Privacy Policy

Last updated: August 18, 2026

1. Introduction

Eutexa ("we", "us", "our") operates the Eutexa CRM platform at eutexa.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

2. Information We Collect

Account Information: When you register, we collect your name, email address, and password (hashed).

Workspace Data: Contacts, companies, deals, emails, sequences, workflows, and other CRM data you create within your workspace.

Email Integration Data: When you connect Microsoft 365 (OAuth) or a custom SMTP/IMAP mailbox (including Gmail via an app password), we access email metadata (sender, recipient, subject, date) and message content to provide inbox sync, reply detection, and contact enrichment features. We do not request Gmail API access or any Google email scopes. We store OAuth tokens and IMAP/SMTP credentials in encrypted form.

Calendar Data: When you connect Google Calendar, we access event data to power scheduling features.

Call Data: When you connect a telephony provider (such as Twilio or Exotel) using your own account credentials, we receive and store metadata about calls placed or received through your workspace: the phone numbers involved, direction, timestamps, duration, and outcome status. Where recording is enabled on your provider account, we also store the call recording and may generate a transcript and an AI summary from it. Your provider credentials are stored in encrypted form. Call recordings and transcripts may contain the personal data and the speech of people who are not Eutexa users. You are the controller of that data and are responsible for the notice and consent required to record it, as described in our Terms of Service.

Meeting Data: Where you enable the meeting notetaker, a bot joins the video meeting you scheduled and produces a recording, transcript, and AI summary that are stored in your workspace. Meeting participants are notified by the meeting platform that a participant has joined and that recording is in progress.

Browser Extension Data: If you install and connect the Eutexa browser extension, it reads information from LinkedIn pages you are viewing so it can tell you whether a person is already in your CRM and save them if you ask it to. Section 6 describes exactly what it reads and when.

Usage Data: We collect server logs, IP addresses, browser type, and feature usage analytics to improve the platform.

Payment Information: Billing is processed by Razorpay. We do not store credit card numbers directly.

3. Consent and Legal Basis

Explicit Consent at Signup:When you create a Eutexa account, whether via email registration, Google OAuth, or Microsoft OAuth, you are required to explicitly consent to this Privacy Policy and our Terms of Service by checking the "I agree to the Terms and Privacy Policy" checkbox before proceeding.

What We Record: Upon your consent, we record the following information on our servers:

  • Your consent status (agreedToTerms: true/false)
  • The exact date and time you gave consent (termsAgreementTimestamp)
  • Your authentication method (email, Google, or Microsoft) used at the time of consent

Legal Basis: Your explicit, informed consent serves as the legal basis for processing your personal data under the Digital Personal Data Protection Act, 2023 (India) and applicable data protection regulations. You cannot create an account without providing this consent.

Withdrawal of Consent: You may withdraw your consent at any time by deleting your account from the account settings page or by contacting us at privacy@eutexa.com. Please note that withdrawing consent will result in the termination of your account and deletion of your data as described in the Data Retention section below.

4. How We Use Your Information

  • Provide, maintain, and improve the CRM platform
  • Sync emails and detect replies for your campaigns and sequences
  • Auto-extract contacts from your connected email accounts
  • Send transactional emails (verification, password reset, notifications)
  • Process payments and manage subscriptions
  • Provide AI-powered features (email generation, lead scoring, copilot, call and meeting transcription and summarisation)
  • Log calls and meetings against the contact, company, and deal records in your workspace
  • Monitor and prevent abuse, fraud, and security threats

5. Third-Party Services

We integrate with the following third-party services:

  • Google APIs: Google Calendar and Google Ads (OAuth 2.0). Subject to the Google API Services User Data Policy, including the Limited Use requirements.
  • Google Ads: When a workspace owner or administrator connects Google Ads, we read the advertising accounts that login can reach, and the performance metrics (such as impressions, clicks, cost, and conversions) of the specific accounts they tick, so that advertising results can be reported alongside the pipeline in your CRM. Eutexa is also a place to act on those results, so that routine ad management does not require a second dashboard: at your direction it can pause or enable a campaign and change a campaign budget. We never create campaigns, ad groups, ads, or keywords, and accounts you do not tick are never read or written. Budget increases are bounded by limits you set in your own workspace, both a maximum percentage increase and an absolute ceiling per currency. A budget decrease is never blocked, because that is the moment you are most likely to need it. An increase beyond your limit fails and requires a person to confirm it, the ceiling itself cannot be waived by any confirmation, and AI agents running unattended may read advertising performance but can never spend. Uploading conversions and syncing customer-match audiences are a separate feature behind a separate Google authorisation, described in section 7. Your OAuth tokens are stored in encrypted form and the connection can be revoked at any time.
  • Microsoft Graph / Outlook: Email and calendar access via OAuth 2.0.
  • Notion: When you connect Notion, we access database schemas, page metadata, and page content via OAuth 2.0 to sync meeting notes, retrieve content for your AI Co-Pilot, and execute workflow actions (creating, updating, or querying pages) on your behalf. We store your Notion OAuth tokens in encrypted form, and we do not modify your Notion workspace settings.
  • Slack: When a workspace owner or administrator connects Slack, we receive a bot token for your Slack workspace, stored in encrypted form. We use it to post the messages your Eutexa workflows send, to send direct messages, to add reactions, to upload files you asked a workflow to send, and to create a channel or set its topic when a workflow step asks for it. We read the list of your public channels so you can choose where messages go, and the workspace member directory so a direct message reaches the right person. Message content is read only from channels you have invited the Eutexa bot to, and only to answer a question you asked the AI Co-Pilot; we do not read channels the bot is not a member of, we do not archive or export your Slack history, and Slack content is never used to train any AI model. We request no user token, so Eutexa never acts as you in Slack and never sees the channels you personally belong to. Disconnecting Slack in Eutexa, or removing Eutexa from your Slack workspace, deletes the stored token and ends all access.
  • Meta (WhatsApp Business Platform): When you connect WhatsApp, we access your WhatsApp Business Account to send messages on your behalf via the Meta Cloud API. We store your access token and phone number ID in encrypted form. We do not read or store incoming WhatsApp messages.
  • Telephony providers (Twilio, Exotel): Connected using your own account credentials. Calls are placed on your account and your provider processes the call, including any recording, under its own terms and privacy policy. We store the resulting metadata, recordings, and transcripts in your workspace.
  • Razorpay: Payment processing.
  • Google Cloud (Vertex AI): AI features (email generation, scoring). Your data is not used to train models.
  • Sentry: Error tracking and performance monitoring.

6. Browser Extension

The Eutexa browser extension ("Eutexa for LinkedIn") is optional. It does nothing until you install it and connect it to a workspace using a pairing code generated from your Eutexa settings. Everything below applies only while it is installed and connected.

What it reads.On a LinkedIn page you have opened yourself, it reads the information already displayed on that page: name, profile URL, headline, job title, employer, location, and connection degree, and (on a company page) the organisation's name, industry, size, website, headquarters, and description. It sends the profile URL to Eutexa to answer one question: is this person already one of your contacts?

Email and phone numbers. For a 1st-degree connection, and only at the moment you press Save, the extension opens LinkedIn's own "Contact info" dialog and reads the email address, phone number, and links that LinkedIn displays there to you. It is never read on page load, and never without that click.

Where it goes. Into your own Eutexa workspace, as a contact or company record, attributed to you. Nowhere else. It is the same data, held under the same terms, as anything else in your CRM.

What it does not do:

  • It runs only on linkedin.com. It cannot read any other website, and it does not collect your browsing history.
  • It never navigates LinkedIn on its own, crawls in the background, queues pages, or bulk-exports. It reads only the page in front of you, when you are on it.
  • It never writes to your CRM without you clicking a button.
  • Raw page HTML never leaves your browser. The extension extracts a small, fixed set of fields and sends only those.
  • We do not sell this data, use it for advertising, share it with third parties, or use it to train AI models. It is used solely to provide the feature you installed it for.

What it stores on your device.A device token identifying the connection, and the name of the workspace it is paired with, in your browser's local extension storage. No CRM data is cached on your device.

Turning it off. Disconnect it from the extension itself, or revoke that browser from Settings → Integrations → Browser extension in Eutexa, which takes effect immediately and on every device separately. Uninstalling the extension removes the stored token. Records already saved to your CRM remain yours and are unaffected.

7. Google API Disclosure

Eutexa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We request only the minimum scopes necessary, and each feature asks only for its own: calendar.readonly and calendar.events (read and create calendar events for scheduling and meeting sync), userinfo.email / userinfo.profile (identify your account at sign-in), and adwords (read your advertising accounts and their performance metrics, and, at your direction, pause or enable a campaign and change a campaign budget). Uploading conversions and syncing customer-match audiences use a different scope, datamanager, which is requested separately and only if you turn that feature on.
  • Connecting one feature never grants another. The Google Ads authorisation requests the adwords scope alone and nothing else, and connecting Google Ads gives us no access to your calendar; connecting your calendar gives us no access to your advertising.
  • Google publishes no read-only variant of the adwords scope, so one scope covers both the reporting we do by default and the campaign controls you choose to use. We use it for exactly two things: reading advertising performance, and carrying out the campaign pause, enable, and budget changes that you, or a workflow you configured, asked for. We never create campaigns, ad groups, ads, or keywords, and we never act on an account you did not tick.
  • We only use Google user data to provide and improve CRM features you explicitly enabled (calendar sync, meeting scheduling, advertising performance reporting, and the advertising controls described above).
  • We do not use Google user data to serve or target advertisements, and we do not use it for any advertising purpose of our own. Google Ads performance data is read on your behalf, shown back to you inside your own workspace, and used for nothing else.
  • We do not sell Google user data to third parties.
  • We do not use Google user data to train AI/ML models.
  • Human access to Google user data is limited to investigating bugs or security issues, with your consent, or as required by law.

8. How We Share, Transfer, and Disclose Your Data

We do not sell your personal data, and we do not sell, rent, or trade Google user data. We share, transfer, or disclose data only in the limited circumstances below, and only to the extent necessary:

  • Infrastructure and hosting providers (sub-processors): We store and process all workspace data (including data obtained from Google APIs, such as Google Calendar events) on Google Cloud Platform (application hosting) and MongoDB Atlas (database hosting), and serve the web application through Vercel. These providers process data solely on our behalf under confidentiality and data-processing obligations. The complete current list is published at eutexa.com/subprocessors.
  • AI processing (Google Cloud Vertex AI): Content you explicitly submit to AI features (for example, email drafting and lead scoring) is processed by Vertex AI to return a result. This data is not used to train Google's models, and Google user data is never used to train any AI/ML model.
  • Payment processor (Razorpay): Receives only the billing information needed to process your subscription. It never receives Google user data or your CRM content.
  • Error and performance monitoring (Sentry): Receives diagnostic and log data so we can detect and fix issues. It is configured to exclude message content and credentials.
  • Transactional email delivery: Our email delivery provider receives the recipient address and message needed to send system emails (verification, password reset, notifications).
  • Integrations you connect: When you connect Microsoft 365, Notion, Slack, Meta (WhatsApp), or Google Ads, we transmit only the data required for that integration, and only while it remains connected.
  • Legal and safety: We may disclose data to law enforcement, regulators, or other parties when required by law, court order, or to protect the rights, property, or safety of our users and the public.
  • Business transfers: If Eutexa is involved in a merger, acquisition, or sale of assets, data may be transferred to the successor entity under the same privacy commitments, and we will notify you before your data becomes subject to a different policy.

We do not share Google user data with any third party except the infrastructure sub-processors named above that are required to operate the features you enabled. We never share Google user data for advertising, and we never disclose it to third parties for their own independent use.

9. Data Storage and Security

Your data is stored in MongoDB databases. Sensitive credentials (OAuth tokens, SMTP/IMAP passwords, MCP integration keys) are encrypted using AES-256 at rest. All data in transit is encrypted via TLS. We implement rate limiting, input validation, and role-based access controls to protect your data.

10. Data Retention

We retain your workspace data for as long as your account is active. When you delete your account or workspace, we delete all associated data within 30 days, except where retention is required by law or for legitimate business purposes (e.g. billing records).

11. Your Rights

You have the right to:

  • Access and export your data
  • Correct inaccurate information
  • Delete your account and all associated data
  • Disconnect third-party integrations at any time
  • Revoke OAuth access from your Google or Microsoft account settings
  • Revoke any paired browser extension, individually per device

12. Cookies

We use essential cookies for authentication (JWT session token) and preferences. We do not use third-party advertising cookies or tracking pixels on our platform.

13. Children's Privacy

Eutexa is a business tool and is not directed at children under 16. We do not knowingly collect information from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or in-app notification at least 14 days before they take effect.

15. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: privacy@eutexa.com