TradeOcto Privacy Policy

How TradeOcto collects, uses, protects, and shares information across the buyer discovery platform, AI workflows, account system, and lead enrichment features.

Last updated: April 25, 2026

This Privacy Policy explains how TradeOcto ("TradeOcto", "we", "us", "our") collects, uses, stores, shares, and protects information related to users, teams, tenants, search tasks, AI interactions, and business leads. TradeOcto is a B2B productivity product for trade teams that discover, verify, and research overseas buyer companies.

By using TradeOcto, you acknowledge this Policy. If you use the service on behalf of a company, team, or other organization, you confirm that you are authorized to submit business data for that organization and that your organization is responsible for how its members use the service.

For most Customer Content submitted by an organization, TradeOcto acts as a data processor (or service provider under California law) and the organization acts as the data controller. For account, billing, and security telemetry, TradeOcto acts as a data controller. Defined terms used here have the meanings given in the TradeOcto Terms of Service.

1. Information We Collect

Account information — name, email, password hash, account role, tenant relationship, team membership, login timestamps, account status, and authentication source. TradeOcto never stores plaintext passwords.

Workspace content — product descriptions, target markets, ICPs, search keywords, exclusion rules, company notes, contact research tasks, chat content, saved sessions, and exported lead fields you submit to the service.

AI and search processing data — prompts, context, model outputs, task status, quality signals, public web snippets, candidate company information, contact leads, translations, scoring inputs, and evidence summaries.

Public web and third-party source data — company websites, public pages, search results, public professional profiles, trade signals, public contact details, page titles, summaries, URLs, source evidence, and collection timestamps.

Technical and usage data — IP address, browser type, device information, logs, request time, API path, error details, performance metrics, quota usage, credit events, cookies, lightweight localStorage preferences, and security audit records.

We do not knowingly collect special categories of personal data (such as race, health, biometrics, or political opinions). Do not submit such categories into the service.

2. How We Use Information

Provide and maintain the service — registration, login, tenant management, saved sessions, lead search, contact discovery, AI analysis, quota tracking, billing plans, notifications, and administration.

Operate generative AI features — understanding prospecting requests, generating search strategies, extracting company profiles, summarizing evidence, translating content, ranking relevance, producing structured fields, and assisting outreach preparation.

Protect the service — authentication, abuse prevention, rate limiting, suspicious-login investigation, account protection, system stability, and enforcement of the Terms.

Improve the product — analysis of feature reliability, search quality, latency, error patterns, and user experience. Where practical, we use aggregated, de-identified, or minimized data.

Comply with legal obligations — respond to lawful requests, preserve necessary audit records, enforce agreements, and protect the rights of TradeOcto, users, and third parties.

3. Legal Bases for Processing (GDPR / UK GDPR)

For individuals in the European Economic Area, the United Kingdom, and other jurisdictions with similar laws, we rely on the following legal bases under Article 6 of the GDPR / UK GDPR:

Performance of a contract — to deliver TradeOcto to you or to your organization under the Terms, including authentication, workspace storage, lead search, and AI analysis.

Legitimate interests — to secure the service against fraud and abuse, to monitor and improve product reliability, and to develop new features. We weigh these interests against your privacy interests and apply safeguards (minimization, access controls, retention limits).

Compliance with legal obligations — to respond to lawful requests, preserve tax and accounting records, and satisfy applicable regulations (including export controls and sanctions).

Consent — for processing where we explicitly ask for it (for example, optional product communications). You may withdraw consent at any time without affecting the lawfulness of prior processing.

4. Generative AI, Model Services, and Training Data Exclusion

To operate the AI features, TradeOcto may transmit your brief, search context, public web snippets, candidate company data, contact signals, and other necessary context to configured model providers or a self-hosted LLM proxy. The choice of model providers is governed by your deployment configuration and your enterprise order form.

TradeOcto does not use Customer Content to train, fine-tune, or improve large language models that are made available to other customers. Where third-party model providers are used, we contract for the same exclusion — Customer Content is processed solely to return the AI output you requested and is not retained by the model provider for training, unless your deployment explicitly opts in through an order form or admin setting.

AI outputs may be inaccurate, outdated, incomplete, or based on inferences from public information. You should verify source evidence before relying on AI outputs for commercial decisions, outreach, procurement, compliance screening, sanctions checks, or other important use cases.

Aggregated, de-identified telemetry (such as feature usage counts, error rates, and prompt length distributions) may be used by TradeOcto to monitor product quality. This telemetry is engineered so individual prompts, accounts, and Customer Content cannot be reconstructed from it.

5. Automated Decision-Making and AI Profiling

TradeOcto uses algorithmic scoring (for example, 0-100 fit scores on companies and contacts) and AI-generated classifications to help users prioritize prospecting work. These outputs are decision-support signals intended for human review — they do not by themselves produce legal effects on, or similarly significantly affect, any data subject.

In line with Article 22 of the GDPR / UK GDPR, we do not use the service to make solely automated decisions that produce legal or similarly significant effects on individuals. Customers must keep a human in the loop before any contact, outreach, contract, hiring, lending, or other consequential action is taken based on an AI output.

If a data subject believes an AI score or classification about them is inaccurate, they may contact us or the relevant Customer (data controller) to request review, correction, or human intervention.

6. Cookies, Local Storage, and Sessions

TradeOcto uses an HttpOnly cookie to manage login state. The default cookie name is tradeocto_auth_token. Browser scripts cannot read this cookie. We do not use third-party advertising or cross-site tracking cookies.

Frontend localStorage is used only for language preference, lightweight UI state, fallback copies of recent workspace sessions, and non-sensitive user metadata. Do not enter unnecessary sensitive personal information into prompts, notes, or custom fields.

You may clear cookies and local storage through your browser settings, but doing so may require signing in again or may remove local UI state that has not yet synced.

7. Sharing, Service Providers, and Sub-processors

We may share information with infrastructure, database, logging, search, crawling, model, email, payment, customer-support, and security service providers (collectively, sub-processors) only as necessary to deliver the service. Each sub-processor is bound by written contracts that require confidentiality, security, purpose limitation, and assistance with data-subject requests.

A current list of sub-processors is maintained by TradeOcto and made available to enterprise customers on request. Material changes to the sub-processor list are communicated through reasonable means with the opportunity to object before the change takes effect for affected customers.

If you connect third-party APIs, search services, model gateways, or internal data tools through TradeOcto, you are responsible for confirming that you may send the relevant data to those services and for understanding their privacy and security terms.

We do not sell user account information or Customer Content, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA / CPRA). If TradeOcto is involved in a merger, acquisition, asset transfer, or reorganization, data may transfer as part of the business and remain protected by this Policy or equivalent safeguards.

8. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, the lifetime of the account, the applicable order form, or as required by law.

Indicative retention periods, which may be adjusted for legal hold, dispute, audit, or contractual obligation: account records — until deletion plus a short residual period for finalisation; workspace content, search tasks, AI outputs, and exports — until deleted by the user, cleared by an administrator, or removed under tenant retention policy; security and access logs — typically up to 12 months; backups — typically up to 35 days.

On termination of an account or order form, we will delete or return Customer Content within a reasonable period unless retention is required by law or by an active dispute. De-identified or aggregated data that no longer identifies any individual may be retained indefinitely.

9. Security and Incident Notification

TradeOcto applies administrative, technical, and physical safeguards designed to protect the service, including password hashing, HttpOnly cookies, role-based access controls, tenant isolation, rate limiting, audit logging, health checks, and configurable CORS protections.

No internet service can be guaranteed absolutely secure. Users should use strong passwords, limit team permissions, protect API keys, avoid submitting unnecessary sensitive data, and revoke accounts or credentials that are no longer needed.

If TradeOcto becomes aware of a personal-data breach that is likely to affect your data, we will notify the relevant Customer (data controller) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, consistent with Article 33 of the GDPR. Notifications will describe the nature of the incident, likely consequences, and the measures taken or proposed to address it.

10. Your Privacy Rights

Subject to applicable law, you have rights with respect to your personal data. To exercise these rights, contact your tenant administrator first; if that route is unavailable, contact [email protected]. We will respond within the timeframes required by the applicable law.

GDPR / UK GDPR / EEA / Swiss residents — right of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, withdrawal of consent, and the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or place of the alleged infringement.

California residents (CCPA / CPRA) — right to know what personal information is collected, right to correct inaccurate information, right to delete, right to limit use of sensitive personal information, right to opt out of sale or sharing for cross-context behavioral advertising (TradeOcto does not engage in such sale or sharing), and right to non-discrimination for exercising these rights.

Brazil (LGPD) — right to confirmation of processing, access, correction, anonymization or deletion, portability, information about sharing, and revocation of consent. Other jurisdictions — equivalent rights as provided by applicable law.

If you believe public-source contact or company information about you is inaccurate, you may also update notes, remove leads in the product, or contact the relevant Customer. For correction or deletion at the original public source, you may need to contact that source directly.

11. Children's Privacy

TradeOcto is a B2B service intended only for business users and is not directed to children under 16. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child under 16 without verifiable parental consent, we will delete that information promptly.

If you believe a child has provided personal data to TradeOcto, please contact [email protected] so we can investigate and act.

12. International Data Transfers

TradeOcto may process data through infrastructure, search services, model providers, or business tools in jurisdictions other than the one from which the data was collected. For transfers from the EEA, the United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and supplementary measures (encryption in transit, access controls, data minimization) consistent with the Schrems II decision and applicable guidance.

If your organization has data residency, cross-border transfer, DPA, or security audit requirements, those requirements should be addressed before production deployment through an order form, data processing agreement, or deployment configuration.

13. Contact, Complaints, and Updates

To exercise privacy rights, report a security concern, or ask about data processing, contact your tenant administrator or [email protected]. Enterprise customers may also use the contacts named in their order form or Data Processing Addendum.

EEA / UK residents may, in addition to contacting us, lodge a complaint with their local supervisory authority (for example, the ICO in the UK, the CNIL in France, the BfDI in Germany). California residents may contact the California Attorney General.

We may update this Policy as the product, law, or operations change. Material changes will be communicated through in-product notices, release notes, or other reasonable methods at least 30 days before they take effect where required by law. Continued use of the service after the effective date means you accept the updated Policy.

Explore TradeOcto