> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firsttouch.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Processing & Security

> How First Touch processes, enriches, and protects your data.

<Note>
  **Disclaimer:** This overview is provided for information purposes only and does not constitute legal advice. Customers are responsible for configuring First Touch to comply with applicable laws.
</Note>

## Roles & Scope

First Touch is purpose-built for B2B sales and go-to-market teams. We define our data relationship with you in two ways:

* **Customer as Controller:** You control the data related to your prospects, customers, and users ("Customer Data"). We act as the **Data Processor**.
* **First Touch as Controller:** For our own account management, billing, and marketing data, we act as the independent **Data Controller**.

## Data We Collect

We aggregate data from four primary sources to power your workspace.

<CardGroup cols={2}>
  <Card title="Directly Provided" icon="user" iconType="duotone">
    **Account & Contact Data**

    * Name, role, team membership
    * Workspace settings & templates
    * Billing details (via PCI processor)
    * Support tickets & screenshots
  </Card>

  <Card title="Integrations" icon="plug" iconType="duotone">
    **From CRM & Email Tools**

    * CRM records (Salesforce, HubSpot)
    * Outreach sequences & templates
    * Email content & activity metrics
    * *You retain ownership of this data*
  </Card>

  <Card title="Product Usage" icon="chart-simple" iconType="duotone">
    **Telemetry & Logs**

    * IP address & approximate region
    * Browser/Device type
    * Feature usage & UI interactions
    * Error logs & timestamps
  </Card>

  <Card title="Enrichment" icon="globe" iconType="duotone">
    **Public Business Data**

    * Public social profiles (LinkedIn etc.)
    * Company websites & tech stacks
    * Funding, hiring, & news data
    * Vendor-provided firmographics
  </Card>
</CardGroup>

<Warning>
  We do not knowingly collect or infer "special category" data (health, religion, political opinions) or target minors.
</Warning>

***

## AI Architecture & Privacy

First Touch utilizes AI to power research, summarization, and content generation. We prioritize data privacy in our AI implementation.

### What We Process

* **Inputs:** Prompts you type, context you highlight, and prospect attributes attached to the prompt.
* **Outputs:** The AI-generated text (emails, scripts) and quality signals (edits, ratings).

<Check>
  **No Public Training:** By default, **we do not authorize third-party model providers to use your Customer Data for training their general models.** We send only the minimum necessary data (prompt + context) to generate the requested output.
</Check>

***

## Security & Compliance

<AccordionGroup>
  <Accordion title="Third-Party Sub-Processors" icon="server">
    To deliver a secure and reliable service, we utilize best-in-class third-party vendors.

    | Category                 | Examples                              |
    | :----------------------- | :------------------------------------ |
    | **Cloud Infrastructure** | AWS, Google Cloud (Hosting & Storage) |
    | **Analytics**            | PostHog (Logging & Performance)       |
    | **Support**              | Pylon                                 |
    | **Intelligence**         | OpenAI, Anthropic, Gemini (AI Models) |

    *A detailed sub-processor list is available on the [Approved Subprocessors](/approved-subprocessors) page.*
  </Accordion>

  <Accordion title="Security Measures" icon="lock">
    We implement technical and organizational measures aligned with modern SaaS standards:

    * **Access Control:** Network and application-level restrictions; least-privilege access for production.
    * **Encryption:** Data is encrypted in transit (TLS 1.2+) and at rest (AES-256) where appropriate.
    * **Monitoring:** Continuous logging of critical systems and defined incident response procedures.
  </Accordion>

  <Accordion title="Data Retention & Deletion" icon="trash">
    We retain data only as long as necessary:

    * **Account Data:** Life of account + reasonable period for tax/audit.
    * **Product/AI Data:** While workspace is active + limited period for support.
    * **Logs:** Short retention (e.g., 30–365 days).
    * **Backups:** Limited rolling window.

    Upon termination or valid request, we delete or de-identify Customer Data in accordance with our DPA.
  </Accordion>

  <Accordion title="Your Privacy Rights (GDPR/CCPA)" icon="gavel">
    **Legal Bases (GDPR):** Performance of Contract, Legitimate Interests, and Consent.

    **Your Rights:** Depending on your jurisdiction, you have the right to **Access**, **Correct**, **Delete**, **Restrict**, or **Port** your data. We also support **Opt-out** mechanisms for marketing or "selling/sharing" as defined by CCPA.
  </Accordion>
</AccordionGroup>

## Contact Us

For security reviews, DPA requests, or privacy inquiries, please reach out to our team.

<CardGroup cols={1}>
  <Card title="Contact Security Team" icon="envelope" href="mailto:info@firsttouch.com">
    Email us at [**info@firsttouch.com**](mailto:info@firsttouch.com) or visit our [Contact Page](https://firsttouch.com/contact).
  </Card>
</CardGroup>
