Paying $79 a seat for LinkedIn outreach?See what you'd save with Hollerly →
Last updated: October 3, 2026

Privacy Policy

This policy explains how Hollerly, operated by Suff Digital, handles personal data about visitors to hollerlyai.com, our customers and their team members, and the people our customers contact through Hollerly. It should be read with our Terms of Service and Acceptable Use Policy. If you were contacted by someone using Hollerly and want it to stop, go straight to section 12.

1. Who we are and what this covers

Hollerly is operated by Suff Digital (“Hollerly”, “we”, “us”). You can reach us about privacy at hello@hollerlyai.com.

This policy covers:

  • Visitors to our website and free tools;
  • Customers and their invited team members who use the Hollerly dashboard, API or MCP server;
  • Prospects, meaning people whose details a customer imports into Hollerly or who are contacted through it.

2. Controller and processor roles

  • We are the controller of account data: your sign-up details, billing records, how you use the Service, support conversations, website visitor data and referral data.
  • We are a processor (or “service provider” under US state laws) for Customer Data, including the lead and contact data that customers import or collect through Hollerly, the messages sent to those people and the replies they send. We process it only on the customer’s instructions, under the Data Processing Addendum.
  • Our customers are the controllers of their lead and contact data. Each customer decides whom to contact and why, and must have a lawful basis to collect, enrich and contact each person and to give them the notices the law requires.

3. Data we collect

Account and billing data (customers)

  • Name, email address, company, password or sign-in link details, workspace and team membership, roles and preferences.
  • Subscription, plan and invoice records. Paddle collects and processes your payment details as Merchant of Record. We receive your name, email, country, plan and payment status, not your full card number.
  • Support emails and feedback you send us.
  • Referral data, such as the referral code you arrived with and who referred you.

Connected account credentials (customers)

  • For LinkedIn: your LinkedIn session cookie, or your LinkedIn email and password with an optional two-factor key, plus the browser profile and session data the cloud browser needs to stay signed in, and your country, which we use to pick a proxy IP.
  • For email: Google or Microsoft OAuth tokens, or SMTP and IMAP host, username and password.
  • For integrations: API keys or OAuth tokens for HubSpot, Pipedrive, Slack, LinkedIn post scheduling and webhook URLs you add.

Customer Data (processed for customers)

  • Lead and contact data customers import from LinkedIn people searches, Sales Navigator searches, post engagers (commenters and reactors) and CSV uploads: name, headline, job title, company, location, LinkedIn profile URL, public profile details and recent posts, and email address when known.
  • Enrichment results: found or verified email addresses, company details, and public pages of company websites.
  • Messages, connection notes and emails sent; replies received; email opens (when open tracking is on) and unsubscribe events; AI tags, scores, notes, tasks, pipeline stages and meeting records.
  • Activity logs of actions taken for each connected account (visits, invites, messages, likes, follows, endorsements, emails).
  • Do-not-contact list entries (an email address or LinkedIn profile URL).

Usage and device data (visitors and customers)

  • IP address, browser and device type, pages visited, referring page, and timestamps, in server and security logs.
  • Information you type into our free tools, which we use only to give you the result.

4. How we use data and our legal bases

Where the GDPR or UK GDPR applies, we rely on these legal bases for data we control:

  • To provide the Service (create your account, run campaigns, connect your accounts, bill you, give support): performance of our contract with you.
  • To secure the Service (prevent fraud, spam and abuse, enforce our policies, keep logs): our legitimate interests in a safe, lawful service.
  • To improve the Service and produce aggregated, de-identified statistics and research: our legitimate interests. Published research never identifies a customer or prospect.
  • To send service emails (sign-in links, alerts, billing, weekly results): contract and legitimate interests. Product news: legitimate interests or consent where required, and you can opt out at any time.
  • To meet legal duties (tax, accounting, responding to lawful requests): legal obligation.

For Customer Data, we act on our customer’s instructions and the customer chooses the legal basis. We do not use Customer Data for our own marketing, and we do not use one customer’s lead data for another customer.

5. AI processing

  • To write messages, research companies, build ideal customer profiles from a customer’s website, score leads, tag replies and draft answers, we send the relevant data (such as a lead’s profile details, recent posts, company website text, and replies) to our AI providers, Anthropic and OpenAI.
  • We use their business APIs, under terms that do not allow them to train their models on this data. They may keep inputs and outputs for a limited time for abuse monitoring, as set out in their terms.
  • We do not use Customer Data to train AI models.
  • Lead scores and reply tags are suggestions to help customers prioritize. Hollerly does not make decisions that have legal or similarly significant effects on anyone.

6. How we share data

We do not sell personal data. We share it only:

  • with the subprocessors listed below, who help us run the Service under written contracts;
  • with platforms you connect and where you act through Hollerly: for example, LinkedIn receives the actions taken through your account, your mailbox provider sends your emails, and recipients see what you send;
  • with integrations you turn on (HubSpot, Pipedrive, Slack, Zapier, Make, Calendly, Cal.com, webhooks, API and MCP clients), which receive the data you send them under their own terms;
  • through Agency client report links: anyone with a report’s tokenized link can view it, so share these links only with the intended client, and revoke them when no longer needed;
  • with your workspace team members, according to their roles;
  • with advisers, authorities or others when the law requires it, or to protect rights, safety and the Service, and with a buyer or successor in a merger, acquisition or sale of assets, subject to this policy.

7. Subprocessors

We use these service providers to process personal data. We will update this list before adding or replacing a subprocessor.

NamePurposeLocation
SupabaseDatabase, file storage and sign-inUnited States (Oregon)
VercelWebsite and app hostingUnited States, global edge network
Fly.ioCloud workers that run LinkedIn browser sessions and send emailUnited States
IPRoyalDedicated proxy IP address for each LinkedIn accountExit IP in the account owner’s country
AnthropicAI (Claude) for writing, research, scoring and reply taggingUnited States
OpenAIAI models for writing and analysisUnited States
Hunter.ioEmail finding, verification and company enrichmentEuropean Union (France)
ResendTransactional email (sign-in links, alerts, weekly results)United States
PaddlePayments, subscriptions, tax and invoicing (Merchant of Record)United Kingdom, United States
GoogleGmail API, when a customer connects GmailUnited States, global
MicrosoftMicrosoft Graph mail API, when a customer connects OutlookUnited States, global

Integrations you choose to connect, such as HubSpot, Pipedrive and Slack, are not our subprocessors. They act for you under your own agreements with them.

8. International transfers

We and several subprocessors are based in, or process data in, the United States and other countries outside the European Economic Area and the United Kingdom. When we transfer personal data from the EEA, the UK or Switzerland, we rely on an adequacy decision (including the EU-US Data Privacy Framework where the recipient is certified), or on the European Commission’s Standard Contractual Clauses with the UK International Data Transfer Addendum, together with additional safeguards such as encryption. You can ask us for a copy of the relevant safeguards at hello@hollerlyai.com.

9. Retention

  • LinkedIn and mailbox credentials are deleted when you disconnect the account, and in any case when your Hollerly account is closed.
  • Account and Customer Data are kept while your account is active. Customers can delete leads, campaigns and messages at any time. After an account is closed, we delete or anonymize its data within 30 days, and it is removed from backups within a further 90 days.
  • Do-not-contact entries are kept for as long as the customer’s workspace exists, because deleting them would allow the person to be contacted again.
  • Billing and tax records are kept for as long as tax and accounting laws require, usually 6 to 10 years.
  • Server and security logs are kept for up to 12 months, unless needed longer to investigate abuse.

10. Security

  • LinkedIn credentials, session cookies, mailbox tokens and SMTP passwords are encrypted with AES-256 before they are stored in our database.
  • Those credentials are used only by the cloud browser and mail sender dedicated to your account.
  • Each LinkedIn account runs in its own isolated browser profile with its own proxy IP.
  • Data is encrypted in transit with TLS. Database access is restricted by row-level security and least-privilege service keys.
  • Unsubscribe and client report links use long random tokens.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the authorities as the law requires. Please report security issues to hello@hollerlyai.com.

11. Your privacy rights

EEA, UK and Swiss residents (GDPR and UK GDPR)

You have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent at any time where we rely on it. You can object at any time to processing for direct marketing. You also have the right to complain to your local data protection authority, such as the UK Information Commissioner’s Office, although we would like the chance to help first.

California and other US states (CCPA/CPRA and similar laws)

  • You have the right to know what personal information we collect, use and disclose; to access, correct and delete it; and to not be discriminated against for using these rights.
  • We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We do not use or disclose sensitive personal information for purposes that would give you a right to limit it.
  • The categories we collect are listed in section 3 (identifiers, commercial information, internet activity, professional information and inferences such as lead scores), for the purposes in section 4, from the sources in section 3, and disclosed to the recipients in sections 6 and 7.
  • You may use an authorized agent. We may need to verify your identity, and your agent’s authority, before acting on a request.

How to exercise your rights

Email hello@hollerlyai.com from the address linked to your request. We respond within one month (GDPR) or 45 days (CCPA), and may extend this where the law allows. If your request is about lead data that a Hollerly customer holds, we will pass it to that customer, who is the controller, and help them respond. We may also act on it directly where the law allows, for example by adding you to the customer’s do-not-contact list.

12. If you were contacted through Hollerly

If you received a LinkedIn message, connection request or email from someone using Hollerly, that person or their company is the controller of your data, and you can contact them directly. Hollerly processes your data for them. You can stop further contact in any of these ways:

  • Use the unsubscribe link in the email. It goes to a page at hollerlyai.com/u/ followed by a unique code. Confirm on that page and the sender will stop contacting you on every channel, by email and on LinkedIn. Email clients that support the List-Unsubscribe header also show a one-click unsubscribe button.
  • Reply to the message or email and ask the sender to stop. Any reply stops the automated sequence.
  • Email us at hello@hollerlyai.com with your email address or LinkedIn profile URL and, if you can, the name of the sender. We will add you to that customer’s do-not-contact list and pass on any other request to them.

Once you are on a customer’s do-not-contact list, Hollerly skips you when they import leads or run campaigns, and blocks further messages to you from that workspace. The list is honored automatically and is not removed when campaigns end.

Where your data came from: customers add people from LinkedIn searches, Sales Navigator, post engagement or their own CSV files, and may find a work email address through our enrichment provider. To report misuse, see our Acceptable Use Policy.

13. Cookies

We only use cookies that are needed to run the site and the Service. We do not use advertising or cross-site tracking cookies.

  • Sign-in cookies (set by Supabase Auth) keep you signed in securely.
  • Workspace cookie (hl_ws) remembers which team workspace you are working in. It lasts up to one year.
  • Security cookies (hollerly_oauth_state, hl_li_state) protect the Gmail, Outlook and LinkedIn connection steps. They last 10 minutes.
  • Referral cookie (hl_ref) remembers a referral code you arrived with so the referrer is credited at sign-up.
  • Checkout: Paddle may set its own cookies when you open the checkout, under Paddle’s policy.

You can block or delete cookies in your browser settings, but sign-in will not work without the essential ones. Email open tracking uses a small image (a pixel) in emails only when the sending customer turns it on. Many email apps let you block remote images.

14. Children

Hollerly is a business tool for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, email hello@hollerlyai.com and we will delete it.

15. Data Processing Addendum (for customers)

This addendum (“DPA”) forms part of the Terms of Service between Suff Digital and each customer. It applies when we process personal data in Customer Data for the customer under the GDPR, UK GDPR, Swiss law, CCPA/CPRA or similar laws.

  • Roles and instructions. The customer is the controller (or business) and we are the processor (or service provider). We process Customer Data only on the customer’s documented instructions, which are the Terms, the customer’s settings and use of the Service. We will tell the customer if we believe an instruction breaks the law.
  • Details of processing. Subject matter and purpose: providing the Service. Duration: the term of the subscription plus the deletion period in section 9. Data subjects: the customer’s prospects, contacts and users. Data: as listed in section 3. No special categories of data are intended to be processed.
  • Customer duties. The customer is responsible for having a lawful basis and giving notices to data subjects, and for the lawfulness of its instructions.
  • Confidentiality. Everyone we authorize to process Customer Data is bound by confidentiality.
  • Security. We maintain the technical and organizational measures in section 10.
  • Subprocessors. The customer gives general authorization to the subprocessors in section 7. We will update that list at least 14 days before adding or replacing one. The customer may object on reasonable data protection grounds by emailing us, and if we cannot address the objection, may cancel the affected Service. We impose data protection terms on each subprocessor that are no less protective than this DPA, and remain responsible for them.
  • Data subject requests. We will help the customer respond to requests, including through the Service’s features such as deletion and the do-not-contact list, and will pass on requests we receive.
  • Breaches. We will notify the customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Data, with the information the customer reasonably needs to meet its own obligations.
  • Assistance. We will give reasonable help with data protection impact assessments and consultations with authorities, to the extent they relate to our processing.
  • Deletion. At the end of the Service, we delete Customer Data as described in section 9, unless the law requires us to keep it.
  • Audits. We will make available information reasonably needed to show compliance with this DPA, including answering security questionnaires once a year. On-site audits require reasonable notice, are at the customer’s cost, and are limited to once a year unless required by an authority or after a breach.
  • Transfers. For transfers of Customer Data from the EEA, the Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller to processor), are incorporated by reference, with the customer as data exporter and us as data importer, the optional docking clause and clause 9(a) option 2 (general authorization) selected, clause 11 optional language omitted, and clauses 17 and 18 governed by the law and courts of Ireland. For the UK, the UK International Data Transfer Addendum applies, and for Switzerland the Clauses apply with the necessary adjustments. Annex I is completed by this DPA and Annex II by section 10.
  • US state laws. As a service provider, we will not sell or share Customer Data, retain, use or disclose it for any purpose other than providing the Service, or combine it with other data except as the law allows. We will comply with applicable obligations and notify the customer if we can no longer meet them.
  • Liability and precedence. The limitation of liability in the Terms applies to this DPA. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data, and the Standard Contractual Clauses prevail over both.

16. Changes to this policy

We may update this policy. If we make material changes, we will tell customers by email or in the dashboard before they take effect. The “Last updated” date at the top shows the current version.

17. Contact

Hollerly, operated by Suff Digital. Email hello@hollerlyai.com.