Last updated 13 September 2026
What we collect,
and what we don’t.
Written from how the product actually behaves rather than from a template. Every processor named below is one the backend genuinely calls.
Who we are
nteni (“nteni”, “we”) provides the customer research and outreach product at this site. We are the data controller for your account and for the way you use the product. For the prospect records you research and contact, you are the controller and we act as your processor.
1 Example StreetLondonEC1A 1AAUnited Kingdomprivacy@example.comWhat we collect, and why
Three kinds of data, for three different reasons.
- Your account
- Your email address, workspace name, sender name and postal address, and the settings you choose. We need these to give you an account and to put a required postal address in the mail you send. Lawful basis: performance of our contract with you.
- What you put into the product
- The website you submit, the briefs you write, uploaded documents, prospect records, drafts, and the replies your campaigns receive. We hold these so the product can work. Lawful basis: performance of our contract with you.
- Operational records
- Which operations ran, what they cost, and errors. We use these to bill correctly and to fix faults. Lawful basis: legitimate interests in running and securing the service.
We do not run advertising or analytics trackers on this site, we do not sell personal data, and we do not use your workspace content to train our own models.
Prospect data
For business campaigns, nteni sources prospect records — name, role, employer, business email — from public company and professional records through the providers listed below. For consumer campaigns it sources nothing: you supply the contacts, and the product requires you to record where each one came from and on what basis you may contact them.
If you are a recipient and want to be removed, email privacy@example.com. We add the address to an organisation-wide suppression list, which cancels anything already queued for it and blocks future sends across every campaign. Unsubscribing from a message does the same thing.
Who processes data for us
These are the services nteni actually calls. Each is bound by a data-processing agreement and may only act on our instructions.
Some of these operate outside the UK and EEA. Where they do, transfers rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.
How long we keep things
- Workspace content — campaigns, prospects, drafts, replies — for as long as your account is open.
- Suppression entries indefinitely: the list only works if it outlives the campaign that created it.
- Billing records for six years, which UK tax law requires.
- Everything else is deleted within 30 days of your account closing.
Security
Data is encrypted in transit and at rest by our infrastructure providers. Access to workspace content is enforced per workspace in the database itself, not only in the application. API keys are stored as hashes, so a key cannot be read back out — only replaced. Mailbox credentials are held by Nylas; nteni stores a reference, not a password.
No system is beyond compromise. If a breach affects you we will tell you, and the regulator, within the time the law allows.
Your rights
- Access
- Ask for a copy of everything held about you.
- Rectification
- Correct anything inaccurate. Most workspace content you can edit directly.
- Erasure
- Ask for your account and its content to be deleted.
- Portability
- Receive your campaigns, prospects and replies in a machine-readable form.
- Objection
- Object to processing carried out on legitimate interests.
- Complaint
- Complain to your data protection authority — in the UK, the ICO.
Email privacy@example.com to exercise any of them. We respond within one month.
Changes to this policy
When this policy changes materially we update the date at the top and email account holders before the change takes effect. Questions go to support@example.com, and the terms of service cover the rest of the relationship.