Privacy Policy

Last updated: June 28, 2026

SmartOps Copilot is operated by Parallax Horizon AI. This policy explains what data we collect, how we use it, and your rights. We keep this clear and honest.

1. Who We Are

SmartOps Copilot is an AI-powered sales operations platform developed and operated by Parallax Horizon AI ("we", "us", "our"). For privacy enquiries, contact us at privacy@parallaxhorizon.com.

Where GDPR applies, Parallax Horizon AI acts as the data controller for account and usage data. For data processed within your connected Google or Microsoft accounts, you are the controller and we act as a data processor on your instructions.

2. What Data We Collect

Account data

Name, email address, and optional company name provided at sign-up. If you authenticate via Google or Microsoft OAuth, we receive your name, email, and profile photo from those providers.

Usage data

Pages visited, features used, and actions taken within the platform (e.g., campaigns created, prospects added, automations configured). This helps us improve the product and diagnose issues.

Email and calendar data

If you connect your Gmail or Google Calendar account, we access your emails and calendar events solely to operate the features you have enabled — including automated follow-ups, meeting scheduling, reply classification, and AI draft generation. We do not sell, share, or use this content for any purpose other than providing the Service to you. We do not use your email or calendar content to train AI models.

Prospect and campaign data

Contact details, email content, and engagement data you upload or that is created as part of running outreach campaigns. You are responsible for ensuring you have a lawful basis to process any personal data belonging to third parties within this content.

CRM data

If you connect a CRM (e.g., HubSpot, Salesforce, or Pipedrive), we exchange contact and deal data to keep records in sync. We store only what is necessary to operate the integration.

Billing data

Subscription and payment information is processed by Paddle, our payment provider. We receive confirmation of your subscription status, plan tier, and billing history. We do not store full payment card details.

Log and technical data

Server logs, IP addresses, browser type, device information, and error reports for security, debugging, and operational purposes. Logs are retained for up to 90 days.

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following legal bases:

ContractProcessing necessary to provide the Service you have signed up for — account management, feature delivery, billing, and transactional communications.
Legitimate interestsProduct improvement, security monitoring, fraud prevention, and analytics, where these do not override your rights and interests.
Legal obligationRetaining billing records and complying with applicable laws.
ConsentWhere we send optional marketing communications, which you may withdraw at any time.

4. How We Use Your Data

  • To create and manage your account
  • To provide the features you use — AI outreach, CRM sync, scheduling, and automation
  • To send transactional emails (e.g., login codes, billing receipts, important account notices)
  • To improve, debug, and develop new product features using aggregated and anonymised data
  • To enforce our Terms of Service and prevent abuse
  • To comply with legal obligations and respond to lawful requests from authorities

We do not sell your personal data. We do not use your email, calendar, or prospect content to train AI models.

5. AI and Automated Processing

SmartOps Copilot uses AI models to generate email drafts, classify replies, and produce outreach suggestions. When you use these features, relevant context — such as prospect details and your AI Knowledge settings — is processed by our AI systems to generate a response. The AI provider we use may change over time; where a third-party provider is involved, we ensure appropriate data processing agreements are in place and current providers are listed in Section 6 (Third-Party Services).

We do not use your data to train AI models. AI-generated content may not always be accurate. You are responsible for reviewing any AI-generated output before sending it to third parties.

6. Third-Party Services

We share data with the following sub-processors only as necessary to operate the Service:

ServicePurposePrivacy policy
GoogleOAuth sign-in, Gmail, and Google Calendar integrationView →
MicrosoftOAuth sign-in and Outlook integrationView →
PaddlePayment processing and subscription management (Merchant of Record)View →
HubSpotCRM integration (when enabled by you)View →
SalesforceCRM integration (when enabled by you)View →
PipedriveCRM integration (when enabled by you)View →
TwilioSMS and WhatsApp messaging (when enabled by you)View →

7. International Data Transfers

We are based in the United Kingdom. Some of our sub-processors (including Google and Vercel) may process your data in the United States or other countries outside the EEA and UK. Where required, we rely on the EU–US Data Privacy Framework, UK adequacy decisions, or Standard Contractual Clauses (SCCs) approved by the European Commission to legitimise these transfers.

8. Data Retention

We keep your account data for as long as your account is active. If you delete your account, we permanently delete your personal data within 30 days, except where required by law (e.g., billing records retained for 7 years for tax purposes).

Email and calendar content accessed via Google is processed in real time to perform the requested action (e.g., generate a draft). It is not stored beyond what is necessary to deliver that specific action.

Server and audit logs are retained for up to 90 days.

9. Cookies

We use session cookies solely to authenticate your session and maintain security. We do not use advertising cookies or third-party tracking pixels. Anonymised analytics may use privacy-preserving cookies to understand aggregate product usage. See our Cookie Policy for full details.

10. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — ask us to correct inaccurate or incomplete data
  • Deletion (right to be forgotten) — request erasure of your data, subject to legal retention obligations
  • Portability — receive your data in a structured, machine-readable format
  • Restriction — ask us to limit processing of your data in certain circumstances
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing

To exercise any of these rights, email privacy@parallaxhorizon.com. We will respond within 30 days (or 1 month under GDPR). If you are unhappy with our response, you have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, or your EU supervisory authority).

11. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect and how it is used, the right to delete your personal information, the right to correct inaccurate personal information, and the right to opt out of the sale or sharing of personal information.

We do not sell or share personal information as defined under the CCPA/CPRA. To exercise your rights, contact privacy@parallaxhorizon.com. We will not discriminate against you for exercising these rights.

12. Security

We apply industry-standard security measures including encrypted connections (HTTPS/TLS 1.2+), encrypted storage of OAuth tokens, least-privilege access controls, and regular security reviews. We do not store your Google or Microsoft passwords.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of the breach, where required by law.

If you discover a security vulnerability, please report it responsibly to security@parallaxhorizon.com.

13. Children

SmartOps Copilot is designed for business and professional use. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided us with personal data, contact us and we will delete it promptly.

14. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will notify you by email or by displaying a prominent notice in the platform at least 14 days before the changes take effect. The date at the top of this page always reflects the most recent version.

15. Contact

Questions or concerns about this policy? Contact us at privacy@parallaxhorizon.com or visit our Help Centre.