Privacy Policy
Effective 5 August 2026
What we collect, why, who it goes to, and how long we keep it. The short version: we collect what running the service requires, we do not sell it, we do not train AI models on it, and you can export or delete it yourself at any time.
1. Who is responsible for your data
LKM Software Ltd is the data controller for the personal data described in this policy — that is, your data as a customer of ours.
LKM Software Ltd is a company registered in England and Wales, company number 15805131. Registered office: 13 Finchfield Road West, Wolverhampton, West Midlands, WV3 8AY, United Kingdom.
For data protection questions, write to privacy@prospexly.com.
There is an important distinction in this policy. For your own account data we are the controller. For the contact records you create, import or discover inside the CRM — other people’s personal data — you are the controller and we are your processor. That relationship is governed by the Data Processing Addendum, and section 8 below summarises what it means in practice.
2. What we collect about you
Account data
Your first name, last name and email address, taken from what you enter at signup. A password is never stored by us in any form — authentication is handled by Supabase, which stores a hash.
Subscription and billing data
Which plan you are on, its status and renewal date, your usage against each allowance, and a Stripe customer identifier. Card numbers are entered directly with Stripe and never reach our servers.
Content you put into the service
Everything you create or import: companies, contacts, opportunities, notes, tasks, calendar events, email copy and campaign settings.
Mailbox credentials
If you connect a sending mailbox, we store the OAuth tokens or SMTP credentials needed to send on your behalf. These are encrypted at rest with AES-256-GCM and are never returned by any API, including to you.
Technical and usage data
IP addresses, which we store only as a salted hash for rate limiting and abuse detection, never in the clear. Aggregate page performance measurements carrying no account identifier. Audit records of significant actions, so that a security question can be answered later.
We do not log authentication tokens, API keys, passwords, or the full bodies of emails you send.
3. Why we use it, and our lawful basis
- To provide the service — running searches, storing your CRM, sending your sequences. Basis: performance of our contract with you.
- To bill you — subscriptions, invoices, quota accounting. Basis: performance of our contract, and legal obligation for tax records.
- To keep the service secure — rate limiting, abuse detection, audit logging. Basis: our legitimate interest in preventing abuse of a system that can send email.
- To notify you — quota warnings, replies received, payment problems. These are in-app notifications and web push, not email. Basis: performance of our contract; push is only used where you have granted browser permission.
- To understand how the product is used — aggregate analytics. Basis: consent, gathered through the cookie banner. See the Cookie Policy.
We do not use your data to train AI models, and we do not sell personal data to anyone, under any definition of “sell”.
4. How we contact you
The application sends no email of its own. The only email you receive from us is sent by Supabase on our behalf, from its authentication templates: confirming your address, resetting a password, changing an email address, and team invitations. Every one of these is triggered by an action you took.
Everything that would conventionally be an email — quota warnings, reply notifications, reminders, payment failures — is an in-app notification, optionally delivered as a web push message if you allow it in your browser. There is no marketing email list to unsubscribe from, because there is no marketing email.
6. International transfers
Our sub-processors operate globally, so your data may be processed outside the country you are in, including in the United States. Where data leaves the UK or the European Economic Area, the transfer relies on the receiving provider’s Standard Contractual Clauses or on an adequacy decision covering it.
7. How long we keep it
- Account and CRM data — for as long as your account is open. When you close it, we soft-delete and keep the data recoverable for 30 days, so that an account closed in error is not a permanent loss, then remove it.
- Billing records — kept for as long as tax law requires, which is longer than the 30-day window above.
- Hashed IP addresses and audit records — retained on a rolling window sized to be useful for investigating abuse and no longer.
- Cached public business facts — a company’s name, address and website, cached to avoid repeating an identical search. Expires automatically. Nothing you create or annotate is ever cached this way.
8. The contact data you hold about other people
When you import a contact list, or run a search that finds named decision-makers, you are processing other people’s personal data. You are the controller of that data and we process it on your instructions.
That puts real obligations on you rather than on us:
- You need a lawful basis to hold and use those records.
- You must be able to answer a request from one of those people — for access, correction or deletion — and the export and delete functions in the product exist so that you can.
- Discovery results are assembled from publicly available sources and always carry the page each fact came from, which is what lets you show where a record originated if you are asked.
The Data Processing Addendum sets out the full terms, and applies automatically — you do not need to sign anything separately.
9. Your rights
Depending on where you live you have some or all of the following rights over your own personal data: access, correction, deletion, restriction, objection, and portability.
Most are self-service. Your settings offer a complete export as a JSON and CSV bundle, and account deletion. For anything the product does not cover, write to privacy@prospexly.com and we will respond within 30 days.
If you are in the UK or the EEA and think we have handled your data badly, you can complain to your national supervisory authority. We would rather you told us first, but you are not required to.
10. Children
The service is for business use and not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, tell us at privacy@prospexly.com and we will delete it.
11. Changes to this policy
When this policy changes, the effective date at the top of the page changes with it. For a material change — a new sub-processor, a new purpose — we will tell you in the application rather than relying on you to re-read the page.
