Privacy & Security
Data Transparency
We believe in responsible data practices. Our platform aggregates publicly available business information from vetted third-party providers and applies strict security, privacy, and access controls to protect it.
Standards & Certifications
Backed by enterprise-grade infrastructure & standards.
GDPR Aligned
Data practices aligned with EU data protection framework.
CCPA Aligned
Opt-out and data subject rights for California residents.
Full Encryption
AES-256 at rest, TLS 1.2+ in transit across all systems.
SOC 2 Infrastructure
Hosted on SOC 2 Type II certified platforms (AWS/Supabase).
Ethical Sourcing
Public data only from vetted, compliant providers.
Our Framework
Our data collection principles.
Public Sources Only
We aggregate data exclusively from publicly available web sources and vetted third-party data providers. We never scrape behind login walls, paywalls, or secured areas.
Vetted Providers
Every third-party data source in our pipeline meets strict compliance standards. Our providers maintain their own GDPR, CCPA, and SOC 2 certifications, and we contractually require adherence to privacy regulations.
Transparency First
We openly disclose how data is collected, processed, and used. Individuals and businesses can see what information is displayed and request corrections or removal at any time.
Data Minimization
We collect only the business-related information necessary to serve our users. We do not aggregate sensitive personal data, private records, or information beyond professional and commercial context.
Data Scope
A clear breakdown of the types of information in our platform.
Data We Process
- Public company information (name, website, industry, size)
- Publicly listed job postings and hiring data
- Business professional profiles from public sources
- Business contact information (professional email, title)
- Industry and event data from public announcements
- Product and service catalogs from company websites
- Customer-supplied data (with explicit consent)
Data We Never Collect
- Private personal data not publicly available
- Social security numbers or government IDs
- Home addresses or personal phone numbers
- Biometric, health, or geolocation data
- Financial records or credit information
- Data from secured login areas or private networks
- Material non-public information (MNPI)
Security
Security & privacy practices.
Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.2+. Our database infrastructure runs on SOC 2 Type II certified cloud platforms with automatic key rotation.
Access Control
Role-based access control with row-level security policies on every database table. Administrative access requires multi-factor authentication and is restricted to authorized personnel only.
Data Retention
We maintain defined retention periods for all data categories. Cache data is automatically purged on a regular schedule. When customers leave our service, their data is deleted in accordance with our retention policy.
Incident Response
We maintain an incident response plan and monitor our systems for unauthorized access. In the event of a security incident, affected parties are notified in accordance with applicable regulations.
Monitoring & Logging
All data access is logged and monitored. We track API usage, authentication events, and data queries to detect suspicious activity patterns and ensure accountability.
Vendor Compliance
Our third-party data providers maintain SOC 2, GDPR, and CCPA certifications. We contractually require all partners to adhere to privacy regulations and ethical data collection standards.
Infrastructure
Security controls — all active.
Privacy Rights
Your rights.
Right to Access
Request a copy of any personal information we hold about you. We respond within 30 days.
Right to Correct
If any information about you is inaccurate, submit a correction request and we'll update it promptly.
Right to Delete
Request removal of your information from our database at any time. We process opt-out requests promptly.
FAQ
