Last updated: 28 July 2026

Privacy Policy

This Privacy Policy (the “Policy”) describes how ClosoraAI (“ClosoraAI”, “we”, “us” or “our”) collects, uses, discloses, transfers, retains and protects personal data in connection with the ClosoraAI website, applications and related services (collectively, the “Services”). This Policy forms part of, and should be read together with, our Terms of Service. By accessing or using the Services you acknowledge that you have read and understood this Policy.

1. Scope and application

1.1. This Policy applies to all visitors of our website, registered account holders, trial users, paying subscribers and any authorised users acting on behalf of an account holder (each, a “User”).

1.2. This Policy does not apply to third-party websites, applications or services that may be linked from, or integrated with, the Services. The processing of personal data by those third parties is governed by their own privacy notices.

1.3. Where you use the Services to process personal data relating to your own leads, contacts or customers, you act as the data controller (or equivalent) in respect of that data and ClosoraAI acts as your processor or service provider, as further described in Section 9.

2. Controller identity and contact details

2.1. For personal data that we process about you as a User (account, billing and usage data), ClosoraAI is the data controller.

2.2. Privacy enquiries, data subject requests and complaints may be addressed to support@closorai.com, marked for the attention of the Privacy Lead.

3. Collections of personal data we collect

3.1. Identity and account data. Name, email address, password credentials in hashed form, profile details, workspace and organisation name, and the role assigned to your account.

3.2. Transaction and billing data. Plan selection, subscription status, entitlement records, transaction references, amounts, currency and payment status. We do not collect or store full payment card numbers; card data is captured and processed directly by our payment provider.

3.3. Service content data. Search queries you submit, saved leads, collections and folders, tags, notes, favourites, imported contact lists, email templates, outreach messages you compose and the associated send, delivery and open events.

3.4. Technical and security data. IP address, browser and device characteristics, a derived device fingerprint hash, session identifiers, sign-in timestamps, password reset events and other security audit events generated to prevent fraud and account abuse.

3.5. Usage and diagnostic data. Feature interactions, request volumes, quota consumption, AI feature usage counts, error reports and performance logs.

3.6. Communications data. Correspondence with our support team and any feedback, testimonials or survey responses you voluntarily provide.

4. Sources of personal data

4.1. Directly from you, when you register, configure or use the Services.

4.2. Automatically, through cookies, local storage and server-side logging when you interact with the Services.

4.3. From third parties, including our payment provider (transaction outcomes), authentication providers where you elect to sign in with them, and connected mailbox providers where you authorise access.

4.4. From publicly accessible sources, in respect of business information surfaced through the lead discovery features described in Section 9.

5. Purposes of processing and lawful bases

5.1. Provision of the Services — to create and administer your account, execute searches, store results and deliver the features you request. Lawful basis: performance of a contract.

5.2. Billing and entitlement management — to process payments, apply plan limits, issue receipts and maintain financial records. Lawful basis: performance of a contract and compliance with a legal obligation.

5.3. Security, fraud prevention and abuse control — to authenticate Users, enforce single-session limits, detect duplicate trial accounts, block abusive devices and investigate incidents. Lawful basis: legitimate interests in protecting the integrity of the Services.

5.4. Service improvement and analytics — to understand feature usage, diagnose faults and improve reliability and performance. Lawful basis: legitimate interests.

5.5. Communications — to send transactional messages such as verification emails, password resets, security notices and service announcements. Lawful basis: performance of a contract and legitimate interests.

5.6. Marketing — to send optional promotional communications about ClosoraAI. Lawful basis: consent, which you may withdraw at any time by using the unsubscribe mechanism in the relevant message.

5.7. Legal claims and compliance — to establish, exercise or defend legal claims and to comply with applicable law, regulation or lawful requests from competent authorities. Lawful basis: legal obligation and legitimate interests.

6. Artificial intelligence features

6.1. Certain optional features generate drafts, summaries, sales angles, proposals and search interpretations using a third-party large language model provider.

6.2. When you invoke such a feature, the relevant prompt content — which may include lead records and instructions you supply — is transmitted to the model provider solely to return the requested output. Requests are routed server-side and API credentials are never exposed to the browser.

6.3. We log the fact and volume of AI requests for quota enforcement and abuse prevention. Outputs may be cached briefly to reduce cost and latency.

6.4. AI outputs are generated automatically, may contain inaccuracies and do not constitute legal, financial or professional advice. No decision producing legal or similarly significant effects concerning you is made solely by automated means.

7. Cookies and similar technologies

7.1. We use strictly necessary cookies and browser storage to maintain your authenticated session, remember your interface preferences (including theme) and protect against cross-site request forgery.

7.2. Where we operate advertising or conversion measurement pixels on marketing pages, those technologies are deployed in accordance with applicable law and, where required, on the basis of your consent.

7.3. Most browsers allow you to refuse or delete cookies. Disabling strictly necessary cookies will prevent you from signing in to, or using, the Services.

8. Disclosure of personal data

8.1. We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.

8.2. We disclose personal data to the following collections of recipients, each bound by contractual confidentiality and data protection obligations:

(a) cloud hosting, database and storage providers; (b) payment processing providers; (c) email delivery, mailbox and messaging providers you connect or we use for transactional mail; (d) business data and enrichment providers used to fulfil your searches; (e) artificial intelligence model providers as described in Section 6; (f) analytics, logging and error-monitoring providers; and (g) professional advisers, auditors and insurers.

8.3. We may disclose personal data where required to comply with applicable law or a binding order, to enforce our Terms of Service, or to protect the rights, property or safety of ClosoraAI, our Users or the public.

8.4. In the event of a merger, acquisition, financing or sale of assets, personal data may be transferred to the counterparty or its advisers, subject to this Policy continuing to apply to the transferred data.

9. Business contact data and your responsibilities

9.1. The Services surface business information that is already publicly accessible online, including trading names, business telephone numbers, published email addresses, websites, physical addresses, ratings and opening hours.

9.2. Where such information relates to an identifiable individual (for example, a sole trader), it constitutes personal data. In respect of that data, you determine the purposes and means of processing and you are therefore the controller.

9.3. You warrant that you will process any data obtained through the Services lawfully, including by (a) establishing a valid lawful basis for your outreach; (b) complying with applicable electronic marketing, anti-spam and telemarketing rules; (c) providing required privacy notices to data subjects; (d) honouring opt-out, erasure and objection requests promptly; and (e) maintaining appropriate records.

9.4. You agree to indemnify ClosoraAI against claims, fines and losses arising from your unlawful use of data obtained through the Services, to the extent permitted by law.

10. Connected mailbox accounts

10.1. If you authorise ClosoraAI to connect a Gmail, Outlook or SMTP mailbox, we store the resulting credentials or tokens in encrypted form and use them solely to send, and record the status of, the messages you compose within the Services.

10.2. We do not read, index or mine the contents of your mailbox beyond what is necessary to perform the actions you request.

10.3. You may revoke the connection at any time from your account settings or from the security controls of the relevant mailbox provider. Revocation takes effect prospectively and does not affect messages already sent.

11. International transfers

11.1. Our providers may process personal data in jurisdictions other than your own, including outside your country of residence.

11.2. Where personal data originating in the European Economic Area, the United Kingdom or another jurisdiction with transfer restrictions is transferred abroad, we rely on an appropriate transfer mechanism, such as standard contractual clauses or a relevant adequacy decision, together with supplementary measures where necessary.

12. Data retention

12.1. Account data is retained for the life of the account and for a reasonable period thereafter to allow for reactivation and dispute resolution.

12.2. Service content data (searches, leads, lists, messages) is retained until you delete it or until the account is closed.

12.3. Security and audit logs are retained for a limited period proportionate to the anti-abuse purpose for which they were collected.

12.4. Financial records are retained for the period required by applicable tax and accounting legislation, notwithstanding any deletion request.

12.5. Backups are cycled on a rolling basis; data deleted from the live environment may persist in backups for a limited period before being overwritten.

13. Security measures

13.1. We implement technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption at rest for sensitive credentials, hashed password storage, row-level access controls scoping data to the owning account, least-privilege administrative access, session revocation, device fingerprinting for abuse detection and security event auditing.

13.2. No method of transmission or storage is entirely secure. We cannot guarantee absolute security, and you are responsible for maintaining the confidentiality of your credentials and for the activity conducted under your account.

13.3. Suspected vulnerabilities or unauthorised access should be reported without delay to support@closorai.com.

14. Your rights

14.1. Subject to applicable law, you may have the right to: (a) obtain confirmation of, and access to, the personal data we hold about you; (b) request rectification of inaccurate data; (c) request erasure; (d) request restriction of processing; (e) object to processing carried out on the basis of legitimate interests or for direct marketing; (f) receive your data in a portable format; and (g) withdraw consent where processing is based on consent.

14.2. Requests may be submitted to support@closorai.com. We may require verification of your identity before acting and will respond within the period prescribed by applicable law, ordinarily within one month.

14.3. You may lodge a complaint with your competent supervisory authority. We encourage you to contact us first so that we may seek to resolve the matter.

15. Children

The Services are intended for business use by persons aged eighteen (18) or over. We do not knowingly collect personal data from children. If we become aware that we have collected such data, we will delete it without undue delay.

16. Changes to this Policy

We may amend this Policy from time to time. The revised version takes effect on the date shown above. Where changes are material, we will provide reasonable prior notice by email or through an in-product notification. Continued use of the Services after the effective date constitutes acceptance of the amended Policy.

17. Contact

Questions concerning this Policy or our data practices should be directed to the ClosoraAI Privacy Lead at support@closorai.com.