The short version
- This website sets no cookies, runs no analytics, has no tracking scripts, and contacts no third party when it loads.
- We never buy, rent or sell contact databases. Company data comes from open, public sources.
- Our first message goes to a company's public inbox. We email a named person only after their employer points us to them.
- Every message has a one-click opt-out, and we honour suppression requests permanently.
- You can ask us what we hold about you, and to delete it, at any time — see Your rights.
1. Who is responsible for your data
The data controller is Pavel Shcherbinin, sole trader (jednoosobowa działalność gospodarcza), trading as Polaim, Zwycięska 9/17, 53-033 Wrocław, Poland (NIP / VAT-UE: PL1132920347) — "OutRichard", "we", "us". OutRichard is a project of Polaim. We are established in Poland, so the EU GDPR applies to everything we do — but we work for the US market, so most of our clients and most of the companies we contact are in the United States. This policy therefore covers both: the GDPR because of where we sit, and US rules such as CAN-SPAM and the CCPA because of where you are. Where they differ, we apply whichever is stricter. We have not appointed a Data Protection Officer; we are not required to. For any privacy question or request, write to sa@polaim.com.
This policy covers three different groups of people, and what we hold differs a lot between them: visitors to this website, clients, and people at the companies we contact on a client's behalf.
2. When you visit this website
This site is deliberately plain. It sets no cookies, stores nothing in your browser, and loads no analytics, advertising or tracking scripts. We do not build a profile of you and we cannot tell who you are.
Fonts are served from our own domain, so loading this page contacts no third party at all. One thing still happens, and you should know about it:
| What | Who | Why |
|---|---|---|
| Standard server logs (IP address, timestamp, page, user agent) | Vercel, our hosting provider | Serving the site securely and diagnosing faults. Kept only briefly by the host. |
3. When you send us a brief
If you fill in the brief form, we collect exactly what you type: your website, your email address, who you want to reach, and — optionally — a note about your business and example client sites. Nothing else — there are no hidden fields.
We use it for one purpose: to prepare the free outreach hypotheses you asked for and to reply to you. The submission is delivered to our team as a notification through a Telegram bot; Telegram therefore processes that message in transit and in the group where we receive it.
We do not add you to any marketing list, and we do not sell or share your brief with anyone. Legal basis: taking steps at your request before entering into a contract, and our legitimate interest in answering enquiries.
4. When you are a client
We hold the ordinary things needed to run a programme: your contact details, the brief, campaign configuration, sending statistics, and the replies your campaign produces. Where we run sending on your behalf we may also process the business contact data of your prospects — in that case you are the controller and we act as your processor under a data processing agreement. Legal basis: performance of our contract with you.
5. If we contacted you — read this one
This is the section for someone who received an email from us and wants to know how we got their address. It is the part of our business we are most often asked about, so here is the whole mechanism.
What we hold
- Company-level information: company name, website, country, industry, and a generic company inbox such as info@ or contact@.
- Only where a company has told us who to speak to, or publishes it for that purpose: a name, role and business email address.
- The messages we sent you and any reply you sent us.
Where it came from
From open, publicly available sources — your own company website, public registers, industry directories and the press. We did not buy it, rent it, or take it from a data vendor, because we do not use contact databases at all. We hold no database of people to sell, and we never will.
Why we are allowed to
A generic organisational address such as info@company.com identifies a company, not an individual, and is generally not personal data. Where we do process an individual's business contact details, we rely on legitimate interest (Article 6(1)(f) GDPR) — a business writing to another business about something relevant to that person's professional role.
We have weighed that against your interests, and this is what we do to keep the balance fair: business context only, no special-category data, no consumer targeting, minimal fields, a short and relevant sequence rather than volume, a clear identification of who we are, and a one-click way out of every message.
If you are in the United States, the rule that governs commercial email is the CAN-SPAM Act. It does not require your permission before a first message, but it does require honesty and a way out. So every message we send carries a truthful "from" address and subject line, says plainly who is writing and on whose behalf, includes a real postal address, and carries a working opt-out. CAN-SPAM gives senders ten business days to process an opt-out; we do it immediately.
How we tell you
Because we obtained your details from public sources rather than from you, Article 14 GDPR requires us to tell you. We do that in the first message we send you, which identifies us and links to this page — that is why you are reading it.
How to make it stop
6. Who else touches the data
We keep the list of third parties as short as we can. Today it is:
| Provider | What for |
|---|---|
| Vercel | Website hosting and the form endpoint |
| Telegram | Delivering brief submissions to our team as a notification |
| Email sending & deliverability providers | Sending and monitoring campaign email on behalf of clients. We name the specific providers in the data processing agreement we sign with each client. |
We never sell personal data, and we never share it for anyone else's marketing.
7. How long we keep it
- Briefs and enquiries: up to 12 months if they do not become a project, then deleted.
- Client records: for the life of the engagement, then as long as tax and accounting law requires.
- Campaign contact data: for the campaign and a short period afterwards for reporting, then deleted.
- Suppression records: kept indefinitely — that is the only way to guarantee we never contact you again.
8. Your rights
Because we are established in the EU, the GDPR applies to our processing wherever you are. You have the rights to access, rectification, erasure, restriction, objection and portability, and — because we rely on legitimate interest for outreach — an absolute right to object to direct marketing, which we act on immediately.
Write to sa@polaim.com. We answer within 30 days and we do not charge for it. If you are unhappy with our response you can lodge a complaint with a supervisory authority. Ours is the Polish DPA: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. You may also complain to the authority where you live or work.
If you are in the United States
California's CCPA/CPRA gives you the right to know what we have collected, to have it deleted or corrected, and to opt out of the "sale" or "sharing" of your personal information. We have never sold personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but the rights to know, delete and correct work exactly as described above, and we will not treat you differently for using them.
To be straight with you: we are a small business well below the revenue and volume thresholds at which the CCPA formally applies to us, and the same is true of the comparable laws in Virginia, Colorado, Connecticut, Texas and elsewhere. We handle these requests the same way regardless of whether we are obliged to.
9. International transfers
We sit in the EU and work primarily with the US market, so data routinely crosses that border — our hosting, sending and messaging providers are largely US companies, and so are most of the companies we contact. Where personal data leaves the EEA we rely on appropriate safeguards: the European Commission's standard contractual clauses, or the EU–US Data Privacy Framework where the provider is certified under it.
10. Security
Access to campaign and client data is limited to the people who need it, over authenticated accounts. Credentials and API tokens are held as environment secrets, never in our source code. We keep the amount of personal data we hold deliberately small — the least risky data is the data you never collected.
11. Children
This is a business-to-business service. It is not directed at children and we do not knowingly collect their data.
12. Changes to this policy
If we change how we handle data, we update this page and the date at the top. Material changes affecting people we have already contacted will be reflected here before they take effect.
13. Contact
Pavel Shcherbinin, sole trader (jednoosobowa działalność gospodarcza), trading as Polaim
Zwycięska 9/17, 53-033 Wrocław, Poland
NIP / VAT-UE: PL1132920347
sa@polaim.com