Legal

Hillwinds, LLC Privacy Statement

Last Modified August 24, 2026

Introduction

Hillwinds, LLC (“Hillwinds,” “we,” “us,” or “our”) respects your privacy and is committed to handling personal information in accordance with this Privacy Statement.

Hillwinds provides business-to-business benefits market intelligence and go-to-market software. Our services include our public websites, web application, data and prospecting features, developer interfaces (including the Hillwinds Intelligence API and webhooks), integrations, and outbound email, sequencing, and inbox features (collectively, the “Services”).

As part of providing the Services, Hillwinds processes personal information about our customers and users, business contacts in our professional datasets, visitors to our websites, and recipients of communications our customers send through the Services.

Our Role

Our role depends on the data and the context in which we process it.

Where we act on our own behalf. For our websites, user accounts, product operations, commercially licensed and publicly sourced professional and company datasets, product analytics, and our own marketing activities, Hillwinds determines the purposes and means of processing and acts as a controller (or, under applicable U.S. state privacy laws, a business).

Where we act on a customer’s behalf. For customer-provided data, connected mailbox content, messages and replies processed through the Outbound Engine, customer-uploaded or customer-built recipient lists, and customer-specific engagement records, Hillwinds generally acts as a processor or service provider on the customer’s instructions. The customer determines who is contacted and what is communicated. If you received a message from a Hillwinds customer and want to exercise rights relating to that customer’s outreach, you should contact the sender; you may also contact us at privacy@hillwinds.ai and we will route the request as appropriate.

Data Security

We are committed to the security of your personal information and have implemented ways to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure.

Unfortunately, the transmission of information via the internet is not completely secure. Although we have implemented measures to protect your personal information, we cannot guarantee the security of your personal information transmitted to the Services. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures deployed on the Services.

Sources of Personal Information

The information described in this Privacy Statement reflects Hillwinds’ practices regarding the collection, use, sale, and sharing of personal information during the twelve (12) months preceding the date this Privacy Statement was last updated.

We obtain personal information from the following sources:

  • Directly from users when you create an account, contact us, configure or use the Services, or otherwise interact with Hillwinds.
  • From our data providers and partners who license or make available professional contact, employment, benefits, and company information.
  • From publicly available sources, such as corporate websites, professional profiles, press releases, and government filings.
  • Automatically when you interact with our websites or Services, through cookies, pixels, local storage, logs, analytics tools, and similar technologies.
  • From activity generated through use of the Services, such as API requests and usage logs and, when customers use the Outbound Engine, information regarding messages sent, bounce status, and reply status.

Customer Content and Connected Accounts

Customers may upload files or enter information into the Services, including CSV files, prospect or recipient lists, notes, prompts, message content, templates, case studies, proof points, brand or voice guidance, and other information provided by the customer (“Customer Content”).

Hillwinds processes and stores Customer Content on behalf of the applicable customer as necessary to provide, maintain, secure, and support the Services. Customer Content is associated with the applicable customer account and is not made available to other Hillwinds customers.

Customers may also choose to connect a business email account to the Services. When a customer connects an email account, Hillwinds may access and process information from that account as necessary to provide the email-related features selected by the customer. For example, Hillwinds may access messages and related metadata to determine whether a recipient has replied to an email sent through the Services and to display that reply to the applicable customer within the Services.

Hillwinds may also maintain authentication information, such as OAuth tokens, necessary to maintain a customer-authorized connection to an email provider.

We do not use Customer Content or the contents of a connected email account to make that information available to other customers, to independently market to the individuals contained in that information, or for advertising purposes.

Cookies, Analytics, and Advertising Measurement

We and our service providers use cookies, pixels, local storage, and similar technologies to operate the Services, understand how our websites and product are used, measure performance, and improve our marketing. These technologies may collect or store information such as page views, feature interactions, referring URLs, browser and device information, IP address or approximate location, timestamps, and pseudonymous session or device identifiers.

PostHog. We use PostHog for website and product analytics, including to understand feature usage, measure product performance, diagnose issues, and improve the Services. Depending on our implementation and your browser settings, PostHog may use cookies or local storage to maintain pseudonymous identifiers and associate events with a browser or session.

LinkedIn. We use the LinkedIn Insight Tag on our public website for advertising measurement and attribution, aggregate audience insights, and, where enabled, website audience or retargeting features. LinkedIn may receive information about visits to pages where the tag is present, such as the page URL, referrer, IP address, device and browser characteristics, timestamp, and website actions such as page views, clicks, or form submissions. LinkedIn uses cookies and other pseudonymous identifiers in connection with these functions and processes that information under its own terms and privacy policies.

Your choices. You can control many cookies through your browser settings and through privacy controls offered by the relevant third party. Disabling some technologies may affect website or product functionality.

Some privacy laws may treat disclosures to advertising or measurement partners as a “sale” or “sharing” even where no money is exchanged. Where applicable, you may exercise an opt-out through our “Do Not Sell or Share My Personal Information” mechanism.

Storage and Use of Customer Content

Customers may upload CSV files or other lists and may type or paste information into the Outbound Engine or other parts of the Services. This may include company or contact information, recipient lists, notes, prompts, templates, case studies, proof points, brand or voice guidance, and message content, all of which is Customer Content as defined above.

We store Customer Content in the applicable customer account to provide the Services. Customer Content is not made available to unrelated Hillwinds customers. It may be accessible to the customer and its authorized users, and to Hillwinds personnel and service providers only as reasonably necessary to provide, secure, support, or maintain the Services, comply with law, or as otherwise authorized by the customer.

We do not use customer-uploaded recipient lists or other Customer Content to build, enrich, correct, or supplement professional datasets that we make available to other customers.

Connected Email Accounts and Outbound Sequencing

Customers may choose to connect a business email account to Hillwinds so they can compose, schedule, send, monitor, and manage outbound messages from within the Services. Connections are authorized through OAuth or another authorization method supported by the customer’s email provider. We do not ask users to provide their mailbox password to Hillwinds.

What we access. When a customer connects an email account, we may access and process:

  • OAuth access and refresh tokens and the identity of the connected account;
  • messages, headers, and metadata associated with messages sent or managed through the Services;
  • replies and related thread information needed to determine whether a recipient replied, associate the response with the correct sequence, stop or adjust future messages, and display the reply to the connected customer in Hillwinds; and
  • delivery and engagement events, including sends, deliveries, bounces, replies, unsubscribe requests, and, where enabled, opens or link interactions.

We request the permissions reasonably necessary to operate the features the customer has enabled. Even where a provider’s technical authorization scope permits broader access, we use connected email data only for the purposes described in this Privacy Statement and to provide the enabled customer-facing features.

How we use connected email data. We use connected email data only to provide, secure, support, and improve the enabled email features for that customer, including to send and synchronize messages, identify and display replies, apply suppression and unsubscribe rules, record delivery status, enforce sending limits, protect deliverability, detect abuse, troubleshoot issues, and provide support. We do not sell connected mailbox content, use it for advertising, use it to build or enrich datasets made available to other customers, or use it to train any artificial intelligence or machine learning models, other than models that operate solely within that customer’s own account.

Human access. Hillwinds personnel do not read connected mailbox content except when the user of the connected account gives explicit prior consent to access specific messages for a support or troubleshooting purpose, when access is reasonably necessary to investigate security or abuse, when required by law, or when information has been aggregated or de-identified for authorized internal operations.

Disconnection. When a customer disconnects a mailbox, we stop ongoing synchronization and revoke or delete the applicable access tokens on a prospective basis. Customer-specific message and reply data already stored in the account may remain available to that customer until deleted or until the account is closed, after which it is handled in accordance with the Data Retention section below. Residual copies may persist for a limited period in routine backups.

Bounce and Delivery Status

When a message sent through Hillwinds bounces or otherwise returns a delivery failure, we record that status in the customer’s account so we can show the result, prevent repeated sending where appropriate, protect mailbox and platform deliverability, and help the customer maintain list quality.

Additional Limits on Use of Google and Microsoft User Data

Where a customer grants Hillwinds access to Google user data through Gmail API scopes, Hillwinds uses that data only to provide or improve user-facing email features that the customer has enabled, or to secure or support those features. We do not use Gmail data for advertising, to train any AI or machine learning models, or to build or enrich datasets made available to other customers. We do not transfer Gmail data to third parties except as necessary to provide, secure, or support the enabled features, to comply with applicable law or regulation, or as part of a merger, acquisition, or sale of assets after obtaining the affected user’s explicit prior consent.

Human access to Google user data is limited to the circumstances described above. Hillwinds’ use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements (available at https://developers.google.com/terms/api-services-user-data-policy).

Where a customer connects a Microsoft account, we apply equivalent limitations to Microsoft Graph data and use it only as necessary to provide, secure, support, and improve the customer-facing features the customer has enabled, subject to applicable Microsoft terms and policies.

API Usage Data

When a customer uses the Hillwinds API or other developer interfaces, we may log the credential or account used, request and response metadata, request parameters as needed to process the request, timestamps, IP addresses, response codes, records returned, credits or other usage consumed, and related diagnostic information. We use this information to authenticate requests, meter and bill usage, enforce limits, secure the API, detect and prevent abuse, provide support, troubleshoot errors, plan capacity, and improve the Services.

Personal information returned through the API is drawn from the same commercially licensed, publicly sourced, and otherwise permitted professional datasets described in this Privacy Statement, and the same rights and choices apply to it. We do not use substantive Customer Content submitted through the API to build or enrich datasets made available to other customers.

How We Use Personal Information

Hillwinds collects, processes, and shares personal information to operate the Services, deliver business insights and workflow features, provide professional data products to customers, and run our business. Personal information may include professional identifiers such as name, business email address, job title, business phone number, company affiliation, industry, work location, professional profile URLs, and related business information, as well as technical and usage information such as browser type, IP address, device identifiers, account activity, and event logs.

Specifically, we may use personal information for the following purposes:

  • To maintain and deliver the Hillwinds websites, platform, data products, integrations, API, Outbound Engine, inbox and sequencing features, process user accounts, and fulfill customer requests.
  • To store and process Customer Content on behalf of the applicable customer and make it available within that customer’s account.
  • To operate connected-email features, including sending or synchronizing messages, detecting and displaying replies, recording delivery and bounce status, applying unsubscribe or suppression rules, and supporting customer sending workflows.
  • To operate, meter, secure, troubleshoot, and bill for API and other usage-based features.
  • To enhance data accuracy, coverage, and quality through aggregation, normalization, and verification processes.
  • To build and refine our AI tools, data models, prospect recommendations, analytics, and other product features using data we are permitted to use. We do not use connected mailbox content or Customer Content to train any AI or machine learning models, other than models that operate solely within the applicable customer’s own account.
  • To collect and maintain databases of professional contact and company information — including names, job titles, company affiliations, business email addresses, phone numbers, and office locations.
  • To respond to user inquiries, provide support, and send technical or administrative notices.
  • To prevent fraud, misuse, unauthorized access, spam, abuse, and deliverability risks, and to protect the security and integrity of our systems and customers.
  • To comply with applicable laws, regulations, and legal requests.
  • To enforce our terms, policies, and contractual rights.
  • To send service updates, feature announcements, and product or marketing communications.
  • To manage internal operations, billing, and audits.
  • In connection with a merger, acquisition, financing, or sale of company assets, personal information may be transferred as part of that transaction.

We do not knowingly sell or license sensitive personal information, personal consumer contact information unrelated to a person’s professional role, connected mailbox content, or Customer Content for non-business or household use.

Hillwinds may sell, share, or license business contact information such as professional names, titles, work email addresses, professional profile URLs, company affiliations, and similar business identifiers to customers and partners that have agreed to contractual use restrictions, for lawful business sales, marketing, research, and related purposes. We do not sell or share Customer Content, connected mailbox content, message content, customer-provided recipient lists, or customer-specific engagement records.

We require all customers to use the data only for lawful business purposes and to comply with applicable privacy and marketing laws.

We may use aggregated, anonymized, or de-identified data (which cannot reasonably identify an individual) for analytics, benchmarking, and product development.

We may disclose your personal information to comply with any court order, law, or legal process, including to respond to any government or regulatory request.

Prohibited data. The Services are business-to-business tools and are not designed to process protected health information under HIPAA, health claims or member data, Social Security numbers, consumer financial account credentials, or other sensitive categories except where expressly agreed in writing. Our terms prohibit customers from submitting such information.

Service Providers and Other Recipients

We use service providers to help host, secure, operate, support, analyze, and improve the Services. These may include cloud hosting and database providers, email connectivity and synchronization providers, payment processors, product analytics providers, customer support providers, and other vendors that process information on our behalf. We require service providers to use information only for authorized purposes and subject to appropriate confidentiality and security obligations.

Some third parties, including advertising or measurement providers such as LinkedIn, may process information under their own terms and privacy policies. We describe our current use of PostHog and the LinkedIn Insight Tag in the Cookies, Analytics, and Advertising Measurement section above. A current list of material subprocessors is available on request at privacy@hillwinds.ai.

Outbound Communications and Acceptable Use

Customers are responsible for the messages they send through the Services and for deciding who receives them. Our terms require customers to send only lawful business communications, to include a functioning unsubscribe or opt-out mechanism in commercial messages where required, to honor opt-out and removal requests, and to comply with applicable anti-spam and marketing laws. We may suspend or terminate accounts that violate these requirements.

Geographic Scope

The Services are intended for use only in the United States, and we do not offer them to individuals or businesses located outside the United States. We store personal information in the United States. Certain service providers or personnel may access personal information from other locations in order to support and maintain the Services; where that occurs, we require appropriate contractual and security safeguards.

Data Retention

We retain personal information for as long as reasonably necessary to provide the Services and fulfill the purposes described in this Privacy Statement, comply with legal obligations, resolve disputes, protect security and prevent abuse, and enforce our agreements. When information is no longer needed, we delete, aggregate, or de-identify it in accordance with our practices and legal obligations.

For Customer Content and customer-specific data that we process on a customer’s behalf, including customer-uploaded lists, connected mailbox content, message content, replies, and customer-specific engagement records, we generally retain the data during the customer’s subscription and for a reasonable period thereafter for operational, security, backup, legal, and dispute-resolution purposes. We may delete or de-identify this information earlier when it is no longer needed. Verified deletion requests are handled as described in the Your Privacy Rights section below, subject to applicable law and exceptions. Residual copies may remain for a limited period in routine backups that are not ordinarily accessible.

OAuth tokens are revoked or deleted when the applicable mailbox is disconnected, subject to limited residual copies in routine backups. Suppression, unsubscribe, security, and fraud-prevention records may be retained for longer where reasonably necessary to honor preferences, prevent abuse, or maintain professional data quality. Analytics and advertising providers may retain information according to our configuration and their applicable retention practices. Where we delete a record from our professional dataset at an individual’s request, we retain the minimum information necessary to identify that person as suppressed — such as a hashed identifier — so that the record is not reintroduced when we next refresh data from our providers. We use suppression records only for that purpose.

Children’s Privacy

Hillwinds does not knowingly collect or process personal information from children under 16 years of age. Our Services are intended for use by business professionals only.

Changes to Our Privacy Statement

We may update this Privacy Statement from time to time to reflect changes in our Services, data practices, legal requirements, or other circumstances. We will post the updated Privacy Statement and update the “Last Modified” date above. Where required by law, or where a change materially affects how we use information previously collected, we will provide additional notice or obtain consent as appropriate.

Your Privacy Rights

Depending on where you reside and subject to applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information about you; to opt out of the sale or sharing of personal information or certain targeted advertising; and to limit certain uses or disclosures of sensitive personal information. You may exercise applicable rights by contacting us at privacy@hillwinds.ai or through the privacy-rights mechanisms available on our website. We may need to verify your identity and may deny or limit a request where permitted by law.

If your request concerns Customer Content or a message sent by a Hillwinds customer, that customer generally controls the relevant data and decision to contact you. We will route the request to the relevant customer or assist that customer as required by applicable law. You may opt out of further marketing email from a Hillwinds customer by using the unsubscribe mechanism included in the message where available.

If you are a business contact in our professional dataset. If you believe your professional information appears in Hillwinds’ datasets and you want to access, correct, or delete it, or opt out of its sale or sharing, email privacy@hillwinds.ai from or referencing the business email address at issue, or use the “Do Not Sell or Share My Personal Information” mechanism on our website. We will process the request whether or not you have ever been a Hillwinds user or customer.

Hillwinds will not discriminate against you for exercising any of your privacy rights under applicable law.

Appeals. If we decline to act on your request, we will tell you why. Where applicable law provides a right to appeal, you may appeal that decision by emailing privacy@hillwinds.ai with the subject line “Privacy Request Appeal” within a reasonable period after you receive our decision. We will respond in writing within the period required by applicable law and, if the appeal is denied, will provide information about how you may contact the relevant state attorney general.

California residents and other individuals with applicable opt-out rights may exercise them by (1) emailing privacy@hillwinds.ai, (2) using the “Do Not Sell or Share My Personal Information” mechanism available on our website, or (3) enabling a browser-based opt-out preference signal such as the Global Privacy Control, which we treat as a valid request to opt out of the sale and sharing of personal information for the browser or device from which it is sent.

Contact Information

If you have questions, requests, or concerns regarding this Privacy Statement or Hillwinds’ handling of personal information, please contact us at:

privacy@hillwinds.ai