Legal

Privacy Policy

How Brand Armor AI V.O.F. handles personal data in Prospectrum, both yours as a customer and the lead data we process on your behalf.

Last updated 28 July 2026.

1. Who is responsible

Prospectrum is operated by Brand Armor AI V.O.F., registered in the Netherlands, company registration number 99567814, VAT number NL869042981B01. We are the data controller for your account data, and every privacy question or request goes to the email address below.

Reach us at admin@prospectrum.app.

Registered address

Brand Armor AI V.O.F., Heeghtakker 48A, the Netherlands.

2. Two kinds of data

Your account data. Data about you as a customer. We are the controller and decide how it is used, within this policy.

Your lead data. Business contact details discovered for your campaigns and the outreach you send. You decide who is contacted and why, so you are the controller and we act as your processor, handling it on your instruction to run the service.

3. What we collect and why

  • Account details (name, email address, password credentials held by Firebase Authentication) to create and secure your account. Legal basis: performance of our contract with you.
  • Billing details (Stripe customer and subscription identifiers, billing country, VAT ID if you give one) to charge you and meet tax obligations. Card numbers go to Stripe and never reach our servers. Legal basis: contract and legal obligation.
  • Campaign configuration and sending settings, to run the service you asked for. Legal basis: contract.
  • Lead data discovered for your campaigns: business name, address, phone, website, publicly listed email, and public signals about that business's online presence. Legal basis: your instruction as controller.
  • Outreach and reply content, so drafts, sends and replies can be shown to you and follow-ups scheduled. Legal basis: contract and your instruction.
  • Operational logs (request metadata, IP address, errors, delivery and bounce events) to keep the service secure, debug problems, and limit abuse. Legal basis: our legitimate interest in a secure, working service.

4. Where lead data comes from

Leads are discovered from public sources, primarily public business listings and the business's own website. We collect business contact details, not private individuals' personal information. If a business asks to be removed, tell us and we will suppress it, and any recipient who unsubscribes is suppressed automatically for future sends.

5. Who we share it with

These providers process data so we can run the service. We do not sell personal data to anyone.

  • Google Cloud and Firebase (authentication, database, file storage, hosting infrastructure).
  • Vercel (application hosting and request logs).
  • Stripe (payment processing, billing, and tax calculation).
  • Resend (sending outreach email and receiving replies).
  • OpenAI (generating and evaluating draft outreach text).
  • Google Maps Platform (discovering public business listings).

We may also disclose data where the law requires it, or to protect our rights, our customers, or the security of the service.

6. International transfers

Some of these providers are based in the United States, so data may be transferred outside the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with the safeguards in each provider's data processing terms.

7. How long we keep it

  • Account and campaign data: for as long as your account is open, then deleted within 90 days of closure.
  • Lead and outreach data: for as long as your account is open, or until you delete the campaign it belongs to.
  • Suppression records (unsubscribes and bounces): kept indefinitely, because forgetting them would mean contacting someone who asked not to be.
  • Billing and invoice records: kept for seven years, as Dutch tax law requires.
  • Operational logs: kept for up to 90 days.

8. Your rights

Under GDPR you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or receive it in a portable format. Email admin@prospectrum.app and we will respond within one month. You can also complain to your local data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.

9. Security

Access to production data is restricted and authenticated. Traffic is encrypted in transit, data is encrypted at rest by our infrastructure providers, and credentials you give us for sending are encrypted before storage. No system is perfectly secure, but if a breach affects your data we will notify you and the relevant authority as the law requires.

10. Cookies

We use a single essential cookie to keep you signed in. It is required for the application to work and is not used for advertising or cross site tracking. We do not run third party advertising or analytics cookies.

11. Changes

We will update this policy as the service changes. Material changes are announced by email, and the date at the top shows when this page last changed.

12. Contact

Privacy questions and requests go to admin@prospectrum.app, or use the contact form.