Trust

Trust Center

How Fullinfo handles privacy, security, and your data. Plain language, real practices, written by the people who actually do the work.

Fullinfo is a B2B data company. We hold information about businesses and the professionals who work in them. Companies that hold data have power, and power without restraint produces predictable failure modes. We’ve tried to build the opposite of that — a platform where what we collect, how we store it, and what happens when someone asks us to stop are all questions with clear, honest answers.

Privacy by design isn’t a policy. It’s a set of structural choices that show up in the product, the data model, and how we respond when a regulator or an individual contacts us. The choices we made — and didn’t make — are what this page is about.

This Trust Center is where we publish everything related to those choices: the legal documents, the technical practices, the sub-processors we use, the security measures we apply, and how to reach us if you’re a customer, a procurement team, or an individual exercising your rights.

Compliance
GDPR-aligned
Hosting
EU · Frankfurt + US · Ohio
Breach notification
Within 72 hours
Sub-processor changes
30-day notice
Removal requests
Immediate & permanent
How we operate

Six structural commitments

01

Minimize what we collect

We collect what is needed for business identification and professional contactability — and not more. No personal phone numbers, no home addresses, no data from breach dumps or sources with unclear chain of custody. The temptation to expand the dataset is constant in this industry; we resist it deliberately.

02

Source provenance on every record

Every data point in Fullinfo carries the URL it came from and when it was last seen there. If you can’t see where a record came from, you can’t audit it — for accuracy, for legal basis, or for whether you should be using it. We treat provenance as a first-class field, not a footnote.

03

Permanent suppression infrastructure

When a person asks to be removed, removal is immediate and complete — deleted from our database, added to a permanent suppression list so they aren’t re-ingested from any source, and removed from every customer Collection that contains them. Active monitoring of that person stops everywhere. There is no delay, no grandfathering, no override.

04

Controller status, taken seriously

For the records in our database, we are a controller under GDPR — not a passive intermediary. For the data our customers place into Fullinfo on their own behalf, we are a processor. Both relationships carry obligations we accept explicitly, in writing. Our Data Processing Agreement describes them in detail.

05

Subject rights as a real product surface

Access, rectification, erasure, and objection requests are handled through a dedicated request page, with verification, status tracking, and confirmation. Not a generic privacy inbox. Not a 30-day wait followed by silence. Real people, working a real process, within statutory timeframes.

06

Honest disproportionate-effort posture

GDPR Article 14(5)(b) recognizes that contacting every data subject individually can be disproportionate for a database built from public sources. We invoke that provision honestly — with a publicly available notice, a clear removal path, and a record we can show a regulator on request. Not as cover for opacity.

Infrastructure

Where data lives and who touches it

Customer Data is hosted on Amazon Web Services in Frankfurt (EU) and Ohio (US). The complete list of sub-processors that touch Customer Data — what they do, where they process, and what transfer mechanism applies for non-EU locations — is in Annex 1 of our DPA.

Amazon Web Services
Cloud hosting and infrastructure
Infrastructure
Frankfurt (EU), Ohio (US)
Google (Gemini API)
AI processing for enrichment, entity resolution, search ranking
AI
EU and US
Google Workspace
Email, document collaboration, productivity for Fullinfo personnel
Productivity
EU and US
Auth0
Authentication, identity, session management
Auth
EU and US
Atlassian (Jira)
Engineering, support ticketing
Internal tools
EU and US
Slack
Internal communications
Internal tools
US

Transfers to non-EU locations operate under the 2021 Standard Contractual Clauses. Changes to this list are notified at least 30 days in advance per Section 5.7 of the DPA. Subscribe to changes at privacy@fullinfo.com.

Security

How we protect data

The full set of technical and organisational measures is in Annex 2 of our DPA. The headlines:

Encryption

TLS 1.2+ in transit. AES-256 at rest. Encrypted backups. Keys managed via cloud provider KMS.

Access control

Personnel access restricted to role-required need. Individual authenticated accounts. Multi-factor authentication required. Periodic review.

Breach notification

Customer notification within 72 hours of our becoming aware. Updates as the investigation progresses. Assistance with your own notification obligations.

Personnel security

Written confidentiality obligations. Data protection training appropriate to role. Access revoked promptly on role change or departure.

Business continuity

Regular backups with tested restoration. Multi-zone deployment. Documented recovery procedures for critical operations.

Sub-processor oversight

Pre-engagement assessment for security and data protection. Contractual obligations consistent with our DPA. Ongoing monitoring of third-party posture.

Formal certifications (ISO 27001, SOC 2) are not yet in place. We’ll publish them here when they are.

Documents

Everything in one place

All Fullinfo legal and policy documents. Each is the current published version; customers under signed Order Forms remain on whichever version was attached to their Order Form until renewal.

Contact

Who to reach

Privacy
privacy@fullinfo.com

Data subject rights, sub-processor change notifications, GDPR matters.

Security
security@fullinfo.com

Vulnerability reports, security incidents, customer security questionnaires.

Legal
legal@fullinfo.com

Contract questions, Order Form negotiation, authority disputes.