For security, privacy and legal reviewers

Security at Clossara

Clossara reads your sales emails, calls and CRM. This page states exactly how that data is protected — what is in place today, and what is still in progress. If something here is not specific enough for your review, write to [email protected].

1 · Architecture

Your data stays in your instance. The model only ever sees redacted text.

Clossara data flow Your CRM, mailbox and call records flow into your dedicated Clossara instance, where data is encrypted at rest and redacted. Only redacted text goes over an encrypted tunnel to Clossara's model server, which keeps no data. Nothing goes to third-party AI providers. Your systems CRM Mailboxes (read-only) Call records Your dedicated instance (EU) Application + database originals encrypted at rest Redaction names and addresses → labels only your users, over TLS redacted encrypted Clossara model server operated by Clossara stores nothing · no training Third-party AI providers nothing is sent
2 · Your data

What Clossara reads, where it is kept, and how it is deleted.

DataWhere it comes fromHow it is stored
Deals, accounts, contactsYour CRM (Salesforce or HubSpot), through a connection you authoriseYour instance's database
EmailsMailboxes your users connect (Gmail or Outlook), read-onlyOriginal text encrypted at rest; a redacted working copy is what the model reads
Call recordsYour CRM's activity records, where connectedYour instance's database
DocumentsFiles your users upload (price lists, proposals)Original file encrypted at rest; redacted text used to ground drafts
Connection credentialsCRM, mailbox and optional enrichment connectionsEncrypted at rest, never stored in plain text
3 · Encryption and access

Encrypted at rest and in transit. No standing access by Clossara staff.

4 · Compliance

GDPR, the EU AI Act, the DPA and subprocessors.

Subprocessors

ProviderPurposeData involved
EU cloud hosting providerHosts your dedicated instanceYour instance's data, encrypted as described above. Named in the DPA.
CloudflareThis website and the waitlistWaitlist email addresses only. No product data.
Email delivery providerAccount emails (sign-up verification, team invitations)Your users' email addresses only. Named in the DPA.

Optional integrations you control

ProviderWhenData sent
Apollo, People Data Labs, ZoomInfoOnly if you connect your own account with that provider, to fill in company detailsCompany website domains only — never conversations or contacts' messages

Your CRM and mailbox providers are your own systems, which Clossara reads with your authorisation.

5 · Certifications and testing

What is in place, and what is in progress.

Questions, or something to report?

Security questions, questionnaires, DPA requests and incident reports all go to the same address.