Skip to content
TOM — The Outreach Machine
Why TOM AI personalization How it works Deliverability Pricing FAQ DNS checker Start the beta

Legal · Privacy

Privacy Policy

Version 1.6 — Effective from 27 September 2026

This Privacy Policy explains how Studio Synapse di Fabrizio Mainardi di Pescia, a sole proprietorship (ditta individuale) under Italian law, with registered office at Via Coste di Lagolo 12, 38076 Madruzzo (TN), Italy, VAT No. IT13965140968 ("we", "us", "our"), collects and processes personal data in connection with The Outreach Machine ("TOM"), the website theoutreachmachine.com and the application at app.theoutreachmachine.com (together, the "Service").

Contact for privacy matters: [email protected]. We have not appointed a Data Protection Officer; privacy requests are handled directly by our team.

1. Our roles, and the role of our payment provider

  • We act as data controller for the data we collect about you when you visit our websites, create an account, use the app, contact support or receive marketing communications from us.
  • Customer campaign data. A customer will generally act as controller for prospect/contact data and campaign content it uploads or asks TOM to obtain or generate, and Studio Synapse will act as processor only to the extent that reflects the actual processing and applicable law. That processing is governed by the Data Processing Addendum when the customer affirmatively accepts the relevant version in the account/signup flow. We process Customer Data only on documented instructions to provide and secure the Service, not for our own marketing, unrelated analytics, data enrichment or AI training. We do not sell personal data or provide lead lists. These role descriptions do not waive or reallocate duties that the law imposes directly on either party.
  • Stripe acts as our payment processor. When you buy a subscription or add-ons, payments are processed by Stripe Payments Europe, Ltd. and its group companies. Stripe receives the data needed to process the payment, issue invoices and receipts, calculate taxes, prevent fraud and comply with its own legal obligations, and shares with us the data we need to provide the Service and support (for example your name, email, billing country and purchase history). Stripe also acts as an independent controller for its own regulatory obligations, such as anti-money-laundering and fraud prevention. You can read Stripe's privacy policy at stripe.com/privacy.

2. Personal data we collect

  • Account data: name, email address, password (stored in hashed form), language preference, and organization details you provide.
  • Purchase and payment data: name, email, billing address and country, VAT or tax ID where provided, purchase history, subscription status, invoice and payment records, and limited payment method details (such as card brand and last four digits — full payment card details are handled by Stripe and are not stored by us).
  • Usage and technical data: IP address, device and browser information, pages and features used, log data, error diagnostics, approximate location derived from IP address.
  • Support and communications: the content of messages you send to us, including attachments and any information you choose to include.
  • Marketing data: email address and preferences if you subscribe to our updates or receive product communications.
  • Customer Data processed on your instructions: prospect and campaign information (including names, email addresses, public website URLs/content, publicly stated roles and company details, AI prompts limited to the identified public prospect website, generated drafts, sender/message content, replies, delivery/bounce records, and unsubscribe/suppression data) submitted to or generated in the Service.

3. Purposes and legal bases

PurposeData involvedLegal basis
Create and manage your account; provide the Service; process Customer Data on customer instructionsAccount data and usage data; prospect, campaign and message data as described in the DPAContract (Art. 6(1)(b) GDPR) for your account and service. For prospect/campaign data processed on a customer's behalf, the customer determines and documents the legal basis; our processing is governed by the DPA and documented instructions.
Process purchases, billing and tax obligations; handle refunds and chargebacks (payment data processed by Stripe)Account data, purchase dataPerformance of a contract; compliance with legal obligations (Art. 6(1)(b) and (c) GDPR)
Provide customer support and manage complaintsAccount data, support communicationsPerformance of a contract; legitimate interests (Art. 6(1)(b) and (f) GDPR)
Protect the Service: security, fraud and abuse prevention, log analysisUsage and technical dataLegitimate interests (Art. 6(1)(f) GDPR)
Understand how the websites and app are used and improve them; measure aggregate performanceUsage and technical data; analytics cookies only after consentConsent for analytics cookies (Art. 6(1)(a) GDPR); legitimate interests for aggregated, non-identifying statistics
Send product updates and marketing communications about TOMContact and marketing dataConsent under Article 6(1)(a) GDPR where required; where an applicable statutory exception permits email marketing without consent, legitimate interests under Article 6(1)(f) GDPR may be relied on only if its requirements and the channel-specific exception (including, in Italy, Article 130(4) of the Privacy Code) are met. GDPR legitimate interest alone does not authorise email marketing where prior consent is required. You can object or opt out at any time.
Comply with legal requests and establish, exercise or defend legal claimsAny of the above as relevantCompliance with legal obligations; legitimate interests (Art. 6(1)(c) and (f) GDPR)

Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal. Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you can contact us for more information.

4. Where the data comes from

  • Directly from you, when you create an account, contact us or use the Service.
  • From you and from our payment provider Stripe, when you complete a purchase or a renewal (as described in section 1).
  • Automatically, from your device and your use of the websites and the app.
  • From our customers and from the public prospect website they identify, for the contact and campaign data processed on their documented instructions. AI personalisation prompts use only information appearing on that identified public website.

The fact that contact details or website information are publicly accessible does not, by itself, make them available for direct marketing or establish permission to send an email. Customers are responsible for assessing the source, purpose, recipient and channel under the rules that apply to their campaign.

5. Recipients and service providers

We share personal data only with providers that help us run the Service, with our payment provider as described above, and where required by law. The main providers we use are:

ProviderServiceLocation
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing, checkout, invoicing and receipts, tax calculation, fraud preventionIreland / United States
Cloudflare, Inc.Cloudflare Pages, Workers and DNS; hosting, edge delivery and request processingUnited States / global edge network
Supabase, Inc.Application database and authenticationProject primary region: AWS eu-west-1, Ireland (EEA); provider support and onward subprocessors may operate elsewhere
Hetzner Online GmbHApplication workloads and hostingFinland (EEA)
Snowlight Ventures OÜ (Mailpool; Estonian registry no. 16370638)Mailpool API, email infrastructure and mailbox/domain provisioning; upstream providers depend on selected configurationPrimarily Estonia and countries where Mailpool's service providers operate; upstream may include Google Workspace, Microsoft 365, SMTP providers and domain registrars
OpenRouter, Inc. and selected model endpoint providersAI inference to generate email drafts from the public prospect website identified by the customer; endpoint may vary by modelOpenRouter, United States; model provider and processing location vary by endpoint and are subject to the DPA's no-training and provider-selection controls
Google Ireland Limited / Google LLCGoogle Analytics 4 (only with your consent) and Google Fonts for the public website; Google Workspace only if selected as a Mailpool upstream providerIreland / United States

Mailpool's published Terms identify Snowlight Ventures OÜ (Estonian registry no. 16370638) as the operator and state that its Article 28 DPA is available on request. Its Privacy Policy describes processing primarily in Estonia and in countries where its providers operate, and identifies providers used for Mailpool services. The exact upstream mailbox/domain provider depends on configuration. Studio Synapse maintains the written subprocessor terms required by law and provides current provider/transfer information on request under the DPA. Mailpool's published Anti-Spam Policy may impose stricter sending rules than applicable law. We do not sell personal data. We may disclose data to competent authorities when required by law.

6. Data processed on behalf of our customers

Where a customer uploads contact lists or instructs the Service to read the public website it identifies and generate personalised emails, the customer will generally determine the purposes and essential means of that campaign and act as controller; Studio Synapse acts as processor only to the extent that reflects the actual processing. The customer is responsible for the lawful source and use of the data, identifying and documenting an appropriate GDPR legal basis, satisfying channel-specific rules for the proposed email, providing any information required by Articles 13 or 14 GDPR, handling objections and other data-subject requests, and setting an appropriate retention period. Public availability, email verification or a GDPR legitimate-interest assessment does not by itself establish permission to send promotional email where the law requires prior consent. In Italy, Article 130 of the Italian Privacy Code generally requires prior consent for promotional email, subject to the narrow existing-customer exception in paragraph 4. We do not determine whether a particular customer may lawfully contact a particular recipient.

Once the customer accepts the DPA, we process Customer Data only on documented instructions to provide and secure the Service and do not use it for our own marketing, data enrichment, unrelated analytics or model training. Prompts sent for AI personalisation contain only information appearing on the public website the customer identified. We apply the security measures and retention periods in the DPA and assist the customer with Data Subject requests and incidents as required by our processor role. Sensitive-category, criminal-conviction and children's data are prohibited.

If you have received an email from one of our customers and want to exercise your rights in relation to the contact data or campaign, please contact that customer, who will generally be the controller. You can also contact us at [email protected]; we will forward the request to the relevant customer and assist as required by our role. If you object to further marketing, tell the sender and/or contact us so the objection can be passed on and applied to the relevant suppression process.

7. International transfers

  • Current primary processing locations for Customer Data include the EEA (Supabase project region eu-west-1 in Ireland; Hetzner workloads in Finland; Mailpool primarily in Estonia) and the United States/global network (Cloudflare and OpenRouter). A selected AI model endpoint and Mailpool's upstream mailbox/domain provider may process data in other countries, depending on the provider configured for the feature.
  • We will not make or instruct a restricted international transfer of Customer Data unless an adequacy decision or another valid transfer mechanism, any required contractual instrument and any required supplementary measures are in place for that transfer. Depending on applicable law, the instrument may include EU Standard Contractual Clauses, the UK IDTA or UK Addendum, or the relevant Swiss adaptations. A U.S. provider is treated as covered by the EU-U.S. Data Privacy Framework only where its current certification and the transfer's scope have been verified.
  • Customer Data transfers, recipient providers and available safeguards are described in the operative DPA. You may request current transfer information and available copies of safeguards at [email protected]. If no required transfer mechanism is available, we will suspend the affected transfer or feature until it can be made lawfully.

8. How long we keep data

  • Account and profile data: for the lifetime of your Account and up to 30 days after closure, after which it is deleted or anonymised, except for records we must retain by law.
  • Purchase, billing and tax records: up to 10 years, as required by Italian accounting and tax law.
  • Support communications: up to 24 months from the last exchange.
  • Technical logs and security data: up to 90 days from creation, after which they are deleted or irreversibly anonymised, unless a specific security incident or legal obligation requires preservation of relevant records.
  • Marketing data: until you withdraw consent or opt out, and in any case reviewed periodically.
  • Customer Data (prospects and campaigns): accessible during the Account term and for up to 30 days after closure to allow export; deleted from TOM active systems and deletion is instructed to Subprocessors within 30 days after closure. Backup copies are deleted on a rolling cycle no later than 30 days after deletion from active systems. Limited technical/security logs may be retained for up to 90 days as described above. A separately maintained, still-active mailbox/domain subscription and its stored message copies are subject to that provider account's terms and retention controls.
  • Analytics data: event data is retained in Google Analytics for no longer than 14 months, and analytics cookies expire within 24 months (see the Cookie Policy).
  • Cookie choice: stored in your browser for 180 days, after which we ask again.

9. Your rights

Under the GDPR you have the right to: access your personal data (Art. 15); have inaccurate data corrected (Art. 16); have data erased where applicable (Art. 17); restrict processing (Art. 18); object to processing based on legitimate interests (Art. 21); receive your data in a portable format (Art. 20); withdraw consent at any time (Art. 7(3)); and lodge a complaint with a supervisory authority (Art. 77). In Italy, the supervisory authority is the Garante per la protezione dei dati personali (garanteprivacy.it).

To exercise your rights, email [email protected]. We will respond within one month, extendable by two months for complex requests. We may need to verify your identity. If your request concerns data processed on behalf of one of our customers, we will forward it to that customer as described in section 6.

10. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS/HTTPS), access controls and authentication requirements for internal systems, logging and monitoring, secure hosting infrastructure and regular backups. Backup copies of Customer Data are retained for no more than 30 days after deletion from active systems; technical and security logs are retained for up to 90 days, subject to the exceptions stated above. No method of transmission or storage is completely secure; we continuously work to improve our safeguards and will notify you and the competent authorities of personal data breaches where required by law.

11. Minors

The Service is intended for adults and is not directed at anyone under 18. We do not knowingly collect personal data from minors; if you believe a minor has provided us with personal data, contact us and we will delete it.

12. Automated decision-making and AI

We do not carry out automated decision-making that produces legal or similarly significant effects on you. The Service uses AI models to help generate email drafts using information on the public website identified by the customer; this is a content-generation feature under the customer's control, does not make decisions about individuals, and its outputs should be reviewed by the customer before use. Studio Synapse does not use Customer Data to train or fine-tune general-purpose AI models. OpenRouter prompt/completion logging and product-improvement use are disabled for TOM; prompt/completion content is not retained by OpenRouter under those settings, although request metadata may be processed for routing, billing, security and abuse prevention. Selected model endpoint providers receive prompts to generate responses and are restricted from training on Customer Data as described in the DPA; their disclosed retention and processing locations may vary by model selection.

13. Cookies and similar technologies

Our websites use cookies and local storage. Strictly necessary storage (such as your theme, language and cookie choice) is used without consent because it is needed to operate the site. Analytics cookies (Google Analytics) are set only with your consent, collected through the banner, and you can change or withdraw your choice at any time via "Cookie settings" in the footer. See the Cookie Policy for details.

14. Marketing communications

We send marketing communications about TOM only where we have consent when required or satisfy a specific existing-customer exception permitted by the law applicable to the channel. For email marketing to recipients in Italy, we rely on prior consent or, only where all statutory conditions are satisfied, the limited exception in Article 130(4) of the Italian Privacy Code for a customer's email address collected in connection with a sale and marketing of our own similar products or services, with an easy and free opt-out at collection and in each message. We do not treat GDPR legitimate interest, public availability of an address or a recipient's business role as a substitute for prior consent where email-marketing law requires it. Every marketing email includes a way to unsubscribe or object, and you can opt out at any time by using it or writing to us. Service and transactional messages (for example purchase confirmations, security notices and essential service updates) are sent as part of the Service, but we will not label promotional content as transactional merely to avoid marketing rules.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect new features, providers or legal requirements. The current version is always published on this page with its effective date. For material changes we will provide notice by email or in the app where required by law.

16. Contact

Studio Synapse di Fabrizio Mainardi di Pescia — ditta individuale · Via Coste di Lagolo 12, 38076 Madruzzo (TN), Italy · VAT No. IT13965140968 · [email protected] · Abuse: [email protected]

Privacy Policy version 1.6, effective 27 September 2026.

TOM — The Outreach Machine

Guided outreach: infrastructure, warmup, AI personalization and sending under control.

Why TOM AI personalization How it works Deliverability Pricing FAQ Blog
Terms of Service Acceptable Use Data Processing Addendum Privacy Policy Refund Policy Cookie Policy Cookie settings Contact Report abuse

© 2026 TOM — The Outreach Machine · theoutreachmachine.com

PERMISSION-BASED OUTREACH ONLY · UNSOLICITED BULK MESSAGING PROHIBITED · THIS PAGE USES GOOGLE ANALYTICS

Studio Synapse di Fabrizio Mainardi di Pescia — ditta individuale · VAT No. IT13965140968 · Via Coste di Lagolo 12, 38076 Madruzzo (TN), Italy · [email protected] · Abuse: [email protected]