Effective: 27 September 2026
1. Who the controller is and how to contact us
1.1 The controller of the personal data described in this policy is HypeDigitaly s.r.o., company ID (IČO) 17665655, registered office Velká Hradební 2800/54, 400 01 Ústí nad Labem, Czech Republic (“we”, “us”). We run the HypeLead service (the “Service”) and the HypeLead website.
1.2 For data protection matters, write to us at info@hypedigitaly.ai. You can also submit a request to exercise your rights through the /privacy-request page (see section 17).
1.3 This policy explains what personal data we process, why, on what legal basis, to whom we pass it, how long we keep it and what rights you have under Regulation (EU) 2016/679 (GDPR).
2. Our roles
2.1 We are the controller of data about our customers and users, billing data, data about website and waitlist visitors, data for the security and operation of the Service, and data we find and enrich about companies and contacts (“lead data”).
2.2 We are a processor of the data that our customers put into the Service and use to contact their recipients, for example their contacts, campaigns, messages and replies. The customer is the controller of that data. We process it on the customer’s instructions and under the Data Processing Agreement (/legal/dpa).
2.3 If one of our customers contacted you through the Service, you will find that customer’s own privacy notice through the link in its message. It describes how the customer handles your data. This policy covers only our part, meaning how we, as controller, found and enriched your data.
2.4 We are also the provider of an AI system within the meaning of Regulation (EU) 2024/1689 (the AI Act).
3. Customers and users of the Service
3.1 What data: name, email, password (stored only as a secure hash), language, role in the workspace, company details, settings, details of connected accounts (for example the mailbox address; we store access credentials encrypted), records of use of the Service, security records (for example IP address and browser at login), support communication, and records of your acceptance of our documents (version, time, IP address and browser).
3.2 Why and on what basis:
- providing the Service and managing the account: performance of a contract (Art. 6(1)(b) GDPR),
- security, preventing misuse and improving the Service: our legitimate interest (Art. 6(1)(f) GDPR),
- proof of acceptance of documents and defence of legal claims: our legitimate interest,
- service emails (for example a verification code, invitations, a reminder that the trial is ending): performance of a contract.
3.3 If you sign in with Google, we receive from Google only your name, email and profile picture. This does not give us access to your Gmail.
4. Billing and payments
4.1 Subscriptions are sold by Stripe as merchant of record under Stripe Managed Payments. At payment the purchase appears as “Sold through Link”.
4.2 For the payment, taxes and the invoice, Stripe is an independent controller. Stripe handles the payment and purchase data it processes and keeps under its own privacy policy. For that data, contact Stripe (stripe.com/privacy). How long Stripe keeps transaction data is decided by Stripe. [OWNER TO CONFIRM: confirmed retention period for transaction data at Stripe]
4.3 Data we hold: billing name and address, company ID and VAT ID, billing email, Stripe customer, subscription and payment identifiers, and the last four digits and type of the payment card. We never receive the full card number or security code. The card form is hosted by Stripe.
4.4 Why and on what basis: performance of a contract, compliance with accounting and tax obligations (Art. 6(1)(c) GDPR), and our legitimate interest in handling payment disputes and claims.
4.5 We check company IDs and VAT IDs in public registers (ARES, VIES, HMRC for UK companies, SEC EDGAR for US companies) so that we can prefill billing details.
4.6 If you ask for erasure, we do not delete the Stripe payment identifiers immediately. We restrict their processing to accounting and the defence of claims and keep them for the period required by law.
5. Trial protection
5.1 To make sure each person gets a trial only once, we store a hash (made with a secret key) of the verified email address and a card fingerprint from Stripe processed the same way. Neither the address nor the card number can be recovered from the hash.
5.2 The basis is our legitimate interest in preventing misuse. We keep the hash for as long as we offer trials, and it stays after the account is deleted. It is erased by replacing the secret key.
6. People we find (lead data)
6.1 The Service helps our customers find companies and work contacts for the people who work there. We are the controller of this search and enrichment.
6.2 What data: name, job title, company, work email, work phone (if available), a link to a public profile (for example LinkedIn), country and city, and public information about the company.
6.3 Where the data comes from:
- from the company and contact database supplier Prospeo,
- from public company registers, for example ARES,
- from public websites that our system reads, including searches through Serper,
- from our own derivation: our system can guess the pattern of a work email address from the company domain and check with the mail server whether the address exists.
6.4 Why and on what basis: so that our customers can find and contact companies that fit their offer. The basis is the legitimate interest (Art. 6(1)(f) GDPR) of us and our customers. We have a written legitimate-interest assessment and review it regularly.
6.5 How we protect you:
- we process only work data; by default the Service does not reveal or use personal addresses at free email providers,
- we do not collect special categories of data (for example health, religion, political opinions), and if our filter catches any, we delete it,
- anyone who contacts you through the Service must include in the first message a link to their privacy notice and an unsubscribe link,
- if you unsubscribe or object, we add you to the unsubscribe list and the Service will not send you anything more.
6.6 Automated scoring: the Service can give a company a score for how well it matches the ideal customer our customer described. The score is only an input. A person decides whom to contact. This is not automated decision-making with legal effects under Art. 22 GDPR.
6.7 We keep lead data while the legitimate interest lasts, or until a customer or we delete it. If you ask for erasure, we delete your data and keep only a hash of your identifiers and an entry on the unsubscribe list, so that nobody can upload and contact you again.
7. Onboarding guide before sign-up
7.1 On the entry screen you can enter your website address or a description of your company and the Service shows you what finding customers would look like. This works before an account is created.
7.2 We process what you enter, the public pages of your website and the results of company and contact searches. Contacts are hidden before sign-up: you see only the first name and the initial of the last name, with no email or profile link. Nothing is revealed or sent.
7.3 The basis is our legitimate interest in showing the Service to a prospective customer. If you do not sign up, we delete everything after 7 days.
7.4 During the guide we use only a necessary session cookie (see the Cookie Notice).
8. Website visitors
8.1 Server logs. When you visit our website, the server records your IP address, the time, the page requested and browser details. We use them for security and troubleshooting on the basis of our legitimate interest. We keep them for 14 days. [OWNER TO CONFIRM: server log retention period] We do not pass them to Google Analytics or to the visit script.
8.2 Google Analytics 4. Only if you allow the Analytics category in the cookie banner do we load Google Analytics 4. It tells us how many people visit the website, which pages they read and what they click. The data is pseudonymous (a random identifier, pages, events, device). We do not send names, emails or text you type into forms to Google. Google signals and ad personalisation are off. The basis is your consent (Art. 6(1)(a) GDPR and § 89(3) of Czech Act No. 127/2005 Coll.). The cookies last 14 months. [OWNER TO CONFIRM: data retention set in GA4 and confirmation of the EU settings]
8.3 Company-level visits. We are preparing our own script which, after your consent in the Company-level visits category, would only find out which company a visit came from. It does not identify people, stores nothing in the browser and keeps the IP address for at most 24 hours. The script is not active yet and the category does not appear in the banner. We will update this policy before we switch it on.
8.4 Website address box on the home page. When you type into it, we send the text to our app so that we can suggest company names. For company name suggestions we use the Clearbit service. After you submit, we redirect you into the app, where section 7 applies.
8.5 Language and appearance. We remember your choice of language and light or dark appearance in your browser (see the Cookie Notice).
8.6 We do not use advertising pixels, session recording, heatmaps or identification of individual visitors on the website.
9. Waitlist
9.1 What data: work email, phone number, optionally your website address, the page language, and a consent record (time, IP address, browser, version of the consent text and of the policies you saw, and whether you ticked product news).
9.2 Why and on what basis:
- adding you to the waitlist, early access and arranging a free onboarding call: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR),
- product news by email: only if you tick the separate optional box, on the basis of consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time through the link in every email.
9.3 We use the phone number only to arrange the free onboarding call. We do not make sales calls to you, send SMS or WhatsApp messages, look up or enrich the number anywhere. We do not copy it into any contact list, campaign or the Service.
9.4 We send the confirmation email through our email supplier Resend.
9.5 How long: we delete unconfirmed sign-ups 7 days after the confirmation link expires. We delete confirmed sign-ups 90 days after the public launch of the Service or on invitation to the app, whichever comes first. If you sign up for the Service, we move your consent to product news to your account; otherwise we delete it together with the sign-up. We shorten the IP address after 30 days. [OWNER TO CONFIRM: waitlist retention periods]
9.6 Deletion: write to info@hypedigitaly.ai or use the /privacy-request page. We delete the sign-up within the period in section 17. You do not need an account for this.
10. Booking a call
10.1 You book the onboarding call in the Cal.com service. Our website only links to it and does not embed it, so it loads no cookies on our website.
10.2 We receive the details you enter in Cal.com (name, email, time, answers to questions) and use them to hold the call. The basis is steps taken at your request before entering into a contract. Cal.com’s privacy policy also applies to the booking itself. [OWNER TO CONFIRM: retention period for booking data]
11. Affiliate programme
11.1 If you join the affiliate programme, we process your contact details, commission payout details and tax details, and information about customers who came through your link, to the extent needed to calculate the commission.
11.2 The basis is performance of a contract and compliance with accounting and tax obligations. We keep the data for the duration of the partnership and then for the period required by accounting and tax law.
12. Our own business outreach
12.1 We also use HypeLead ourselves to contact companies that may find it useful. In that case we are the controller and section 6 applies to you. Every message we send contains a link to this policy and an unsubscribe link. [OWNER TO CONFIRM: whether HypeDigitaly uses the Service for its own outreach]
13. Artificial intelligence
13.1 The Service uses artificial intelligence to find companies from a description, to research public information about companies, to score fit with the ideal customer, to write message drafts, to sort replies and in the in-app assistant.
13.2 We send tasks that may contain personal data only to AI model providers with whom we have a data processing contract. We do not promise that a provider stores no data at all. What it may do with the data is set by its contract. The providers are listed in the Sub-processor List.
13.3 Speech-to-text runs on our own servers. We delete the audio right after transcription.
13.4 We mark emails with content created by artificial intelligence in a machine-readable way in the message header.
13.5 More information is on /legal/ai.
14. Open and click tracking in campaigns
14.1 Email open and click tracking is off by default in the Service. A customer can turn it on for a specific campaign, and only on its own verified domain. This is the customer’s decision and responsibility as controller.
14.2 If tracking is on, the customer states this in its privacy notice, which every one of its messages links to. The recipient can unsubscribe at any time with one click.
15. Who we pass data to
15.1 We pass data only where needed:
- to our sub-processors and suppliers, for example for hosting, email, search and artificial intelligence; the current list is on /legal/subprocessors,
- to Stripe as seller and independent controller for payments,
- to public registers in which we check company details,
- to authorities and courts where the law requires it.
15.2 We do not sell personal data to anyone.
15.3 Where the data is. We store Service data on Hetzner servers in the European Union. Some suppliers, especially providers of artificial intelligence and web search, are based in the USA or other countries outside the EU. In those cases we use standard contractual clauses approved by the European Commission together with a transfer impact assessment, or the EU-US Data Privacy Framework where the supplier is certified. We will give you a copy of the safeguards on request.
16. How long we keep data
| Data | Retention |
|---|---|
| Account and workspace data | For the term of the contract, then 30 days for export, then deletion |
| Lead data | While the legitimate interest lasts (reviewed regularly) or until deleted |
| Unsubscribe list and identifier hashes after erasure | As long as needed for unsubscribes and objections to keep working |
| Onboarding guide before sign-up | 7 days if you do not sign up |
| Trial protection hash | As long as we offer trials |
| Billing and payment records | For the period required by accounting and tax law |
| Records of document acceptance and consents | For the term of the contract and then as long as needed to defend legal claims [OWNER TO CONFIRM: specific period] |
| Service operational logs | 7 to 90 days depending on the type of log |
| AI search history | 90 days |
| Audit records | Not deleted; personal data in them is made unreadable after erasure |
| Backups | 30 days |
| Audio recordings for speech-to-text | Deleted right after transcription |
| Website server logs | 14 days |
| Google Analytics 4 | Cookies 14 months; data as set out in section 8.2 |
| Waitlist | As set out in section 9.5 |
17. Your rights
17.1 You have the right:
- of access to your data, including where we got it,
- to have inaccurate data corrected,
- to erasure,
- to restriction of processing,
- to data portability for data you gave us,
- to object to processing based on legitimate interest; an objection to direct marketing always succeeds,
- to withdraw consent at any time, without affecting processing before the withdrawal.
17.2 How to exercise your rights: use the /privacy-request page, where you do not need an account, or write to info@hypedigitaly.ai. We verify your identity with a confirmation email to the address the request is about. If you do not want to receive messages from a specific sender, just click the unsubscribe link in their message.
17.3 If the request concerns data controlled by one of our customers, we pass it to that customer and help them handle it.
17.4 We reply within one month. For complex or numerous requests we may extend this by two further months; we will tell you within the first month, with the reason. Handling is free of charge, except for manifestly unfounded or excessive requests.
18. Complaint to the supervisory authority
18.1 If you believe we process your data unlawfully, you have the right to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, www.uoou.gov.cz) or with the supervisory authority in the country where you live or work.
19. Security
19.1 We protect data with encrypted transfer, encrypted storage of access credentials, separation of each customer’s data at database level, secure password storage, encrypted backups and access control. Details are on /security.
20. Age
20.1 The Service is intended for people aged 18 or over. We do not knowingly process children’s data.
21. EU representative
21.1 We are established in the European Union, so we do not need to appoint a representative under Art. 27 GDPR.
22. Cookies
22.1 The cookies and similar technologies we use are described in the Cookie Notice (/legal/cookie).
23. Changes to this policy
23.1 We may update this policy. Each version has an effective date and stays available at a permanent link. We will tell you about material changes in the app or by email.