Privacy policy
Effective 21 July 2026
Peragam is operated by Adria Holding Ltd, a company registered in England and Wales (company number 16090876), with its registered office at Flat 3 Bench Apartments, 22 Kings Bench Street, London SE1 0QX, United Kingdom. In this policy, “Peragam”, “we”, and “us” mean Adria Holding Ltd.
This policy explains what personal data we collect when you visit peragam.com or use the Peragam platform, why we collect it, who we share it with, and the rights you have over it. Questions and requests about this policy go to alex@adriaholding.co.uk.
Our two roles
For your account, billing, and our website, Adria Holding Ltd is the data controller: we decide why and how that data is processed.
Peragam also does work on our customers’ instructions: sourcing sales prospects, sending outreach, posting to accounts a customer has connected, and running ad campaigns in a customer’s own ad account. For personal data processed in that work, the customer is the controller and we act as their processor (or “service provider” under US state law). We process that data only on the customer’s documented instructions.
Data we collect
- Account data. Your name, email address, and a hashed password — we never store passwords in plain text. If you sign in with Google, we receive your name and email address from your Google account instead.
- Workspace content. The companies you create, task briefs, task outputs, verification receipts, and approval decisions. This can include personal data you choose to put in it.
- Billing data. Subscription and payment records held with Stripe, our payment processor. Card numbers go directly to Stripe and never touch our servers.
- Connected-account credentials. When you connect an external account (for example Google Ads, Meta, X, or LinkedIn), we store the resulting access credentials encrypted, and use them only to act on your instructions in that account.
- Prospect data (processed for customers). Business contact details — name, job title, company, and work email — sourced from data providers and verified, at a customer’s direction, to run their sales outreach. Prospect sourcing is currently limited to United States business contacts.
- Technical data. Server logs including IP address, browser type, and request metadata, kept for security and troubleshooting.
- Correspondence. Emails you send us, including replies to outreach and support requests.
Our performance analytics are aggregated and cookieless (Vercel Speed Insights). We do not run advertising trackers or cross-site analytics on peragam.com.
Why we use it, and the legal basis
- Providing the service — operating your account, running and verifying tasks, billing, and transactional email (performance of a contract).
- Waitlist and access emails — if you join the waitlist, we use your email to contact you about access. You can opt out at any time (consent).
- Security and abuse prevention — log analysis, rate limiting, and fraud prevention (legitimate interests in keeping the platform safe).
- Legal compliance — tax, accounting, and responding to lawful requests (legal obligation).
- Customer-directed work — prospect sourcing, outreach, social posting, and ad campaigns, performed as a processor on the customer’s instructions; the customer holds the controller’s legal basis.
We do not use automated decision-making that has legal or similarly significant effects on you.
Google user data
If you sign in with Google we receive only your basic profile (name and email). If you connect Google Ads, we receive OAuth tokens scoped to the Google Ads API and your ad account identifiers, and we use them solely to create and check the advertising campaigns you have approved, funded by your own ad account. We store these tokens encrypted and never use Google user data for advertising to you, profiling unrelated to the service, or resale.
Peragam’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies
We set only strictly necessary cookies: your sign-in session and short-lived security cookies used during account connection flows (for example, OAuth state). We set no advertising, preference, or third-party tracking cookies, which is why you do not see a cookie banner.
Who we share data with
We never sell personal data, and we do not share it for cross-context behavioural advertising. We share data only with service providers that run parts of the platform, under contracts restricting them to processing on our instructions:
- Supabase — managed database hosting.
- Vercel — application hosting and content delivery.
- Fly.io — the isolated machines that execute tasks.
- Cloudflare — DNS, artifact storage, and encrypted backups.
- Stripe — subscription payments; customer revenue runs through the customer’s own Stripe account.
- Resend and Maildoso — email delivery for transactional email and customer-approved outreach.
- Anthropic — the AI model provider that processes task content to perform work. Under its API terms this data is not used to train models.
- GitHub — private repositories holding work product.
- Apollo and Reoon — business-contact sourcing and email verification, used only for customer-directed prospecting.
- Google, Meta, X, LinkedIn — only when a customer connects their own account on that platform, and only to act in it as instructed.
We may also disclose data where the law requires it, to protect our rights or users, or as part of a corporate transaction such as a merger or acquisition, in which case this policy continues to apply to the transferred data.
International transfers
We are a UK company and most of our service providers process data in the United States. Where personal data leaves the UK or the EEA, we rely on safeguards recognised under UK and EU law: the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, and, where a provider is certified, the EU–US Data Privacy Framework and its UK Extension.
How long we keep it
- Account and workspace data — for as long as your account is active. When you delete your account, we delete it, and it rolls out of encrypted backups within 90 days.
- Connected-account credentials — until you disconnect the account or delete your account, whichever comes first.
- Billing records — up to six years, as UK tax law requires.
- Prospect data — for the duration of the customer campaign it serves. Opt-outs go on a suppression list so the person is not contacted again.
- Server logs — short-lived and rotated automatically.
Security
All traffic is encrypted in transit. Connected-account credentials are encrypted at rest with per-workspace keys, and every workspace’s data is isolated by database-level row security. Task execution happens in sandboxed machines with default-deny network egress, and passwords are stored only as salted hashes. The security page describes the trust model in full.
Your rights
If you are in the UK or EEA, you can ask us for access to your personal data, correction, deletion, restriction, portability, or object to processing based on legitimate interests, and withdraw consent at any time where consent is the basis. You can also complain to the UK Information Commissioner’s Office at ico.org.uk.
If you are a resident of a US state with a comprehensive privacy law (including California, Colorado, Connecticut, Texas, and Virginia), you can ask to know, access, correct, or delete the personal data we hold about you, and to opt out of sale, sharing, or targeted advertising — noting that we do none of those. We will not discriminate against you for exercising these rights, and if we decline a request you may appeal by replying to our response.
To exercise any right, email alex@adriaholding.co.uk from the address associated with your data. We verify requests before acting on them and respond within the timelines the applicable law sets. Where we hold data as a customer’s processor, we will refer your request to that customer and support them in answering it.
If a Peragam customer contacted you
If you received a sales email sent through Peragam, your business contact details were sourced from a business-contact data provider at the direction of the customer named in the message. Reply to the message or email alex@adriaholding.co.uk to opt out; we add opt-outs to a suppression list so Peragam-sent campaigns do not contact you again.
Children
Peragam is a business tool for adults. It is not directed at anyone under 18, and we do not knowingly collect personal data from children.
Changes to this policy
When we change this policy we will post the new version here with a new effective date, and for material changes we will notify account holders by email. The effective date at the top of this page always tells you which version you are reading.