Privacy Policy

Effective Date: January 1, 2026

This policy explains how BraveOkays ("BraveOkays," "we," "our," or "us") handles personal data. We run done-for-you B2B outbound, so we handle data in two different roles, and it matters which one applies.

1. The two roles we act in

  • As a controller:for our own website visitors, enquiries, prospective clients and clients — the people who contact us or buy from us.
  • As a processor:for the prospects we contact on a client’s behalf during an engagement. In that case the client is the controller, decides who is contacted and why, and we act on their documented instructions under a data processing agreement.

2. Data we collect as a controller

  • Contact and enquiry data: name, work email, company, role, and anything you tell us when you email us or book a call.
  • Booking data: when you book a call, our scheduling provider collects your name, email and chosen time so the meeting can be created.
  • Client and billing data: the contact details, billing information and engagement records needed to deliver and invoice the service. Card details are handled by our payment processor; we do not store full card numbers.
  • Website usage data: IP address, browser and device information, pages viewed and timestamps, collected via cookies and analytics. See our Cookie Policy.

3. Why we use it, and our legal bases

  • To answer enquiries and run booked calls — legitimate interests, or steps taken at your request before a contract.
  • To deliver the service, report on it and invoice you — performance of a contract.
  • To keep the site and our infrastructure secure and to prevent abuse — legitimate interests.
  • To measure how the site is used — consent, where required, via the cookie banner.
  • To meet accounting, tax and other legal obligations — legal obligation.

We do not sell personal data, and we do not use your data to train generalised AI models.

4. Data we handle as a processor during an engagement

To run outbound for a client we process business contact data about people at target companies — typically name, job title, employer, work email, work phone number, public professional profile information, and the record of our correspondence with them. Where we make outbound calls, we may record them, and we obtain consent to record where the relevant jurisdiction requires it.

We use that data only to run the client’s campaigns. We honour opt-out, unsubscribe and do-not-contact requests promptly and permanently, and we suppress those contacts across future campaigns. If you have been contacted by us on behalf of a client and want to know who that client is, be removed, or exercise any other right, email [email protected] and we will handle it and pass the request to the client.

5. Lead Catcher and website visitor identification

Clients may enable Lead Catcher, which identifies the organisations visiting their website using IP-to-company lookup and first-party analytics. It is designed to identify companies, not named individuals, and clients are responsible for disclosing its use in their own privacy notice and for obtaining any consent their jurisdiction requires.

6. Who we share data with

We share data only with service providers who help us deliver the service, under contract and only for that purpose. These fall into a few categories:

  • Hosting, infrastructure and error monitoring.
  • Email sending, domain registration and deliverability tooling.
  • Contact data and verification vendors.
  • Telephony and call recording providers.
  • Scheduling, CRM, analytics and payment providers.

We may also disclose data where legally required, or in connection with a merger or acquisition, in which case we will tell affected clients.

7. International transfers

Our providers may process data outside your country, including in the United States. Where data leaves the UK or EEA, we rely on appropriate safeguards such as the Standard Contractual Clauses or an adequacy decision.

8. How long we keep it

  • Enquiries that do not become engagements: up to 24 months.
  • Client engagement records: for the engagement, then as required for accounting and legal purposes.
  • Campaign data processed for a client: deleted or returned within 60 days of the engagement ending, unless the client asks us to keep it or the law requires otherwise.
  • Suppression and do-not-contact lists: kept indefinitely, because that is the only way to guarantee we do not contact someone again.

9. Security

We use encryption in transit, access controls, least-privilege access for our team, and vetted providers. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant regulator as required by law.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, to withdraw consent, and to complain to your data protection authority. To exercise any of these, email [email protected]. We respond within the period required by law, normally within 30 days, and we will not discriminate against you for exercising a right.

11. Children’s data

Our services are for business use and are not directed at anyone under 18. We do not knowingly collect data from children.

12. Changes

We will post any updates on this page and change the effective date above. If a change materially affects how we handle your data, we will tell affected clients directly.

13. Contact

Privacy questions, requests, or a data processing agreement: [email protected]. See also our Terms of Service and Cookie Policy.

B
braveokays

Done-for-you B2B outbound. We research and qualify before we send, then book meetings on your calendar.

[email protected]

Product

  • How it works
  • Playbook
  • Pricing
  • FAQ

Company

  • Support

Legal

  • Privacy Policy
  • Terms of Service
  • Cookies

© 2026 BraveOkays. All rights reserved.

LinkedIn
B
braveokays
How it worksPlaybookPricingFAQSupport