Warm.DealsTrust Center →

Privacy Policy

Last updated 2026-10-06

Warm.Deals is B2B sales software. Our customers use it to find business contacts, send outreach, and manage their pipeline. This policy explains what we do with personal data — both the data of the people who use Warm.Deals, and the business contact data our customers store in it.

Warm.Deals is operated by Denha Nexus s.r.o., Pekná cesta 2459/19, 831 52 Bratislava – Rača, Slovakia, company ID (IČO) 56 690 819, registered in the Business Register of the Municipal Court Bratislava III, section Sro, insert no. 184002/B. For account data (the people who log in), Denha Nexus s.r.o. is the data controller. For customers in Ukraine, FOP Denha Anastasiia Valeriivna (ФОП Деньга Анастасія Валеріївна, taxpayer number 3084004406), the seller under the Ukrainian Public Offer, is a joint controller of the account and payment data needed to sell and invoice the subscription. For the lead and contact records a customer stores, the customer is the controller and Warm.Deals is the processor, acting on their documented instructions under our Data Processing Agreement.

Data we collect about account holders

  • Identity: name, work email, job title, phone number, and profile photo if provided.
  • Authentication: a hashed password, two-factor secrets if enabled, and session records including IP address and user agent.
  • Organisation: the workspace you belong to, your role, and your permissions.
  • Usage: pages visited, features used, and audit records of actions that change data.
  • Billing: plan, subscription status, and invoices. Card details are handled by our payment provider and never reach our servers.

Data our customers store about their prospects

Customers collect business contact data — company name, website, business address, publicly listed business email and phone, job title, and public social profile links — from public sources such as business directories, OpenStreetMap, company websites, and optional third-party enrichment providers the customer connects. Customers may also import their own lists and record notes, call outcomes, and message history against a contact.

  • We do not sell this data, and we do not use one customer's data to enrich another's.
  • We do not build a shared people database across customers.
  • Customers are responsible for having a lawful basis for their outreach and for honouring objections.

Why we process it

  • To provide the service: storing records, sending the messages a customer composes, and showing analytics.
  • To keep the service secure: rate limiting, audit logging, fraud and abuse prevention.
  • To support customers: diagnosing problems they report.
  • To meet legal obligations: tax records, and responding to lawful requests.
  • Our lawful bases are performance of a contract, our legitimate interest in operating and securing the service, and consent where required.

AI processing

Warm.Deals uses third-party language models to draft messages, score leads, and summarise conversations. When a customer asks for a draft, the relevant record and conversation context is sent to the model provider to generate it.

  • Providers used: Anthropic, OpenAI, and DeepSeek, depending on the task.
  • We use these providers' API tiers, which do not train their models on submitted content.
  • AI output is a draft. A person reviews and sends it — nothing is delivered to a prospect without a user's action or an automation the customer configured.

AI assistants you connect

You can connect an AI assistant — ChatGPT, Claude, Codex, Cursor, VS Code, Gemini CLI or another MCP client — to Warm.Deals through our MCP server. You sign in on a Warm.Deals page and approve one workspace, with full or read-only access. The assistant then calls Warm.Deals tools on your behalf, within your role in that workspace.

  • What we store: the assistant's registration (its name and the address it returns to), and the connection itself — your account, the workspace, the access level, when it was approved and last used. Access and refresh tokens are stored only as hashes. We receive what the assistant sends in a tool call — a search query, a record to save, a request to draft a message — not the rest of your conversation.
  • What the assistant receives: the results of the tools it calls — the leads, contacts, deals, campaigns, tasks and reports it asks for in that workspace. From then on that data is also handled by the assistant's provider under its own terms and privacy policy, which apply to your use of the assistant.
  • Tool calls are recorded like any other API request made with your account, for security and support.
  • Assistants cannot delete records, manage users, connect mailboxes or change workspace settings.
  • Access tokens last one hour and refresh tokens rotate on every use. Disconnecting an assistant in Settings → API keys & MCP, changing your password, or leaving the workspace ends the connection at once; the record of a revoked connection is kept for security audit.

Google user data: Gmail and Google Calendar

You can connect a Gmail address as a sending mailbox and a Google Calendar for meeting bookings. Both use Google sign-in (OAuth); we never see or store your Google password, and you can disconnect at any time.

  • Gmail (scope gmail.send): used only to send the emails you or your sequences write, from your address, to the recipients you choose. We do not read, search, archive or delete your mail, and we do not use the scope for anything else.
  • Google Calendar (scope calendar.events): used only to create, update and cancel the meeting events booked through Warm.Deals and to show the busy times needed to offer free slots. We do not read other events' content or attendees.
  • What we store: the email address of the connected account, the OAuth access and refresh tokens (encrypted at rest), and the log of messages and events Warm.Deals itself created. Tokens are deleted when you disconnect the mailbox or calendar, remove the workspace, or revoke access at myaccount.google.com/permissions.
  • Google data is never sold, never used for advertising, never used to train AI models, and never shared with third parties except as needed to deliver the email or calendar action you requested, for security, or where the law requires. People who can see it inside Warm.Deals are limited to the members of your workspace and our engineers for support and abuse investigation.
  • Warm.Deals' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing

We share data with the sub-processors listed on our Sub-Processors page, each under a data processing agreement. Optional providers — CRMs, enrichment services, messaging providers — receive data only if the customer connects them. We also disclose data where legally compelled, and to a successor in the event of a merger or acquisition, in which case we will give notice.

International transfers

Our infrastructure runs in Germany. Some sub-processors are in the United States; those transfers rely on Standard Contractual Clauses.

Retention

  • Account data is kept while the account is active and deleted within 90 days of closure, except records we must keep for tax or legal reasons.
  • Customer-controlled data follows the retention periods each workspace sets, with defaults of 365 days for email events, 730 days for audit events, and 180 days for campaign logs.
  • Backups are retained for 30 days and then overwritten.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to it. Warm.Deals provides these in the product: a preference centre for recipients, and export and erasure endpoints for account holders.

  • If a Warm.Deals customer contacted you and you want your data removed, use the unsubscribe or preference link in their message, or write to us and we will route your request to that customer and add you to our suppression list.
  • We respond to requests within 30 days.
  • You may complain to your local data protection authority.

Security

  • Traffic is encrypted with TLS. Credentials for connected mailboxes and integrations are encrypted at rest.
  • Passwords are hashed with bcrypt and never stored or logged in plain text.
  • Access is scoped per organisation; API keys carry only the permissions granted to them.
  • Every change to data is written to an audit log.
  • Our current certification status is published on the Trust Center. Where a certification is in progress, we say so rather than implying it is complete.

Cookies

We use cookies that are necessary for the service: a session refresh cookie, and local storage for your language and interface preferences. We do not use advertising cookies and we do not sell personal information.

Children

Warm.Deals is a business tool and is not directed to anyone under 16.

Changes

If we make a material change we will update the date above and notify account administrators before it takes effect.

Contact

Privacy questions, data requests, and removal requests: privacy@warm.deals.