Legal

Privacy Policy

Beaver Solutions (BeavrDam) Effective: June 1, 2026 Last updated: July 14, 2026

01Who we are

Beaver Solutions ("Beaver Solutions", "we", "us", "our") operates BeavrDam, an autonomous outbound sales platform that helps users send personalized outreach from their own email inboxes and route replies.

This Privacy Policy describes how we collect, use, share, and protect information when you use BeavrDam (the "Service"), our website at beaver.solutions, and any related products.

By using the Service, you agree to the practices described in this Policy. If you do not agree, do not use the Service.

02Information we collect

Information you provide directly
  • Account information: name, email address, company name, role, password (hashed)
  • Billing information: payment card details, processed by our payment provider and never stored on our servers
  • Configuration data: your Ideal Customer Profile (ICP) criteria, your voice and tone preferences, your sequence rules
  • Prospect lists: names, email addresses, LinkedIn URLs, and company information you provide or import
  • Message drafts and approvals you create or edit within the platform
Information from connected accounts
  • Google account data when you authorize Gmail send and Calendar access (see Section 6)
  • LinkedIn account data where you activate the LinkedIn Outreach Module through your own connected Unipile account (Unipile is your provider account, not ours, see Section 5)
Information collected automatically
  • Usage data: features used, pages visited, actions taken
  • Device and connection data: IP address, browser type, device identifiers, operating system
  • Cookies and similar technologies (see Section 11)
Information from third parties
  • Lead enrichment data from approved data providers (publicly available business contact information)
  • Buying signal data from public sources and approved providers

03How we use information

We use information to:

  • Provide, operate, and maintain the Service
  • Send outbound messages on your behalf from your authorized email account, and create calendar events when a meeting is booked
  • Capture and route replies to messages sent through the Service, via a managed reply address on your outbound mail (we do not read your inbox)
  • Research and qualify prospects against your ICP
  • Generate, draft, and quality-check outbound messages
  • Authenticate users and prevent unauthorized access
  • Process billing and payments
  • Communicate with you about your account, the Service, and product updates
  • Improve the Service, subject to the Limited Use restrictions in Section 6
  • Comply with legal obligations

04Legal bases and roles (PDPA and GDPR)

Beaver Solutions is a Malaysian company. Where you use BeavrDam to run outreach to your own prospects, you (our client) are the data controller for that prospect data: you determine the purposes of the outreach and are responsible for its lawfulness. Beaver Solutions acts as your data processor, and complies directly with the processor obligations under Malaysia's Personal Data Protection Act 2010 (as amended in 2024), including the Security Principle in section 9 of the PDPA.

For users in the European Economic Area, United Kingdom, or Switzerland, we additionally process personal data on the following legal bases:

  • Contract performance to provide the Service you signed up for
  • Legitimate interests to operate, secure, and improve the Service, prevent fraud, and conduct business analytics
  • Consent for cookies, marketing communications, and certain integrations (you may withdraw consent at any time)
  • Legal obligations to comply with applicable laws

05How we share information

We share information only as follows:

  • Service providers (subprocessors) under contractual confidentiality obligations: Railway (application hosting), Supabase and Neon (managed databases), Mailgun (inbound reply capture), and Telegram (operational alerts, where you opt in)
  • Google integration you authorize (Gmail send, Calendar, account identification), only as needed to provide the connected functionality, see Section 6
  • Your own connected provider accounts, where you connect and pay for them directly under your own terms with that vendor, for example OpenAI, Brave Search, email-finding and verification services, and, where you activate the LinkedIn Outreach Module, Unipile. These are your direct vendor relationships, not our subprocessors, and we do not control their data practices
  • Legal compliance when required by law, court order, or to protect rights, safety, or property
  • Business transfers in connection with a merger, acquisition, or sale of assets, subject to confidentiality

We do not sell personal information.

06Google API Services User Data Policy

BeavrDam uses Google APIs to send outbound messages on your behalf and create calendar events when you book a meeting. We never read your Gmail inbox.

Scopes we request
  • gmail.send to send outbound messages composed in BeavrDam from your authorized Gmail account on your behalf
  • calendar.events to create meeting events on your Google Calendar when you book a meeting with a prospect
  • userinfo.email to identify the connected account
How we use Google user data

Google user data is used exclusively to send outbound messages composed by you in BeavrDam, create calendar events for meetings you book, and identify your connected account. BeavrDam does not request gmail.readonly or gmail.modify, and does not scan or read your inbox. Replies to messages sent through the Service are captured through a managed reply address on your outbound mail, not by accessing your mailbox.

Limited Use compliance

Beaver Solutions' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We affirm:

  • We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models
  • We do not use Google user data for serving advertisements, including retargeting, personalized advertising, or interest-based advertising
  • We do not sell Google user data or transfer it to third parties for purposes unrelated to providing or improving the Service
  • We do not allow humans to read Google user data unless we have obtained your affirmative agreement to view specific messages, for security investigation, abuse detection, to comply with applicable law, or for operations where the data has been aggregated and anonymized
Revoking access

You may revoke BeavrDam's access to your Google account at any time at myaccount.google.com/permissions or by emailing hello@beaver.solutions. All retained Google user data will be deleted within 30 days of revocation.

07International data transfers

Beaver Solutions is based in Malaysia. We process information in Malaysia, the United States, and other jurisdictions where our service providers operate. Where personal data is transferred out of Malaysia, we rely on contractual safeguards with our providers consistent with the Personal Data Protection (Cross-Border Personal Data Transfer) Guidelines 2025. When we transfer personal data out of the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses or equivalent safeguards as required by applicable law.

08Data retention

We retain your data for as long as your account (your "room") is active, so the crew can operate and keep learning. After termination:

  • Sending stops immediately and your room is deactivated
  • If you request it within 14 days of termination, we provide an export of your configuration, prospects, and message history in a portable format
  • We delete your room data within 30 days of termination, except minimal records kept for billing, tax, or legal purposes
  • The crew's learned guidance built for your account is deleted with it
  • Google user data is deleted within 30 days of revocation (see Section 6)
  • Billing records are retained for the period required by tax and accounting laws
  • Anonymized analytics data may be retained indefinitely

You may request earlier deletion by emailing hello@beaver.solutions.

09Security

We use industry-standard measures to protect information:

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Role-based access controls with audit logging
  • Least-privilege production access restricted to authorized engineering personnel
  • Regular security reviews and dependency monitoring
  • An isolated database per client, with no shared tables
  • Provider API keys encrypted at rest and entered only by you, the client
  • A mandatory quality gate and human approval in front of every outbound send, with a daily volume hard cap

No system is perfectly secure. If we become aware of a personal data breach affecting your data, we will notify you promptly with what we know and what we are doing about it, and provide all reasonable assistance with your notification obligations under the PDPA, including notification to the Personal Data Protection Commissioner as soon as practicable and within 72 hours where the breach causes or is likely to cause significant harm, and to affected individuals within 7 days of the Commissioner notification, where required. We will also notify affected users and authorities as required by other applicable law.

10Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete personal data
  • Delete your personal data
  • Restrict or object to certain processing
  • Portability: receive your data in a machine-readable format
  • Withdraw consent for processing based on consent
  • Lodge a complaint with your local data protection authority

For California residents, additional rights apply under the CCPA and CPRA, including the right to opt out of any sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising.

To exercise these rights, email hello@beaver.solutions. We will respond within 30 days.

11Cookies and similar technologies

We use cookies and similar technologies to:

  • Keep you logged in
  • Remember your preferences
  • Measure how the Service is used
  • Detect and prevent fraud

You can control cookies through your browser settings. Disabling some cookies may affect Service functionality.

12Children

The Service is not intended for individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data, email hello@beaver.solutions and we will delete it.

13Changes to this Policy

We may update this Policy from time to time. Material changes will be communicated by email or in-app notice at least 14 days before they take effect. Continued use of the Service after changes take effect constitutes acceptance.

14Contact

Questions, requests, or complaints about this Policy or our data practices:

Beaver Solutions
Reg. No. 202603168716 (003864610-M)
Email: hello@beaver.solutions

For Google API-related requests, mark your email subject Google API Data Request so we can prioritize it.