This Privacy Policy explains how personal data is handled in connection with gtm-api.com, an MCP-first GTM API that lets AI agents and developers run LinkedIn automation, email outreach, and data enrichment through a single unified interface, with built-in per-account sending safety limits and observability. It describes the two very different roles we play: the data we handle about you, our account holder (where we decide the purposes and means, acting as a controller), and the data we handle on your instructions about the prospects you target (where you decide, and we merely act on your behalf as a processor).

Effective date: 2026-06-22

1. Who we are and how to reach us

The service is operated by Individual Entrepreneur Evgenii Salamatov, identification number 324080203, registered as an individual entrepreneur in the country of Georgia (registered address: Abi (down the lake), Akhaltsikhe District, Georgia). For most data described below, Individual Entrepreneur Evgenii Salamatov is the controller.

You can contact us at:

As an individual entrepreneur established in the country of Georgia, Individual Entrepreneur Evgenii Salamatov is not required under the GDPR to appoint a Data Protection Officer, and we have not appointed one. The data protection contact above is responsible for handling privacy and data-protection matters.

2. Two roles: controller vs. processor

Understanding which role applies is central to this policy.

3. Data we collect as a controller

When you create and operate an account, we collect:

4. Data we process as a processor on your behalf

To run multichannel outbound, the API processes B2B prospect and contact data that you select and supply. This typically includes prospects' names, job titles, employer, public LinkedIn profile URLs, business email addresses, and the content of the messages you send. We hold and transmit this data to execute the actions you configure (such as connection requests, messages, and enrichment lookups) and to enforce your per-account safety limits. We act on your instructions only. As the controller of this data, you are responsible for establishing a lawful basis, providing any required notices to data subjects, honoring their rights, and ensuring your outreach complies with applicable law and the terms of the third-party platforms you use.

5. Purposes and legal bases (GDPR Article 6)

Where the GDPR applies, we rely on the following bases for the data we control:

For prospect data processed as a processor, the legal basis is determined by you as the controller.

6. Sharing and sub-processors

We do not sell personal data for money. We share personal data only with vendors that help us run, secure, analyze, and market the service, under contracts that require appropriate safeguards. As of 2026-06-22 (subject to change), our sub-processors and key service providers are:

Sub-processorPurposeLocation
Cloudflare, Inc.CDN, WAF, DNSUnited States
DigitalOcean LLCCloud hostingUnited States
Hetzner Online GmbHCloud hostingGermany
Paddle.com Market LtdPayments / merchant of recordUnited Kingdom
Twilio Inc. (SendGrid)Transactional email deliveryUnited States
Grafana LabsObservability (logs and traces)United States
Google LLCSign-in (OAuth), website & product analytics, advertisingUnited States
Meta Platforms, Inc.Advertising and conversion measurement (Meta Pixel)United States
Amplitude, Inc.Product analyticsUnited States
EnchargeLifecycle and marketing emailEuropean Union

Some of these providers, in particular Google, Meta, Amplitude, and Encharge, receive limited personal data about you, such as your email address and product-usage events (hashed or pseudonymised where the provider supports it), so we can measure and improve the product, run lifecycle email, and match advertising audiences. We use personal data with these providers where it is useful for those purposes, and, where analytics or advertising requires consent, only after you consent through our cookie banner; you can withdraw consent at any time.

We may also disclose data where required by law, to enforce our terms, or in connection with a merger, acquisition, or sale of assets, in which case this policy will continue to govern the transferred data, and we will notify you of any material change in control.

7. International transfers

We and our sub-processors may process personal data outside your country, including outside the EU/EEA and the UK. Where we transfer data internationally, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, for transfers from the UK, the UK International Data Transfer Addendum (IDTA), together with supplementary measures where needed. A copy of the relevant safeguards is available on request at [email protected].

8. Retention

We keep controller data for as long as your account is active and as needed to provide the service. After you close your account, we delete or anonymize account and prospect data we hold within 30 days, except where we must retain certain records longer to meet legal, tax, accounting, or security obligations, or to resolve disputes. Server and security logs are kept for a limited period proportionate to their purpose. For prospect data we process on your behalf, you control retention through your use of the service, and we delete it on your instruction or on account termination within the same 30-day window.

9. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit, access controls and secret management for API keys, network protections (WAF/CDN), isolated execution environments for automation sessions, audit logging, and continuous observability. We do not store third-party platform passwords. No system is perfectly secure, but we work to protect your data and will notify you and any relevant authority of a personal data breach where the law requires.

10. Your rights

Subject to applicable law, you have rights over your personal data. Under the GDPR (EU/EEA and UK), you may request access, rectification, erasure, restriction, portability, and you may object to processing based on legitimate interests, and withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.

Under the CCPA/CPRA, California residents may request to know, access, correct, and delete personal information, and may opt out of the "sale" or "sharing" of personal information. We do not sell personal information for monetary value. We may "share" personal information for cross-context behavioural advertising, for example through advertising and analytics cookies set by Google and Meta, only where you have consented. You can opt out at any time through our cookie controls or by emailing [email protected], and we do not discriminate against you for exercising your rights.

To exercise any right, contact [email protected]. We will verify your request and respond within the timeframes the law requires. If your request concerns prospect data we process for one of our customers, we will refer you to, or coordinate with, the relevant customer who controls that data.

11. Cookies

We use cookies and similar technologies for authentication, security, preferences, analytics, and, where you consent, advertising. You can control non-essential cookies through your browser and our cookie controls. For details on what we set and why, see our Cookie Policy.

12. Children

gtm-api.com is a business-to-business product intended for use by professionals and organizations. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us data, contact [email protected] and we will delete it.

13. Acceptable use and platform responsibility

Because the API automates outreach on third-party platforms, certain responsibilities rest with you. You must comply with the terms of every platform you reach through the API, including LinkedIn's User Agreement and Professional Community Policies, and with all applicable laws. You are responsible for configuring your automated actions and managing your outreach volume sensibly; while we provide built-in per-account safety limits, these limits do not guarantee that messaging cannot be excessive, and automation on third-party platforms is inherently risky. We are not liable for account restrictions, blocks, or bans imposed by any platform. Individual Entrepreneur Evgenii Salamatov operates gtm-api.com independently and has no affiliation with LinkedIn Corporation. We mention LinkedIn only to explain how the Service interoperates with it; LinkedIn is a trademark of its owner.

14. Changes to this policy

We may update this policy from time to time. When we make material changes, we will revise the effective date above and, where appropriate, notify you. Your continued use of the service after an update means you accept the revised policy.

15. How to contact us

For any privacy matter, write to [email protected] or our data protection contact at [email protected]. This policy is governed by the laws of the country of Georgia, and any dispute is subject to the courts of Georgia, following a 60-day good-faith resolution period.