising identifiers; and
  • conversion events.

Certain disclosures for cross-context behavioral advertising may be considered “sharing” under California law even where no money is exchanged.

Where required, SmartReach provides mechanisms to opt out of qualifying sale or sharing.

SmartReach honors legally recognized opt-out preference signals, including Global Privacy Control, where required by applicable law.

14. How We Disclose Personal Information

We may disclose personal information to the following categories of recipients.

14.1 Service Providers and Subprocessors

We may use providers for:

  • cloud hosting;
  • infrastructure;
  • security;
  • databases;
  • AI;
  • email;
  • telecommunications;
  • SMS;
  • WhatsApp;
  • telephone services;
  • CRM functionality;
  • analytics;
  • customer support;
  • payment processing;
  • appointment scheduling;
  • website hosting;
  • data enrichment;
  • data verification;
  • professional data;
  • marketing;
  • development;
  • storage;
  • monitoring; and
  • other business operations.

These providers may process information only for permitted purposes subject to applicable contractual arrangements.

14.2 SmartReach Clients

Where SmartReach provides Services on behalf of a Client, information may be disclosed to that Client.

For example, information submitted through a Client’s SmartConvert chatbot may become part of that Client’s CRM.

14.3 Connected Services

If a Client connects SmartReach to another platform, we may transmit information to that platform according to Client instructions.

Examples may include:

  • calendars;
  • CRMs;
  • email systems;
  • social platforms;
  • payment systems;
  • communication systems;
  • analytics services; and
  • other integrations.

14.4 Affiliates

Information may be disclosed to SmartReach Affiliates for legitimate business purposes subject to appropriate protections.

14.5 Professional Advisers

We may disclose information to:

  • attorneys;
  • accountants;
  • auditors;
  • insurers;
  • financial institutions;
  • consultants; and
  • other professional advisers.

14.6 Legal and Regulatory Disclosures

We may disclose information when reasonably necessary to:

  • comply with law;
  • respond to legal process;
  • respond to lawful government requests;
  • protect legal rights;
  • investigate fraud;
  • protect safety;
  • enforce agreements; or
  • protect SmartReach, Clients, Users, or third parties.

14.7 Business Transactions

Information may be transferred as part of:

  • a merger;
  • acquisition;
  • financing;
  • restructuring;
  • reorganization;
  • bankruptcy;
  • sale of assets;
  • investment;
  • due diligence process; or
  • transfer of all or part of SmartReach’s business.

Appropriate confidentiality and data protection measures will be used where required.

15. Sale and Sharing of Personal Information

SmartReach does not sell personal information for money in the ordinary meaning of the word “sell.”

Some privacy laws define “sale” or “sharing” more broadly.

For example, certain advertising or analytics disclosures may qualify as sale or sharing even if SmartReach receives no direct monetary payment.

Where SmartReach engages in activities that qualify as sale, sharing, or targeted advertising under applicable law, eligible individuals may opt out.

De-identified and aggregated information that does not constitute personal information under applicable law may be used, disclosed, licensed, or commercialized as described in this Policy.

SmartReach does not knowingly sell or share for cross-context behavioral advertising the personal information of individuals under 16 years old without legally required authorization.

16. Retention

SmartReach retains personal information only for as long as reasonably necessary for the purposes described in this Policy, subject to legal, contractual, operational, security, and compliance requirements.

Retention periods vary depending on the information.

16.1 Customer and Account Information

Account and Service information may be retained during the customer relationship and for a reasonable period afterward for:

  • contractual records;
  • dispute resolution;
  • security;
  • fraud prevention;
  • tax;
  • accounting;
  • legal compliance; and
  • legitimate business records.

Financial and contractual information may be retained for longer periods where required by law.

16.2 Client Data

Where SmartReach acts as processor, retention is generally governed by:

  • Client instructions;
  • the applicable Service;
  • Client configuration;
  • the DPA; and
  • applicable law.

16.3 CRM and SmartConvert Data

SmartConvert information may be retained while the applicable Client account remains active and for a limited period afterward according to account configuration, applicable contractual terms, technical requirements, backup cycles, and legal requirements.

Clients should export information they require before terminating Services.

16.4 Communications

Customer service, sales, and business communications may be retained for as long as reasonably necessary to maintain business records, resolve issues, comply with law, or support the customer relationship.

16.5 Voice and Call Data

Call recordings, transcripts, summaries, and related information may be retained according to Client configuration, contractual terms, provider settings, applicable law, and operational requirements.

16.6 B2B Professional Data

Business contact information may be retained for as long as it remains relevant to legitimate B2B purposes, subject to applicable rights, suppression requests, accuracy controls, legal requirements, and periodic updating.

16.7 Suppression Information

Certain minimal information may be retained after an opt-out or deletion request when reasonably necessary to ensure that the individual is not contacted again.

16.8 Website and Analytics Information

Website and cookie-related data is retained according to the applicable technology, configuration, and Cookie Policy.

16.9 Backups

Information may remain temporarily in secure backup systems after deletion until those backups are overwritten according to normal backup cycles.

17. International Data Transfers

SmartReach operates from the United States and works with service providers located in multiple countries.

Personal information may therefore be processed outside the country where it was originally collected.

Where applicable law requires safeguards for international transfers, SmartReach uses appropriate transfer mechanisms.

These may include:

  • adequacy decisions;
  • Standard Contractual Clauses;
  • the UK International Data Transfer Addendum;
  • contractual safeguards;
  • approved certifications or frameworks; or
  • other legally recognized transfer mechanisms.

Additional transfer terms may be included in our DPA.

18. Security

SmartReach uses reasonable administrative, technical, and organizational safeguards designed to protect personal information.

Measures may include:

  • access controls;
  • authentication;
  • encryption;
  • secure communications;
  • restricted administrative access;
  • monitoring;
  • logging;
  • backup processes;
  • vendor controls;
  • confidentiality obligations;
  • security policies; and
  • incident response procedures.

No website, network, communications system, cloud service, or storage system can be guaranteed completely secure.

Users are responsible for protecting their own credentials and devices.

Please notify SmartReach promptly if you believe your SmartReach account or information has been compromised.

19. Your Privacy Rights

Your rights depend on where you live and applicable law.

You may have the right to:

  • obtain information about processing;
  • request access to personal information;
  • request correction;
  • request deletion;
  • request restriction of processing;
  • request portability;
  • object to certain processing;
  • withdraw consent;
  • opt out of direct marketing;
  • opt out of certain sale or sharing;
  • opt out of targeted advertising;
  • limit certain uses of sensitive personal information;
  • object to certain profiling;
  • appeal a privacy request decision;
  • lodge a complaint with a supervisory authority; and
  • receive equal service without unlawful discrimination for exercising privacy rights.

Not every right applies in every situation.

Certain legal exceptions may allow or require us to retain information.

20. Right to Object to Direct Marketing

You may object to the use of your personal information for direct marketing at any time.

You may:

  • use the unsubscribe mechanism in a marketing email;
  • reply to an appropriate B2B communication asking not to be contacted;
  • follow opt-out instructions provided in a message; or
  • contact privacy@smartreachai.com.

SmartReach may retain minimal suppression information after an opt-out to help ensure the request is honored.

21. California Privacy Rights

This section applies to California residents to the extent SmartReach is subject to the California Consumer Privacy Act, as amended (“CCPA”), with respect to the relevant processing.

21.1 Categories Collected

During the preceding 12 months, depending on the interaction or Service, SmartReach may have collected the following statutory categories of personal information:

Identifiers

Examples include:

  • name;
  • email address;
  • postal address;
  • telephone number;
  • online identifiers;
  • IP address; and
  • account identifiers.

Customer Records Information

Examples may include:

  • contact information;
  • business information;
  • account information;
  • payment-related information; and
  • customer records.

Commercial Information

Examples include:

  • products or Services purchased;
  • subscription information;
  • transactions;
  • customer history;
  • account activity; and
  • Service usage.

Internet or Other Electronic Network Activity

Examples include:

  • browsing activity;
  • website interactions;
  • device information;
  • pages viewed;
  • click activity;
  • cookie information; and
  • SmartReach platform activity.

Geolocation Information

We may process approximate location based on IP address or business information. SmartReach does not generally require precise geolocation for its standard Services.

Audio, Electronic, or Similar Information

Examples may include:

  • voice communications;
  • call recordings where enabled;
  • transcripts;
  • chat communications; and
  • electronic messages.

Professional or Employment-Related Information

Examples include:

  • employer;
  • title;
  • department;
  • role;
  • seniority;
  • professional profile; and
  • business contact information.

Inferences

Examples may include:

  • lead scores;
  • prospect classifications;
  • intent signals;
  • engagement classifications;
  • predicted interests;
  • campaign classifications; and
  • recommended actions.

Sensitive Personal Information

Certain account credentials, message contents, or other information may fall within statutory sensitive information definitions. SmartReach does not generally use sensitive personal information for purposes requiring a right to limit unless otherwise disclosed.

21.2 Sources

California personal information may come from:

  • the individual;
  • SmartReach Clients;
  • employers;
  • public sources;
  • business websites;
  • professional sources;
  • licensed data providers;
  • service providers;
  • integrations;
  • analytics providers; and
  • use of our Services.

21.3 Purposes

We use these categories for the purposes described in this Policy, including:

  • providing Services;
  • Managed Outbound;
  • SmartConvert;
  • SmartDesign;
  • B2B research;
  • account administration;
  • customer support;
  • security;
  • billing;
  • analytics;
  • product development;
  • marketing;
  • legal compliance; and
  • business operations.

21.4 Categories Disclosed for Business Purposes

During the preceding 12 months, we may have disclosed the categories described above to:

  • cloud and hosting providers;
  • AI providers;
  • payment processors;
  • telecommunications providers;
  • email providers;
  • messaging providers;
  • analytics providers;
  • CRM and integration providers;
  • professional data and verification providers;
  • customer support providers;
  • SmartReach Clients;
  • professional advisers; and
  • other service providers described in this Policy.

21.5 Sale or Sharing

SmartReach does not sell personal information for money in the ordinary meaning of “sell.”

Certain advertising or analytics disclosures involving identifiers or internet activity may constitute “sharing” or a “sale” under the CCPA’s broader statutory definitions.

Where applicable, California residents may opt out.

SmartReach may license de-identified or aggregated datasets that are not intended to identify individual consumers.

21.6 California Rights

Subject to applicable exceptions, California residents may have the right to:

  • know categories of personal information collected;
  • obtain specific pieces of personal information;
  • know sources;
  • know purposes;
  • know categories of third parties receiving information;
  • request deletion;
  • request correction;
  • opt out of sale or sharing;
  • limit certain uses of sensitive personal information; and
  • receive equal treatment for exercising privacy rights.

21.7 Global Privacy Control

Where legally required, SmartReach recognizes qualifying Global Privacy Control signals as an opt-out request for the browser or device from which the signal is sent.

21.8 Authorized Agents

California residents may use an authorized agent to submit a request where permitted by law.

We may require reasonable verification of the consumer, the agent’s authority, or both.

22. Other United States Privacy Rights

Residents of certain U.S. states may have additional rights under applicable comprehensive state privacy laws.

Depending on the jurisdiction, these may include rights to:

  • access;
  • correct;
  • delete;
  • obtain copies of data;
  • opt out of sale;
  • opt out of targeted advertising;
  • opt out of certain profiling;
  • restrict certain sensitive data processing; and
  • appeal decisions concerning privacy requests.

SmartReach will process valid requests according to applicable law.

Where applicable law provides a right to appeal a denied privacy request, you may appeal by contacting:

privacy@smartreachai.com

Include the word “Privacy Appeal” in the subject line.

23. EEA and UK Privacy Rights

Where GDPR or UK GDPR applies, you may have rights including:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • data portability;
  • objection;
  • withdrawal of consent; and
  • the right to complain to an applicable supervisory authority.

Where processing is based on legitimate interests, you may object based on your particular circumstances.

Where personal information is processed for direct marketing, you may object at any time.

Where processing is based on consent, withdrawing consent does not affect processing lawfully performed before withdrawal.

24. Privacy Requests

To exercise an applicable privacy right, contact:

privacy@smartreachai.com

Please identify:

  • your name;
  • your email address;
  • your relationship with SmartReach;
  • the right you wish to exercise; and
  • enough information for us to locate the relevant records.

We may request additional information reasonably necessary to verify identity and protect personal information against unauthorized disclosure.

We will respond within the period required by applicable law.

We may deny or limit requests where permitted or required by law.

25. SmartConvert End Users

If you interact with a company using SmartConvert, that company may be the controller or business responsible for your personal information.

For example, if you:

  • chat with a company’s AI assistant;
  • submit a contact form;
  • send that company an SMS;
  • communicate through WhatsApp;
  • call the company;
  • receive an AI voice call;
  • schedule an appointment;
  • submit lead information; or
  • otherwise communicate through a SmartConvert-enabled system,

SmartReach may process your information on behalf of that company.

Privacy questions concerning how that company uses your information should generally be directed to that company.

SmartReach will assist its Clients in responding to valid requests where required.

26. Managed Outbound Recipients

SmartReach may process professional information about individuals in connection with B2B research or outreach performed for SmartReach or its Clients.

This may include information obtained from public, professional, licensed, Client-provided, or business sources.

If you receive a communication and do not wish to receive further outreach:

  • use the unsubscribe or opt-out mechanism provided;
  • reply requesting removal where appropriate; or
  • contact privacy@smartreachai.com.

Valid opt-out requests will be processed as required by applicable law.

SmartReach may retain limited suppression information to prevent renewed outreach.

27. Client Responsibilities

Clients using SmartReach Services are responsible for their own privacy and data protection obligations.

Depending on how a Client uses the Services, this may include:

  • providing privacy notices;
  • establishing lawful bases;
  • obtaining consent;
  • maintaining consent records;
  • honoring opt-outs;
  • providing cookie notices;
  • obtaining call-recording consent;
  • complying with telecommunications rules;
  • responding to individual rights requests;
  • configuring data retention;
  • maintaining accurate data; and
  • entering into legally required data processing agreements.

SmartReach’s Privacy Policy does not replace a Client’s own privacy policy.

28. Communications Compliance

SmartReach and its Clients may be subject to laws governing commercial communications.

Client use of email, SMS, WhatsApp, telephone, voice, or other communications must comply with applicable:

  • privacy laws;
  • electronic communication laws;
  • marketing laws;
  • consent requirements;
  • opt-out rules;
  • telecommunications laws;
  • platform requirements; and
  • carrier requirements.

SmartReach may maintain records necessary to manage consent, opt-outs, suppression, delivery, abuse prevention, and compliance.

29. Children

SmartReach Services are designed primarily for businesses and are not directed to children.

SmartReach does not knowingly solicit personal information directly from children under 18 through its business Services.

If you believe a child has provided personal information directly to SmartReach improperly, contact:

privacy@smartreachai.com

If SmartReach learns that personal information was collected from a child in violation of applicable law, appropriate steps will be taken.

SmartReach does not knowingly sell or share for cross-context behavioral advertising personal information of individuals under 16 without legally required authorization.

30. Third-Party Websites and Services

SmartReach Services may contain links to, integrate with, or direct users to third-party websites or services.

Those third parties operate under their own privacy policies.

SmartReach is not responsible for privacy practices independently controlled by third parties.

Users should review the applicable third-party privacy terms.

31. Data Processing Addendum

Where SmartReach processes Client Personal Data as a processor, service provider, or contractor, our Data Processing Addendum applies where required.

The DPA addresses matters including:

  • processing instructions;
  • confidentiality;
  • security;
  • subprocessors;
  • assistance with data subject requests;
  • breach response;
  • international transfers;
  • deletion and return of data; and
  • other processor obligations.

32. Subprocessors

SmartReach uses third-party providers to support its Services.

Subprocessors may include providers of:

  • cloud infrastructure;
  • hosting;
  • AI;
  • databases;
  • telecommunications;
  • email;
  • messaging;
  • CRM technology;
  • analytics;
  • security;
  • payment processing;
  • customer support;
  • data enrichment;
  • data verification;
  • scheduling; and
  • integrations.

Where required, SmartReach enters into appropriate contractual protections with subprocessors.

Where the DPA applies, subprocessors are handled according to the DPA.

33. Do Not Track and Privacy Signals

Some browsers offer “Do Not Track” settings.

There is not one universally accepted standard governing all Do Not Track signals.

SmartReach responds to legally recognized opt-out preference signals, including Global Privacy Control, where applicable law requires such recognition.

Cookie preference controls may also be available on the SmartReach website.

34. Changes to This Policy

SmartReach may update this Privacy Policy as our Services, technology, business practices, or legal obligations change.

The “Last Updated” date indicates when the Policy was most recently revised.

Where required by law, we will provide additional notice of material changes.

If a new use of personal information requires consent under applicable law, we will obtain consent before beginning that use.

35. European Representative

Where applicable law requires SmartReach to appoint a representative in the European Economic Area or United Kingdom, information concerning the applicable representative will be made available to affected individuals.

Current legacy EU representative information to be confirmed before publication:

Alexandru Ganea

Email: eurep@ssc-digital.com

SmartReach should confirm that this appointment remains valid for SmartReach AI LLC following the June 2026 business transfer before publishing this section.

36. Contact Us

Questions, concerns, or privacy rights requests may be sent to:

SmartReach AI LLC

Privacy: privacy@smartreachai.com

Legal: legal@smartreachai.com

Website: https://www.smartreachai.com

For requests relating to information controlled by a SmartReach Client, you may be directed to that Client.

37. Summary of Privacy Practices

SmartReach’s core privacy practices include:

  • collecting information needed to provide business technology and services;
  • processing Client data according to Client instructions where SmartReach acts as processor;
  • using professional B2B data for legitimate business research and outreach where legally permitted;
  • providing opt-out mechanisms for marketing communications;
  • processing AI, chat, voice, CRM, messaging, and website activity as needed to operate SmartConvert;
  • using appropriate providers and subprocessors;
  • using safeguards designed to protect information;
  • honoring applicable privacy rights;
  • maintaining suppression information where needed to honor opt-outs;
  • using aggregated and de-identified information for analytics, research, product development, AI development, and commercial data products; and
  • not intentionally placing direct personal identifiers into externally licensed de-identified datasets unless legally permitted and separately authorized.

Questions about this policy? Contact us at legal@smartreachai.com.