How Fullinfo handles privacy, security, and your data. Plain language, real practices, written by the people who actually do the work.
Fullinfo is a B2B data company. We hold information about businesses and the professionals who work in them. Companies that hold data have power, and power without restraint produces predictable failure modes. We’ve tried to build the opposite of that — a platform where what we collect, how we store it, and what happens when someone asks us to stop are all questions with clear, honest answers.
Privacy by design isn’t a policy. It’s a set of structural choices that show up in the product, the data model, and how we respond when a regulator or an individual contacts us. The choices we made — and didn’t make — are what this page is about.
This Trust Center is where we publish everything related to those choices: the legal documents, the technical practices, the sub-processors we use, the security measures we apply, and how to reach us if you’re a customer, a procurement team, or an individual exercising your rights.
We collect what is needed for business identification and professional contactability — and not more. No personal phone numbers, no home addresses, no data from breach dumps or sources with unclear chain of custody. The temptation to expand the dataset is constant in this industry; we resist it deliberately.
Every data point in Fullinfo carries the URL it came from and when it was last seen there. If you can’t see where a record came from, you can’t audit it — for accuracy, for legal basis, or for whether you should be using it. We treat provenance as a first-class field, not a footnote.
When a person asks to be removed, removal is immediate and complete — deleted from our database, added to a permanent suppression list so they aren’t re-ingested from any source, and removed from every customer Collection that contains them. Active monitoring of that person stops everywhere. There is no delay, no grandfathering, no override.
For the records in our database, we are a controller under GDPR — not a passive intermediary. For the data our customers place into Fullinfo on their own behalf, we are a processor. Both relationships carry obligations we accept explicitly, in writing. Our Data Processing Agreement describes them in detail.
Access, rectification, erasure, and objection requests are handled through a dedicated request page, with verification, status tracking, and confirmation. Not a generic privacy inbox. Not a 30-day wait followed by silence. Real people, working a real process, within statutory timeframes.
GDPR Article 14(5)(b) recognizes that contacting every data subject individually can be disproportionate for a database built from public sources. We invoke that provision honestly — with a publicly available notice, a clear removal path, and a record we can show a regulator on request. Not as cover for opacity.
Customer Data is hosted on Amazon Web Services in Frankfurt (EU) and Ohio (US). The complete list of sub-processors that touch Customer Data — what they do, where they process, and what transfer mechanism applies for non-EU locations — is in Annex 1 of our DPA.
Transfers to non-EU locations operate under the 2021 Standard Contractual Clauses. Changes to this list are notified at least 30 days in advance per Section 5.7 of the DPA. Subscribe to changes at privacy@fullinfo.com.
The full set of technical and organisational measures is in Annex 2 of our DPA. The headlines:
TLS 1.2+ in transit. AES-256 at rest. Encrypted backups. Keys managed via cloud provider KMS.
Personnel access restricted to role-required need. Individual authenticated accounts. Multi-factor authentication required. Periodic review.
Customer notification within 72 hours of our becoming aware. Updates as the investigation progresses. Assistance with your own notification obligations.
Written confidentiality obligations. Data protection training appropriate to role. Access revoked promptly on role change or departure.
Regular backups with tested restoration. Multi-zone deployment. Documented recovery procedures for critical operations.
Pre-engagement assessment for security and data protection. Contractual obligations consistent with our DPA. Ongoing monitoring of third-party posture.
Formal certifications (ISO 27001, SOC 2) are not yet in place. We’ll publish them here when they are.
All Fullinfo legal and policy documents. Each is the current published version; customers under signed Order Forms remain on whichever version was attached to their Order Form until renewal.
How we handle personal data, including GDPR and CCPA disclosures.
The contract that governs use of the Fullinfo platform.
Article 28 processor relationship and Article 26 joint controllership under GDPR.
Rules for using the fullinfo.com website. Distinct from the product MSA.
Request access, correction, or removal. We respond within statutory timeframes.
Vulnerability reports, security incidents, customer security questionnaires.