Privacy Policy
How Exacta, Inc. collects, uses, discloses, and otherwise processes personal information.
Effective Date: July 30, 2026
Exacta, Inc. (“Exacta,” “we,” “our,” or “us”) provides an artificial intelligence-powered email sales agent and related software, integrations, websites, and services, collectively referred to as the “Services.”
This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information when you visit our website, request a demonstration, communicate with us, use the Services, or receive a communication sent through the Services.
This Privacy Policy applies to:
- Visitors to our website;
- Prospective and current customers;
- Authorized users of customer accounts;
- Business contacts and prospects whose information is processed through the Services; and
- Other individuals who communicate with Exacta.
When Exacta processes information on behalf of a business customer, that customer generally determines why and how the information is processed. In those circumstances, Exacta acts as a service provider or processor to the customer, and the customer’s privacy policy and agreement with Exacta also apply.
1. Information We Collect
The information we collect depends on how you interact with Exacta and how our customers configure and use the Services.
A. Information You Provide Directly to Exacta
We may collect information you provide to us, including:
- Contact and account information. This may include your name, work email address, telephone number, job title, employer, account credentials, and similar business contact information.
- Demo and sales information. When you request a demonstration, submit a website form, communicate with our AI sales agent, or speak with our sales team, we may collect the information you submit, your responses, your interests, your business needs, and information about your organization.
- Customer configuration information. Customers and authorized users may provide instructions, prompts, sales playbooks, messaging guidelines, pricing rules, approval requirements, escalation procedures, contact lists, and other information used to configure the Services.
- Communications. We collect information contained in emails, support requests, meeting notes, feedback, and other communications you send to us.
- Payment and transaction information. When a customer purchases the Services, our payment processors may collect payment card, banking, billing, and transaction information. Exacta may receive limited transaction details, but we generally do not directly store complete payment card information.
B. Customer Data Processed Through the Services
Our customers may provide information to Exacta or connect third-party accounts and systems to the Services. Depending on the customer’s configuration, this information may include:
- Names, work email addresses, telephone numbers, job titles, professional profiles, and other business contact information;
- Company, industry, location, employee-count, financing, technology, and other firmographic information;
- Customer relationship management records;
- Account, lead, opportunity, and pipeline information;
- Email messages, replies, threads, signatures, attachments, and associated metadata;
- Calendar information, meeting availability, and meeting details;
- Website-form submissions and inbound inquiries;
- Product, pricing, purchasing, contract, and negotiation information;
- Sales notes, call summaries, prior interactions, and communication history;
- Customer-created documents, knowledge materials, and sales collateral;
- Customer-defined instructions, prompts, guardrails, workflows, and escalation rules; and
- Information generated through the operation of the Services, including email drafts, responses, summaries, classifications, recommendations, and CRM updates.
We refer to information processed through the Services on behalf of a customer as “Customer Data.”
Customers are responsible for determining what Customer Data they provide to Exacta, ensuring that they have an appropriate legal basis to process that information, and configuring the Services in accordance with applicable laws and their own privacy commitments.
C. Information From Integrations
Customers may connect the Services with email providers, customer relationship management systems, calendars, data providers, document systems, electronic-signature services, and other third-party products.
When an integration is enabled, we may receive information from and send information to the connected service as directed by the customer or authorized user. The information received depends on the integration, the permissions granted, and the customer’s configuration.
Third-party services process information according to their own terms and privacy policies.
D. Information From Public and Third-Party Sources
We may obtain professional and business-related information from:
- Publicly available websites and professional profiles;
- Company websites;
- Government and public records;
- Business-data and enrichment providers;
- Customer relationship management and marketing platforms;
- Event, webinar, or conference organizers;
- Referral partners; and
- Customers and their authorized users.
This information may include business contact information, job information, company information, and publicly available professional activity.
E. Information Collected Automatically
When you visit our website or use the Services, we and our service providers may automatically collect:
- Device information. This may include your IP address, browser type, operating system, device identifiers, device type, and language settings.
- Usage information. This may include pages viewed, links clicked, features used, dates and times of activity, referring pages, session information, and interactions with the Services.
- Log and security information. We may collect authentication activity, system events, error reports, audit logs, and information used to detect and respond to security events.
- Email engagement information. Where permitted, we may collect information about whether an email sent through the Services was delivered, opened, clicked, replied to, or rejected.
F. Cookies and Similar Technologies
We and our service providers use cookies, pixels, local storage, and similar technologies to operate our website and Services, remember preferences, understand usage, measure performance, secure accounts, and manage customer relationships.
We use HubSpot for website analytics and customer relationship management. HubSpot may place cookies, including cookies such as hubspotutk, on your browser. When you submit a form, information you provide may be associated with the applicable cookie, your IP address, referral information, and pages you viewed.
You can control cookies through your browser settings. Disabling cookies may prevent certain portions of the website or Services from functioning properly.
We do not currently respond to browser-based “Do Not Track” signals. Where required, we will recognize legally valid opt-out preference signals.
2. How We Use Information
We may use personal information to:
Provide and Operate the Services
- Create and administer accounts;
- Authenticate users;
- Connect customer-authorized integrations;
- Process Customer Data according to customer instructions;
- Generate, personalize, schedule, and send communications;
- Analyze and categorize incoming responses;
- Summarize conversations and account activity;
- Recommend or initiate follow-up actions;
- Route conversations to the appropriate person;
- Update customer systems and records;
- Schedule meetings;
- Apply customer-defined sales, pricing, negotiation, and approval rules; and
- Provide support, implementation, and account-management services.
Power AI-Assisted Features
The Services use artificial intelligence and machine-learning technologies to analyze information, generate content, identify patterns, recommend actions, and automate portions of sales communications and workflows. This may include using information to:
- Research and understand companies and business contacts;
- Review prior communications and CRM history;
- Generate personalized email content;
- Interpret inquiries and replies;
- Identify interest, intent, objections, and requested next steps;
- Select or recommend follow-up timing;
- Answer questions using customer-provided materials;
- Operate within customer-configured pricing and negotiation guardrails;
- Identify unusual, sensitive, or higher-risk situations for human review; and
- Evaluate and improve the performance, reliability, and safety of the Services.
Communications sent through Exacta may be created, selected, or sent automatically by an AI-powered agent. Customers control the agent’s configuration, instructions, authorized data sources, recipients, and applicable approval or escalation requirements.
Unless otherwise agreed in writing with a customer, Exacta does not use Customer Data to train generalized artificial intelligence models for use by other customers. We may use aggregated or de-identified information that cannot reasonably be associated with an individual or customer to analyze and improve the Services.
Communicate With You
- Respond to inquiries and support requests;
- Provide demonstrations;
- Send account, security, service, and administrative communications;
- Provide product updates;
- Send promotional communications;
- Conduct surveys;
- Request feedback; and
- Communicate about our business relationship.
Improve and Develop Exacta
- Understand how the Services are used;
- Monitor performance and reliability;
- Troubleshoot problems;
- Test features;
- Improve AI outputs and workflow performance;
- Develop new products and services;
- Conduct analytics and research; and
- Generate aggregated or de-identified insights.
Protect Exacta, Customers, and Others
- Prevent fraud, spam, abuse, and unauthorized access;
- Detect and investigate security incidents;
- Enforce our agreements and policies;
- Protect our rights, property, personnel, customers, and others;
- Maintain audit and security records; and
- Comply with legal obligations.
Business and Administrative Purposes
We may use information for billing, accounting, tax, auditing, corporate governance, insurance, financing, due diligence, and other internal business purposes.
3. How We Disclose Information
We may disclose personal information in the following circumstances.
A. Service Providers and Subprocessors
We may disclose information to vendors and service providers that perform services for us, including:
- Cloud hosting and infrastructure;
- Artificial intelligence and language-model services;
- Email infrastructure and delivery;
- Customer relationship management;
- Authentication and identity management;
- Security and fraud prevention;
- Monitoring, logging, and error detection;
- Customer support;
- Analytics;
- Payment processing;
- Document and electronic-signature services;
- Professional services; and
- Other services needed to operate Exacta.
These providers are authorized to process information only for the purposes of providing services to Exacta, subject to their agreements with us.
Enterprise customers may request information about our material subprocessors by contacting us at privacy@getexacta.ai.
B. Customers and Authorized Users
Information processed through a customer account may be available to that customer, its administrators, and its authorized users.
For example, a customer may receive access to emails, replies, summaries, contact records, activity history, meeting information, and other information generated or processed through its use of Exacta.
C. Customer-Directed Integrations
We disclose information to third-party services when a customer or authorized user enables an integration or directs us to transfer information to that service.
D. Business Contacts and Communication Recipients
The Services disclose information to recipients of emails and other communications as directed by our customers. This may include the identity and contact information of the customer, its representatives, and the individual or agent sending the communication.
E. Professional Advisers
We may disclose information to lawyers, accountants, auditors, insurers, financial institutions, investors, and other professional advisers where reasonably necessary for their services.
F. Legal Requirements and Protection of Rights
We may access, preserve, and disclose information when we reasonably believe doing so is necessary to:
- Comply with applicable law, regulation, legal process, or governmental request;
- Enforce our agreements;
- Investigate potential violations;
- Detect, prevent, or address fraud, security, or technical issues;
- Protect the rights, property, safety, and security of Exacta, our customers, users, or others; or
- Establish, exercise, or defend legal claims.
G. Business Transactions
Information may be disclosed or transferred in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, due diligence process, or similar corporate transaction.
H. With Your Direction or Consent
We may disclose information when you direct us to do so, authorize the disclosure, or otherwise consent.
I. Aggregated or De-Identified Information
We may disclose information that has been aggregated or de-identified so that it cannot reasonably be used to identify an individual or customer.
4. Our Role When Processing Customer Data
When Exacta processes Customer Data on behalf of a customer, the customer generally acts as the controller or business, and Exacta generally acts as the processor or service provider.
Exacta processes Customer Data:
- To provide the Services;
- According to the customer’s instructions;
- As described in the customer’s agreement with Exacta;
- As necessary to protect the security and integrity of the Services; and
- As required by applicable law.
The customer determines matters such as:
- Which systems and data sources are connected;
- Which contacts may be processed;
- Which recipients may be contacted;
- The purposes of the communications;
- The content, tone, timing, and frequency of communications;
- Applicable approval and escalation requirements; and
- How long Customer Data should be retained, subject to the customer’s agreement with Exacta.
When we receive a privacy request concerning Customer Data, we may direct the requester to the relevant customer. We will assist customers with responding to requests as required by our agreement and applicable law.
5. Automated Processing
Exacta uses automated systems to analyze information, generate communications, classify responses, prioritize follow-up activity, and perform other customer-configured sales functions.
AI-generated outputs may be incomplete, inaccurate, or inappropriate in some circumstances. Customers are responsible for establishing appropriate instructions, permissions, approval requirements, escalation procedures, and human oversight for their use of the Services.
Exacta does not use personal information on its own behalf to make decisions that produce legal or similarly significant effects concerning an individual, such as decisions regarding employment, credit, housing, insurance, education, or access to essential services.
Customers may not configure or use the Services to make such decisions unless expressly permitted under their agreement with Exacta and allowed by applicable law.
6. Marketing and Sales Communications
We may send promotional communications to prospective and current customers.
Customers may also use the Services to send business and commercial communications. Customers are responsible for ensuring that their communications comply with applicable marketing, advertising, privacy, and electronic-communications laws.
You may opt out of promotional emails sent by Exacta or through Exacta by:
- Clicking the unsubscribe link in the email;
- Replying to the email and asking the sender to stop;
- Contacting the customer identified in the communication; or
- Emailing privacy@getexacta.ai.
We may maintain limited information about an opt-out request, such as an email address on a suppression list, to ensure that the request continues to be honored. Opting out of promotional communications will not prevent us from sending necessary transactional, security, legal, or account-related communications.
7. Sale, Sharing, and Targeted Advertising
Exacta does not sell personal information for monetary consideration.
We do not currently use personal information for cross-context behavioral advertising or targeted advertising based on activity across unaffiliated websites and services.
We may disclose personal information to service providers and subprocessors for the business purposes described in this Privacy Policy. Such disclosures are not intended to constitute a sale of personal information.
Should our practices change, we will update this Privacy Policy and provide legally required choices before using personal information for those purposes.
8. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy. The applicable retention period depends on factors including:
- The nature and sensitivity of the information;
- The purposes for which it was collected;
- The duration of the customer relationship;
- Customer instructions and contractual requirements;
- Security and fraud-prevention needs;
- Legal, accounting, tax, and regulatory obligations;
- Applicable limitation periods; and
- The need to establish, exercise, or defend legal claims.
Customer Data is retained according to the applicable customer agreement, the customer’s configuration, and Exacta’s deletion procedures.
When Customer Data is deleted from active systems, copies may remain temporarily in encrypted backups, security records, or other systems designed to prevent accidental loss. Such information will be isolated from ordinary use and deleted or overwritten according to our backup-retention practices, unless continued retention is legally required.
We may retain de-identified or aggregated information for longer periods. We may retain suppression records for as long as necessary to honor email opt-out requests.
9. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards may include:
- Access controls;
- Authentication protections;
- Encryption in transit and, where applicable, at rest;
- Logging and monitoring;
- Vendor review;
- Employee confidentiality obligations;
- Security testing;
- Incident-response procedures; and
- Data-minimization practices.
No method of transmission or storage is completely secure. We cannot guarantee that information will never be accessed, used, or disclosed without authorization.
Customers are responsible for protecting their account credentials, managing user access, and configuring the Services appropriately.
10. Sensitive Information
The Services are designed primarily for business sales communications and are not intended for the processing of highly sensitive personal information.
Customers and users should not provide sensitive information — such as government identification numbers, financial account credentials, medical information, biometric information, precise location information, information about children, or other legally protected sensitive information — unless that processing is specifically authorized by Exacta, necessary for an approved use of the Services, and permitted by applicable law.
11. Your Privacy Rights
Depending on where you live and subject to applicable exceptions, you may have the right to:
- Request access to personal information we maintain about you;
- Confirm whether we process your personal information;
- Request correction of inaccurate personal information;
- Request deletion of personal information;
- Obtain a portable copy of certain personal information;
- Object to or restrict certain processing;
- Opt out of the sale of personal information;
- Opt out of targeted advertising;
- Opt out of certain profiling or automated decision-making;
- Withdraw consent where processing is based on consent;
- Appeal a decision concerning a privacy request; and
- Receive equal service without unlawful discrimination for exercising your rights.
You may submit a request by emailing privacy@getexacta.ai.
Please describe your request and provide sufficient information for us to identify the relevant records. We may need to verify your identity before fulfilling a request. We will use information provided for verification only to process and respond to the request.
Where permitted, you may authorize an agent to submit a request on your behalf. We may require evidence of the agent’s authority and may need to verify your identity directly.
Certain information may be exempt from a request, including information we must retain for legal, security, fraud-prevention, or contractual reasons.
Requests Concerning a Customer’s Data
When Exacta processes your information on behalf of a customer, the customer is generally responsible for responding to your privacy request.
Please contact the organization that collected your information or initiated the communication. You may also contact us at privacy@getexacta.ai, and we will direct or assist with the request where appropriate.
Appeals
If applicable law provides a right to appeal and we deny your privacy request, you may appeal by emailing privacy@getexacta.ai with the subject line “Privacy Request Appeal.”
12. International Data Transfers
Exacta is based in the United States, and we and our service providers may process information in the United States and other countries.
These countries may have data-protection laws that differ from those in your jurisdiction. Where required, we use appropriate safeguards for international transfers, which may include contractual protections or other legally recognized transfer mechanisms.
Customers should not use the Services to contact individuals in jurisdictions in which the customer’s use has not been approved or configured to comply with applicable privacy and electronic-communications requirements.
13. Third-Party Services and Links
The Services may contain links to third-party websites or allow customers to connect third-party products.
Exacta is not responsible for the privacy, security, or data-handling practices of third parties. We encourage you to review the privacy policies of third-party services before providing information or enabling an integration.
14. Children’s Privacy
The Services are intended for businesses and individuals who are at least 18 years old.
We do not knowingly collect personal information from anyone under 18. If you believe that a child has provided personal information to us, please contact us at privacy@getexacta.ai so that we can take appropriate action.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to the Services, our information practices, or applicable legal requirements.
When we make changes, we will update the effective date at the top of this Privacy Policy. If changes are material, we may provide additional notice through the Services, by email, or through another appropriate method.
Your continued use of the Services after an updated Privacy Policy becomes effective is subject to the updated policy.
16. Contact Us
Questions or requests regarding this Privacy Policy or Exacta’s privacy practices may be directed to:
Exacta, Inc.
251 Little Falls Drive
Wilmington, New Castle County, Delaware 19808
United States
Email: privacy@getexacta.ai