Skout AI Logo
TRUST, SECURITY & PRIVACY

Trust, Security & Privacy

At Skout AI, we understand that our customers rely on our Services to support prospecting, sales intelligence, outbound engagement, workflow automation, communications, and AI-enabled sales operations.

Protecting customer data, maintaining platform security, and operating responsibly are fundamental principles of how we design and operate Skout AI.

This page explains our approach to security, privacy, data protection, responsible AI, international data processing, account security, and regulatory considerations.

Unless otherwise stated, capitalized terms have the meanings given to them in our Terms of Service.

Jump to Policy Section

Security & Reliability

We maintain technical, administrative, and organizational safeguards designed to protect the security, confidentiality, integrity, and availability of the Services.

Skout AI operates using cloud infrastructure and specialized technology providers that support application hosting, databases, storage, communications, authentication, analytics, monitoring, AI functionality, enrichment, and other platform operations.

Depending on the Services and configuration used, data transmitted through Skout AI is protected using encrypted transport protocols.

Access to production systems is restricted to authorized personnel and service providers who have a legitimate operational need to access those systems.

Our security practices may include:
  • authentication and access controls
  • role-based permissions
  • multi-factor authentication
  • encryption in transit and, where appropriate, at rest;
  • production-access restrictions
  • system logging and monitoring
  • vulnerability management
  • security testing and review
  • backup and recovery procedures
  • infrastructure monitoring
  • incident-response procedures
  • abuse and fraud prevention
  • data retention and deletion controls
  • vendor and subprocessor security reviews

We regularly review our infrastructure, operational practices, security controls, and technology providers as our Services and technology evolve.

We maintain incident-response procedures designed to identify, investigate, contain, and remediate security incidents.

Where required by applicable law or our contractual commitments, we will notify affected customers of confirmed security incidents involving their data.

No internet-based service can be guaranteed to be completely secure, uninterrupted, or error-free. We nevertheless maintain commercially reasonable safeguards designed to protect the Services and support operational continuity.

Additional security information may be made available to eligible customers upon request and, where appropriate, subject to confidentiality obligations or an NDA.

Security Certifications

Skout AI is not currently SOC 2 or ISO 27001 certified.

We do not represent or imply that Skout AI has obtained a security certification unless that certification is expressly identified and verifiable.

We continue to develop and mature our security and compliance program as our platform, infrastructure, and customer requirements evolve.

Your Data & Privacy

You retain ownership of the data and content that you submit to or process through Skout AI, subject to the rights necessary for us to provide the Services.

Depending on how you use Skout AI, information processed through the Services may include:
  • account and user information
  • company and business information
  • prospect and contact information
  • professional information
  • email addresses and other contact information
  • CRM and sales data
  • campaign and sequence information
  • communication content and metadata
  • enrichment information
  • workflow and automation data
  • information obtained through authorized integrations
  • authentication and security information
  • billing and subscription information
  • other information submitted by you or on your behalf
We process customer data as necessary to:
  • provide and operate the Services
  • maintain and improve the Services
  • provide customer support
  • maintain platform security
  • prevent fraud and abuse
  • authenticate users
  • respond to customer requests
  • operate integrations and connected services
  • process transactions
  • comply with applicable law
  • perform our contractual and operational obligations
We do not sell your customer data.

Access to customer data is limited to authorized personnel and service providers who have a legitimate business need to access such information, including providing support, maintaining the platform, troubleshooting technical issues, maintaining security, investigating abuse, complying with applicable law, or performing related operational functions.

Personnel and service providers with access to customer data are subject to appropriate confidentiality and security obligations.

We may generate and use aggregated, anonymized, or appropriately deidentified information that does not reasonably identify a customer or individual for purposes including:
  • analytics
  • security
  • fraud and abuse prevention
  • service reliability
  • performance measurement
  • product improvement
  • capacity planning
  • other lawful business purposes

We maintain data retention and deletion practices designed to account for operational requirements, contractual obligations, legal requirements, security considerations, and applicable customer or data-subject requests.

Additional information about our processing of personal information is provided in our Privacy Policy and, where applicable, our Data Processing Agreement.

Customer-Provided and Prospect Data

Skout AI is designed to support sales intelligence, prospecting, enrichment, workflow automation, and outbound communications.

As a result, customers may submit or process information relating to businesses, prospects, contacts, employees, customers, leads, and other individuals.

Customers are responsible for ensuring that the information they provide to Skout AI, or instruct Skout AI to process, has been obtained and may be used lawfully.

This includes ensuring, where applicable, that customers have:
  • an appropriate legal basis for processing personal information
  • obtained required consents
  • provided required privacy notices
  • complied with applicable data-source restrictions
  • complied with applicable marketing and communications laws
  • honored individual rights and requests
  • maintained appropriate suppression and opt-out records
  • obtained any permissions required to use third-party data or integrations

Skout AI provides technical functionality and infrastructure but does not determine the legal basis for a customer's particular processing activities.

Customers remain responsible for determining whether their specific use of prospect, contact, enrichment, or communication data is lawful.

International Data Processing

Skout AI may be used by customers and individuals located in different countries and regions.

Depending on the Services used, your configuration, and the location of our personnel and authorized service providers, information may be processed in countries other than the country in which you or your users are located.

This may include processing in the United States, India, countries within the European Economic Area, the United Kingdom, Canada, Australia, New Zealand, Japan, Singapore, and other jurisdictions where Skout AI or its authorized service providers operate.

Where required by applicable law, Skout AI uses appropriate legal mechanisms and safeguards for international transfers of personal information.

Depending on the circumstances, these mechanisms may include:
  • Standard Contractual Clauses (SCCs)
  • the UK International Data Transfer Addendum
  • applicable adequacy decisions
  • contractual data-protection commitments
  • appropriate technical and organizational safeguards
  • other legally recognized international transfer mechanisms

The specific mechanism applicable to a particular processing activity may depend on the customer's location, the individuals whose data is processed, the relevant service providers, and applicable law.

Additional information regarding international transfers may be provided through our Data Processing Agreement or upon request.

Privacy & Data Protection Framework

Skout AI is designed to support responsible processing of personal information and business data.

Depending on your location, the individuals whose information you process, and how you use the Services, applicable requirements may include privacy, data protection, electronic communications, marketing, consumer protection, cybersecurity, and other laws and regulations.

Depending on the circumstances, these may include:
European Union / EEA
General Data Protection Regulation (GDPR)
United Kingdom
UK GDPR and applicable UK data-protection legislation
Switzerland
applicable Swiss data-protection requirements
United States
applicable federal and state privacy and communications laws, including the CCPA/CPRA where applicable
Canada
applicable federal and provincial privacy requirements; Canada's Anti-Spam Legislation (CASL), where applicable
Australia
Privacy Act 1988 and applicable Australian privacy requirements
New Zealand
Privacy Act 2020 and applicable New Zealand requirements
China
applicable privacy and cybersecurity requirements, including the Personal Information Protection Law (PIPL), where applicable
Japan
applicable privacy requirements, including the Act on the Protection of Personal Information (APPI)
Singapore
Personal Data Protection Act (PDPA)
Other Jurisdictions
Other national, regional, state, provincial, or local privacy, data-protection, cybersecurity, marketing, electronic communications, and consumer-protection laws may also apply depending on the circumstances

The applicability of a particular law depends on the relevant facts and circumstances.

Skout AI does not represent that every law listed above applies to every customer or every use of the Services.

Customers are responsible for determining the laws applicable to their particular business, data, recipients, communications, and use of the Services.

Skout AI provides technical and administrative capabilities designed to support responsible use of the Services but does not provide legal or regulatory advice.

Licensing, Permissions & Regulatory Requirements

Skout AI is a software-as-a-service platform.

Privacy and data-protection laws such as GDPR, UK GDPR, CCPA/CPRA, and similar laws generally establish requirements concerning the processing and protection of personal information rather than operating as a universal license that a SaaS customer must obtain simply to use Skout AI.

Skout AI does not represent that customers need a universal privacy or data-protection license simply to use the platform.

However, certain activities, industries, jurisdictions, communication channels, or use cases may be subject to additional:
  • registrations
  • licenses
  • permits
  • consents
  • sender registrations
  • business verifications
  • telecom requirements
  • contractual requirements
  • other regulatory obligations
These requirements may depend on:
  • where the customer operates
  • where recipients are located
  • the type of information being processed
  • the customer's industry
  • the type of communication being sent
  • whether communications are commercial or transactional
  • the communication channel being used
  • applicable telecom requirements
  • applicable marketing and anti-spam requirements
  • requirements imposed by third-party platforms, mailbox providers, carriers, or service providers

Customers are responsible for determining whether their activities require any registration, license, consent, notification, permit, or other authorization.

Where a specific Skout AI feature requires a regulatory authorization, sender registration, verified business identity, third-party approval, or similar requirement, Skout AI may require the customer to provide the information or documentation necessary to enable that feature.

Skout AI does not provide legal or regulatory advice and does not guarantee that a customer's particular use of the Services satisfies every legal or regulatory requirement applicable to that customer.

Account Security & Authentication

Protecting customer accounts is an important part of the Skout AI security architecture.

We may collect and process information necessary to authenticate users, protect accounts, detect suspicious activity, prevent unauthorized access, and support account recovery.

This information may include:
  • email addresses
  • phone numbers
  • authentication identifiers
  • one-time verification codes
  • multi-factor authentication information
  • login events
  • authentication timestamps
  • IP addresses
  • device and browser information
  • session information
  • security events
  • other information reasonably necessary to protect an account or the Services

Skout AI may send account and security communications through supported channels, including email, SMS, authentication applications, push notifications, or other supported mechanisms.

These communications may include:
  • account verification
  • one-time passwords (OTP)
  • two-factor or multi-factor authentication (2FA/MFA)
  • password resets
  • account recovery
  • login verification
  • suspicious-login alerts
  • security alerts
  • account-change notifications
  • team invitations
  • integration security notifications
  • other communications necessary to operate or secure an account

These communications are service, transactional, or security communications rather than promotional marketing communications and may be sent even when a user has opted out of promotional communications, subject to applicable law.

Service & Transactional Communications

To operate Skout AI, we may send communications relating to your account, subscription, security, usage, integrations, and Services.

These may include:
  • onboarding communications
  • account notifications
  • authentication and security messages
  • OTP and 2FA messages
  • password-reset messages
  • billing and payment notifications
  • subscription and renewal notices
  • product and service notifications
  • credit and usage notifications
  • integration notifications
  • support communications
  • compliance notifications
  • important Terms or Privacy Policy updates
  • security incident notifications
  • other administrative or transactional communications

These communications are necessary to provide and administer the Services and are distinct from promotional marketing communications.

Outbound Communications & Compliance

Skout AI may provide functionality that enables customers to create, schedule, personalize, automate, or analyze outbound communications.

Customers remain responsible for the communications they send through the Services.

Customers must ensure that their use of Skout AI complies with applicable:
  • anti-spam laws
  • privacy laws
  • marketing laws
  • electronic communications laws
  • consumer-protection requirements
  • telecom requirements
  • platform rules
  • mailbox-provider requirements
  • other applicable laws and regulations

Customers are responsible for ensuring that communications contain required disclosures, sender information, unsubscribe mechanisms, opt-out functionality, and other legally required information.

Customers are also responsible for honoring unsubscribe, objection, suppression, do-not-contact, and similar requests.

Skout AI may restrict, suspend, throttle, or terminate communications activity where we reasonably believe it presents a legal, security, abuse, deliverability, or platform-integrity risk.

Additional requirements are contained in our Terms of Service and Acceptable Use Policy.

Responsible AI Practices

Skout AI includes AI-enabled functionality designed to support activities such as:
  • prospect research
  • lead qualification
  • personalization
  • communication drafting
  • workflow automation
  • classification
  • summarization
  • sales intelligence
  • enrichment
  • recommendations
  • other sales and productivity functions

We design and operate AI functionality with a focus on transparency, reliability, security, privacy, and responsible use.

Some AI features may rely on authorized third-party AI providers.

Where third-party AI providers are used, information submitted through an AI feature may be processed by those providers as necessary to provide the requested functionality.

We do not use customer data to train generalized artificial-intelligence or machine-learning models for the benefit of other customers unless expressly agreed in writing.

AI-generated content may contain inaccurate, incomplete, outdated, or unintended information.

Customers remain responsible for reviewing AI-generated content and determining whether it is appropriate before sending, publishing, relying upon, or otherwise using it.

Additional requirements relating to AI functionality may be described in our AI Terms.

Third-Party Integrations

Skout AI may integrate with third-party services, including CRM systems, email providers, calendars, communication platforms, data providers, enrichment providers, analytics services, AI providers, and other business applications.

When you connect a third-party service, you authorize Skout AI to access and process information from that service as necessary to provide the functionality you have enabled.

Your use of third-party services remains subject to the terms and policies of those third parties.

Skout AI does not control and is not responsible for the availability, accuracy, security, privacy practices, or continued operation of third-party services.

Customers are responsible for ensuring that they have the necessary permissions and authorizations to connect third-party services to Skout AI.

Vendors & Subprocessors

Skout AI works with specialized technology providers and subprocessors that help us operate, secure, support, and improve the Services.

Depending on the Services and features used, these providers may support:
  • cloud infrastructure
  • databases and storage
  • authentication
  • email and communications
  • SMS and messaging
  • analytics
  • monitoring
  • customer support
  • AI functionality
  • enrichment
  • data processing
  • integrations
  • security
  • payment processing
  • other operational functions

Our subprocessors are authorized to process customer data only as necessary to provide their contracted services.

Where appropriate, we maintain contractual confidentiality, privacy, security, and data-processing protections with our service providers.

Our subprocessors may change as Skout AI's technology stack and Services evolve.

Information regarding current subprocessors may be provided through our Subprocessor List, Data Processing Agreement, customer documentation, or upon request.

Data Processing Agreement

For customers that process personal information through Skout AI in circumstances where a Data Processing Agreement is required or appropriate, Skout AI may provide a Data Processing Agreement (DPA) addressing matters including:

  • processing instructions
  • roles and responsibilities
  • confidentiality
  • security measures
  • subprocessors
  • international data transfers
  • data-subject rights
  • security incidents
  • retention and deletion
  • assistance with applicable privacy obligations
  • other contractual data-protection requirements

Enterprise customers may contact our privacy or legal team regarding DPA requirements.

Security Incident Response

We maintain procedures designed to detect, investigate, contain, remediate, and learn from security incidents.

If Skout AI determines that a confirmed security incident has occurred involving customer data, we will provide notice where required by applicable law or contractual obligations.

Our response may include:
  • identifying and assessing the incident
  • containing affected systems
  • investigating the nature and scope of the incident
  • taking appropriate remediation measures
  • communicating with affected customers where required
  • implementing corrective and preventive measures

Data Retention & Deletion

Skout AI maintains data retention and deletion practices designed to balance operational requirements, security, contractual obligations, and applicable legal requirements.

Retention periods may vary depending on:
  • the type of information
  • the purpose for which it was collected
  • the Services being used
  • account status
  • customer configuration
  • legal requirements
  • security requirements
  • applicable contractual obligations

When information is no longer required for legitimate business, contractual, security, or legal purposes, it may be deleted, anonymized, or otherwise handled in accordance with our applicable retention procedures.

Additional retention and deletion terms may be specified in our Privacy Policy, Data Processing Agreement, or applicable customer agreement.

Compliance & Governance

We maintain contractual, technical, and operational practices intended to support responsible data handling throughout the Services.

Our compliance program is designed to evolve as Skout AI expands into additional markets, products, technologies, and regulatory environments.

Skout AI is designed to support customers operating across major international markets, including:

  • North America
  • the European Union and EEA
  • the United Kingdom
  • Canada
  • Australia
  • New Zealand
  • India
  • Japan
  • Singapore
  • other jurisdictions

subject to applicable laws, service availability, third-party provider requirements, and customer configuration.

Nothing on this page constitutes legal advice or guarantees that a customer's particular use of Skout AI complies with every law applicable to that customer.

Security Reporting

We encourage responsible disclosure of potential vulnerabilities, security issues, or privacy concerns affecting Skout AI.

Security concerns can be reported to:

Privacy & Data Protection:
privacy@skoutai.io
Customer Support:
support@skoutai.io

When reporting a security issue, please provide enough information for our team to understand and investigate the potential vulnerability where possible.

Privacy Requests

Privacy-related requests may be submitted to:

Depending on applicable law and the nature of the request, we may need to verify the identity or authority of the requester before processing the request.

Customers may also use the contact methods described in our Privacy Policy and Data Processing Agreement, where applicable.

Ongoing Commitment

Trust, security, privacy, and responsible AI are ongoing responsibilities.

As Skout AI grows, we will continue to evaluate and improve our:
  • security controls
  • privacy practices
  • infrastructure
  • access controls
  • vendor management
  • incident-response processes
  • data governance
  • AI safeguards
  • compliance processes
  • customer-facing security documentation

Our objective is to build Skout AI so customers can confidently use the platform for prospecting, sales intelligence, outbound engagement, workflow automation, and AI-enabled sales operations while maintaining appropriate control over their data and communications.