Privacy Policy

Your case data never reaches us.
Here is what does.

Outcomer software and the AI model it uses run inside the customer’s own environment. Outcomer does not process the case, claim, complaint or customer records handled there. This policy covers the limited business and account information Outcomer itself holds as controller. Version 1.0, effective 2 September 2026.

Privacy Policy — Version 1.0

Outcomer Limited · Company No. 17323030 · Read with the Terms of Service

OUTCOMER DOES NOT RECEIVE, ACCESS OR STORE THE CASE FILES, CLAIMS OR CUSTOMER RECORDS THAT ORGANISATIONS PROCESS USING OUTCOMER SOFTWARE. THAT DATA STAYS IN THE ORGANISATION'S OWN ENVIRONMENT. THIS POLICY COVERS THE LIMITED BUSINESS AND ACCOUNT INFORMATION OUTCOMER ITSELF HOLDS.

1. Who We Are

Outcomer Limited is a company incorporated in England and Wales (Company No. 17323030) with its registered office at 124–128 City Road, London EC1V 2NX. We provide enterprise case-orientation software that organisations deploy inside their own IT environment. For the personal data described in this policy we are the controller. You can contact us about privacy through the contact form at outcomer.ai/contact, by telephone on +44 20 4577 1442, or by post to the address above. We do not publish an email address on our website.

2. What This Policy Does and Does Not Cover

2.1 Case data belongs to our customers

Under our Terms of Service the software and the AI model it uses both run inside the customer's own environment. Under this customer-controlled deployment, Outcomer does not process the case, claim, complaint, investigation or customer records ("Customer Case Data") on the customer's behalf, because Outcomer does not receive or have access to them. If you are an individual whose information is contained in a file reviewed by an organisation using Outcomer, that organisation is the controller of your data and any request about it should be made to them. We are unable to access it.

2.2 What we do hold

We hold the ordinary business and account information needed to run a software company and its website: details of people who visit our site, enquire, take part in an evaluation, hold a licence seat, approve a configuration, or deal with us as a supplier or adviser. That is what this policy describes.

3. The Personal Data We Collect, Why, and on What Basis

Website visitorsServer logs recording IP address, browser and device type, pages requested and timestamps. Used for security, to keep the site working and to understand which pages are read. Basis: our legitimate interest in operating a secure website. We do not use third-party analytics or advertising cookies.
Campaign linksSome letters and emails we send contain a web address specific to the organisation we sent it to. When that address is visited we record the visit, its time and the pages read, and attribute it to that organisation so we know whether our approach was of interest and when to follow up. This is done on our own server, without cookies, and is not shared with advertising networks. Basis: our legitimate interest in conducting business-to-business outreach. You can ask us not to record this by contacting us.
Enquiries, demo requests and sample-report requestsName, work email address, organisation, role and the content of your message. Used to answer you, send what you asked for and follow up once. Basis: taking steps at your request before entering a contract, and our legitimate interest in responding to business enquiries.
Evaluation and customer contactsBusiness contact details of the sponsor, IT contact, approvers and other personnel named in an Evaluation Plan or Order Form, and correspondence with them. Used to deliver the service and administer the agreement. Basis: performance of a contract with your organisation, and our legitimate interest in managing customer relationships.
Client portal accountsName, work email, role, organisation, login and authentication records, and the pages and actions used. Used to give named people access to their organisation's configuration, specifications and approvals. Basis: performance of a contract with your organisation.
Sign-Off RecordsThe name of the individual who approved a configuration version, the version approved, the date and time, and the rendering they approved. This is the evidence, required by our Terms, that a configuration was approved by an authorised person before use. Basis: performance of a contract, and our and our customer's legitimate interest in an auditable record.
Licence seat recordsThe name or identifier of each Authorised User holding a licence seat and the dates of that holding, as recorded in the Entitlement File. Used to administer seats and confirm compliance with the licence. Basis: performance of a contract.
Billing and supplier recordsContact names on invoices and purchase orders, bank-transfer remittance details for directly invoiced customers, subscription records received from Microsoft or any other agreed marketplace, reseller or payment provider, and correspondence with suppliers and advisers. We do not take card payments and hold no card data. Basis: performance of a contract and our legal obligations to keep accounting records.
Support and correspondenceEmails, messages and call notes with customers, prospects and suppliers. Basis: performance of a contract and our legitimate interest in providing support and keeping a record of what was agreed.

We do not collect special category data in the course of these activities, and we ask that you do not send it to us. We do not carry out automated decision-making about individuals that has legal or similarly significant effects.

4. Who We Share Personal Data with

We share personal data only with providers that help us run the business, each under a written contract limiting what they may do with it:

  • website hosting and content delivery (Vercel);
  • database and application hosting for the client portal and our business records (Supabase, hosted in the European Union, Ireland region);
  • business email and calendar (Google Workspace), and transactional email sent from this website — form acknowledgements and verification links — through Resend (EU region);
  • Microsoft, where the software is purchased through Azure Marketplace: Microsoft acts as merchant of record, bills and collects payment under its own terms and privacy statement, and shares limited purchaser, subscription and usage details with us through Microsoft Partner Center so that we can provision and support the subscription; and any other marketplace, reseller or payment provider through which we agree with a customer that payment will be made, which will handle payment under its own terms and share with us only the details needed to provision and support the subscription;
  • our professional advisers, insurers and, where an escrow arrangement applies, the escrow agent; and
  • regulators, courts or law-enforcement bodies where we are legally required to disclose.

We do not sell personal data, and we do not share it with advertising networks or data brokers.

5. International Transfers

Our business records and the client portal are stored in the European Union. Some of our providers, including website hosting, may process limited technical data (such as server logs) in the United States or other countries. Where personal data leaves the United Kingdom we rely on the UK's adequacy regulations or on the UK International Data Transfer Agreement or Addendum, and we will provide details on request. Customer Case Data is never transferred to us and so is not affected by this section.

6. How Long We Keep Personal Data

Server logs and campaign-link recordsTwelve months, then deleted.
Enquiries that do not lead to an evaluation or contractTwelve months from our last contact with you, then deleted.
Evaluation, portal and licence-seat recordsFor the life of the evaluation or agreement, then twelve months, unless retained as part of a Sign-Off Record.
Sign-Off RecordsSix years after the end of the agreement, because they evidence what was approved and may be needed if a review conducted with the software is later challenged.
Billing and accounting recordsSix years after the end of the financial year to which they relate, as required by UK company and tax law.
CorrespondenceSix years, then reviewed and deleted unless a longer period is needed for a claim.

7. Security

We apply technical and organisational measures appropriate to the data we hold, including access controls limited to named staff, multi-factor authentication for our systems, encryption in transit and at rest, and logging of administrative access. Our software and the customer's model both run inside the customer's environment, so the security of Customer Case Data is governed by the customer's own controls, not ours.

8. Cookies

Our public website sets no cookies. The client portal sets a strictly necessary session cookie so that you stay logged in; it is deleted when you log out or the session expires. We do not use analytics, advertising or tracking cookies.

9. Your Rights

Under UK data protection law you have the right to ask us for a copy of the personal data we hold about you, to have it corrected or deleted, to restrict or object to our processing of it, to receive it in a portable form where we process it under a contract or with your consent, and to withdraw any consent you have given. You may also object at any time to our recording of campaign-link visits or to direct marketing. To exercise any of these rights contact us using the details in section 1. We will respond within one month. You have the right to complain to the Information Commissioner's Office (ico.org.uk) if you are not satisfied with how we handle your data.

If you are outside the United Kingdom, you may have similar rights under the law where you live, including in the European Economic Area and in certain US states. We do not sell personal information. Requests from any jurisdiction may be made using the same contact details.

10. Business Users Only

Our services and website are directed at organisations and professionals acting in the course of business. We do not knowingly collect personal data from consumers or from anyone under 18.

11. Changes to This Policy

We will post any revised version of this policy at outcomer.ai/privacy with a new version number and effective date. Where a change materially affects people whose data we already hold, we will notify the contacts we have for the organisations concerned.

OUTCOMER LIMITED

Company No: 17323030 | Registered Office: 124–128 City Road, London EC1V 2NX

Privacy contact: outcomer.ai/contact, 020 4577 1442, or by post to the registered office

Version 1.0 — Effective 2 September 2026

/mnt/user-data/outputs/Outcomer_Privacy_Policy_v1.0.docx