TRUST & SECURITY

Outbound should be useful without giving up control.

Client approval before anything sends, suppression written the moment it arrives, purposeful data use, human judgement on real conversations, and no claim we cannot show you.

Client control

Nothing is sent until the programme has been prepared and you have approved it.

Suppression by design

An unsubscribe is written to the suppression list at the moment it arrives, not on a later sweep.

Data is not a product

We do not sell, rent or share personal information with any third party for commercial gain.

WHERE YOUR DATA LIVES

Hosting, stated plainly.

Two regions, named. An EU client’s first question is who touches the data, and a US compute tier is exactly what they are asking about — so we say it first.

DatabaseSupabase, eu-west-1 — Dublin, Ireland. Our database provider is SOC 2 Type II audited.
Application serversRailway, US West — United States. Railway operates on SOC 2-audited infrastructure.
BackupsDaily automated database backups, retained for 7 days, held in the same region as the database (Dublin, Ireland).
Cross-border transfersWhere data crosses borders we apply appropriate safeguards. We do not claim paper we have not produced.
CertificationWe are not ISO 27001 certified. It is a roadmap target, and we will say so until it is not.
SUPPRESSION & OPT-OUT

An opt-out is a write, not a queue.

Every programme email carries a working unsubscribe. Clicking it, or replying to ask, does the same thing.

Written on receiptThe unsubscribe link and a reply asking for removal run the identical code path. The blocklist entry is written on the request, not on a nightly job.
Checked before sendSuppression is checked inside the execution flow, before a message goes out — not as a configuration step somebody has to remember.
Permanently retainedOpt-out records are kept permanently. That is the one category we never delete, because deleting it would lose the instruction.
No re-activationA suppressed contact is not returned to a programme.
Removal by emailAnyone can ask directly: privacy@get-kind.com with “Unsubscribe” in the subject.
HOW WE CONTACT PEOPLE

Legitimate interest, and we say which.

Outbound B2B email under GDPR Article 6(1)(f) operates on a legitimate interest basis. That is the basis we use, and it is not the same thing as consent — so we do not describe it as consent.

GDPR (EU and UK)Legitimate interest under Article 6(1)(f). An opt-out is treated as a withdrawal and actioned immediately.
POPIA (South Africa)The outreach sequence model constitutes a legitimate interest basis for initial contact. Opt-outs are honoured immediately and permanently.
CAN-SPAM (United States)Every email carries accurate sender identification, a valid physical postal address and a working unsubscribe that is honoured on receipt.
CCPA / CPRA (California)Right to know, right to delete and right to opt out are honoured. We do not sell personal information, so the opt-out of sale is always active.
Email-onlyWe do not make phone or voice outreach at all.
YOUR RIGHTS

Asking us to stop, or to hand it over.

One address handles all of it — privacy@get-kind.com. We aim to respond within 5 business days and resolve within 30 days.

AccessRequest a copy of the personal data we hold about you.
ErasureRequest deletion. We action deletion within 30 days.
RectificationCorrect anything inaccurate.
PortabilityReceive your data in a machine-readable format.
ObjectionObject to processing carried out on a legitimate-interest basis.
ComplaintThe ICO at ico.org.uk/make-a-complaint, or the Information Regulator at inforegulator.org.za.
TECHNICAL SECURITY

Hardened at each layer.

EncryptionTLS 1.3 in transit. AES-256 at rest. API keys encrypted at rest and never logged. Email credentials vault-stored and not accessible to staff.
Access controlRole-based access on all accounts. Operator actions on client accounts are audit-logged.
Code and dependenciesPrivate repository. Every change is tested before it reaches production.
Incident responseA documented plan: contain within 0–2 hours, assess within 24, notify within 72 hours where required, then recover and review within 7 days. Every incident is logged with root cause and remediation.
Security contacthello@get-kind.com
EMAIL INFRASTRUCTURE

Deliverability is a trust problem too.

Landing in the inbox rather than the spam folder is not a growth trick — it is what stops a programme becoming a nuisance.

Our own sending mailboxesProgrammes send from business mailboxes on our own sending domains, not from a shared pool, so we do not inherit another sender’s reputation problems.
AuthenticationSPF published and validated, DKIM signing on all outbound mail, DMARC policy set to quarantine or reject.
Daily limitsEvery sending mailbox has a daily limit, and sending stops when it is reached.
List hygieneVida validates contact data before sending. Addresses are verified before sending. Hard bounces are removed automatically and catch-all domains are flagged.
No open trackingWe removed the open-tracking pixel from sequence email on 20 August 2026. We do not record whether you opened a message.
COMMITMENTS

What we don’t do.

No scraped listsWe source prospects from Apollo.io, a licensed B2B data provider. We never scrape websites or buy lists from brokers.
No re-use of opt-outsA suppressed contact is not re-activated under a new programme or a new sender identity.
No data sold — everYour programme data, contact records and conversation history are yours. We do not sell, rent or share them.
No indefinite retentionRecords are removed when a client closes their account, or on request. Deletion is actioned within 30 days.
No hidden sub-processorsThe full list is published in our Privacy Policy and our Data Processing Agreement. We do not add one without notifying affected clients.
No cold calls — everMilla & Vida is email-only outreach.
No claim we cannot showNo invented traction, no fake statistics, and no certification we do not hold.
DESIGN BOUNDARIES

What M&V should and should not do.

Prepare the programme contextYes — make the meeting target, audience and programme visible before go-live.
Check suppression before sendYes — suppression and opt-out controls belong inside the execution flow.
Guarantee a sales outcomeNo — meeting targets are targets, not guarantees of meetings, revenue or closed business. If fewer qualified meetings are delivered, the difference is credited against your next programme — once per client, within 90 days.
Expose unrestricted client dataNo — client information is used only for the service and access stays controlled.
Escalate judgement to a humanYes — a reply that needs judgement is answered by a person, not forced through automation.
No mystery automation. The useful workflow is the one that shows what was approved, what is running, what has changed and when a human should take over.
THE PAPER

Everything above is written down.

The Privacy Policy carries the full sub-processor list with locations. The Terms carry the programme, the payment timing and the liability position. A Data Processing Agreement is available for every client.

Read the Privacy PolicyRead the TermsRead the DPA