eProspector Privacy Policy

Effective date: [BETA LAUNCH DATE] Last updated: [BETA LAUNCH DATE]


SUMMARY. eProspector is a business-to-business prospecting platform. This Privacy Policy explains two different things: (a) how we handle personal data about you, an Authorized User of one of our customers, which we control; and (b) how we handle personal data about Prospects — third parties our customers research and contact using the Service — which we process on our customer's behalf and at its direction as a processor. If you are a Prospect and want to exercise your privacy rights, Section 11.3 explains why we will usually need to route your request to the customer that researched you, and how we help with that.

1. Scope and Who This Policy Applies To

1.1 Who we are. This Privacy Policy is issued by Net Sales Solutions, Inc., a Georgia Corporation doing business as Net Sales Solutions ("NSSI", "eProspector," "we," "us," or "our"), 37 Alease Drive, Fayetteville, TN 37334. We operate the eProspector agentic prospecting platform, including the web application at eprospector.com, its AI agents, Agentic Strategies, Generative Campaigns, the built-in CRM, APIs, and related documentation and support (together, the "Service").

1.2 What this Policy covers. This Policy describes how we collect, use, disclose, and protect personal data in connection with the Service and our public website. It applies to:

(a) Customers and Authorized Users — the businesses that create an Account and the individuals they invite to use the Service; (b) Prospects — individuals whose personal data our customers research, store, or contact using the Service; and (c) Website visitors — people who browse eprospector.com without signing in.

1.3 Relationship to the Terms of Service. This Policy is incorporated by reference into our Terms of Service at https://www.eprospector.com/terms (the "Terms"). Capitalized terms not defined here have the meanings given in the Terms. Where the Terms allocate data-protection roles between you and eProspector (in particular Section 9.5 of the Terms), this Policy follows that allocation. Where a customer has executed our Data Processing Addendum ("DPA"), the DPA governs our processing of Prospect and other Customer Data on that customer's behalf, and controls over this Policy in the event of conflict.

1.4 Business-to-business only. The Service is offered to businesses and is not directed at consumers. Personal data we collect about Authorized Users is collected in their capacity as representatives of our customer.

2. Definitions

  • "Account Data" means information about our customer and its Authorized Users that we collect to create and administer an Account — see Section 3.
  • "Connected Mailbox Data" means email message content and metadata that the Service sends, receives, or reads through a Connected Mailbox — see Section 4.3.
  • "Control-Plane Database" means the central database in which we store Account identity, billing references, and the tenant catalog. It contains no Prospect data or Connected Mailbox Data.
  • "Controller" and "processor" have the meanings given in the GDPR; "business" and "service provider" have the meanings given in the CCPA. Where this Policy says "controller" it includes "business," and "processor" includes "service provider."
  • "Personal data" means information that identifies, relates to, or could reasonably be linked to an identified or identifiable individual, and includes "personal information" as defined under the CCPA.
  • "Prospect Data" means personal data about Prospects that the Service locates, compiles, enriches, verifies, stores, or transmits on a customer's behalf, including Prospect Dossiers, contact and company records, pipeline data, campaign content, and related Connected Mailbox Data.
  • "Sub-processor" means a third party we engage to process personal data on our behalf in order to provide the Service — see Section 7.
  • "Tenant Database" means the dedicated, logically and physically isolated database we provision for each Account. Prospect Data and Connected Mailbox Data live only in the customer's own Tenant Database.
  • "Usage Data" has the meaning given in the Terms: technical, performance, and aggregated information about how the Service is accessed and used, excluding the content of Customer Data.

3. Personal Data About You, Our Customer's Authorized User

This Section describes the personal data we collect about people who sign in to the Service. For this data, eProspector is the controller.

3.1 Account and profile information. When you create an Account or accept an invitation we collect your name, email address, the Organization(s) you belong to, and your role within each Organization (for example, owner, admin, or member). We collect this directly from you or from the Account owner or admin who invited you.

3.2 Authentication data. Authentication is provided by Neon Managed Better Auth using one-time passcodes sent to your email address. We do not store passwords. We store session identifiers, the time and approximate source of sign-ins, and the passcode-verification records needed to operate and secure sign-in.

3.3 Billing and subscription information. If you manage billing for an Account we collect the billing contact name and email, plan and Seat selections, invoice history, tax identifiers you provide, and a tokenized reference to your payment method issued by our payment processor, Stripe. Payment card numbers are entered directly into Stripe-hosted forms and never touch eProspector's own servers.

3.4 Usage and device information. When you use the Service we automatically collect Usage Data such as IP address, browser type and version, device and operating system, pages and features accessed, timestamps, error reports, metered infrastructure consumption for your Tenant Database (compute hours, storage, and data transfer), and counts of calls to Third-Party Providers.

3.5 Support and communications. If you contact us for support we collect the content of your messages, your contact details, and any diagnostic information you provide. If you use the in-product support assistant we collect the questions you ask it.

3.6 BYOK Credentials. If you supply API keys for Third-Party Providers (currently Anthropic, Tavily, Hunter.io, ZeroBounce, and Firecrawl), we store those credentials encrypted at rest in AWS Secrets Manager, use them solely to make calls to that provider on your Account's behalf, and never use them for any other customer. BYOK Credentials are not personal data about you as such, but we treat them with at least the same care.

3.7 Connected Mailbox account information. If you connect a Gmail or Microsoft 365 mailbox we collect the mailbox address, the OAuth tokens needed to act on the mailbox, and the scopes you granted. The content of messages sent and received through that mailbox is Connected Mailbox Data and is described in Section 4.3.

3.8 Information we do not collect about you. We do not collect government identifiers, precise geolocation, biometric data, health data, or other special-category data about Authorized Users, and we ask you not to submit it to us.

4. Personal Data About Prospects, Collected on Our Customer's Behalf

This Section describes the personal data the Service handles about Prospects — individuals who have not signed up for eProspector and typically have no direct relationship with us. For this data, our customer is the controller and eProspector is the processor, as set out in Section 9.5 of the Terms. We collect, use, and disclose Prospect Data only on our customer's documented instructions, as expressed through its use of the Service.

4.1 What Prospect Data may include. Depending on how a customer configures its strategies and campaigns, Prospect Data may include a Prospect's name, job title, employer and company details, business email address, business phone number, business postal address, professional social-media profile URLs, publicly available biographical and professional information, the customer's own notes and pipeline status, AI-generated research summaries and qualification verdicts with their cited evidence, email verification results, campaign messages drafted for or sent to the Prospect, and engagement signals such as replies, bounces, unsubscribes, and email opens.

4.2 Where Prospect Data comes from. The Service does not maintain a contributor or resale database of business contacts. Prospect Data is located and assembled, per customer instruction, from:

(a) the customer itself — briefs, targeting criteria, imported contacts, and notes; (b) publicly available web sources, discovered via web search (Tavily) and page retrieval (Firecrawl); (c) third-party business-contact providers (Hunter.io) for professional email discovery; (d) email verification services (ZeroBounce) to confirm whether an address is deliverable; and (e) the customer's Connected Mailboxes, for replies and bounces to messages the customer sent.

4.3 Connected Mailbox Data. When a customer connects a Gmail or Microsoft 365 mailbox, the Service, within the OAuth scopes the customer approves, sends campaign messages from that mailbox, reads replies and bounce notifications to those messages, and stores the related message content and metadata (sender, recipient, subject, timestamps, message identifiers, threading headers) in the customer's own Tenant Database. We read only what is needed to attribute replies and bounces to the campaign that generated them. Connected Mailbox Data is Prospect Data to the extent it identifies a Prospect, and Account Data to the extent it identifies the Authorized User. Section 6 describes the additional commitments that apply to data obtained through Google APIs.

4.4 Engagement tracking. Campaign emails may include a one-pixel tracking image and tokenized unsubscribe links. When a recipient's mail client loads the image or the recipient clicks unsubscribe, we record the event, timestamp, and the token that identifies the message. We use the requesting IP address transiently for abuse prevention and rate-limiting of these public endpoints and do not store it against the Prospect's record.

4.5 Tenant isolation. Every Account's Prospect Data is stored in its own dedicated Tenant Database and is not commingled with any other customer's data. We do not sell, rent, share, or pool Prospect Data across customers, and we do not use one customer's Prospect Data to enrich another's.

4.6 Sensitive data. The Terms prohibit customers from directing the Service to collect special-category or sensitive personal data (such as health, biometric, or precise geolocation data, or data about minors) about Prospects, and the Service is not designed to do so. If we become aware that such data has been collected, we will work with the customer to delete it.

5. How We Use Personal Data

5.1 Account Data (as controller). We use Account Data to:

(a) create, authenticate, and administer Accounts, Organizations, Seats, and roles; (b) provide, operate, maintain, and secure the Service, including detecting and preventing fraud, abuse, spam, and security incidents; (c) meter usage, calculate Infrastructure Usage Fees, invoice, and collect payment; (d) provide customer support and respond to your requests; (e) send service, security, and billing notices (which you cannot opt out of while you hold an Account), and, with your consent where required, product updates and marketing; (f) analyze aggregated Usage Data to understand how the Service is used and to improve it; (g) comply with law, enforce the Terms, and protect our rights and those of our customers and Third-Party Providers.

5.2 Prospect Data (as processor). We use Prospect Data only to provide the Service to the customer that controls it, in accordance with its instructions and the Terms — namely to research, compile, enrich, verify, qualify, store, and organize Prospect records; to draft and send the customer's outreach from its Connected Mailboxes; to attribute replies, bounces, opens, and unsubscribes; to honor unsubscribe requests; and to provide support to that customer. We do not use Prospect Data for our own marketing, for profiling unrelated to the customer's instructions, or for any purpose the customer has not authorized.

5.3 No training on Customer or Prospect Data. Consistent with Section 9.3 of the Terms, we do not use Customer Data, Prospect Data, Connected Mailbox Data, or Output to train or fine-tune generalized machine-learning models, and we do not share them with Third-Party Providers for that purpose. Where AI model providers process Customer Data on our behalf, they do so under terms that prohibit training on that data.

5.4 Automated decision-making. The Service's AI agents produce research summaries, qualification verdicts, and drafted messages as recommendations for the customer's human review. We do not make decisions producing legal or similarly significant effects about any individual by solely automated means, and the Terms require customers to review Output before relying on it.

5.5 Aggregated and de-identified data. We may create aggregated or de-identified data from Usage Data that does not identify you, your Organization, or any Prospect, and may use it for any lawful purpose. We will not attempt to re-identify such data.

6. Google API Services User Data Policy and Microsoft Developer Terms

6.1 Google Limited Use disclosure. eProspector's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, with respect to data obtained through the Gmail scopes a customer grants (currently gmail.send, gmail.readonly, and userinfo.email):

(a) we use Gmail data only to provide or improve user-facing features of the Service that are prominent in the Service's user interface — sending the customer's campaign messages, detecting replies and bounces to those messages, and displaying the connected address; (b) we do not transfer Gmail data to third parties except as necessary to provide or improve those features (to the Sub-processors that host the customer's Tenant Database and run the Service's background jobs, listed in Section 7), to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to the customer; (c) we do not use Gmail data for serving advertisements, including retargeting, personalized, or interest-based advertising; (d) we do not allow humans to read Gmail data unless (i) we have the customer's affirmative agreement to view specific messages, (ii) it is necessary for security purposes such as investigating abuse, (iii) it is necessary to comply with applicable law, or (iv) the data has been aggregated and anonymized for internal operations; and (e) we do not use Gmail data to train or develop generalized or non-personalized AI or machine learning models, and we do not transfer it to any AI or ML tool for that purpose.

6.2 Revoking Google access. A customer or Authorized User may disconnect a Gmail mailbox at any time in the Service's settings or at myaccount.google.com/permissions. Revocation stops future sends and reads but does not by itself delete messages already stored in the Tenant Database; Section 9 describes how to delete them.

6.3 Microsoft. Our use of information received from Microsoft Graph APIs for Microsoft 365 mailboxes adheres to Microsoft's applicable developer and API terms. The commitments in Section 6.1 apply equally to data obtained from Microsoft 365 mailboxes.

7. Sub-processors and International Transfers

7.1 Sub-processors. We use the following third parties to process personal data on our behalf. Each is bound by a written agreement requiring it to protect personal data at least as protectively as this Policy and to process it only on our instructions.

Sub-processorRoleData it may process
Neon, Inc.Database hosting (Control-Plane Database and each Tenant Database); managed authentication (Neon Managed Better Auth)Account Data, authentication data, Prospect Data, Connected Mailbox Data
Vercel, Inc.Application hosting, edge network, and serverless computeAll data in transit through the Service; server logs including IP addresses
Amazon Web Services, Inc. (AWS Secrets Manager)Encrypted storage of BYOK Credentials and per-tenant connection secretsBYOK Credentials, tenant connection references
Upstash, Inc.Caching and rate-limitingTenant-resolution cache keys, hashed identifiers, IP-keyed rate-limit counters
Inngest, Inc.Background job orchestration for AI agents, campaigns, and meteringJob payloads referencing Account and Prospect records; Output
Stripe, Inc.Payment processing, subscription billing, invoicing, and tax calculationBilling contact details, payment method (held by Stripe only), invoice and usage-metering records
Anthropic, PBCAI model provider for the Service's agentsPrompts containing Prospect Data, Customer Data, and Output, under no-training terms
Tavily, Inc.Web search for prospect researchSearch queries derived from customer briefs and Prospect names/companies
Hunter.io (Hunter Web Services SAS)Professional email discoveryProspect names, companies, and domains
Firecrawl (Mendable.ai / SideGuide Technologies Inc.)Web page retrieval and enrichmentPublic URLs to fetch; retrieved page content
ZeroBounce (Hertza LLC)Email address verificationProspect email addresses
Google LLCOAuth mailbox provider (Gmail / Google Workspace)Connected Mailbox Data, mailbox address, OAuth tokens
Microsoft CorporationOAuth mailbox provider (Microsoft 365 / Outlook)Connected Mailbox Data, mailbox address, OAuth tokens

Where a customer supplies its own BYOK Credentials for Anthropic, Tavily, Hunter.io, Firecrawl, or ZeroBounce, calls to that provider are made under the customer's own agreement with the provider, and the provider acts for the customer directly rather than as our Sub-processor.

7.2 Changes to Sub-processors. We will update this Section and give customers at least thirty (30) days' notice by email or through the Service before engaging a new Sub-processor that will process Prospect Data. A customer that reasonably objects on data-protection grounds may terminate the affected Service as provided in the Terms or DPA.

7.3 Other disclosures. We may also disclose personal data (a) to professional advisers (lawyers, accountants, auditors) under confidentiality; (b) to law enforcement, regulators, or courts when required by law or legal process, in which case we will notify the affected customer where legally permitted; (c) to protect the rights, property, or safety of eProspector, our customers, Prospects, or the public, including to enforce the Terms; and (d) to a successor in connection with a merger, acquisition, financing, or sale of assets, with prior notice to customers. We do not sell personal data and we do not share it for cross-context behavioral advertising.

7.4 International transfers. eProspector is located in the United States and our Sub-processors primarily process data in the United States. Tenant Databases are provisioned in AWS US-EAST REGION. If you access the Service from the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with data-transfer restrictions, your personal data will be transferred to the United States. Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) with our Sub-processors, and we will enter into them with customers through the DPA.

8. Legal Bases (GDPR / UK GDPR)

8.1 Account Data. Where the GDPR or UK GDPR applies to our processing of Account Data as controller, we rely on the following legal bases:

PurposeLegal basis
Creating and administering Accounts, authentication, providing the ServicePerformance of our contract with the customer (Art. 6(1)(b)); legitimate interest in providing the Service to the customer you represent (Art. 6(1)(f))
Billing, invoicing, tax, and accountingContract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Security, fraud and abuse prevention, rate-limiting, audit loggingLegitimate interest in protecting the Service, our customers, and Prospects (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))
Service, security, and billing noticesContract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f))
Product and marketing communicationsConsent (Art. 6(1)(a)) where required; otherwise legitimate interest, with the right to object at any time
Aggregated analytics and Service improvementLegitimate interest in understanding and improving the Service (Art. 6(1)(f))
Compliance with law, responding to legal process, enforcing the TermsLegal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f))

8.2 Prospect Data. We process Prospect Data as processor on the customer's behalf. The customer, as controller, is responsible for establishing its own legal basis (typically legitimate interest for business-to-business outreach, or consent where required), for providing any notices to Prospects required under Article 14 of the GDPR, and for honoring Prospects' rights, as set out in Section 9.5 of the Terms. We assist the customer as described in Sections 11.3 and 11.4 of this Policy.

8.3 EU/UK representative. NOT REQUIRED

9. Data Security

9.1 Safeguards. Consistent with Section 9.8 of the Terms, we maintain administrative, technical, and physical safeguards designed to protect personal data, including:

(a) per-tenant database isolation — each Account's Prospect Data and Connected Mailbox Data live in a dedicated Tenant Database, separate from every other customer's and from the Control-Plane Database; (b) encryption in transit (TLS) for all connections between your browser, the Service, and our Sub-processors, and encryption at rest for databases and backups; (c) encrypted secret storage — BYOK Credentials and per-tenant connection secrets are held in AWS Secrets Manager, are resolved into memory only when needed, and are never written to logs or job records; (d) role-based access control within the Service, and, for eProspector personnel, a dedicated, audit-logged administrative role described in Section 9.2; (e) rate-limiting and abuse controls on authentication, public tracking, and unsubscribe endpoints; and (f) one-time-passcode authentication with no stored passwords.

9.2 Platform support access. As described in Section 4.5 of the Terms, eProspector support and engineering personnel may access a customer's Account — including by viewing the Service as that Account would see it — using a dedicated administrative role, solely to provide requested support, investigate abuse or security incidents, diagnose faults, or comply with law. Every such access is logged, identifies the staff member and the Account, and is limited to the minimum necessary. Staff with this access are bound by confidentiality obligations.

9.3 Limits. No method of transmission or storage is completely secure. We cannot guarantee that personal data will never be accessed, disclosed, altered, or destroyed by unauthorized means. You are responsible for securing the email accounts used to receive one-time passcodes and for promptly removing Authorized Users who leave your organization.

9.4 Breach notification. If we become aware of a personal data breach affecting a customer's Account or Tenant Database, we will notify the Account owner without undue delay and, where the customer is a controller subject to the GDPR or a U.S. state privacy law, within the period required for the customer to meet its own notification obligations. Report suspected security issues to security@eprospector.com.

10. Data Retention and Deletion

10.1 During the Term. We retain Account Data and Prospect Data for as long as the customer's Account is active. Customers can delete individual Prospect records, contacts, companies, campaigns, and Connected Mailboxes at any time through the Service, and can export contacts, companies, and pipeline data.

10.2 After termination. Consistent with Section 9.9 of the Terms, when an Account is terminated or expires the customer has [30] days to export Customer Data, after which we de-provision the Tenant Database and delete Customer Data (including all Prospect Data and Connected Mailbox Data) within a commercially reasonable period. Trial Accounts that remain unpaid for [30] days after the Trial Period ends may be deleted on notice, as described in Section 6.3 of the Terms.

10.3 Exceptions. We may retain (a) data we must keep to comply with law, resolve disputes, or enforce the Terms; (b) Usage Data and billing records, which we keep for [7] years to satisfy tax and accounting obligations; (c) administrative-access audit logs, which we keep for [AUDIT LOG RETENTION PERIOD]; and (d) copies in routine encrypted backups, which are overwritten in the ordinary course within [BACKUP RETENTION PERIOD].

10.4 OAuth tokens and BYOK Credentials. We delete Connected Mailbox OAuth tokens when the mailbox is disconnected, and BYOK Credentials when they are removed by the customer or the Account is de-provisioned.

10.5 Suppression records. To honor unsubscribe requests permanently, we may retain a minimal suppression record (a hashed or plain email address and the date of the request) within the customer's Tenant Database after the underlying Prospect record is deleted.

11. Your Rights and How to Exercise Them

11.1 Rights that may apply to you. Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; restrict or object to certain processing; receive your data in a portable format; withdraw consent where processing is based on consent; opt out of the sale or sharing of personal data or of targeted advertising (we do neither); not be discriminated against for exercising your rights; and lodge a complaint with a supervisory authority.

11.2 If you are an eProspector customer or Authorized User. eProspector is the controller of your Account Data. You may update your name and email in the Service's settings. For any other request, email privacy@eprospector.com from the address associated with your Account. We will verify your identity (typically by sending a one-time confirmation to that address) and respond within thirty (30) days, or forty-five (45) days for California residents, extendable as permitted by law. Account owners and admins may also remove Authorized Users and delete Prospect records directly within the Service.

11.3 If you are a Prospect. eProspector does not decide to research or contact you — one of our customers does, using the Service. That customer is the controller of your personal data and is responsible for responding to your request, as set out in Section 9.5 of the Terms. Because your data is held in that customer's isolated Tenant Database and we have no direct relationship with you, in most cases we cannot identify which customer holds your data, and we will not search across customers' Tenant Databases to find out. To exercise your rights:

(a) Use the unsubscribe link in any email you received. It works without signing in, takes effect immediately within that customer's Account, and is honored permanently. (b) Contact the sender. Every message sent through the Service identifies the customer that sent it. Direct your access, correction, deletion, or objection request to them. (c) If you cannot reach the sender, email privacy@eprospector.com with a copy of the message you received (including its headers, if possible). We will use the message's tracking identifiers to determine which Account sent it, forward your request to that customer, and confirm to you that we have done so. We will not disclose the customer's identity to you beyond what the message itself already shows unless the customer authorizes it or the law requires it.

11.4 How we assist customers with Prospect requests. When a customer receives a request from a Prospect, or when we forward one under Section 11.3(c), we (a) provide tools in the Service to locate, export, correct, delete, and permanently suppress the Prospect's record; (b) on the customer's written instruction, carry out the deletion or correction on its behalf where it cannot do so itself; (c) do not respond to the Prospect directly except to acknowledge receipt and confirm forwarding, unless the customer instructs us to; and (d) keep a record of the request and our actions.

11.5 Appeals and complaints. If we decline a request, we will explain why and how to appeal by replying to our response. You may also lodge a complaint with your local data protection authority. In the EEA, a list of authorities is available at edpb.europa.eu; in the UK, the Information Commissioner's Office at ico.org.uk.

12. Cookies and Similar Technologies

12.1 Strictly necessary cookies. The Service uses a small number of first-party cookies set by Neon Managed Better Auth to keep you signed in: a session token cookie and a signed session-data cookie that caches your session so pages load without a round trip to the authentication server. These are essential to operate the Service, expire when your session ends or after a period of inactivity, and cannot be disabled while you are signed in.

12.2 Preferences. We may use local storage or cookies to remember interface preferences (such as a dismissed banner or a selected Organization). These contain no Prospect Data.

12.3 Analytics. We use PostHog, a product analytics tool, to understand how the Service and our public website are used. On our public marketing pages, PostHog runs in cookieless mode: it does not set cookies or use browser local storage, and it does not create or store a persistent identifier tied to your browser or device — visits are aggregated anonymously, and no anonymous visitor identifier is ever linked to any Account you may later create. Within the authenticated Service, we separately record certain account-level usage events (for example, that an Account completed setup, compiled an Agentic Strategy, or sent a Generative Campaign) tied to your organization's account, not to you individually as a natural person. Because no persistent per-visitor cookie is set and no individual-level identifier is used, we do not display a cookie consent banner for this analytics use; we do not use advertising or cross-site tracking cookies, and we do not respond differently to "Do Not Track" signals because we do not track you across third-party sites. Where required, we honor Global Privacy Control signals as an opt-out of sale or sharing (we do neither).

12.4 Tracking in outreach emails. As described in Section 4.4, campaign emails sent by our customers may contain a tracking pixel and tokenized unsubscribe links. These are used only to report engagement to the customer that sent the message and to honor unsubscribes. Recipients can prevent open tracking by disabling remote image loading in their mail client.

12.5 Managing cookies. You can clear or block cookies in your browser settings, but doing so will sign you out of the Service.

13. Children's Privacy

The Service is a business-to-business product and is not directed at children. Consistent with Section 1 of the Terms, you must be at least 18 years old to use the Service. We do not knowingly collect personal data from anyone under 18, and the Terms prohibit customers from directing the Service to collect data about minors. If you believe we hold personal data about a minor, contact privacy@eprospector.com and we will delete it.

14. California and Other U.S. State Privacy Disclosures

This Section applies to residents of California and, to the extent required, other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon).

14.1 Categories of personal information collected and disclosed. In the preceding twelve months we have collected the following categories of personal information, as defined in the CCPA, and disclosed them to the Sub-processors identified in Section 7 for the business purposes described in Section 5:

CategoryCollected about Authorized UsersProcessed about Prospects (as service provider)
Identifiers (name, email, IP address, account identifiers)YesYes (name, business email, professional identifiers)
Customer records (billing contact, payment token)YesNo
Commercial information (plan, purchase and usage history)YesYes (customer's pipeline and engagement records)
Internet or network activity (pages viewed, feature usage, device/browser)YesLimited (email open and unsubscribe events)
Professional or employment information (employer, title, role)YesYes
Inferences (AI-generated qualification verdicts and summaries)NoYes, generated for and controlled by the customer
Sensitive personal informationNoNot knowingly; prohibited by the Terms
Geolocation (precise), biometric, health, or characteristics of protected classificationsNoNo

14.2 No sale or sharing. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under 16.

14.3 Service-provider role for Prospect Data. With respect to Prospect Data, eProspector acts as a service provider to its customers. We process that information only for the business purposes specified in our contract with the customer, do not retain, use, or disclose it outside the direct business relationship or for any other commercial purpose, and do not combine it with personal information we receive from other customers or collect from our own interactions with consumers.

14.4 Your California rights. California residents have the right to know what personal information we collect and how it is used and disclosed, to access it, to correct it, to delete it, to opt out of sale or sharing (not applicable), to limit the use of sensitive personal information (we collect none), and not to receive discriminatory treatment for exercising these rights. Exercise these rights as described in Section 11 — including, if you are a Prospect, by directing your request to the customer that contacted you, as explained in Section 11.3. You may designate an authorized agent to submit a request on your behalf; we will require proof of the agent's authority and may verify your identity directly.

14.5 Retention. Our retention practices are described in Section 10.

15. Changes to This Policy

We may update this Policy by posting a revised version at https://www.eprospector.com/privacy and updating the "Last updated" date. For material changes that reduce your rights or expand how we use personal data, we will give at least thirty (30) days' notice by email to the Account owner or through the Service before the changes take effect (except for changes required by law, which are effective immediately). Your continued use of the Service after the effective date constitutes acceptance. If you object to a material change, you may terminate under Section 14.2 of the Terms before it takes effect.

16. Contact

Net Sales Solutions, Inc. 37 Alease Drive Fayetteville, TN 37334 Privacy requests: privacy@eprospector.com · Security: security@eprospector.com · Legal: legal@eprospector.com · General support: support@eprospector.com · Billing: billing@eprospector.com

DATA PROTECTION OFFICER — NONE IS REQUIRED


eProspector is the successor to the original eProspector marketing suite by Net Sales Solutions, Inc. References to "eProspector" in this Policy mean the current operating entity identified in Section 1.