By using the Services, you consent to the practices detailed below. When required by law, we will seek explicit consent prior to processing your information.
1. Information we collect
Account and engagement data such as name, email, telephone, billing address, company information, questionnaires and supporting documentation; platform analytics such as usage logs, IP addresses, device identifiers and performance metrics; newsletter data such as email address, optional name and subscription metadata; and functional cookies such as wedge_origin to remember which public reading started the flow and attribute conversion correctly without storing sensitive answers in that cookie. Marketing events linked to an anonymous Lite Scan session are retained for that session TTL, normally 30 days, and are purged in cascade when the session expires.
2. How we use information
We process personal information to provide and improve Services, prepare legal deliverables, personalize communications, comply with legal obligations and safeguard our systems. We may anonymize or aggregate data for analytics and benchmarking.
3. Legal basis
For US users, processing is based on consent, performance of a contract, legitimate interest or legal obligation. For EEA, UK and other international users, account delivery, checkout, support and report generation normally rely on contract necessity; accounting, tax and abuse-prevention records rely on legal obligation or legitimate interests; marketing, optional cookies and optional outreach use consent or legitimate interests where the applicable framework allows it.
4. Sharing information
We share personal information with vetted professional partners strictly as required to deliver engagements, subject to confidentiality obligations. We may disclose information when required by law, court order or regulatory authorities.
5. Operational processors and carve-outs
Enabled operational processors may include Stripe for checkout and billing, EmailIt for transactional email, Breakcold and Encharge for CRM or email automation, RepliQ for optional personalized follow-up video workflows, and Consolto for scheduling or video-consultation widgets. RepliQ and Consolto are treated as operational carve-outs: Outmove scrubs local records and records deletion follow-up, but the current OSA code does not call an unverified external search or delete endpoint and RepliQ has no verified server-side erasure API in our implementation. We do not treat credentials alone as approval to activate a processor; each live processor needs an operational owner and a recorded deletion/escalation path.
5A. Session Intelligence
Session Intelligence covers recorded consultation sessions. A recorded session requires prior notice and acceptance: Outmove keeps an encrypted copy of the recording for a limited period for service follow-up, quality control and defence against possible claims. External transcription and AI analysis are separate consents: only if you accept them and the processors are production-approved with a validated transfer basis may the audio be sent to OpenAI or the configured transcription provider, and the minimized transcript be analyzed by Anthropic or the configured LLM processor. We do not keep raw transcripts; we store hashes, minimized or generalized results, and retention metadata. This workflow may identify frequent questions, report gaps, draft content ideas, commercial objections and satisfaction signals, but it is not used to produce automated legal advice or to change RiskMap findings, rules, source authority or client reports. Retained analysis records are limited by the Session Intelligence retention schedule, currently 60 days; encrypted recordings have their own defensive retention window; and you can revoke transcription, AI or future-processing consents from your account or by contacting privacy@outmove.io.
6. International transfers
Personal data may be transferred to, stored in or processed within jurisdictions where we or our partners operate. When data leaves its origin jurisdiction, the transfer basis may include a vendor data-processing agreement, standard contractual clauses where appropriate, an adequacy or Data Privacy Framework route where valid, or another documented mechanism required by the applicable framework. A processor is not production-approved where the required transfer basis cannot be validated.
7. Data retention
We retain personal data for as long as necessary to fulfill engagements, comply with legal obligations, resolve disputes and enforce agreements. Outmove operational logs are retained for at least 24 months unless otherwise required.
8. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete or restrict processing of your personal data, as well as portability and objection rights. Submit requests via privacy@outmove.io.
9. Security
We implement administrative, technical and physical safeguards including encryption, access controls, vendor diligence and regular security reviews. No system is fully secure; notify us immediately if you suspect unauthorized access.
10. Children’s privacy
The Services are not directed to children under 13. We do not knowingly collect personal data from children and will delete it promptly if discovered.
11. Updates
We may update this Privacy Policy to reflect changes in law or our practices. We will post revisions with a new effective date and highlight material changes through the Site or direct communication.
12. Contact
For privacy inquiries, contact Outmove Suite at privacy@outmove.io or by mail at 30 N Gould St Ste R, Sheridan, WY 82801, USA.