Legal
Privacy notice
What Corral collects, why, and your choices, for customers and for the people Corral writes to. Last updated 30 September 2026.
Draft for review. Items marked TODO are still being confirmed; this page isn’t indexed until they are.
About this notice
This Privacy Notice explains how Uzski Corp ("we", "us" or "our") collects, uses, shares and protects personal information when you visit the Corral website, use the Corral app, API or MCP server (the "Services"), or when Corral processes information about you on behalf of one of our customers.
It covers two groups of people: our customers and their team members who use Corral ("users"), and the people our customers research and write to with Corral ("prospects"). For prospects' data, the customer is the controller and we process it on the customer's behalf; for users' account data and our website, we are the controller.
Questions or concerns: privacy@uzskicorp.agency. [TODO for Sean: confirm whether Corral gets its own privacy address.]
Summary of key points
We collect account details when you sign in, the content your workspace puts into Corral, and — for our customers — business contact information about prospects from imports, public web pages and data providers. We use it to run Corral and nothing else we don't say here. We do not sell personal information and do not use customer content to train general-purpose AI models. We use service providers (listed below) to host, email, verify and analyse data under contract. Prospects can opt out of any Corral email with one click, and anyone can ask us or the customer what we hold about them.
What information we collect
Account information. When you sign in, our authentication provider WorkOS gives us your name, work email address, profile picture (if your Google or Microsoft account has one) and the organisation you sign in for. We record your role in the workspace and when you sign in.
Workspace content. What you add to Corral: products and their descriptions; files you upload to a knowledge base (PDF, DOCX, Markdown) and web pages you add; lead, company and contact records you create or import from CSV; segments, sequences, emails and replies in connected mailboxes; notes; and settings. Files you upload can contain personal information; you choose what to upload.
Prospect information. On a customer's instructions, Corral collects business contact information about people at companies that may fit the customer's product: name, job title, work email address and its verification status, company, country and company size, public professional profile links, the public web pages Corral read about the company, and the history of emails, replies, unsubscribes and meetings with that customer. It comes from the customer's own imports, from public websites, and from the data providers listed below.
Connected services. When a customer connects a mailbox (Google Workspace or Microsoft 365), Corral accesses the messages needed to send sequences and sort replies, and stores the connection's tokens encrypted. When a customer connects a scheduling tool or an ERP, Corral exchanges the meeting and deal details needed for the handoff.
API and MCP use. For API keys and MCP connections we record which client or key made each call, what it did, and when, so owners can review activity.
Technical information. Our servers log IP addresses, browser and device details, and requests, to keep the Services secure and working. [TODO for Sean: log retention period, and whether we use any website analytics.]
We do not intentionally collect sensitive personal information (such as health, religion or biometric data), and customers must not upload it.
How we use information
To provide the Services: sign you in, keep your session, run your workspace, read your knowledge base, find and score companies, find and verify contacts, send the emails you approve, sort replies, and hand booked meetings to your connected systems.
To keep the Services safe: prevent fraud and abuse, enforce sending limits and suppression, and investigate security incidents.
To support and improve Corral: answer requests, fix problems and understand, in aggregate, how features are used. We do not use customer content or prospect data to train general-purpose AI models.
To communicate with users about their account, security, billing and material changes. Product news only if you opt in, with an unsubscribe link in every message.
To comply with law and respond to lawful requests.
Legal bases
Where laws such as the Kenya Data Protection Act 2019 or the EU/UK GDPR apply, we rely on: performance of our contract with customers (running the Services); our legitimate interests in securing and improving the Services; consent where we ask for it (for example product news); and legal obligations. For prospect data, the customer decides the legal basis for its outreach (typically legitimate interest in business-to-business contact) and is responsible for it; we process that data on the customer's instructions.
Pages Corral reads, and data providers
Corral reads only public web pages: ones anyone can open without signing in. Its crawler identifies itself as CorralBot, respects robots.txt, does not follow private or local network addresses, and limits how much it reads from each site.
Email addresses Corral finds are business addresses. Before a sequence writes to an address, Corral checks it can receive email (through ZeroBounce) and skips addresses that bounce or are on the workspace's suppression list.
AI features
Corral uses AI models to score how well a company fits a product and explain why, to classify replies, and to draft messages and replies. Knowledge-base passages, company pages and the relevant email thread are sent to the model provider for that request. Drafts are suggestions: a person reviews them before they're sent. Scores and drafts can be wrong; each shows where its claims came from so they can be checked.
AI providers process this data under contract only to return the result. [TODO for Sean: confirm each provider's retention period and that none train on our data.]
How long we keep information
Account and workspace content: for as long as the workspace is active. When a customer removes a knowledge-base source it leaves search at once and can be restored for a short time; removed sources, files and their passages are then deleted. [TODO for Sean: set the restore window and the purge schedule for removed sources and files.]
When a workspace is closed we delete its content, including prospect data, within [TODO for Sean: number] days, except what we must keep by law (such as billing records) and encrypted backups, which expire within [TODO for Sean: number] days.
Suppression list entries (people who unsubscribed or asked not to be contacted) are kept for as long as the workspace exists, because deleting them would let the address be contacted again. We keep only what's needed to recognise the address.
Server logs: [TODO for Sean: retention period].
How we keep information safe
We use organisational and technical safeguards: encryption in transit (TLS) and of connection secrets at rest, workspace isolation enforced in the database with row-level security, least-privilege access for our staff, and an audit trail for API keys and MCP connections. The Security page has details. No system is 100% secure, so please use strong sign-in methods and tell us about anything suspicious.
International transfers
Uzski Corp is based in Kenya, and our service providers may process information in other countries, including the United States and the European Union. Where the law requires it, we use safeguards such as standard contractual clauses for these transfers. [TODO for Sean: confirm where production data is hosted.]
Minors
Corral is a business service for people aged 18 and over. We do not knowingly collect information from children. If you believe we have, contact privacy@uzskicorp.agency and we will delete it.
Your rights and choices
Depending on where you live, you may have the right to access, correct or delete your personal information, object to or restrict its processing, receive a copy in a portable format, withdraw consent, and complain to a data-protection authority. In Kenya that is the Office of the Data Protection Commissioner (odpc.go.ke); in South Africa, the Information Regulator (inforegulator.org.za).
If you are a prospect: every Corral email has an unsubscribe link, and replying to ask not to be contacted works too. Either adds you to that customer's suppression list, so Corral stops writing to you for that customer. To find out what a customer holds about you, or to ask for deletion, contact the customer (the sender) or write to privacy@uzskicorp.agency and we will pass it on and help them respond.
If you are a user: you can update your profile through your sign-in provider, and workspace owners can export or delete workspace data. To exercise any right, email privacy@uzskicorp.agency. We will respond within the time the law requires and may need to verify your identity. [TODO for Sean: confirm whether we keep the Termly DSAR form used on uzskicorp.agency or use email only.]
Updates to this notice
We will update this notice when our practices change or the law requires. The date at the top shows the latest version (30 September 2026); for material changes we will tell users by email before they take effect.
How to contact us
Email privacy@uzskicorp.agency, or write to Uzski Corp, Abc Place Nairobi, Waiyaki Way, Nairobi, Nairobi County 00100, Kenya.
Also: Terms of service · Data processing agreement. Questions: legal@corral.app.