βœ“ Plain-English summary

Under GDPR, Pitch2Retail acts as the data processor for the recipient contact data you upload or build into audiences. You're the controller. We process that data only on your documented instructions, store it in Canada (DigitalOcean Toronto), encrypt it at rest and in transit, and honor data subject rights (access / correction / deletion / portability) within 30 days. We have a Data Processing Agreement available on request β€” see our DPA.

On this page

When does GDPR apply to you?

GDPR applies to your Pitch2Retail outreach if any of the following is true:

GDPR penalties: up to €20M or 4% of global annual turnover, whichever is higher.

If you're a Canadian or US brand pitching to North American buyers only, GDPR doesn't directly apply β€” but PIPEDA (Canada) and CASL still do.

Data controller vs. processor

Data typeControllerProcessor
Your brand profile, products, campaignsYouPitch2Retail
Recipient contact data (audiences)YouPitch2Retail
Pitch content sent to recipientsYouPitch2Retail
Account data (your email, billing)Pitch2Retail(Stripe handles billing)

This means: you decide WHAT to do with the data; we provide the tools to DO it. Both have GDPR obligations.

Lawful basis under Art. 6

For B2B outreach, the most common GDPR lawful bases are:

Pitch2Retail's audience builder and templates are designed to support legitimate interest processing. To rely on this:

  1. Conduct a Legitimate Interest Assessment (LIA) documenting the balancing test
  2. Inform recipients in your privacy policy that you contact business buyers under legitimate interest
  3. Honor opt-outs immediately (we enforce this automatically via the suppression list)
  4. Don't use legitimate interest for special-category data (Art. 9 β€” health, religion, etc.)

Need help with a Legitimate Interest Assessment template? Email hello@pitch2retail.com β€” we provide one for Growth+ customers.

Data subject rights (Arts. 12-22)

Recipients (data subjects) have these rights under GDPR. We support all of them within Pitch2Retail and pass requests directly to you when received:

RightWhat we doTime limit
Access (Art. 15)You can export all data we hold on a recipient via GET /v1/contacts/:id30 days
Rectification (Art. 16)Edit contact data in the Contacts UI30 days
Erasure (Art. 17 β€” "right to be forgotten")Delete contact via UI or DELETE /v1/contacts/:id β€” also adds to suppression list30 days
Restriction (Art. 18)Mark contact as do_not_contact via Settings30 days
Portability (Art. 20)Bulk JSON / CSV export of all your audiences and pitches30 days
Object (Art. 21)Same as restriction + suppression β€” automatic block on future sendsInstant
Automated decision-making (Art. 22)Pitch generation is AI-assisted but always reviewed by you before send β€” no purely automated decisions affecting recipientsN/A

Our sub-processors

Pitch2Retail engages the following sub-processors. All are SOC 2 Type II certified and have appropriate transfer mechanisms (Standard Contractual Clauses) for any data leaving the EU.

Sub-processorPurposeRegionTransfer mechanism
DigitalOceanCloud hostingToronto, CanadaSCCs Β· adequacy (Canada PIPEDA)
AnthropicAI pitch generationUSASCCs (EU 2021/914)
ResendEmail deliveryUSA Β· globalSCCs Β· DPA
Apollo.ioVerified contact databaseUSASCCs Β· DPA
StripePayment processingUSA Β· Ireland (EU)SCCs Β· DPA
NocoDB on private DigitalOceanDatabaseToronto, CanadaAdequacy (Canada PIPEDA)

We notify customers via email at least 14 days before adding a new sub-processor. Customers may object in writing within 14 days; if we can't accommodate, you may terminate the affected service.

International transfers

Customer-uploaded data is stored in Canada (DigitalOcean Toronto). Canada has an EU adequacy decision under PIPEDA β€” meaning EU personal data can be transferred to Canada without additional safeguards beyond our DPA.

For sub-processors in the US (Anthropic, Resend, Apollo, Stripe), transfers rely on:

Breach notification (Arts. 33-34)

If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will:

Data Processing Agreement (DPA)

For Growth+ tier customers, we provide a counter-signed DPA covering all the requirements of GDPR Art. 28 (controller-processor agreements). Key terms:

Read the full template at /dpa.html or request a counter-signed PDF version at hello@pitch2retail.com.

GDPR-ready out of the box.

Start your 14-day trial. Counter-signed DPA available on Growth+ tier.

Start free trial β†’