Data protection

Last updated:

CampaignStack holds public professional profiles of people who never signed up, so that agencies can contact them. That makes us a controller under the GDPR, and it means the usual "we are only a processor" page would be false. This page lists each obligation next to the mechanism that meets it. Every row is something that runs in the product today; nothing on this page is a plan.

Rights and the mechanism behind each

Right or obligationWhat existsWhere
Know what is held and whyThe privacy policy lists the fields in the shared professional database, the legal basis (legitimate interest, Article 6(1)(f)), the retention rule and every processor./privacy
Access, correction, a copyA public request form, no account needed. Requests are verified by email, logged, and answered within one month. The form never says whether an identifier matched anything, so it cannot be used to check who is in the database./your-data
ErasureA verified erasure request deletes the profile, its enrichment data, signals, scores and conversations across every workspace, and keeps only the email address and LinkedIn URL in the suppression register so the person is never re-imported./your-data
ObjectionA verified objection lands in a platform-wide suppression register. Every sourcing path, every signal intake and every send re-checks it, below every customer's own exclusion list, which can only add names and never remove one./your-data
Stop one sender's emailEvery outbound email carries an RFC 8058 one-click unsubscribe header and link. One click stops that workspace's email to the address; no sign-in, no confirmation page that reveals anything.In every email
Storage limitationA daily sweep deletes any profile that no customer has attached to a workspace, a list or a conversation for 18 months. Attribution records live 90 days. Mirrored calendar events live 90 days.Daily job, listed in the privacy policy
Contact frequencyPer-account daily budgets per action type, a weekly invitation cap paced across the week, warm-up for new accounts and human review by default. A reply, a booking or an unsubscribe stops the sequence./safety
Processors and transfersBackend drafting, critique and judging run only on Anthropic and OpenAI under their data processing agreements, enforced in code and pinned by a test. The browser agents on the automation server read profiles and inbox threads on DeepSeek (China) as primary, Anthropic as fallback. The complete vendor list with what each receives is on the security page./security
Processor terms for customersA published Article 28 data processing agreement, part of the terms, that incorporates the security page for measures and subprocessors and the privacy policy for retention. A countersigned copy on request./dpa
Customer account deletionFrom Settings. Deleting a workspace or an account stops everything in it at once and revokes its keys and invitations; 90 days later a daily job deletes the private leads, lists, imports and conversations it held. Profiles in the shared database stay under the 18-month rule. A workspace other people work in must be handed over first.Dashboard, Settings
CredentialsThe LinkedIn session cookie is never stored in any database. Connected API keys are encrypted with AES-256-GCM. Disconnecting an account destroys its browser profile./security

Legal basis, in short

Direct marketing to business decision-makers is a legitimate interest (Recital 47). The processing is limited to professional fields the person published themselves, contact volume is capped per account by the safety system, a human reviews outbound messages by default, and one action stops it. The full assessment weighs those safeguards against the impact on the person and is reviewed whenever the database, its readers or its retention change.

What is not there yet

  • No SOC 2 report and no external penetration test yet. The architecture is described on the security page instead.
  • The balancing assessment for the shared database is on file and summarised in the privacy policy; it is not published in full.
  • The browser agents still run on a model provider hosted in China. Moving them to a DPA-covered provider is a cost decision that has not been taken.

For an agency's own DPO

You are the controller for what you import and for whom you contact; CampaignStack is your processor for that, and the controller for the shared database. Your client's data never leaves your workspace: campaigns, lists, tags, notes, conversations and results are invisible to every other tenant. The data processing agreement is published; write to privacy@campaignstack.io for a countersigned copy or a subprocessor notification.