Inflection Point Business Development Platform
Privacy Policy
Last updated: September 13, 2026
This policy explains how Inflection Point ("we," "us") processes information through the Inflection Point Business Development Platform ("BDP"). It covers visitors, authorized workspace users, and people whose business contact information or correspondence is managed in the BDP.
Workspace organizations determine their own research and outreach purposes. Their separate privacy notices may also apply. Contact us at julie.wohlberg@meetinflectionpoint.com with questions about our handling of information.
1. Information we process
- Account and workspace information: names, email addresses, account identifiers, memberships, permissions, settings, and activity history.
- Business research: company websites, public business information, professional contact details, source evidence, qualification decisions, notes, and information imported or supplied by authorized users or configured providers.
- Outreach information: templates, AI instructions and outputs, draft and sent message content, recipients, replies, campaign status, delivery events, and suppression or unsubscribe records.
- Connection information: provider identifiers, granted permissions, encrypted OAuth credentials or API credentials, and integration status.
- Operational information: request identifiers, timestamps, technical errors, usage and cost records, audit events, and infrastructure logs, which may include IP addresses and browser information.
We use this information to provide research, review, drafting, delivery, reply handling, reporting, support, access control, and abuse prevention. Some records are created by automated processes configured by a workspace administrator.
2. Google and Gmail data
A Google connection is optional and requires authorization. Depending on the enabled integration and permissions granted, the BDP can access your Google account identifier and email address; Gmail message and thread identifiers; labels, headers, participants, timestamps, subjects, snippets, and message content; and drafts or sent-message information relevant to outreach.
This access supports identifying the connected mailbox, creating or updating Gmail drafts where enabled, sending authorized outreach where enabled, matching replies and delivery notices, observing sent messages, and preventing inappropriate follow-ups. Read permissions can technically cover more mailbox data than the outreach records shown in the BDP; they are used for these mailbox features, not to build an unrelated profile of your personal communications.
Relevant message content and metadata may be stored in the BDP with the associated workspace's outreach records. We store OAuth credentials encrypted rather than asking for or storing your Google password. An authorized connection may remain active between visits so configured background work can continue.
Google-connected information is handled under the Google API Services User Data Policy and its Limited Use requirements. We do not sell Google user data, use it to target advertising, or use it to train general-purpose AI models. Transfers are limited to authorized user-facing features, security, applicable legal obligations, or a business transfer with the consent required by Google's policy.
Access to mailbox content by people is limited to the user-authorized workflow and permitted circumstances, such as your affirmative permission for support, necessary security investigation, or legal compliance. Connecting a mailbox does not authorize unrestricted staff review.
You can revoke the BDP's access through Google Account connections. Revocation prevents further authorized API access once it takes effect, but does not automatically delete previously stored BDP records or copies already delivered to recipients.
4. Cookies and outreach measurement
The BDP uses session and security cookies for sign-in and request protection, and browser storage for interface preferences. These public product and policy pages do not embed advertising trackers or third-party analytics scripts.
Where a workspace enables email measurement, messages may contain an open-tracking image and tracked links. Records can include an opaque tracking identifier, event time, link destination, and limited technical information used to distinguish automated traffic. Opens are estimates, not proof that a person read a message.
First-party website attribution, when configured, can associate consented visits, page activity, and conversion events with outreach. Its availability and data collection depend on the site's integration and consent choices. A website's own notice applies to its separate analytics. See the email measurement notice for additional information.
5. Storage, protection, and retention
We use encrypted credential storage, access controls, workspace boundaries, and HTTPS for the hosted application. No system can guarantee absolute security.
Business records, correspondence, and audit history are retained for workspace operations, continuity, security, and applicable obligations. Retention differs by record type and workspace configuration; analytics retention controls are separate from company and correspondence records. We do not promise that disconnecting an integration automatically erases all associated data.
Request deletion through your workspace administrator or the contact below. We may verify your identity and authority before responding. Some information may need to remain for legal or security reasons, required audit history, or suppression of further unwanted contact. Backup copies may remain until their normal replacement or expiry. We will explain applicable limits when handling your request.
6. Your choices and requests
You may ask to access, correct, export, or delete information about you, or object to or restrict particular processing, subject to applicable law and the rights of others. Contact julie.wohlberg@meetinflectionpoint.com and identify the workspace or message involved. Do not include passwords, access tokens, or other secrets.
Recipients can use the unsubscribe link where provided or reply requesting no further outreach. We may retain a minimal suppression record to honor that choice. Workspace administrators can control integrations and campaign activity; mailbox owners can independently revoke Google access.
7. Children and policy changes
The BDP is intended for adult business users, not children. We update this policy when our practices change and show the latest revision date here. Material changes to connected Google data use require appropriate notice and any necessary renewed consent before the new use begins.
8. Contact Inflection Point
For privacy, access, deletion, or support requests: julie.wohlberg@meetinflectionpoint.com.