Version 1
outry platform privacy policy
Last updated: [DATE]
1. Controller
QARYA S.r.l. [to verify: registered office, VAT no., privacy@[DOMAIN]] ("outry", "we") is the controller for data of users who register on the platform. For contact data uploaded by customers, outry acts as a processor (Art. 28 GDPR) under the DPA accepted by the customer.
2. Data we process
- Account data: email, password (stored only as a hash by the authentication service), workspace membership and role.
- Workspace data: legal name, VAT number, country, address, privacy contact email, customer privacy notice URL.
- Activity log: administrative actions (e.g. inviting a member, launching a campaign) with date and author. The log never contains email open events.
- Technical data: technical session cookies required to sign in. We use no third-party analytics, advertising or tracking tools.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service and managing the account | Contract (Art. 6.1.b) |
| Security, abuse and spam prevention | Legitimate interest (Art. 6.1.f) |
| Tax and accounting obligations | Legal obligation (Art. 6.1.c) |
4. Retention
Account data: for the contract term and up to [N] months after closure. Activity log: [N] months. Tax records: 10 years.
5. Recipients
Providers acting as sub-processors, listed on the "Sub-processors" page.
6. Transfers outside the EU
Data storage locations are listed in the sub-processor list. Any transfer only takes place with Art. 44-49 GDPR safeguards (adequacy decision or Standard Contractual Clauses).
7. Your rights
You may request access, rectification, erasure, restriction, portability and object to processing by writing to privacy@[DOMAIN]. You may lodge a complaint with your supervisory authority (in Italy: Garante per la protezione dei dati personali).
Domains in use
- outry.io: public website, free tool, legal documents and status page. Sets no cookies.
- app.outry.io: the application (sign-in, private area). Session credentials stay on this domain only.
- go.outry.io: pages for email recipients (unsubscribe, "Why am I receiving this email?", rights requests, bookings, aggregate pixel, shared reports). Sets no cookies and is not indexed.
- test.outry.io: redirect to the free tool only.
Newsletter
DRAFT – to be reviewed by a lawyer. Consent version: privacy-v1-newsletter-2026-10-08-draft.
The optional outry newsletter contains one email a month with practical privacy/B2B email guides and product news. The controller is QARYA SRL. The legal basis is consent (Art. 6.1.a GDPR), collected through an unchecked checkbox and separately confirmed by email. No newsletter is sent before double opt-in.
We process only the encrypted email address, a deduplication HMAC identifier, language, source “tool”, consent text, notice version and UTC request, confirmation and withdrawal dates. The source and results analysed by the tool never leave the browser and are never linked to the subscription. No IP addresses are retained and no external anti-abuse services are used: requests are limited per address and a honeypot field is used.
The address is retained until withdrawal; unconfirmed requests are deleted after 7 days and confirmation links expire after 48 hours. Withdrawal or erasure immediately removes the encrypted address. Only minimal evidence (hash, consent text/version and event dates) remains for 180 days and is then deleted. The register is append-only except for this scheduled deletion. Subscribers may withdraw consent with one click using a signed link in every newsletter, without an account. Newsletters will include no pixels or person-tracked links.
Only platform administrators may view language counts; viewing addresses, exporting and erasing require recent two-step verification. Confirmations are platform transactional emails, never sent through customer mailboxes. Recurring delivery will be enabled only with a service authorised for newsletters. You may exercise the rights in section 7 and request erasure; tool use remains free and independent of subscription.