The short version
We collect three categories of data: the account info you give us when you sign up, the leads + campaign content you put into the product, and the technical logs we need to run the service. We don’t sell your data. We don’t use it to train third-party models. EU customers stay on EU infrastructure by default. You can export everything or delete it from Settings → Data, no support ticket required.
Who is the data controller
Netounim SAS, registered in France, is the data controller for your account information and any administrative data we collect about you (your name, email, billing address, login activity).
For the leads and contact data you upload or enrich through the product, you are the controller and Netounim is the processor — we only touch that data on your instructions, as set out in our standard Data Processing Agreement (DPA).
What we collect
ACCOUNT DATA — your name, work email, password (hashed with bcrypt), workspace name, billing details (handled by Stripe, see sub-processors), and the IP address you signed up from.
PRODUCT DATA — the lead lists, contact records, email templates, campaign content and workflow definitions you create inside the platform. This is *your* data; we hold it on your behalf.
USAGE TELEMETRY — anonymised metrics about which features you use, how often, and whether they error. We use these to fix bugs and prioritise the roadmap. We do not link telemetry events to individual lead records.
SECURITY LOGS — successful and failed login attempts, API calls, admin actions, billing events. Retained 18 months in an append-only audit log per workspace.
How we use it
To run the service — fulfilling your enrichment, verification and outreach requests, billing you for what you use, sending you transactional messages (receipts, security alerts, password resets).
To improve the product — fix bugs, identify slow queries, plan capacity, prioritise features. Telemetry only, never the contents of your messages.
To keep the platform safe — detect abuse (mass enumeration, scraping, fraud), enforce rate limits, investigate security incidents.
To comply with the law — respond to lawful requests from authorities, defend ourselves in disputes, meet tax and accounting obligations.
Legal basis (GDPR Art. 6)
CONTRACT — most of what we do is necessary to deliver the service you signed up for: storing your data, running enrichment jobs, sending campaigns.
LEGITIMATE INTEREST — security monitoring, abuse prevention, product analytics, and direct marketing to existing customers about features they already use.
LEGAL OBLIGATION — keeping invoices for the period required by French tax law, responding to court orders.
CONSENT — for optional cookies, marketing emails to non-customers, and any enrichment of data categories that fall outside the standard B2B contact profile.
How long we keep it
Active workspace data — for as long as your account is active.
Deleted records — purged within 30 days from production and within 90 days from backups.
Closed accounts — your workspace is preserved for 30 days after cancellation in case you change your mind, then permanently deleted.
Billing records — kept 10 years to comply with French commercial law (Code de Commerce).
Security audit logs — 18 months.
Your rights
Under GDPR you have the right to access your data, correct mistakes, delete it, port it elsewhere, restrict our processing, and object to certain uses. Most of these you can exercise yourself from Settings → Data (one-click export, one-click delete).
For anything you can’t do in-app, email [email protected]. We answer within 30 days, usually within 5 business days. If we ever turn down a request we’ll tell you why and which complaint channel applies — for EU residents that’s your national supervisory authority (CNIL in France).
International transfers
Primary data centre: eu-west-3 (Paris). Backups replicated to eu-central-1 (Frankfurt). Both EU.
The sub-processors we use that operate outside the EU (currently OpenAI for AI features, when you opt in) are covered by the European Commission’s Standard Contractual Clauses (2021 version) plus additional technical safeguards — encryption at rest with EU-controlled keys, no human review of customer content.
If an EU-only deployment is a hard requirement for your procurement, contact sales — we can pin every part of your workspace to EU infrastructure including AI features (we route to EU-hosted models on request).
Children
Netounim is a B2B tool intended for professional use. We don’t knowingly collect data from anyone under 16. If you believe a child has signed up, email us and we’ll close the account and erase the data.
Contact us
Data protection: [email protected]
General privacy questions: [email protected]
Mailing address: Netounim SAS, 12 rue de la République, 75001 Paris, France.
If you’re unhappy with our response, you can lodge a complaint with the CNIL (cnil.fr) or your local EU supervisory authority.
Changes to this policy
When we update this policy materially — meaning anything that changes the scope of what we collect, how we use it, or who we share it with — we notify workspace admins by email at least 30 days before the change takes effect.
For cosmetic edits (a typo, a clearer sentence) we update the page silently and bump the date at the top.
Questions about this document? Email us — we read every message.
Email our DPO