1. Data Controller
The data controller responsible for your personal data is:
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide when you:
- Fill out our contact form (name, email, company, job title, message)
- Request a demo or consultation
- Create an account for our Service
- Communicate with us via email or other channels
- Subscribe to our newsletter or updates
2.2 Information Collected Automatically
When you visit our Website, we automatically collect:
- IP address (anonymized for analytics)
- Browser type and version
- Operating system
- Referring website
- Pages visited and time spent
- Date and time of visit
2.3 Customer Data (Service)
When you use our Service, you may transmit email event data (delivery logs, engagement metrics, bounce information) from your email service providers. This data is processed on your behalf as outlined in our Data Processing Agreement (DPA).
Important: Engagor processes email metadata and events. We do not access, store, or process the content of your emails or your subscribers' personal information beyond what is necessary for the Service (e.g., hashed email addresses for deduplication).
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain our Website and Service
- Respond to your inquiries and provide customer support
- Send you information about our products and services (with your consent)
- Process transactions and send related information
- Analyze usage patterns to improve our Website and Service
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
4. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
| Purpose | Legal Basis |
|---|---|
| Responding to contact form submissions | Legitimate interest (responding to inquiries) |
| Providing our Service to customers | Contract performance |
| Processing customer email data | Contract performance (DPA) |
| Sending marketing communications | Consent |
| Website analytics | Legitimate interest (improving services) |
| Security and fraud prevention | Legitimate interest |
| Legal compliance | Legal obligation |
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
5.1 Service Providers
Third-party vendors who perform services on our behalf, such as hosting providers, analytics services, and payment processors. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
5.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
6. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
- Contact form submissions: 2 years from last contact
- Customer account data: Duration of contract plus 7 years (legal requirement)
- Customer email event data: As specified in your service agreement (typically 12-36 months)
- Website analytics: 26 months (anonymized)
After retention periods expire, data is securely deleted or anonymized.
7. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Access controls and authentication
- Regular security assessments
- Employee training on data protection
- Incident response procedures
While we strive to protect your personal data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
8. International Data Transfers
EU Data Residency: Our Service infrastructure is hosted within the European Union (Amsterdam, Netherlands). Customer data does not leave the EU unless explicitly requested and agreed upon.
For any transfers outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
9. Your Rights Under GDPR
As a data subject, you have the following rights:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Restrict Processing
Request limitation of how we process your data.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent.
Right to Lodge a Complaint
File a complaint with a supervisory authority.
To exercise any of these rights, please contact us at privacy@engagor.ai. We will respond within 30 days.
Supervisory Authority: You have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit): www.gegevensbeschermingsautoriteit.be
11. Third-Party Services
Our Website and Service may integrate with third-party services:
- Google Analytics: Website analytics (Privacy Policy)
- Anthropic: AI processing for insights (Privacy Policy)
These services have their own privacy policies governing their use of your data.
12. Children's Privacy
Our Website and Service are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Effective Date" at the top.
For significant changes, we will provide additional notice (e.g., email notification for customers).
14. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
We aim to respond to all inquiries within 30 days.