Terms, privacy and security

What is Reachkit?

Reachkit has three public pages that describe the rules of the service, how personal data is handled, and how the platform is secured. They are the source of truth for compliance questions, so this article points you to the right one rather than repeating them.

The three pages

  • Terms of Service: the agreement between you and Reachkit. Acceptable use, billing and cancellation, intellectual property, liability, and the data processing terms that apply when Reachkit processes contact data on your behalf (Section 10).
  • Privacy Policy: what personal information Reachkit collects about its own users and website visitors, how it is used and shared, how long it is kept, and the rights you have under GDPR and CCPA.
  • Security: how customer data is protected. Hosting, encryption, how connected inboxes are accessed, backups, data retention, sub-processor categories, certifications, and how to report a vulnerability.

Who to contact

Common questions

  • Does Reachkit have a SOC 2 or ISO 27001 certification? The current answer is on the Security page under Compliance, along with how to request a questionnaire.
  • Where is my data stored, and is it encrypted? Covered on the Security page under Infrastructure and Encryption.
  • Who are Reachkit’s sub-processors? The category list is on the Security page; a full list is available on request.
  • Does Reachkit sign a DPA? The data processing terms are built into Section 10 of the Terms of Service.
  • How do I delete my data? Inboxes, campaigns, leads and conversations can be deleted in the app. For a whole workspace or account, email support@reachkit.ai.