Privacy Policy
How Implest handles customer, prospect, AI, connected-service and operational data.
Last updated: 6 October 2026
1. Who we are and the roles we may have
Implest is operated by Komaneca SL, tax identification number B21790761, at Calle Balmes 191, 6º 1º, 08006 Barcelona, Spain. Privacy contact: msegura@implest.com.
For our own account administration, billing, website operation, security, support, product governance and legal compliance, Komaneca SL determines the purposes and means of processing and acts as controller. For prospect, campaign, CRM, conversation and scheduling data that a business customer submits, connects or instructs Implest to process, the customer normally acts as controller and Komaneca SL acts as processor under the Data Processing Addendum. Contract labels do not change the factual role required by applicable law.
2. Information we process
Account and customer information may include names, work contact details, company details, workspace membership, plan, Credits, invoices, billing status, support communications, product settings and acceptance records.
Commercial and campaign information may include professional names, employers, job titles, business contact details, LinkedIn identifiers, public business information, CRM records, targeting criteria, relationship status, provenance, messages, replies, qualification data, meetings and activity history. Sources may include the customer, connected services, public business sources and professional data providers such as Apollo or Lusha when enabled.
Technical and security information may include session identifiers, request metadata, device or browser information, audit events, provider responses, errors, account-health indicators, suppression records, webhook identifiers and logs needed to operate, secure and troubleshoot the service.
Connected-service data may include OAuth tokens, account identifiers, calendar identifiers, CRM identifiers, message or conversation references and other permissions needed to provide an integration. Payment card details are handled by Stripe rather than stored as full card details in Implest.
3. Why we process information and legal bases
We process customer account and service data to enter into and perform our agreement, operate the requested service, provide support and administer subscriptions. We process billing and accounting records where needed to comply with legal obligations. We process proportionate security, abuse-prevention and service-reliability data on the basis of our legitimate interests in protecting users, recipients and the service.
For prospecting and campaign data processed on a customer’s instructions, the customer is responsible for determining the applicable legal basis, transparency obligations and communications rules. Connecting an account, finding a professional profile or purchasing Implest does not create consent from a prospect.
Where we process professional contact data for our own business purposes, we assess the applicable lawful basis and communications rules separately. Where consent is legally required, the relevant feature or communication must obtain it.
4. Artificial intelligence and automated processing
Implest uses AI to understand Missions, analyse business context, research and prioritise opportunities, generate and classify messages, interpret replies, detect objections, recommend or execute next actions, qualify opportunities and support scheduling. OpenAI is one of the AI providers used for model inference.
We seek to minimise the personal data sent to AI providers and do not intentionally send payment credentials, OAuth tokens, passwords or special-category personal data when those data are not necessary for the requested feature. Implest applies product rules designed to prevent sensitive-data targeting and prohibited high-impact uses.
Autonomous features may execute actions without an individual approving every step. The selected execution mode, compliance decisions, material actions and relevant policy versions may be logged. Implest can also require human review or block an action. The service is not designed to make decisions producing legal or similarly significant effects about individuals in areas such as employment, credit, insurance, healthcare or access to essential services unless a separately reviewed and approved use case is provided.
Where applicable law requires a person to be informed that they are interacting with an AI system, Implest may provide an AI disclosure and record that the disclosure was delivered.
5. Direct marketing, objections and suppression
Implest may help customers carry out business communications, but the customer remains responsible for the lawfulness of its campaign purpose, audience and legal basis. Implest may apply channel- and country-specific compliance rules before an action is executed.
If a recipient objects to further contact, asks to stop, unsubscribes or makes an equivalent request, Implest may place identifiers on a suppression list and cancel pending outreach. We may retain the minimum suppression information needed to avoid contacting the person again even after other campaign data has been deleted.
6. Google Calendar and Microsoft integrations
Connecting a calendar is optional. The integration may access the connected account identity, calendar identifiers, free/busy availability, event information needed for scheduling and OAuth access or refresh tokens. These permissions are used to check conflicts, calculate available times, create or manage authorised meeting events and, where requested, create conferencing information.
Google Workspace API data is used only for the user-facing features authorised by the user. We do not use Google Calendar contents or OAuth tokens to build prospecting datasets, advertising audiences or generalised AI training datasets. Human access is restricted to authorised support, security, legal or operational situations.
A customer may disconnect a calendar or revoke permissions at the relevant provider. Revocation prevents future authorised access but does not automatically remove meetings already created or records that must be retained for legal or security purposes.
7. Recipients and service providers
Our core infrastructure and service providers may include Supabase for managed database, authentication and Edge Functions; Vercel for application hosting and delivery; OpenAI for AI inference; Unipile for connected messaging and account connectivity; Resend for transactional or operational email; and Hetzner for optional self-hosted infrastructure and auxiliary services.
Stripe processes payments and related fraud, billing and financial data under roles that may vary by processing activity. Google and Microsoft process data when customers connect their services. HubSpot and other CRMs may receive or provide data when a customer directs an integration. Apollo and Lusha may provide professional B2B data and may act as independent controllers or in other roles described in their own terms.
The current list and classification of providers is maintained on our Subprocessors & Third-Party Services page.
8. International transfers
Implest’s primary Supabase production project is configured in the European Union. Some providers or their subprocessors may process data outside the European Economic Area. Where a restricted international transfer occurs, the relevant parties use an available lawful transfer mechanism such as an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, or the European Commission Standard Contractual Clauses with any required supplementary measures.
The location of a primary database does not by itself mean that every service or support operation remains exclusively within that location. We assess transfer arrangements by provider and service.
9. Retention and deletion
We retain data for the period needed to provide the active service, maintain security and auditability, resolve disputes, comply with legal obligations and establish or defend legal claims. Different categories have different retention periods; operational logs, raw webhook payloads, campaign data, billing records, OAuth credentials and compliance audit records do not necessarily have the same retention period.
OAuth credentials are deleted or disabled when no longer needed for the connected feature, subject to technical and legal retention requirements. Raw operational data may be deleted earlier than compliance or suppression records. When a customer terminates the service, processor data is returned or deleted in accordance with the Data Processing Addendum, subject to legal retention and backup cycles.
10. Security
Implest uses technical and organisational measures designed to protect personal data, including HTTPS/TLS in transit, server-side secret management, access controls, Row Level Security where appropriate, restricted backend privileges, audit logging, environment separation, credential rotation, backups and incident-response procedures.
OAuth tokens and provider credentials are handled by server-side services and are not intentionally exposed in public browser responses. Access is limited to authorised personnel and providers that need it to operate or secure the service. No internet service can guarantee absolute security.
11. Your rights and choices
Where applicable, you may request access, correction, deletion, restriction, portability or object to processing, including direct marketing. You may withdraw consent where processing is based on consent without affecting earlier lawful processing. We may need to verify your identity and, for business workspaces, your authority to make the request.
If Implest processes your information solely on behalf of a customer, we may refer the request to that customer or assist it in responding. You may lodge a complaint with your competent supervisory authority; in Spain, the authority is the AEPD.
12. Changes, privacy contact and Data Protection Officer
We may update this policy to reflect changes in the service, providers or law. Material changes will be communicated through the service or an appropriate account contact where required.
Privacy questions and rights requests may be sent to msegura@implest.com.
Komaneca SL has designated Cloga Management S.L. (NIF B75954123) as its external Data Protection Officer (DPD/DPO). The designated contact person is Miguel Segura Mañero. The DPO can be contacted at dpo@implest.com or by post at Calle Balmes 191, 6º 1ª, 08006 Barcelona, Spain. The designation was communicated to the Spanish Data Protection Agency (AEPD) on 6 October 2026.
Questions or requests: msegura@implest.com.