CoherentConnectCoherentConnect
How it worksComparePricingAboutHelpContactBook a demo

Legal

Privacy Policy

This Privacy Policy explains what data CoherentConnect (“Company”, “we”, “us”) collects when you use our web application, desktop companion client, and related services (the “Service”), how we use that data, who we share it with, and the choices you have. It applies to all users of CoherentConnect and should be read alongside our Terms and Conditions.

On this page

  1. 1.Scope of this Policy
  2. 2.Data We Collect
  3. 3.How We Use Your Data
  4. 4.Desktop Client — Local Data Commitment
  5. 5.Outreach Data and Outlook Access
  6. 6.Sub-processors and Third Parties
  7. 7.Cookies and Local Storage
  8. 8.Data Storage and Retention
  9. 9.Security
  10. 10.Your Rights and Choices
  11. 11.Children's Privacy
  12. 12.International Transfers
  13. 13.Changes to this Policy
  14. 14.Contact

Privacy questions?

See Section 14 for contact details.

On this page
  1. 1.Scope of this Policy
  2. 2.Data We Collect
  3. 3.How We Use Your Data
  4. 4.Desktop Client — Local Data Commitment
  5. 5.Outreach Data and Outlook Access
  6. 6.Sub-processors and Third Parties
  7. 7.Cookies and Local Storage
  8. 8.Data Storage and Retention
  9. 9.Security
  10. 10.Your Rights and Choices
  11. 11.Children's Privacy
  12. 12.International Transfers
  13. 13.Changes to this Policy
  14. 14.Contact
1.

Scope of this Policy

This Policy covers personal data we collect from you when you (a) sign up for an account, (b) use the web application, (c) install the desktop companion client and link it to your Outlook installation, or (d) interact with our marketing site or support channels.

Where you act on behalf of an organisation, references to “you” may also include that organisation. You are responsible for ensuring that anyone you invite to your workspace has notice of and accepts this Policy.

2.

Data We Collect

We collect the following categories of data:

  • Account data. Name, email address, organisation, password hash (for email/password accounts), and authentication identifiers from Google or other SSO providers when you sign in via those services.
  • Profile and product data. The company description, product catalog, ICP definition, target industries, and any documents you upload to train the agent on your business.
  • Outreach data. Recipient lists, drafted emails, scheduled sends, reply history, open and click events, and feedback you give on suggestions.
  • Outlook outreach data. The desktop companion client reads from your local Microsoft Outlook installation only the data needed to place approved drafts, confirm dispatch, and match replies, read receipts, and bounces against outreach the agent has sent. See Section 4 for the full scope.
  • Usage data. Pages visited, features used, run history, error logs, device type, browser, IP address, and approximate location derived from IP.
  • Billing data. If you purchase a paid plan, our payment processor handles your card details directly. We receive transaction metadata (last four digits, country, status) but never the full card number.
  • Support data. Messages you send to support, screenshots you attach, and any diagnostic information you choose to share.
3.

How We Use Your Data

We use your data to:

  • Provide, operate, maintain, and improve the Service.
  • Authenticate you, secure your account, prevent fraud and abuse, and enforce our Terms.
  • Run the autonomous agent — discover signals, identify companies, generate emails, and dispatch outreach you have approved.
  • Send service-related emails (receipts, security alerts, important account notices, and material policy changes).
  • Respond to support requests and communicate updates about features you have asked about.
  • Conduct internal analytics and research to understand product usage and improve features.
  • Comply with legal obligations, respond to lawful requests by public authorities, and protect our rights.

Legal bases (where the GDPR or UK GDPR applies). We process personal data on the following lawful bases:

  • Performance of a contract (Art. 6(1)(b)) — to provide the Service you have signed up for.
  • Legitimate interests (Art. 6(1)(f)) — to secure and improve the Service, prevent abuse, conduct B2B outreach research from publicly available sources, and operate our business, balanced against your rights and interests.
  • Consent (Art. 6(1)(a)) — for optional analytics cookies and any processing for which we ask your explicit permission. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, anti-money-laundering, and other regulatory requirements.

Automated decision-making and AI processing. The Service uses large-language-model and machine-learning systems to score signals, suggest target companies, draft emails, and prioritise follow-ups. These outputs are recommendations — a human (you) approves what is sent unless you explicitly enable Auto-send for a defined campaign. We do not make decisions producing legal or similarly significant effects on data subjects without human review.

We do not sell your personal data, your User Content, or your recipient lists. Ever. We do not use your User Content to train third-party foundation models, and we do not authorise our LLM sub-processors to use prompts or outputs derived from your account to train their public models.

4.

Desktop Client — Local Data Commitment

The CoherentConnect desktop client is a thin Windows companion that connects to your Microsoft Outlook installation to dispatch outreach you have approved in the web app, and to detect replies, read receipts, and bounces for those specific outreaches. It is not a general-purpose agent or file scanner on your computer.

What the desktop client uses on your machine:

  • It writes the emails you approved into your Outlook so they go out from your address, and checks that they were sent.
  • From your Outlook inbox it only pulls in the replies, read receipts, and bounce notices for messages the agent sent for you — so you can see them inside the app and the agent can suggest a follow-up. Anything else in your inbox is left alone.
  • It pulls your Outlook contacts into the app so you can browse and reach them from one place. This happens on a regular sync (about every five minutes while the app is open) and when you press Sync yourself. You can stop it any time by closing the app.
  • It remembers your settings, the contacts it imported, and the current outreach queue locally on your machine, so you can review them offline.

What the desktop client does NOT access:

  1. It does not scan files, documents, photos, source code, downloads, or any other folder on your disk outside its own application data.
  2. It does not read messages in your Inbox unrelated to outreach the agent has sent.
  3. It does not access your calendar, browsing history, or clipboard.
  4. It does not access your microphone, camera, keystrokes, or screen contents.
  5. It does not scan or interact with other applications running on your machine.
  6. It does not run a background data-collection process. When the client is closed, no telemetry is silently transmitted.

The only data that flows between the desktop client and our servers is (a) the outreach drafts, recipient list, and schedule we generated for your account; (b) reply, read-receipt, and bounce status for those specific outreaches; and (c) the Personal Access Token (PAT) you issued from the web app, used to authenticate the connection. You can revoke the PAT at any time from Settings → Advanced → Desktop Client in the web app, which immediately stops all sync.

You can clear the local cache at any time from Settings → Web Sync in the desktop client. If a future version ever needs an additional permission for any reason, we will ask you in plain language, document the exact scope, and let you decline.

5.

Outreach Data and Outlook Access

When you install the desktop companion client and link it to your Microsoft Outlook installation, you grant CoherentConnect permission to place approved drafts into Outlook and send them from your Outlook account on the schedule and within the limits you configure in the web app.

We use Outlook access strictly to:

  • Dispatch the outreach drafts you have approved (or auto-approved via the Auto-send setting).
  • Track delivery, replies, read receipts, and bounces for those specific messages so you can see what is working.
  • Surface replies that come in to drafts the agent has sent, so it can suggest a follow-up.

We do not read mail in your Outlook inbox that is unrelated to outreach the agent has sent. We do not scan your folders, archive, or contacts for marketing or analytics. You can revoke the desktop client's access at any time by deleting its Personal Access Token from Settings → Advanced → Desktop Client in the web app, which immediately stops all sync, sending, and tracking.

6.

Sub-processors and Third Parties

We rely on a small set of trusted vendors to operate the Service. Each is bound by written confidentiality and data-processing obligations and receives only the data necessary for its role:

  • Cloud hosting — for application servers, databases, and object storage.
  • Outlook (on your machine) — the desktop companion places drafts into and sends through your local Microsoft Outlook installation. We do not host or relay your outreach; it leaves your machine via Outlook directly. Transactional service-related email (receipts, security notices) is sent through a separate transactional-email vendor.
  • Large-language-model providers — for signal analysis, lead scoring, and email drafting. Prompts and outputs may transit these providers under contractual confidentiality, and are not used to train their public models.
  • Authentication — a managed identity platform and Google sign-in for web-app access.
  • Payment processing — for handling card details on paid plans.
  • Analytics and error tracking — for product analytics and crash reporting.

We will publish an updated list on request. We never share recipient lists, drafts, or reply history with third parties for their own marketing use.

7.

Cookies and Local Storage

We use cookies and similar local-storage mechanisms for (a) keeping you signed in, (b) remembering your preferences, and (c) basic product analytics to understand which features are used. Strictly necessary cookies cannot be turned off without breaking the Service. Optional analytics cookies can be declined where applicable law requires consent.

8.

Data Storage and Retention

We retain your data while your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements.

  • Account and profile data — retained until you close your account, then deleted within 90 days unless legally required to retain longer.
  • Outreach data — retained while your account is active and archived for 12 months after closure for audit and chargeback resolution.
  • Backups — encrypted backups roll off automatically within 30 days; deletions you make are reflected in restorable backups within that window.
  • Diagnostic logs — retained for up to 90 days, then aggregated or deleted.

You may request earlier deletion at any time by writing to the address in Section 14, subject to legal retention requirements.

9.

Security

We employ administrative, technical, and physical safeguards designed to protect your data, including:

  • TLS 1.2+ encryption for data in transit between you, the Service, and our sub-processors.
  • Encryption at rest for databases and sensitive fields (Personal Access Tokens, password hashes).
  • Role-based access control on internal systems and the principle of least privilege for employee access.
  • Centralised secret management; no production credentials in source code or configuration files.
  • Logging and monitoring of access to production systems, with periodic security reviews.
  • Vendor due diligence and written data-processing agreements with sub-processors.

Breach notification. No system is perfectly secure. If a security incident materially affects your personal data, we will notify you and the relevant supervisory authorities without undue delay and, where the GDPR applies, no later than seventy-two (72) hours after becoming aware of the breach, to the extent required by applicable law. Notice will describe the nature of the breach, the categories of data affected, the measures we have taken, and steps you can take to protect yourself.

10.

Your Rights and Choices

Depending on your jurisdiction (including the GDPR/UK GDPR for users in the EEA and UK, the DPDP Act, 2023 for users in India, and the CCPA/CPRA for residents of California), you may have the following rights:

  • Access — confirmation of whether we process your personal data and a copy of that data.
  • Rectification — correction of inaccurate or incomplete data.
  • Erasure (“right to be forgotten”) — deletion of your data, subject to legal retention requirements.
  • Restriction — limitation of processing in certain circumstances.
  • Portability — receipt of your data in a structured, commonly used, machine-readable format.
  • Objection — objection to processing based on legitimate interests, including B2B prospecting, and to direct marketing.
  • Withdraw consent — where processing is based on consent, withdrawal at any time without affecting prior lawful processing.
  • Lodge a complaint — with a supervisory authority. EU users may complain to the data-protection authority of their member state; UK users to the ICO; Indian users to the Data Protection Board of India.
  • Non-discrimination (CCPA) — we will not deny goods or services, charge a different price, or provide a different level of service because you exercised a privacy right.

To exercise any of these rights, write to the contact in Section 14. We will verify your identity and respond within the timeframe required by the applicable law (no later than thirty (30) days under the GDPR, extendable by a further sixty (60) days for complex requests with notice). There is no charge for reasonable requests; manifestly unfounded or excessive requests may attract a reasonable fee or be refused.

Self-service controls. You can edit your profile from Settings, revoke the desktop client's Personal Access Token at any time, export your outreach data on request, and close your account permanently from Settings → Account.

11.

Children's Privacy

CoherentConnect is not directed at children under 18 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12.

International Transfers

We are based in India and operate primarily on infrastructure located in India and the United States. If you access the Service from another jurisdiction, your data may be transferred to and processed in those locations. We rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) where required by applicable law.

13.

Changes to this Policy

We may update this Policy from time to time. If a change is material, we will notify you by email or via the Service before the change takes effect.

14.

Contact

For any privacy-related questions or to exercise any of your rights:

Coherent Market Insights

Pune, Maharashtra, India

support@coherentconnect.ai

← Back to home
Pricing
CoherentConnectCoherentConnect

AI-powered B2B sales intelligence for the Indian market. A venture of Coherent Market Insights Pvt Ltd.

support@coherentconnect.ai
Company
Contact UsAbout UsHelp Center
Legal
Terms & ConditionsPrivacy PolicyDisclaimerReturn Policy
SALES OFFICE (U.S.)
533 Airport Blvd, Suite 400, Burlingame, CA 94010, United States
+1-252-477-1362
SALES OFFICE (U.K.)
Office 15811, 182–184 High Street North, East Ham, London E6 2JA, UK
+44-203-957-8553 / +44-203-949-5508
APAC INTELLIGENCE CENTER (INDIA)
401-402, Bremen Business Center, University Road, Aundh, Pune – 411007
8482850837

© 2026 CoherentConnect — All rights reserved. A venture of Coherent Market Insights Pvt. Ltd.