Privacy Policy
This Privacy Policy explains how Kristiyan Tsvetanov, trading as Warmerly ("we", "us", "Warmerly") collects, uses, and protects information about you when you use our website and services.
Data controller: Kristiyan Tsvetanov, trading as Warmerly, 318 Shady Lane, Birmingham, B44 9EB, England, United Kingdom. Contact: privacy@warmerly.com.
If you are not a Warmerly customer and we hold data about you because you appear in our business-contact database, the notice that applies to you is our Prospect Privacy Notice. If you are a resident of California or another US state with a comprehensive privacy law, see our US State Privacy Notice for the categories/disclosure table and rights specific to those laws.
1. Information we collect
We collect the following categories of information:
- Account data: your name, email address, hashed password, workspace and team membership, and billing details.
- Mailbox connection data: when you connect a mailbox, we store encrypted OAuth refresh tokens or encrypted IMAP/SMTP credentials, together with metadata such as the mailbox address, provider, and folder structure.
- Mailbox contents: where you use the Warmerly inbox, we periodically read your connected mailbox and store the messages we find — sender and recipient addresses, subject, message body (plain text and HTML), attachment metadata, and threading headers. This covers your Inbox and your Sent folder. It includes ordinary business mail that has nothing to do with Warmerly, because that is what an inbox contains.
- Warmup mail: the conversational messages Warmerly generates and exchanges between mailboxes in the warmup network. Connecting a mailbox to the warmup network means that mailbox's address, display name, and signature are visible to the other participating customers' mailboxes it exchanges mail with, because that is how the network functions — it is not a one-way simulation, it is real mail sent between real customer mailboxes.
- Campaign data: the outreach sequences you build, the recipient lists you upload or select, the messages sent, and engagement events (delivery, opens, clicks, replies, bounces, unsubscribes).
- Other channel data: where you connect LinkedIn, WhatsApp, or Instagram accounts, the messages and contacts on those accounts that are synced into the Warmerly inbox, together with the connection credentials held by our integration provider.
- Business contact data: information about companies and business contacts held in our lead database, used by the lead finder and email finder. See the Prospect Privacy Notice.
- Support data: messages you send us through the in-app support chat or by email, including anything you choose to include in them.
- Usage data: IP address, browser type, pages viewed, and timestamps, collected via standard server logs and analytics.
We do not sell your personal data.
2. How we use your information
- To provide the services you signed up for — warmup, inbox, campaigns, deliverability testing, and lead discovery.
- To send service and relationship mail (see below).
- To send you marketing about Warmerly, where you have opted in. You can withdraw at any time using the unsubscribe link in any such message.
- To improve our product through aggregated, anonymised analytics.
- To detect and prevent abuse of the platform, including spam, fraud, and security incidents.
- To comply with legal obligations.
Service and relationship mail is not marketing. Once you have an account, running the service necessarily involves sending you mail about it. This includes:
- Deliverability and sender-health reports — warmup progress, inbox placement results, and reputation summaries for mailboxes you connected.
- Blocklist and DNS alerts — a connected domain or mailbox failing authentication (SPF/DKIM/DMARC), a blocklist listing, or a mailbox disconnecting.
- Onboarding sequence and setup emails — guidance while you get set up and milestone check-ins on your account.
- Billing notices — receipts, failed-payment and dunning emails, and plan-change confirmations.
- Account, security, and workspace mail — sign-in codes, verification, password resets, and team invitations.
- Replies to support requests you raised, and AI-lead digests summarising activity in your own inbox.
These arise from the contract we have with you as a customer, not from marketing consent, so they are not subject to opt-in and are not affected by declining marketing cookies. This is legally and practically distinct from marketing and broadcast mail — product announcements, guides, and offers — which is sent only to people who have opted in and always carries an unsubscribe link. Most of the mail above is genuinely optional and can be turned off individually from Settings → Notifications in the app (mailbox alerts, lead digests, and setup tips each have their own toggle); account, security, and billing mail cannot be turned off because it keeps the service and your account working.
3. Automated processing and AI
Several Warmerly features are built on large language models supplied by third parties. Specifically, we send data to an AI provider in order to:
- classify messages in your inbox as leads, not relevant, or spam — this sends the sender address, the subject, and an extract of the message body;
- draft suggested replies to messages in your inbox;
- generate personalised opening lines and message content for your campaigns, which involves the recipient's details and publicly available information about their company;
- power the support chat assistant.
AI processing produces output for you, inside your workspace. We do not use your content to train our own models, and we do not permit our AI provider to train on data submitted through our account. The providers we use are listed in our Data Processing Agreement.
None of this processing produces decisions with legal or similarly significant effects about you within the meaning of Article 22 UK/EU GDPR. Classification and drafting are suggestions; you remain in control of what is sent.
4. Access by our staff
Warmerly administrators can, for support and abuse-investigation purposes, temporarily access a customer workspace, including the inbox. This is audit-logged, time-limited, and indicated in the interface while it is happening. We do this only where it is necessary to resolve a problem you have raised, or to investigate a credible abuse report.
5. Google and Microsoft mailbox data
Warmerly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Warmerly's use of information received from Microsoft APIs adheres to the Microsoft Identity Platform terms.
In plain terms: mailbox data obtained through these APIs is used to provide the features you have turned on — warmup, inbox sync, inbox classification and reply drafting, and campaign sending — and for no other purpose. It is not used for advertising, it is not sold, it is not used to train generalised AI or machine-learning models, and it is transferred to third parties only where necessary to provide those features (our hosting provider, and our AI provider for the classification and drafting features described in section 3), to comply with law, or as part of a merger or acquisition.
Human access to this data is limited to the circumstances in section 4, to what you explicitly ask us to look at, and to what is required for security or to comply with law.
6. Lawful basis (UK GDPR / EU GDPR)
- Performance of a contract — providing the service to you, billing, and support.
- Legitimate interests — securing the platform, preventing abuse, understanding product usage, and maintaining our business-contact database (see the Prospect Privacy Notice for the balancing test behind that one).
- Consent — non-essential cookies, and marketing email to individuals who have opted in. You may withdraw consent at any time.
- Legal obligation — accounting and tax records, and responding to lawful requests.
Where you use Warmerly to process other people's data — your campaign recipients, your imported lists, the contacts in your mailbox — you are the controller of that data and we act as your processor. Our DPA governs that relationship, and you are responsible for having a lawful basis to contact those people.
7. Data storage and security
OAuth refresh tokens and IMAP credentials are encrypted at rest using AES-256-GCM. Passwords are hashed using Argon2id. All data in transit is encrypted using TLS 1.2 or higher. Access to production systems is restricted and audit-logged. Our primary infrastructure is hosted in the European Union (Falkenstein and Helsinki); see section 9 for transfers outside the EEA.
8. Data retention
- Account and billing data: retained while your account is active and for 90 days after deletion, except where longer retention is required for tax and accounting (currently 6 years under UK law).
- Mailbox tokens and credentials: deleted immediately when you disconnect a mailbox.
- Mailbox contents synced into the Warmerly inbox: deleted within 30 days of the mailbox being disconnected, or within 90 days of account deletion, whichever comes first.
- Warmup activity logs: 12 months, then deleted.
- Campaign records and engagement events: retained while the campaign exists, and for 90 days after account deletion.
- Suppression and unsubscribe records: retained indefinitely. We have to keep these — deleting the record that someone opted out would risk them being contacted again.
9. International transfers
Some of our sub-processors are outside the UK and EEA — in particular our AI provider, our payment provider, our analytics provider, and some integration providers. Where personal data is transferred outside the UK/EEA, we rely on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, together with supplementary technical measures. The full list of sub-processors and their locations is in our DPA.
10. Your rights
Under UK and EU data protection law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Export your data in a portable format.
- Object to processing carried out on the basis of legitimate interests.
- Restrict processing in certain circumstances.
- Withdraw consent, where processing is based on consent.
- Lodge a complaint with the Information Commissioner's Office (ICO) or your local supervisory authority.
To exercise any of these, email privacy@warmerly.com. We respond within one month, as required by law.
11. Cookies
We use a small number of cookies for authentication, and — only if you accept them — for analytics and marketing attribution. See our Cookie Policy for the full list.
12. Children
Warmerly is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.
13. Changes to this policy
We will post any updates to this policy on this page and update the "last updated" date. Material changes will be notified by email.
14. Contact
Kristiyan Tsvetanov, trading as Warmerly, 318 Shady Lane, Birmingham, B44 9EB, England, United Kingdom. Email privacy@warmerly.com for privacy matters, or hello@warmerly.com for anything else.