DATA PRACTICE

6sense Privacy Policy

Effective July 20, 2026

This informational site

This site presents installation and workflow information. It does not include a lead form or request sales contact. Standard infrastructure may process basic request information such as IP address, browser details, timestamps, and requested pages for delivery and security. Such request data should not be used as a substitute for consent to sales outreach.

Agent and provider data

Installing the skill is separate from visiting this site. The data processed by an installed workflow depends on your agent runtime, selected providers, configuration, and destination systems. Review each component before connecting business or personal data. Determine which party controls each dataset, why the field is necessary, and which regional requirements apply before beginning production research.

Credentials

Store API keys using your runtime's supported secret mechanism. Do not paste credentials into prompts, public issues, analytics fields, or committed files. Rotate or revoke keys when access is no longer needed. Scopes should be limited to the task being tested, and separate environments should use separate credentials where the provider supports that boundary.

Research records and inference

Company facts, contact details, intent observations, and inferred buying roles are different data classes. Keep inference visibly separate from a sourced observation. Before exporting a record, review its provenance, freshness, permitted use, suppression status, and whether the business purpose justifies retaining it.

Retention and deletion

Retention is configuration-dependent across the runtime and connected services. Establish a deletion procedure for local artifacts, provider records, exports, logs, and downstream destinations before production use. Removing the skill from an agent does not automatically delete a spreadsheet, CRM entry, provider record, cached response, or backup held elsewhere.

Security and disclosure

Use approved devices, current runtime versions, least-privilege credentials, and sanitized logs. If public documentation does not disclose a security property, treat it as not disclosed rather than verified. Send incident information only through an appropriate private channel and never include live credentials or unredacted contact data.

Your choices

You can avoid installing the package, decline optional connections, limit permissions, remove local components, and revoke provider access. Contact the relevant service provider for rights concerning data it independently controls. Your organization should document correction, objection, suppression, export, and deletion handling for every destination used by the workflow.