Privacy

Privacy controls built around lead data, consent, and outreach history.

Novobound is designed for teams that need useful growth automation without losing control of sensitive lead and campaign data.

Compliance-first storage

Consent, suppression, unsubscribe, bounce, and reply state are stored with operational context.

Server-side safeguards

Sessions, roles, audit logs, and provider secrets stay server-side in the application flow.

First-party deployment model

Core account, campaign, lead, and queue data lives in your configured database.

Data we collect

We collect account details, workspace settings, imported lead data, campaign content, sender configuration metadata, usage events, audit logs, and support communications needed to operate Novobound.

  • Account data: name, email, organization, membership role, sessions, and billing state.
  • Lead data: emails, phone numbers, company fields, status, consent state, source, score, notes, and campaign membership.
  • Outreach data: templates, campaign steps, email sends, replies, failures, unsubscribes, bounces, and tracking events.

How we use data

We use data to run the platform, validate leads, send campaigns through configured providers, detect delivery issues, power analytics, support users, enforce compliance controls, and prevent abuse.

  • Lead validation and suppression checks before outreach.
  • Queue health, sender health, campaign analytics, and automation workflows.
  • Audit logs for admin, billing, automation, webhook, and delivery events.

Your role as controller

For lead and campaign data, your organization is the data controller and Novobound acts as a processor. You are responsible for having a lawful basis to contact leads and for honoring applicable marketing rules.

  • Keep consent records accurate and current.
  • Do not import illegally obtained or purchased lists where use is not lawful.
  • Use opt-out, unsubscribe, and suppression tools promptly.

Retention and deletion

Workspace data is retained while your account is active or as needed to provide the service. You can request deletion, export, correction, or restriction of processing by contacting the privacy team.

  • Suppression records may be retained as needed to prevent future unwanted contact.
  • Audit records may be retained for security, compliance, and abuse prevention.
  • Deleted workspaces are queued for deletion or anonymization unless legal retention applies.

Privacy requests

For access, deletion, export, correction, processing restriction, or DPA requests, contact privacy@novobound.com. Include your workspace name and the request type so it can be routed correctly.

Email and messaging compliance

Novobound provides unsubscribe links, suppression checks, opt-out handling, sender visibility, and audit trails. Your organization remains responsible for lawful outreach and message content.