Skip to main content
S SpecSavi
Privacy Policy Cookie Policy Terms of Service Service Level Agreement

Last Updated: September 28, 2026

← Back to Home

Privacy Policy

SpecSavi Ltd.

Effective Date: September 28, 2026 Last Updated: September 28, 2026

Table of Contents

  1. Summary
  2. Introduction
  3. Our Role: Controller or Service Provider
  4. Information We Collect
  5. Prospecting and Outbound Email
  6. How We Use Your Information
  7. AI and Automation
  8. Legal Bases and Consent
  9. How We Share Your Information
  10. International Data Transfers
  11. Data Retention
  12. Data Security and Breaches
  13. Cookies and Tracking Technologies
  14. Your Rights and Choices
  15. Children's Privacy
  16. Changes to This Privacy Policy
  17. Contact Us and Complaints

Summary

This summary is for convenience. The full policy below is what applies.

  • We are a B2B GTM operations company based in Toronto, Canada. We collect business contact details, what you tell us, and how you use our website.
  • When we work on a client's CRM, data or outbound campaigns, the client decides how that data is used and we follow their instructions.
  • We send business outreach by email. Every message says who we are, and you can opt out at any time. We honour opt-outs across every campaign.
  • We use AI tools to research, draft and summarize. A person reviews outreach before it is sent, and we do not let AI providers train their models on the data we send them.
  • We do not sell personal information.
  • You can ask to see, correct or delete your information by emailing privacy@specsavi.com.

1. Introduction

SpecSavi Ltd. ("SpecSavi," "we," "us," or "our") provides go-to-market (GTM) operations services to businesses. These include revenue, sales, marketing and customer success operations, CRM implementation and migration, reporting and analytics, GTM engineering and automation, AI systems built inside a client's own tools (such as the GTM Brain Build, AI SDR and AI ops monitor), outbound prospecting and cold email, and GTM systems diligence for investors.

This Privacy Policy explains how we collect, use, disclose and protect personal information when you visit specsavi.com, use our website tools, book a meeting, receive email from us, become a client, or are contacted in an outbound campaign we run.

Our services are for businesses. We handle personal information about people in their professional roles, such as names, job titles and work email addresses.

2. Our Role: Controller or Service Provider

Privacy laws treat an organization differently depending on who decides how personal information is used.

When SpecSavi is responsible

We decide how information is used, and this policy applies in full, for:

  • Visitors to our website and users of our website tools
  • People who contact us, book a meeting or subscribe to our emails
  • Business contacts at our clients, partners and suppliers
  • People we contact in our own outbound prospecting

When we act for a client

When we build or run systems for a client, including their CRM, marketing automation, AI tools or outbound campaigns, we process personal information on the client's behalf and under the client's instructions. Under PIPEDA we are then a third-party service provider. Under the GDPR and UK GDPR we are a processor, and the client is the controller.

In that role, the client's own privacy policy governs how the information is used, and our contract with the client (including any data processing terms) governs how we handle it. If you want to exercise your rights over data we process for a client, please contact that client. If you contact us instead, we will pass your request to them and help them respond.

3. Information We Collect

Information You Provide Directly

Forms, bookings and website tools:

  • Name, work email address, phone number, company name and job title
  • Meeting bookings made through our scheduler, including the time you choose and anything you write in the booking form
  • Your answers to the RevOps Health Score and similar tools, and the results we show you
  • Downloads you request, such as checklists and guides
  • Choices you make in the pricing estimator, if you send them to us with a booking
  • Anything else you choose to tell us in messages or calls

Email subscriptions:

  • Email address, name and, optionally, company name

Client engagements:

  • Business contact details for the people we work with
  • Access to the client's CRM, marketing, sales and support systems, and the data in them, as needed to deliver the work
  • Billing details, handled through our payment processors
  • Project communications, meeting notes and documentation

Information We Collect Automatically

On www.specsavi.com, our analytics and marketing tools collect:

  • Pages you visit, how long you stay, links you click and how you scroll
  • Browser, device and operating system information
  • The website that referred you
  • Approximate location (country or city), derived from your IP address
  • Cookie and similar identifiers
  • Whether you open and click our marketing emails

Microsoft Clarity records how pages are used (mouse movement, clicks and scrolling) so we can find what is confusing or broken. It masks text you type into form fields.

To show prices in the right currency, our website reads the country your connection comes from. This check happens when the pricing page loads and is not stored.

Information from Other Sources

  • Public business sources: company websites, press releases, job postings, and professional profiles that people publish about their work
  • Business data and enrichment providers: work contact details, job titles and company information, used for prospecting (see Section 4)
  • Partners and referrals: contact and business details when someone introduces you to us
  • Client systems: data in the CRM and other tools we are engaged to work on (see Section 2)

We do not intentionally collect sensitive personal information, such as health, financial account or government ID details. Please do not send it to us.

4. Prospecting and Outbound Email

Our own outreach

We contact businesses that we believe could use our services. To do this, we use the work contact details and professional information described in Section 3, from public business sources and business data providers. We contact people about matters related to their role.

  • Every message identifies SpecSavi, gives a way to reach us, and includes a way to opt out.
  • If you opt out or ask us to stop, we add you to a suppression list and do not contact you again. We process opt-outs within 10 business days, and usually much sooner.
  • You can ask us where we got your details, and we will tell you.
  • For people in Canada, we send commercial electronic messages only where Canada's Anti-Spam Legislation (CASL) allows it, for example with your express consent, or with implied consent where your business email address is conspicuously published and the message relates to your role.
  • For people in the United States, our messages follow the CAN-SPAM Act.
  • For people in the EU, UK and other regions, we contact business people only where the local rules for business email allow it.

Outreach we run for clients

When we run cold email or AI SDR programs for a client, the client decides who may be contacted, is responsible for having a lawful basis to contact them, and is the organization you are hearing from. We act as the client's service provider, as described in Section 2. In those programs:

  • Messages are sent from domains set up for the client, and identify the client.
  • We apply the client's suppression lists, exclude the client's existing customers and open deals where the client asks us to, and honour every opt-out across all of that client's campaigns.
  • A person reviews AI-drafted messages before they are sent.

5. How We Use Your Information

To deliver our services:

  • Scope, deliver, support and report on client work
  • Build, configure, migrate and run CRM, automation and AI systems for clients
  • Run outbound programs for clients, under their instructions
  • Communicate about projects, deliverables and support

To run our business:

  • Respond to enquiries and hold the meetings you book
  • Invoice, collect payment, and keep tax and accounting records
  • Manage relationships with clients, partners and suppliers
  • Understand how our website is used, and improve it and our services

For marketing:

  • Send newsletters and information about our services, where the law allows or you have agreed
  • Contact prospective clients, as described in Section 4
  • Measure which content and campaigns work

For legal and security reasons:

  • Comply with laws, regulations and valid legal requests
  • Protect our rights and the rights, safety and property of others
  • Detect and prevent fraud, abuse and security problems

6. AI and Automation

We use AI models, such as Anthropic's Claude, and automation platforms, such as n8n, Zapier, Make and Activepieces, to research accounts, draft and summarize content, enrich and route records, and monitor data quality. We do this both for our own work and in systems we build for clients.

  • People stay in charge. A person reviews outreach before it is sent. We do not use AI to make decisions about you that have legal or similarly significant effects.
  • No model training on your data. We use AI providers through business or API accounts whose terms do not allow the provider to train its models on the data we send. We do not use personal information to train AI models of our own.
  • Client systems stay with the client. AI systems we build for clients run in accounts the client owns, under the client's instructions.
  • Only what is needed. We send AI tools only the information needed for the task.

7. Legal Bases and Consent

Canada. We collect, use and disclose personal information with your knowledge and consent, which may be express or implied depending on the information and the purpose, as PIPEDA and applicable provincial laws allow. You may withdraw consent at any time, subject to legal or contractual limits, and we will tell you what that means for the service.

EU and UK. Where the GDPR or UK GDPR applies, we rely on:

  • Contract: to deliver services you or your company asked for, or to take steps before a contract
  • Legitimate interests: to run and improve our business and website, keep records, prevent fraud, and contact business people about services relevant to their role. We weigh these interests against your rights, and you can object at any time.
  • Consent: for newsletters where consent is required, and for any cookies that require it
  • Legal obligation: to meet tax, accounting and other legal requirements

India. Where the Digital Personal Data Protection Act, 2023 applies, we process personal data on the basis of your consent or for legitimate uses the Act permits, such as information you voluntarily provide for a specific purpose.

8. How We Share Your Information

We do not sell personal information, and we do not rent or trade contact lists.

Service providers

We share information with companies that provide services to us, under contracts that limit their use of it to providing those services. These include:

  • CRM, marketing and scheduling: HubSpot (our CRM, forms, meeting scheduler and email)
  • Website hosting: Vercel
  • Analytics and advertising measurement: Google Analytics, Microsoft Clarity and the LinkedIn Insight Tag
  • Productivity and storage: Google Workspace and cloud storage providers such as Amazon Web Services
  • AI and automation: Anthropic, and automation platforms such as n8n, Zapier, Make and Activepieces
  • Prospecting data and email delivery: business data and enrichment providers such as Clay, and email sending tools
  • Payments: payment processors such as Stripe and PayPal

Our delivery team

Members of our delivery team work from India and the Philippines. They may access client data and our business records to deliver services. They work under our direct management, are bound by confidentiality obligations, and access only what their work needs.

Partners

With a client's agreement, we may involve specialist partners, such as development agencies, consultants or technology vendors, for work outside our core services. Partners sign confidentiality or data processing agreements before they receive any personal information.

Legal reasons and business changes

We may disclose information where the law requires it, to respond to valid legal requests, or to protect rights and safety. If SpecSavi is involved in a merger, acquisition or sale of assets, personal information may transfer to the new owner, who must continue to protect it as this policy describes.

9. International Data Transfers

SpecSavi is based in Canada. Our service providers store and process data in other countries, mainly the United States, and our delivery team works from India and the Philippines. Information held in another country is subject to that country's laws and may be accessible to its courts and authorities.

  • We use contracts and security measures to protect information wherever it is processed.
  • For personal information from the EU, EEA or UK, we rely on adequacy decisions (including Canada's) where they apply, and otherwise on the European Commission's Standard Contractual Clauses or the UK equivalents.
  • For personal information about Quebec residents, we assess the protection it will receive before it is communicated outside Quebec, as Quebec law requires.

10. Data Retention

We keep personal information only as long as we need it for the purposes in this policy, or as the law requires.

  • Client business records (contracts, invoices, project records): for the engagement and seven years after it, for tax and legal purposes
  • Data we process for a client: as the client's contract instructs. By default, we return or delete it within 90 days after the engagement ends, except where the law requires us to keep it.
  • Enquiries, bookings and subscribers: until you unsubscribe or ask us to delete it, or three years after your last interaction with us
  • Prospecting records: up to 24 months after we last contacted you if you have not replied, then deleted
  • Opt-out and suppression lists: kept for as long as we send email, holding only what we need to honour your request, so that we never contact you again
  • Google Analytics: 14 months
  • Microsoft Clarity: according to Microsoft's retention schedule, currently 30 days for most session recordings
  • Legal holds: until the matter is resolved

When we no longer need information, we delete it or make it anonymous.

11. Data Security and Breaches

We use administrative, technical and physical safeguards suited to the sensitivity of the information, including:

  • Encryption in transit (TLS), and providers that encrypt data at rest
  • Access limited to the people who need it, with multi-factor authentication where our tools support it
  • Confidentiality obligations for our team, contractors and partners
  • Periodic reviews of who has access and of the providers we use

No system is completely secure. If a breach of security safeguards involving your personal information creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify you as soon as feasible, as PIPEDA requires. Where the GDPR or UK GDPR applies, we notify the relevant supervisory authority within 72 hours where required. Where we act for a client, we notify the client without undue delay so that they can meet their obligations.

12. Cookies and Tracking Technologies

Our website uses cookies and similar technologies. Our Cookie Policy lists each cookie and how long it lasts.

  • Essential: needed for the website to work
  • Analytics: Google Analytics and Microsoft Clarity, to understand how the website is used
  • Marketing: HubSpot, to connect website visits with enquiries and email engagement, and the LinkedIn Insight Tag, to measure our LinkedIn campaigns

These tools run only on www.specsavi.com. If your browser sends a Global Privacy Control signal, we do not load the LinkedIn Insight Tag. You can also block or delete cookies in your browser settings, although parts of the website may then work less well.

13. Your Rights and Choices

Everyone

Wherever you are, you can ask us to:

  • Tell you what personal information we hold about you and how we use it, and give you a copy
  • Correct information that is wrong or incomplete
  • Delete your information, subject to what the law requires us to keep
  • Stop sending you marketing or outreach
  • Withdraw your consent, where we rely on it

To opt out of email, use the unsubscribe link in any message or email privacy@specsavi.com.

Canada

Under PIPEDA you have the right to access your personal information and to challenge its accuracy. If you are not satisfied with how we handle your request or concern, you may complain to the Office of the Privacy Commissioner of Canada.

If you live in Quebec, you also have the rights given by Quebec's Act respecting the protection of personal information in the private sector, including the right to receive computerized personal information you provided in a structured, commonly used format. You may complain to the Commission d'accès à l'information du Québec.

EU, EEA and UK

You also have the rights to restrict processing, to object to processing based on legitimate interests or for direct marketing, and to data portability. You may complain to the data protection authority where you live or work, or in the UK to the Information Commissioner's Office.

India

Under the Digital Personal Data Protection Act, 2023, you may ask for a summary of your personal data and how it is processed, ask us to correct, complete, update or erase it, nominate another person to exercise your rights, and raise a grievance with us. Please contact us first. If we do not resolve your grievance, you may complain to the Data Protection Board of India.

United States

We do not sell personal information. Some US state laws treat advertising measurement tools, such as the LinkedIn Insight Tag, as "sharing" for targeted advertising. We honour Global Privacy Control signals, as described in Section 12, and you can also opt out by emailing us. Where a state privacy law applies to us, you can ask to know, correct or delete your information, and we will not treat you differently for asking.

How to make a request

Email privacy@specsavi.com. We may need to confirm your identity before we act on a request. We respond within 30 days, or sooner where the law requires, and tell you if we need more time and why. Requests are free unless they are clearly unfounded or excessive.

14. Children's Privacy

Our website and services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, please contact us and we will delete it.

15. Changes to This Privacy Policy

We update this policy when our services, tools or legal obligations change. We will change the "Last Updated" date at the top of this page. For material changes, we will also post a notice on this page and, where we have your email address and the change affects you, email you before it takes effect. Where the law requires your consent to a change, we will ask for it.

16. Contact Us and Complaints

Our Privacy Officer is responsible for our compliance with this policy and with privacy law, and handles requests, questions and grievances from every region, including Quebec, the EU, the UK and India.

Privacy Officer

Email: privacy@specsavi.com
Organization: SpecSavi Ltd.
Location: Toronto, Ontario, Canada

Response Time: We respond to privacy requests within 30 days of receipt.

If we cannot resolve your concern, you can contact the authority for your region, listed in Section 13.

Next: Cookie Policy →