This Privacy Policy explains how personal data is handled in connection with gtm-api.com, an MCP-first GTM API that lets AI agents and developers run LinkedIn automation, email outreach, and data enrichment through a single unified interface, with built-in per-account sending safety limits and observability. It describes the two very different roles we play: the data we handle about you, our account holder (where we decide the purposes and means, acting as a controller), and the data we handle on your instructions about the prospects you target (where you decide, and we merely act on your behalf as a processor).
Effective date: 2026-06-22
1. Who we are and how to reach us
The service is operated by Individual Entrepreneur Evgenii Salamatov, identification number 324080203, registered as an individual entrepreneur in the country of Georgia (registered address: Abi (down the lake), Akhaltsikhe District, Georgia). For most data described below, Individual Entrepreneur Evgenii Salamatov is the controller.
You can contact us at:
- Privacy questions and data-subject requests: [email protected]
- Data protection contact: [email protected]
- Legal and contractual matters: [email protected]
- General support: [email protected]
As an individual entrepreneur established in the country of Georgia, Individual Entrepreneur Evgenii Salamatov is not required under the GDPR to appoint a Data Protection Officer, and we have not appointed one. The data protection contact above is responsible for handling privacy and data-protection matters.
2. Two roles: controller vs. processor
Understanding which role applies is central to this policy.
- We are the controller for data about your relationship with us as a customer, your account identity, API credentials, billing, usage logs, and support history.
- We are the processor for the B2B prospect and contact data you push through, or pull from, the API to run your campaigns. You are the controller of that data. We process it only to deliver the service on your documented instructions, and we do not use it for our own independent purposes. The terms governing this relationship are set out in our Data Processing Addendum (DPA), available on request and incorporated into your subscription contract.
3. Data we collect as a controller
When you create and operate an account, we collect:
- Account identity: your name, business email address, and the credentials you use to sign in (including via Google sign-in, where we receive your basic profile and email).
- API keys and authentication material: the keys you generate to call the API, and metadata about their use. We treat these as secrets.
- Billing data: plan, subscription status, and payment records. Card and payment processing is handled by our merchant of record, Paddle; we do not store full card numbers.
- Usage and server logs: API calls, timestamps, IP addresses, request and response metadata, rate-limit and sending-safety events, error traces, and observability data used to operate, secure, and debug the platform.
- Support correspondence: the content of emails and tickets you send us.
- Cookies and similar technologies: as described in our Cookie Policy (see section 11).
4. Data we process as a processor on your behalf
To run multichannel outbound, the API processes B2B prospect and contact data that you select and supply. This typically includes prospects' names, job titles, employer, public LinkedIn profile URLs, business email addresses, and the content of the messages you send. We hold and transmit this data to execute the actions you configure (such as connection requests, messages, and enrichment lookups) and to enforce your per-account safety limits. We act on your instructions only. As the controller of this data, you are responsible for establishing a lawful basis, providing any required notices to data subjects, honoring their rights, and ensuring your outreach complies with applicable law and the terms of the third-party platforms you use.
5. Purposes and legal bases (GDPR Article 6)
Where the GDPR applies, we rely on the following bases for the data we control:
- Performance of a contract (Art. 6(1)(b)): creating your account, authenticating API calls, delivering the service, and processing payments.
- Legitimate interests (Art. 6(1)(f)): securing the platform, preventing abuse and fraud, enforcing sending-safety limits, maintaining logs and observability, and improving the service. We balance these against your rights.
- Legal obligation (Art. 6(1)(c)): retaining records for tax, accounting, and compliance.
- Consent (Art. 6(1)(a)): non-essential cookies and any optional marketing, which you can withdraw at any time.
For prospect data processed as a processor, the legal basis is determined by you as the controller.
6. Sharing and sub-processors
We do not sell personal data for money. We share personal data only with vendors that help us run, secure, analyze, and market the service, under contracts that require appropriate safeguards. As of 2026-06-22 (subject to change), our sub-processors and key service providers are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | CDN, WAF, DNS | United States |
| DigitalOcean LLC | Cloud hosting | United States |
| Hetzner Online GmbH | Cloud hosting | Germany |
| Paddle.com Market Ltd | Payments / merchant of record | United Kingdom |
| Twilio Inc. (SendGrid) | Transactional email delivery | United States |
| Grafana Labs | Observability (logs and traces) | United States |
| Google LLC | Sign-in (OAuth), website & product analytics, advertising | United States |
| Meta Platforms, Inc. | Advertising and conversion measurement (Meta Pixel) | United States |
| Amplitude, Inc. | Product analytics | United States |
| Encharge | Lifecycle and marketing email | European Union |
Some of these providers, in particular Google, Meta, Amplitude, and Encharge, receive limited personal data about you, such as your email address and product-usage events (hashed or pseudonymised where the provider supports it), so we can measure and improve the product, run lifecycle email, and match advertising audiences. We use personal data with these providers where it is useful for those purposes, and, where analytics or advertising requires consent, only after you consent through our cookie banner; you can withdraw consent at any time.
We may also disclose data where required by law, to enforce our terms, or in connection with a merger, acquisition, or sale of assets, in which case this policy will continue to govern the transferred data, and we will notify you of any material change in control.
7. International transfers
We and our sub-processors may process personal data outside your country, including outside the EU/EEA and the UK. Where we transfer data internationally, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, for transfers from the UK, the UK International Data Transfer Addendum (IDTA), together with supplementary measures where needed. A copy of the relevant safeguards is available on request at [email protected].
8. Retention
We keep controller data for as long as your account is active and as needed to provide the service. After you close your account, we delete or anonymize account and prospect data we hold within 30 days, except where we must retain certain records longer to meet legal, tax, accounting, or security obligations, or to resolve disputes. Server and security logs are kept for a limited period proportionate to their purpose. For prospect data we process on your behalf, you control retention through your use of the service, and we delete it on your instruction or on account termination within the same 30-day window.
9. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit, access controls and secret management for API keys, network protections (WAF/CDN), isolated execution environments for automation sessions, audit logging, and continuous observability. We do not store third-party platform passwords. No system is perfectly secure, but we work to protect your data and will notify you and any relevant authority of a personal data breach where the law requires.
10. Your rights
Subject to applicable law, you have rights over your personal data. Under the GDPR (EU/EEA and UK), you may request access, rectification, erasure, restriction, portability, and you may object to processing based on legitimate interests, and withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.
Under the CCPA/CPRA, California residents may request to know, access, correct, and delete personal information, and may opt out of the "sale" or "sharing" of personal information. We do not sell personal information for monetary value. We may "share" personal information for cross-context behavioural advertising, for example through advertising and analytics cookies set by Google and Meta, only where you have consented. You can opt out at any time through our cookie controls or by emailing [email protected], and we do not discriminate against you for exercising your rights.
To exercise any right, contact [email protected]. We will verify your request and respond within the timeframes the law requires. If your request concerns prospect data we process for one of our customers, we will refer you to, or coordinate with, the relevant customer who controls that data.
11. Cookies
We use cookies and similar technologies for authentication, security, preferences, analytics, and, where you consent, advertising. You can control non-essential cookies through your browser and our cookie controls. For details on what we set and why, see our Cookie Policy.
12. Children
gtm-api.com is a business-to-business product intended for use by professionals and organizations. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us data, contact [email protected] and we will delete it.
13. Acceptable use and platform responsibility
Because the API automates outreach on third-party platforms, certain responsibilities rest with you. You must comply with the terms of every platform you reach through the API, including LinkedIn's User Agreement and Professional Community Policies, and with all applicable laws. You are responsible for configuring your automated actions and managing your outreach volume sensibly; while we provide built-in per-account safety limits, these limits do not guarantee that messaging cannot be excessive, and automation on third-party platforms is inherently risky. We are not liable for account restrictions, blocks, or bans imposed by any platform. Individual Entrepreneur Evgenii Salamatov operates gtm-api.com independently and has no affiliation with LinkedIn Corporation. We mention LinkedIn only to explain how the Service interoperates with it; LinkedIn is a trademark of its owner.
14. Changes to this policy
We may update this policy from time to time. When we make material changes, we will revise the effective date above and, where appropriate, notify you. Your continued use of the service after an update means you accept the revised policy.
15. How to contact us
For any privacy matter, write to [email protected] or our data protection contact at [email protected]. This policy is governed by the laws of the country of Georgia, and any dispute is subject to the courts of Georgia, following a 60-day good-faith resolution period.