This policy explains what we collect, why we collect it, and the choices you have. It covers celentra.io and the Celentra outreach platform. Where you use Celentra through an employer's workspace, that organisation is the controller of the prospect and campaign data it uploads, and we process it on their behalf.
01Overview
Celentra is an outbound sales platform. We handle two broad categories of data: information about our own customers and website visitors, and information our customers load into their workspace about the people they want to reach.
For the first category we act as the controller and decide how the data is used. For the second we act as a processor and only act on our customer's documented instructions, under the terms of our data processing agreement.
02Information we collect
Information you give us
- Account details such as your name, work email, job title, and workspace name.
- Billing details including company address and tax identifiers. Card numbers are handled by our payment processor and never reach our servers.
- Content you create in the product: sequences, message templates, notes, and campaign settings.
- Anything you send us through support requests, demo forms, or community channels.
- Support chat messages and attachments. When you contact us from the signed-in product, we also send your account name, email address, user identifier, workspace identifier and name, and product environment to our support system so we can identify your request.
Information we collect automatically
- Product usage events such as pages viewed, features used, and campaigns launched.
- Device and connection data including browser type, operating system, approximate location derived from IP address, and timestamps.
- Deliverability telemetry from connected mailboxes: send volume, bounce and complaint rates, and reputation signals.
Information from third parties
- Contact and company enrichment data from licensed data providers and public sources.
- Profile and mailbox data from integrations you authorise, such as Google Workspace, Microsoft 365, LinkedIn, and your CRM.
- Referral and attribution data from advertising and analytics partners.
03Google Workspace data
When you connect a Google Workspace mailbox, Celentra uses Google OAuth to access only the Google account and Gmail data needed to provide the connection. The Google consent screen identifies the permissions requested before the connection is created.
Data we access
- Basic Google account and OpenID data, including your email address, display name, profile image, and stable account identifier, to identify the mailbox you selected and show it in your workspace.
- Gmail mailbox data, including the mailbox address, message and thread identifiers, headers, labels, snippets, message bodies, and attachments, to synchronize Inbox, reply context, and delivery state.
- Gmail mailbox state and actions, including sending messages and changing read, archive, star, trash, or snooze state, only when you or an authorized workspace workflow requests those actions.
- Where a workspace separately enables Google Calendar features, the event details needed to create, update, or cancel a Celentra booking, such as the title, time, attendees, description, and location.
How we use Google user data
- Authenticate and identify the connected Google account and mailbox.
- Sync messages, threads, labels, attachments, and reply changes so your team can use Inbox and campaign workflows in Celentra.
- Send messages that you or your authorized workspace workflows approve, and apply mailbox actions needed to keep Celentra and Gmail in sync.
- Provide reporting, reply tracking, deliverability controls, and other Celentra features that depend on the connected mailbox.
Celentra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, share it with data brokers, or use it to train generalized AI models. We use Google user data only to provide and improve the Celentra features you request.
Sharing, security, and retention
Google user data may be processed by contracted providers that host Celentra, store encrypted application data, run background synchronization, monitor reliability, or deliver messages on your behalf. Those providers act only on Celentra's instructions and may not use Google user data for their own purposes. OAuth tokens are kept in server-side secret storage, are not exposed to the browser, and are protected by encryption in transit, encryption at rest, tenant isolation, least-privilege access, and audit controls.
We retain synchronized Gmail content and derived workspace data for as long as the connected mailbox and related workspace data are active, subject to the retention periods described below. Disconnecting a mailbox stops future access, removes its stored OAuth credential references, and stops its Gmail push subscription; it does not automatically erase messages already copied into the workspace. You can delete that workspace data through the product's deletion controls or by contacting privacy@celentra.io. You can also revoke Celentra's access from your Google Account permissions. Application copies are deleted under the workspace deletion process, subject to legal obligations and time-limited backups.
04How we use data
- Provide, operate, and maintain the platform and the integrations you connect.
- Authenticate users, enforce workspace permissions, and prevent abuse of the service.
- Pace sending, validate contacts, and surface deliverability risk before it damages your domain.
- Generate campaign analytics, reply scoring, and reporting for your workspace.
- Improve and troubleshoot the product, including aggregated and de-identified benchmarking.
- Send service notices, billing messages, and — where permitted — product and marketing updates you can opt out of at any time.
We do not sell personal data, and we do not use the prospect data in a customer workspace to train models that serve other customers.
05Legal bases for processing
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and equivalent laws.
- Contract: to deliver the service you or your employer signed up for, including billing and support.
- Legitimate interests: to secure the platform, prevent fraud and abuse, improve our products, and carry out business-to-business marketing in a way that is proportionate and expected.
- Consent: for optional cookies, marketing emails where consent is required, and any processing you specifically agree to. You can withdraw consent at any time.
- Legal obligation: to meet tax, accounting, and lawful request requirements.
06Sharing and sub-processors
We share personal data only where it is necessary to run the service, and always under a written contract that restricts what the recipient may do with it.
- Cloud hosting, storage, and content delivery providers.
- Email and messaging infrastructure used to send and receive campaign traffic.
- Analytics, error monitoring, and support tooling.
- Our self-hosted support chat service at support.celentra.io, which processes support messages and technical connection data when you open the chat widget.
- Payment processing and billing providers.
- Data enrichment providers, where you have enabled enrichment.
- Professional advisers, and acquirers or successors in the event of a merger, acquisition, or asset sale.
A current list of sub-processors is available on request, and customers on a signed data processing agreement receive advance notice of material changes so they have the opportunity to object.
We may also disclose data where we are legally required to do so, or where disclosure is necessary to protect the rights, safety, or property of Celentra, our customers, or the public.
07International transfers
Celentra operates globally, so personal data may be transferred to and processed in countries other than the one you live in, including the United States.
Where data leaves the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses together with the UK Addendum, supported by transfer risk assessments and technical measures including encryption in transit and at rest. Enterprise customers can request regional data residency so that campaign data stays in a chosen region.
08Data retention
We keep personal data only for as long as we need it for the purposes described in this policy, or for as long as our customer instructs us to.
- Account and billing records: for the life of the account and then as required by tax and accounting law.
- Workspace content and campaign data: for the term of the subscription. After termination it is available for export for 30 days and then deleted or anonymised within 90 days.
- Product usage logs: typically retained for 13 months in identifiable form.
- Security and audit logs: retained for up to 24 months to support investigations.
- Support conversations and attachments: deleted after 12 months without activity unless a legal hold applies. Encrypted daily backups expire under a 30-day retention policy; deletion is repeated after a recovery before service is reopened.
09How we protect data
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, loss, and misuse. These include encryption in transit and at rest, role-based access control, least-privilege internal access, continuous monitoring, and regular third-party testing.
No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant supervisory authority within the timeframes the law requires. You can read more about our programme on the security page.
10Your rights and choices
Depending on where you live, you may have some or all of the following rights over your personal data.
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete data where we no longer have a lawful reason to keep it.
- Restrict or object to certain processing, including direct marketing and profiling.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us using the details below. We will verify your identity before acting and will respond within the period the applicable law requires — usually one month. If your data sits inside a customer's workspace, we will forward your request to that customer and support them in responding.
11Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember preferences, measure how the site performs, and understand which campaigns bring people to us.
- Strictly necessary cookies keep sessions secure and cannot be switched off.
- Preference cookies remember settings such as language and billing cycle.
- Analytics cookies help us understand aggregate usage and improve the product.
- Marketing cookies measure the performance of our advertising, where you have consented.
Support chat loads only when you choose Contact support. It then uses cookies to maintain your conversation. You can use email instead, or clear and block cookies in your browser. We do not currently load optional analytics or advertising cookies on this website. If we introduce these cookies, we will provide consent controls before loading them.
12Children's data
Celentra is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13Changes to this policy
We may update this policy as the product and the law evolve. When we make material changes we will update the effective date at the top of this page and, where appropriate, notify you in the product or by email before the change takes effect.
14Contact us
For privacy questions, data requests, or to reach our data protection officer, email privacy@celentra.io or write to Celentra, Data Protection, 1 Harbour Street, Suite 400, San Francisco, CA 94111, United States.
Customers who need a signed data processing agreement, our list of sub-processors, or help with a data subject request should contact their account team or use the form at the bottom of this page.
This policy describes Celentra's current data practices as of 28 September 2026. We update the dates above when our practices materially change.