Skip to content

Legal

Privacy policy

This policy explains what EthosMR does with personal information — both the information of people who use EthosMR Lead Generator, and the information of people our customers research and contact through it.

Last updated 24 August 2026

Draft — needs legal review

This document is an engineering skeleton, not finished legal copy. It has not been reviewed by counsel, several sections contain bracketed placeholders, and it must not be relied on as the operative policy until that review is complete.

1. Who is responsible for your information

EthosMR operates EthosMR Lead Generator. We act in two different capacities, and which one applies changes your rights and who you should contact.

  • As a controller, for information about our own customers and website visitors — account details, billing records, support correspondence and site analytics. We decide why and how that information is processed.
  • As a processor, for the prospect and contact data our customers bring into or generate inside their workspace. Our customer is the controller of that data; we process it on their documented instructions under our data processing agreement.

If you were contacted by a company using EthosMR and want your data corrected or erased, the fastest route is usually that company. You can also use our global do-not-contact form, which suppresses your email address across every workspace on the platform, and we will pass a rights request to the relevant customer where we can identify them.

2. What we collect

Information you give us

  • Account data: name, work email, password hash, workspace and organisation details.
  • Billing data: plan, subscription state and payment identifiers held by our payment processor. We do not store full card numbers.
  • Content you create: ICP definitions, campaign copy, notes, uploaded lists and messages you send through the product.
  • Provider credentials you connect (CRM, mailbox, enrichment, social). These are encrypted at rest and used only to perform actions you configure.
  • Support correspondence.

Information generated by using the product

  • Usage and diagnostic logs, including IP address, user agent, timestamps and the actions taken in the app.
  • Audit records of security-relevant events such as sign-in, permission changes and credential updates.
  • Delivery and engagement events for messages sent through the platform (sent, bounced, replied, unsubscribed).

Information about prospects, processed for our customers

  • Business contact details such as name, job title, employer, work email and public profile links.
  • Publicly observable events used as buying signals — for example a job posting, a funding announcement, a role change or public engagement with a topic.
  • Data returned by third-party enrichment providers our customer has connected using their own credentials.
  • Scores and model-generated summaries derived from the above, labelled by whether they were observed, enriched or inferred.

We do not seek out special category data, government identifiers or payment information about prospects, and the product is not designed to process it.

3. Lawful basis

Where the UK/EU GDPR applies, we rely on the following bases. Equivalent reasoning applies under PIPEDA and comparable regimes.

Lawful basis by processing activity
ProcessingBasisNotes
Providing the product to an account holderContractNecessary to deliver what was signed up for.
Billing, fraud prevention, and enforcing our termsLegitimate interests / legal obligationBalanced against the account holder's interests.
Security logging and audit recordsLegitimate interestsProtecting accounts and data from misuse.
Processing prospect data inside a customer workspaceDetermined by our customerTypically legitimate interests for B2B outreach; the customer is responsible for establishing and documenting it.
Marketing emails to our own prospects and usersConsent or legitimate interests, depending on jurisdictionOpt-out available in every message.
Maintaining a suppression listLegal obligation / legitimate interestsWe must retain a do-not-contact record to honour it.

4. How we use information

  • To operate, secure and support the product.
  • To generate scores, explanations and message drafts inside the workspace that owns the data.
  • To enforce plan limits, credits and sending caps.
  • To detect abuse, spam and violations of our acceptable use rules.
  • To meet legal, tax and accounting obligations.

We do not use customer content or prospect data to train general models, and we do not pool one customer's data into another customer's workspace. What the product learns from performance — which openers work, which score thresholds are worth queuing — is stored against that workspace and stays there.

5. Subprocessors

We use a small number of subprocessors to run the service. Each is bound by a written agreement with confidentiality and security obligations at least as protective as this policy. The categories are stable; the named vendors below must be completed and kept current before publication.

Subprocessor categories
CategoryPurposeVendorRegion
Cloud hostingApplication and database hosting[vendor][region]
Managed databasePrimary data store and backups[vendor][region]
Email deliveryTransactional and outbound email[vendor][region]
PaymentsSubscription billing and invoicing[vendor][region]
Model providerScoring explanations and message drafting[vendor][region]
Error monitoringDiagnostics and uptime[vendor][region]

Enrichment, CRM and social providers that a customer connects with their own credentials are that customer's vendors, not ours. We pass data to them only as instructed by the customer's configuration.

We will publish material changes to this list and, where a data processing agreement requires it, give advance notice and an opportunity to object.

6. Retention

Retention periods
DataRetained forThen
Active account and workspace dataFor the life of the accountDeleted or anonymised after closure — see below
Closed account data[30] days after closurePermanently deleted
Backups[35] days on a rolling windowOverwritten
Security and audit logs[12] monthsDeleted
Billing and tax recordsAs required by law ([7] years)Deleted
Suppression and do-not-contact entriesIndefinitelyRetained deliberately — deleting them would allow contact to resume

Suppression records are the deliberate exception to erasure: we keep the minimum needed (typically a normalised email address and the date and reason) precisely so the request keeps being honoured.

7. Your rights

Depending on where you live, you may have the right to access a copy of your personal information, correct it, delete it, restrict or object to processing, withdraw consent, receive it in a portable format, and to not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise any of these, email privacy@ethosmr.com. We will acknowledge within [5] business days and respond within the period required by applicable law (one month under GDPR, extendable where permitted). We may need to verify your identity before acting, and we will not charge you for a first request.

Scoring is not an automated decision about you. Scores rank business accounts for a human to review, they do not deny anyone a service, and messages are held for human approval by default.

If we act as a processor for a customer, we will forward your request to them and support their response rather than acting unilaterally on their data. You may also complain to your supervisory authority — in Canada, the Office of the Privacy Commissioner; in the EU/UK, your national authority.

8. International transfers

We are established in Ontario, Canada. Where personal information is transferred out of the UK, EEA or another jurisdiction with transfer restrictions, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses or the UK Addendum, together with a transfer risk assessment. [Confirm the exact mechanism per subprocessor before publication.]

9. Security

Workspaces are isolated, provider credentials are encrypted at rest, access is role-based and security-relevant actions are written to an audit log. Our security page describes the controls in detail — including, honestly, the certifications we do not currently hold.

If we become aware of a personal data breach affecting your information, we will notify affected controllers without undue delay and regulators and data subjects where the law requires it.

10. Children

EthosMR Lead Generator is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.

11. Changes to this policy

We will post any change here and update the date at the top. For changes that materially reduce your rights, we will give notice by email or in-product before they take effect.

12. Contact

EthosMR, Ontario, Canada. [Registered address to be added.]

Privacy enquiries and rights requests: privacy@ethosmr.com. [If a Data Protection Officer or EU/UK representative is appointed, add their details here.]

Questions

Write to privacy@ethosmr.com for anything on this page, or support@ethosmr.com for the product. To be removed from all outreach sent through this platform, use the do-not-contact form.