Privacy Policy

Effective 5 August 2026

What we collect, why, who it goes to, and how long we keep it. The short version: we collect what running the service requires, we do not sell it, we do not train AI models on it, and you can export or delete it yourself at any time.

1. Who is responsible for your data

LKM Software Ltd is the data controller for the personal data described in this policy — that is, your data as a customer of ours.

LKM Software Ltd is a company registered in England and Wales, company number 15805131. Registered office: 13 Finchfield Road West, Wolverhampton, West Midlands, WV3 8AY, United Kingdom.

For data protection questions, write to privacy@prospexly.com.

There is an important distinction in this policy. For your own account data we are the controller. For the contact records you create, import or discover inside the CRM — other people’s personal data — you are the controller and we are your processor. That relationship is governed by the Data Processing Addendum, and section 8 below summarises what it means in practice.

2. What we collect about you

Account data

Your first name, last name and email address, taken from what you enter at signup. A password is never stored by us in any form — authentication is handled by Supabase, which stores a hash.

Subscription and billing data

Which plan you are on, its status and renewal date, your usage against each allowance, and a Stripe customer identifier. Card numbers are entered directly with Stripe and never reach our servers.

Content you put into the service

Everything you create or import: companies, contacts, opportunities, notes, tasks, calendar events, email copy and campaign settings.

Mailbox credentials

If you connect a sending mailbox, we store the OAuth tokens or SMTP credentials needed to send on your behalf. These are encrypted at rest with AES-256-GCM and are never returned by any API, including to you.

Technical and usage data

IP addresses, which we store only as a salted hash for rate limiting and abuse detection, never in the clear. Aggregate page performance measurements carrying no account identifier. Audit records of significant actions, so that a security question can be answered later.

We do not log authentication tokens, API keys, passwords, or the full bodies of emails you send.

3. Why we use it, and our lawful basis

  • To provide the service — running searches, storing your CRM, sending your sequences. Basis: performance of our contract with you.
  • To bill you — subscriptions, invoices, quota accounting. Basis: performance of our contract, and legal obligation for tax records.
  • To keep the service secure — rate limiting, abuse detection, audit logging. Basis: our legitimate interest in preventing abuse of a system that can send email.
  • To notify you — quota warnings, replies received, payment problems. These are in-app notifications and web push, not email. Basis: performance of our contract; push is only used where you have granted browser permission.
  • To understand how the product is used — aggregate analytics. Basis: consent, gathered through the cookie banner. See the Cookie Policy.

We do not use your data to train AI models, and we do not sell personal data to anyone, under any definition of “sell”.

4. How we contact you

The application sends no email of its own. The only email you receive from us is sent by Supabase on our behalf, from its authentication templates: confirming your address, resetting a password, changing an email address, and team invitations. Every one of these is triggered by an action you took.

Everything that would conventionally be an email — quota warnings, reply notifications, reminders, payment failures — is an in-app notification, optionally delivered as a web push message if you allow it in your browser. There is no marketing email list to unsubscribe from, because there is no marketing email.

5. Who we share it with

We use the following sub-processors. Each one is here because the code genuinely calls it, and each receives only what it needs to do its part.

Supabase
Database, authentication and file storage. Sends the platform's account emails. Account details, and every CRM record you create or import — companies, contacts, opportunities, messages.
Vercel
Application hosting, serverless functions and aggregate performance analytics. Request metadata in transit, and page performance measurements that carry no account identifier.
Google
The Gemini API performs grounded lead discovery, enrichment and email drafting. Google OAuth authorises a Gmail mailbox you choose to connect. The search criteria and the record context you submit for a generation, and — only if you connect a Gmail mailbox — the tokens that let us send on your behalf.
Microsoft
OAuth authorisation for a Microsoft 365 mailbox you choose to connect. Mailbox authorisation tokens, only if you connect a Microsoft 365 mailbox.
Stripe
Payment processing and subscription billing. Billing email, subscription state and payment metadata. Card numbers are entered directly with Stripe and never reach our servers.
Upstash
Redis used for rate limiting and for caching public company facts. Hashed IP addresses for rate limiting, and cached public business facts. No private CRM data is cached.

We will add to this list as the product grows, and the effective date at the top of this page will change when we do.

Beyond these, we disclose personal data only where the law requires it, and where we are permitted to tell you about such a request, we will.

6. International transfers

Our sub-processors operate globally, so your data may be processed outside the country you are in, including in the United States. Where data leaves the UK or the European Economic Area, the transfer relies on the receiving provider’s Standard Contractual Clauses or on an adequacy decision covering it.

7. How long we keep it

  • Account and CRM data — for as long as your account is open. When you close it, we soft-delete and keep the data recoverable for 30 days, so that an account closed in error is not a permanent loss, then remove it.
  • Billing records — kept for as long as tax law requires, which is longer than the 30-day window above.
  • Hashed IP addresses and audit records — retained on a rolling window sized to be useful for investigating abuse and no longer.
  • Cached public business facts — a company’s name, address and website, cached to avoid repeating an identical search. Expires automatically. Nothing you create or annotate is ever cached this way.

8. The contact data you hold about other people

When you import a contact list, or run a search that finds named decision-makers, you are processing other people’s personal data. You are the controller of that data and we process it on your instructions.

That puts real obligations on you rather than on us:

  • You need a lawful basis to hold and use those records.
  • You must be able to answer a request from one of those people — for access, correction or deletion — and the export and delete functions in the product exist so that you can.
  • Discovery results are assembled from publicly available sources and always carry the page each fact came from, which is what lets you show where a record originated if you are asked.

The Data Processing Addendum sets out the full terms, and applies automatically — you do not need to sign anything separately.

9. Your rights

Depending on where you live you have some or all of the following rights over your own personal data: access, correction, deletion, restriction, objection, and portability.

Most are self-service. Your settings offer a complete export as a JSON and CSV bundle, and account deletion. For anything the product does not cover, write to privacy@prospexly.com and we will respond within 30 days.

If you are in the UK or the EEA and think we have handled your data badly, you can complain to your national supervisory authority. We would rather you told us first, but you are not required to.

10. Children

The service is for business use and not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, tell us at privacy@prospexly.com and we will delete it.

11. Changes to this policy

When this policy changes, the effective date at the top of the page changes with it. For a material change — a new sub-processor, a new purpose — we will tell you in the application rather than relying on you to re-read the page.