Legal
Privacy Policy
Effective July 21, 2026.
Who we are and when this policy applies
Intakra is a signal-driven go-to-market platform operated by Soxoa LLC ("Intakra", "we", "us"), based in Sacramento, California, USA. This policy covers intakra.com, Intakra accounts and workspaces, public scans and lead forms, support, billing, integrations, and customer-configured signal and outreach features. Questions and privacy requests may be sent to [email protected].
Our roles
Soxoa LLC acts as an independent controller or business for account administration, billing, security, our website and lead forms, service operations, consented analytics, and business information that Intakra independently selects and uses for its own purposes. Intakra is not currently offering processor or service-provider terms; /dpa is a release-status notice, not an operative addendum. Do not submit personal data that requires processor or service-provider terms unless Intakra confirms the applicable data flow and terms in writing before use.
Account, authentication, and workspace information
We process your name, work email, account identifiers, password hash or authorized sign-in profile, session and verification records, IP address, user agent, workspace membership and role, company domain, ICP, offer and value proposition, signal definitions and weights, settings, integration configuration, support communications, and any files or records you choose to import. Connected CRM and identity providers may also give us authorized profile fields, OAuth tokens, scopes, and selected CRM records.
Target-account, professional contact, and signal information
We process company names, domains, descriptions, industries, locations, employee ranges, technology and hiring data, public profile links, provider identifiers, funding and company events, source links and excerpts, professional names, job titles, seniority, business email addresses and phone numbers, and related verification status. We create signal matches, fit and timing scores, explanations, source citations, account recommendations, and other inferences. This information can come from customers, connected CRMs, public websites and job boards, licensed business-data providers, and grounded web research.
Generated content, assessment activity, and outbound records
We process prompts, customer instructions, generated assessments and outreach drafts, source citations, review and publication state, page-view counts, and the most recent viewing time for shared assessments. If a customer uses sending features, we process sender and recipient business contact details, subject and message body, sending domain, sequence state, sent status, bounces when reported, unsubscribe requests, and replies. Intakra does not add open-tracking or click-tracking pixels to its current sequenced outbound email. We use suppression records to screen future customer-directed sends after an address or domain is added to a suppression list.
Website, scan, lead, billing, and technical information
Public scans process the submitted domain, generated scan results, and limited request information used for abuse prevention, including IP-address rate-limit records. Lead forms process the work email, company domain, market or ICP, source, fulfillment status, and optional marketing choice you submit. A report request is used to fulfill that request. Only a separately selected checkbox causes us to stage up to three related Intakra product follow-ups; each includes an unsubscribe method, and opting out stops later staged messages. Billing records include Stripe customer and subscription identifiers, plan, billing status, discounts, renewal information, invoices, and transaction metadata; full payment-card details do not pass through Intakra servers. We also process necessary logs, request data, device and browser details, errors, and security events.
How we use information
We use information to create and secure accounts; operate workspaces; discover, enrich, rank, and explain business signals; generate and host assessments; verify sending domains; carry out customer-directed CRM, alerting, and email actions; classify replies; provide support; process billing; prevent abuse; troubleshoot and monitor reliability; measure product use where permitted; comply with law; enforce agreements; and protect people, rights, and the Service.
Legal bases in the EEA and UK
When Soxoa LLC acts as controller and GDPR or UK GDPR applies, we rely as appropriate on performance of a contract, legitimate interests in operating, securing, supporting, and improving a business service, consent for optional browser analytics or marketing where required, and compliance with legal obligations. We balance legitimate interests against individual rights.
Cookies, local storage, and analytics consent
Necessary cookies and similar storage keep you signed in, preserve security state, and remember essential preferences. Optional PostHog browser analytics do not initialize until you affirmatively choose Allow analytics. Declining does not affect core functionality. The choice is stored in your browser and can be changed through Analytics choices in the site footer. We disable optional browser analytics when a recognized Global Privacy Control or Do Not Track signal is active. Intakra does not run Meta Pixel or another third-party advertising or retargeting pixel. Sentry may receive limited error and request context for service security and reliability; session replay is disabled in the current configuration.
AI processing
Feature-specific prompts are routed through OpenRouter to the selected model provider. Depending on the feature, a prompt may contain public signal text, company context, customer instructions, an assessment draft, outreach content, or a reply that needs classification. Current model routes include Anthropic models and Perplexity Sonar for grounded web research. We limit the prompt to context needed for the request. Those providers handle the submitted context under their applicable service terms, settings, and privacy commitments.
Providers and disclosures
We disclose information only as needed for the feature involved. Core providers include Vercel, Neon, OpenRouter and routed model providers, Resend, and Trigger.dev. AgentMail and its AWS SES infrastructure process customer-directed email. Optional or feature-dependent providers include PostHog, Sentry, Langfuse, Cloudflare/R2, Composio, Svix, Stripe, identity providers, connected CRMs, and Slack. Business information may be obtained or verified through Apollo, TheirStack, BuiltWith, Exa, Abstract API, and optional sources such as Lusha, Crunchbase, or Indeed. The Trust page identifies each provider's purpose and status. Some data sources and customer-connected services act as independent controllers under their own notices rather than as our subprocessors.
Other disclosures
We may disclose information to professional advisers and authorities where reasonably necessary to comply with law, protect rights and safety, investigate abuse or fraud, or establish or defend legal claims. If Soxoa LLC is involved in a merger, financing, reorganization, sale of assets, or similar transaction, information may be reviewed or transferred subject to appropriate confidentiality and this policy. We do not sell personal information for money and do not share personal information for cross-context behavioral advertising.
Data retention
Retention depends on the record and why it is needed. Account, workspace, CRM, target-account, generated-content, and outreach records are generally kept while the workspace is active and afterward only as needed for customer instructions, disputes, security, legal obligations, or an orderly return or deletion process. Suppression records are kept as long as reasonably necessary to honor opt-outs. Billing and tax records are retained for required legal periods. Public scan results may be cached to provide and improve the scan. Scan IP rate-limit records become eligible for deletion after 48 hours, and deterministic cleanup runs at the start of each quota check. Optional analytics and error data follow the configured provider retention and our operational need. Deletion from active systems may not immediately remove encrypted backups, which age out through normal backup cycles.
International processing
Soxoa LLC is based in the United States, and providers may process information in the United States or other countries. Where a restricted international transfer requires a legal mechanism, the relevant parties will use a mechanism recognized by applicable law. Contact us for transfer information relevant to your use of the Service.
Your privacy rights
Depending on your location and our role, you may have rights to access, correct, delete, or receive personal data; object to or restrict processing; withdraw consent; opt out of certain marketing; and complain to a regulator. You may exercise a right at [email protected]. Authenticated workspace owners and administrators may also export workspace data from Settings. We may need to verify identity and authority. Withdrawing consent does not affect earlier lawful processing.
California and other US state notices
The categories described above include identifiers, customer records, commercial information, internet or network activity, professional or employment information, geolocation at city or region level, and inferences. Sources, purposes, and recipient categories are described in this policy. Where an applicable US state law grants a right to know, correct, delete, obtain a copy, opt out, limit certain sensitive-data use, use an authorized agent, or appeal a decision, submit the request to [email protected]. We do not offer a financial incentive for personal information. Because we do not sell personal information or use it for cross-context behavioral advertising, Global Privacy Control does not trigger a sale or sharing opt-out, but it does keep optional PostHog browser analytics disabled.
Business contacts obtained indirectly
Intakra often receives professional contact and company information from a customer, public source, connected CRM, or licensed business-data provider rather than directly from the individual. Where Soxoa LLC acts as controller and applicable law requires direct notice, we will provide it or document an applicable exception and safeguards. A recipient can reply with an opt-out or contact [email protected] for the source and handling of their record.
Security
We use encryption in transit, access controls, workspace-scoped data access, protected credentials, logging, monitoring, and incident-response procedures appropriate to the Service. No system is perfectly secure. If a personal-data incident creates a legally required notice or assistance obligation, we will handle it under applicable law.
Children
Intakra is a business service and is not directed to children. Do not use it to submit information about anyone under 16.
Changes and contact
We will revise the effective date when this policy changes and provide additional notice when a change materially affects privacy rights. Contact Soxoa LLC, 3575 Arden Way, Unit #2173, Sacramento, CA 95864 at [email protected].