Data & compliance

    How ReachNow handles personal data

    A plain description of what we process, where it comes from, how long we keep it, and how anyone can be removed. No compliance badges — just the mechanics, so you can reach your own conclusion.

    Why this page does not say “GDPR compliant”

    Because it would not mean anything. Whether processing a particular person's contact details is lawful depends on who they are, where they are, where you are, what you send them and on what basis — variables that sit with you, the customer, not with the tool.

    A vendor claiming blanket compliance is either describing its own internal practices in misleading shorthand, or implying a guarantee about your use of the data that it has no ability to give. Neither helps you.

    So instead, this page describes exactly what happens to data in our systems. If you are assessing ReachNow for use in a regulated context, take this description to your own advisers — that is what it is for.

    What ReachNow does, in one paragraph

    ReachNow is a B2B contact data enrichment service. A customer supplies information about specific people they want to contact — most often a professional profile URL, entered individually, imported in a CSV, or saved with a browser extension. For each one, ReachNow uses the information provided to match and enrich the prospect record, identifies the employer's mail domain, constructs the business email addresses that domain is likely to use for that person's name, and tests those candidates against the employer's mail server. Verified business contact records are returned to the customer who asked for them.

    The data processed is business contact data in a professional context: a person's name, their role, their employer and their work email address. ReachNow does not process, and cannot return:

    • Personal (non-business) email addresses
    • Phone numbers
    • Home or postal addresses
    • A pre-built contact database to search or browse
    • Native write-back into a CRM

    Enrichment happens only for prospects a customer has specifically supplied. ReachNow does not crawl for people nobody asked about, does not build a database of contacts for others to search, and does not sell contact data to anyone.

    Processing

    What is processed, and why

    Categories of personal data processed by ReachNow, their sources and purposes
    CategoryExamplesWhere it comes fromWhy
    Prospect business contact dataName, job title, employer, company domain, business email addressProfessional profiles that a ReachNow customer supplies, plus verification against the employer's mail serverTo return an enriched contact record to the customer who requested it
    Customer account dataEmail address, password credential, account settingsProvided by the customer at sign-upTo operate the account, authenticate the user and provide support
    Usage and billing dataCredit balance, enrichment history, purchase recordsGenerated by using the service; payment records held by StripeTo meter credits, show history and process payments
    Suppression recordsEmail address of a person who asked to be removedSubmitted through the public data removal formRetained specifically so the address is never returned again — deleting the suppression record would defeat the removal

    Removing your data

    If your details have appeared in someone's outreach and you want them out of our systems, you can do that yourself. You do not need an account, you do not need to explain why, and you do not need to have any relationship with ReachNow.

    Submit your email address on the removal page. It is erased from our records and added to a suppression list, which means it will not be returned by any future enrichment — including for customers who supply that person's profile again later.

    The suppression record itself is retained deliberately. It holds the address for the sole purpose of continuing to block it; deleting it would allow the data to reappear, which is the opposite of what was asked for.

    Practices

    How data is handled

    Access and correction

    Anyone can ask what data we hold about them and ask for it to be corrected or deleted. Requests go to the address at the foot of this page and are answered within the period set out in the Privacy Policy.

    Contacts are not shared between accounts

    Contact records belong to the account that enriched them. We cache verification work at the level of company mail domains to avoid repeating it, which does not expose one customer's contacts to another.

    Credentials

    ReachNow never receives or stores your password for any third-party platform. The browser extension only sends ReachNow the prospect information you choose to save.

    We do not sell data

    Contact data is not sold, licensed or made available to third parties. It is returned to the customer who requested it, and to nobody else.

    Retention

    Data is kept while your account is active and for the period described in the Privacy Policy afterwards. Suppression records are the deliberate exception and are kept indefinitely.

    Your obligations as a customer

    Contacting people carries duties that vary by country — around lawful basis, opt-outs and unsolicited messages. The Terms of Service require lawful use, and that responsibility sits with you.

    Who else is involved

    ReachNow relies on a small number of service providers to operate. They are listed here by role. Customers who need the named list for a data processing agreement can request it.

    StripePayment processing. Card details are entered on Stripe-hosted pages and are never seen by ReachNow.
    Cloud hosting providerRuns the application and stores its data.
    Email verification infrastructurePerforms the mail-server checks that confirm an address accepts mail.

    For a data processing agreement or the named sub-processor list, write to support@reachnow.io.

    FAQ

    Questions about data

    Not answered here? Email support or read how ReachNow works.