Trust

Security, privacy and compliance

Buying contact data means trusting someone with other people's details. This page sets out exactly how we hold them, who can reach them, how long we keep them and how anyone can have theirs removed.

Controls

What is in place today

Access control

One owner account, decided inside the database rather than by anything a browser can claim. Every client workspace is isolated by row-level security, so one customer's records can never be read by another.

Audit trail

Every privileged action and every refused attempt is written to an audit log with the account, the target and the time. Privacy requests record what was found and what was removed.

Encryption

Data is encrypted in transit and at rest. Secrets live only in the server runtime and an automated check fails the build if a private key or supplier name can be read from the browser.

Retention

A daily sweep deletes stored contact files 90 days after delivery. Exports are generated on demand rather than piling up.

Backups and recovery

The database is backed up automatically by the managed platform with point-in-time recovery. Restores are tested before any schema change of consequence.

Vendor review

Every subprocessor is reviewed before use and recorded, covering hosting, database, payments, email and data supply.

Abuse prevention

Public forms are rate limited per address, screened for automated submission, and free text is stripped of anything that could act as an instruction further down the line.

Secure development

Dependencies are scanned for known vulnerabilities, every server action passes a single shared permission gate, and public endpoints verify the caller before doing anything.

Your rights

GDPR, UK GDPR and California

Europe and the UK

You can ask to see what we hold, have it corrected, have it deleted, restrict how it is used, object to it being used at all, or receive a copy in a file. We answer within 30 days, free of charge. Business records are held on the legitimate interests basis for business-to-business contact, and an objection ends that immediately and permanently.

California

You can ask what categories we hold and where they came from, ask for deletion or correction, and tell us never to share your information. We answer within 45 days and never treat anyone differently for asking. The do-not-share instruction takes effect the moment it is submitted.

Subprocessors

Who else touches the data

CategoryPurposeRegion
Cloud hosting and edge deliveryServing the site and running background workUnited States
Managed database and file storageStoring accounts, contacts and documentsUnited States
Object storageCompressed contact archiveUnited States
PaymentsSubscriptions and invoicesUnited States
Transactional emailDelivery of lists and account emailUnited States
Business data suppliersLicensed business contact recordsUnited States and Europe

Named suppliers and full processing details are shared under a signed data processing agreement.

Questions

Common compliance questions

Where does the contact data come from?

Business contact records are licensed from established business data suppliers and enriched from publicly available professional sources. We publish the categories of source rather than naming individual suppliers, which is standard practice and protects both sides of those agreements.

What is the lawful basis for holding business contacts?

Legitimate interests for business-to-business outreach, as recognised under UK and EU GDPR. Every record is business contact information: a work role, an employer, a work email and a business number. We run a balancing test, honour objections immediately, and never build special category data.

How does someone remove themselves?

Through the privacy request page or the opt-out page, with no account and no cost. Removal is permanent: the person is added to a do-not-contact list that every build and every delivery checks before anything is created or sent.

Are you SOC 2 certified?

Not yet. The controls a SOC 2 Type II audit tests are in place and evidenced: least-privilege access, row-level database isolation, full audit logging of privileged actions, encrypted data at rest and in transit, automated backups, retention limits and vendor review. Formal certification requires an independent auditor over an observation window, which is the next step.

How long is client data kept?

Exported contact files are deleted 90 days after delivery by an automatic daily sweep. Documents a client uploads themselves stay until the client deletes them or closes the account. Delivered records stay in the client's own workspace, visible only to that client.

Do you sell personal information?

We do not sell personal information in the ordinary sense, and Californians can still tell us never to share theirs. That instruction takes effect the moment it is submitted, before anyone reviews it.