CRM Software for Economic Development Organizations
+1 (805) 967-1280 | email: sales@outreachsystems.com

Privacy Policy

Introduction

This Privacy Policy explains how OutreachSystems.com ("we," "our," or "us") collects, uses, stores, discloses, and protects information through the Neoserra CRM and eCenter Direct client portal and related services (collectively, the "Service"). The Service is provided primarily to organizations that use it to manage relationships, programs, clients, projects, events, and related business activities. In most cases, our customers determine what personal information is entered into the Service and how that information is used. In those circumstances, the customer acts as the data controller or business, and we act as its data processor or service provider.

Information We Process for Customers

Our customers determine the information entered into the Service. Depending on how a customer configures and uses the Service, this information may include:

  • Names and contact information
  • Business affiliations and job titles
  • Postal addresses, email addresses, and telephone numbers
  • Program participation and service history
  • Appointments, events, and registrations
  • Notes, correspondence, and customer relationship history
  • Documents uploaded by authorized users
  • Other information entered or imported by the customer

We process this information to provide, maintain, secure, support, and improve the Service in accordance with our agreements with customers.

Information Collected Automatically

When users access the Service, we may automatically collect technical and operational information, including:

  • IP address
  • Browser type and version
  • Operating system and device information
  • Date and time of access
  • Authentication and security events
  • Pages, features, or records accessed
  • Diagnostic, performance, and error logs

We use this information to operate the Service, authenticate users, maintain audit records, investigate security events, troubleshoot technical issues, and improve reliability and performance.

How We Use Information

We use information as reasonably necessary to:

  • Provide and administer the CRM Service
  • Authenticate users and manage access
  • Store, retrieve, organize, and report customer data
  • Deliver customer-requested communications and integrations
  • Provide customer support, maintenance, and troubleshooting
  • Monitor availability, performance, and security
  • Prevent fraud, misuse, and unauthorized access
  • Comply with applicable legal and contractual obligations

We do not sell customer data or personal information. We do not use customer data for third-party advertising.

Customer Responsibility

Our customers generally determine:

  • What personal information is collected or entered into the Service
  • The purposes for which that information is used
  • Who is authorized to access the information
  • How long the information is retained
  • The legal basis or authorization for processing the information

Individuals who believe that a customer has stored their personal information in the Service should normally direct requests for access, correction, deletion, restriction, or other privacy rights to that customer.

Customer Data Ownership and Access

As between us and the customer, the customer retains all right, title, and interest in the data that the customer or its authorized users enter, upload, import, or otherwise submit to the Service. We do not claim ownership of customer data. We access customer data only as reasonably necessary to provide, maintain, secure, and support the Service; to investigate technical or security issues; as authorized or directed by the customer; or as required by applicable law. Our personnel are permitted to access customer data only when such access is appropriate for their job responsibilities and subject to applicable confidentiality and security obligations.

Sharing of Information

We do not sell, rent, or disclose customer information for third-party marketing purposes. We may disclose information to trusted third-party service providers that assist us in operating, securing, supporting, or delivering the Service. These providers may process information only to the extent reasonably necessary to perform services on our behalf and are subject to contractual, legal, or professional obligations to protect the information they receive.

Depending on the services enabled for a customer, these providers may include:

  • Cloud hosting and infrastructure providers
  • Email delivery providers
  • SMS or messaging providers
  • Backup, monitoring, logging, and security providers
  • Customer-authorized integration providers

We may also disclose information:

  • At the direction or with the authorization of the customer
  • When required by applicable law, regulation, subpoena, court order, or legal process
  • To protect the rights, safety, security, or property of our customers, users, company, or the public
  • In connection with a merger, acquisition, financing, reorganization, or sale of all or substantially all of our business or assets, subject to applicable confidentiality and legal requirements

Data Storage and Hosting

Customer data is hosted using infrastructure provided by Amazon Web Services (“AWS”). Hosting locations and any customer-specific data residency commitments are governed by the applicable customer agreement. We use reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, and destruction.

Security

Our safeguards may include:

  • Encryption of data in transit using TLS
  • Role-based access controls and authentication controls
  • Network security controls
  • System logging and monitoring
  • Security updates and vulnerability management
  • Backup and recovery procedures
  • Administrative access controls and confidentiality obligations

No method of electronic transmission or storage is completely secure. Although we use reasonable safeguards, we cannot guarantee absolute security.

International Data Transfers

Information may be processed in the countries or regions in which we and our service providers operate. Where required, we use appropriate contractual, organizational, and technical safeguards to support lawful international transfers of personal information.

Data Retention

We retain customer data for as long as necessary to provide the Service and as directed by the customer, subject to the applicable customer agreement and legal requirements. Following termination of service, customer data will be returned, retained, or deleted in accordance with the applicable agreement, established retention procedures, and applicable law. Information may remain temporarily in backups or archives until those systems are overwritten in the ordinary course. Security records, system logs, billing records, and similar operational information may be retained for limited periods for security, legal, audit, and business purposes.

Cookies and Similar Technologies

The Service may use cookies or similar technologies that are necessary for authentication, session management, security, user preferences, and system performance. We do not use cookies within the Service to build advertising profiles or deliver third-party behavioral advertising.

Privacy Rights

Depending on applicable law and the circumstances, individuals may have rights to request access to, correction of, deletion of, restriction of, or portability of personal information, or to object to certain processing. Because our customers generally control the personal information entered into the Service, requests relating to customer-controlled data should normally be submitted directly to the organization that collected or entered the information. We will provide reasonable assistance to customers in responding to valid requests as required by applicable law and our customer agreements.

Children's Privacy

The Service is intended for use by organizations and authorized business users. It is not directed to children for their own independent use. Customers are responsible for ensuring that any information concerning minors is collected and processed lawfully.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Contact

You may contact us with questions regarding this Privacy Policy at outreach@outreachsystems.com or in writing at: 5385 Hollister, Suite 104, Santa Barbara, CA 93111. Or by telephone at (805) 967-1280.