Data protection package

Workspace: Sample workspace · Generated on 08/10/2026, 14:08:55 · listplus.ai

For the data protection officer — everything ListPlus does with this workspace's data, in one file.

Draft: the legal texts are under legal review; items marked [TO CHECK] are still to be confirmed.

Contents

  1. 0. Our position on data protection
  2. 1. Workspace policy
  3. 2. Data processing agreement (DPA) with annexes
  4. 3. Service providers and data sources
  5. 4. Notice for the people in the data
  6. 5. Privacy policy

0. Our position on data protection

Last updated: 8 October 2026

This page is for data protection officers and anyone who reviews ListPlus before using it. It sums up how we see our role and why. The binding texts are the data processing agreement, the privacy policy and the provider list; this page explains them.

1. A tool, not a database

ListPlus does not collect people and does not sell data. Every search, enrichment or research run happens because a customer triggers it in their workspace, and its result belongs to that workspace alone. Nothing about people is shared between customers; across customers we keep only company data without personal reference, for 30 days. Nobody can search for people on ListPlus without an account.

That is why we see ourselves as the customer's processor (Art. 28 GDPR): the customer decides whether, about whom and for what purpose data is retrieved; we provide the tools. The data providers we query on the customer's behalf are controllers of their own databases and receive only the search key. Whether they count as sub-processors or as independent recipients for that search key is being clarified with our lawyers; until then we treat them like sub-processors (information, right to object).

2. The customer is in control, on the server

The owner of a workspace switches off in the workspace policy whatever their data protection officer does not want: individual data providers, AI features, connected systems, the Inbox address, the Agent API, pipeline emails, the support chat, usage events, contributing to the company cache. Off means: no member and no connected AI system can use the feature, and no data reaches the respective provider — checked on the server, not merely hidden in the interface.

Two features we treat specially. Monitoring people (Watchlist alerts) is off in every workspace until the owner switches it on after a notice of their responsibility; who switched it on and when is recorded. Rating research hits (fit score: how well a hit matches the search description) is on but can be switched off; then nobody is rated.

The policy exports as a text file, and the data protection package (policy, DPA with annexes, provider list, notice for the people in the data, privacy policy) opens as one file to print, or as a 30-day link to pass on.

3. Transparency: one list, every name

Every service provider, data provider and source is in one list with seat, data transmitted and third-country safeguard (listplus.ai/en/subprocessors), which is also Annex 3 of the DPA and the recipients section of the privacy policy — generated from one source so there are never two versions. We also name what is uncomfortable: that public sources such as LinkedIn, Crunchbase, Reddit or X are read by scrapers of a data collection platform, that some providers are in the USA, and what still has to be confirmed with a provider (marked [TO CHECK]).

4. The people in the data

Anyone found or completed through ListPlus finds an explanation addressed to them at listplus.ai/en/contact-data-notice: what ListPlus is, where the data comes from, who receives it, which rights they have. An objection to support@listplus.ai goes, as a checksum, into a suppression list that applies to all customers: the person is no longer retrieved through ListPlus, no longer recorded as a hit and no longer monitored. One limit we name: in a search by name and company only, we learn email address and profile only when the provider answers; we then do not store the result.

5. AI

AI models run only on our servers, never in the browser. Requests to OpenAI go with the “do not store” setting and, according to the provider, without use for training; the judgement model works without storage at the provider. Which data a feature sends is in the privacy policy (section 12), including where it is whole texts. No AI output decides anything with legal effect; all of it is suggestions the user reviews.

6. What we deliberately do not do

7. What is still open

We also write down what is not finished. The legal texts are under legal review (draft notice on every page). With some providers, contracts or seat details are still to be confirmed (marked in the provider list). Whether we have to appoint a data protection officer we are clarifying with our lawyers; the features most likely to trigger that duty (monitoring, rating, search without an account) we have put under the customer's instruction or switched off. The Pipedream service, through which connections to CRM systems run, is being replaced. Questions: support@listplus.ai.

1. Workspace policy

Workspace: Sample workspace · never changed — every switch on

What the owner of this workspace switched off for all members. “Off” means: no member and no connected AI system can use the feature, and no data reaches the respective provider — enforced on the server.

Sample without a workspace: a new workspace starts with every switch on. Which switches a customer has flipped is in the package they generate from their workspace settings.

Features
onAI features (commands, checks, AI columns, import recognition, Inbox, research, dictation) — OpenAI, Groq, TypeSafe AI
OFFWatchlist alerts (monitoring of people) — HarvestAPI
onAI research rates each hit 0–100 (fit score: how well it matches your brief; off = no hit is rated)
onInbox forwarding address @in.listplus.ai — Postmark (USA)
onAgent API and MCP (your own AI reads and writes lists)
onConnected systems: CRM, sheets, Slack, HubSpot — Pipedream (USA)
onPipeline e-mails with contact data — Postmark (USA)
onSupport chat in the app — Chatwoot (USA)
onUsage events (pseudonymous) — PostHog (EU)
onContribute company data to the shared company cache
Data providers
onProspeo — contact database, e-mail and phone
onFullEnrich — e-mail and phone (USA)
onCompanyEnrich — company data (Turkey / Finland)
onLinkedIn data (HarvestAPI, Enrich.so) — profiles, companies, posts
onMillionVerifier — e-mail verification (Hungary)
onGoogle search via Serper
onScrapers via Apify — LinkedIn imports, Crunchbase, Reddit, X, Google Maps
AI research sources
onReddit
onX (Twitter)
onLinkedIn posts and the people who reacted
onLinkedIn people search by employer
onReading arbitrary web pages

2. Data processing agreement (DPA) with annexes

Last updated: 8 October 2026

This Data Processing Agreement (“DPA”) governs the processing of personal data by airrange software GmbH, Sperberweg 7, 82152 Krailling, Germany (“ListPlus”, “processor”) on behalf of the customer (“Customer”, “controller”) when using ListPlus. It supplements the ListPlus Terms of Service (listplus.ai/terms, “Terms”) and becomes part of the contract when the user agreement is concluded, without the need for a separate signature. A signed copy is available on request (support@listplus.ai).

§ 1 Subject matter and definitions

(1) This DPA covers the processing of personal data that ListPlus carries out on behalf of the Customer when providing the Service under the Terms (“Customer Data”). Nature, purpose, categories of data and data subjects are set out in Annex 1.

(2) Terms such as “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the meaning given in Art. 4 GDPR.

(3) “Retrieval Tools” are the features of the Service with which the Customer queries data from external data providers or publicly available sources, in particular enrichment, person and segment search, email verification, LinkedIn imports, AI research and signal lookups, including via the Agent API.

§ 2 Roles of the parties

(1) ListPlus as processor. The Customer is the controller and appoints ListPlus as processor for

The Customer decides whether, about which persons, with which tools and for what purpose data is processed. It is responsible for complying with the obligations data protection law imposes on controllers.

(2) ListPlus as controller. ListPlus processes the following on its own responsibility and not on behalf of the Customer:

The ListPlus Privacy Policy (listplus.ai/privacy) applies to this processing.

(3) Data providers. External data providers are themselves responsible for their own databases. ListPlus owns no contact database and does not pass data from a database of its own to the Customer. Data providers and sources are listed in Annex 3, Part B; on a lookup they receive only the search key. Whether they are sub-processors (§ 7) in that respect or independent recipients to which the Customer transfers on its own legal basis is being clarified with our lawyers; until then the information and objection rights of § 7 apply to them accordingly.

§ 3 Instructions

(1) ListPlus processes Customer Data only on documented instructions from the Customer, unless required to do so by Union or Member State law; in that case ListPlus informs the Customer of that legal requirement before processing, unless that law prohibits it.

(2) The Customer's instructions are set out in full in the Terms, this DPA, the workspace policy and the Customer's operation of the Service. Every action triggered by the Customer or its users — such as an import, a search, an enrichment, a Watchlist alert, an AI research run with the search description written and the sources chosen by the Customer, a pipeline or an export — counts as a documented instruction to the extent defined by that action. The same applies to actions the Customer triggers via the Agent API or an AI system it connects. With the workspace policy (Terms § 3(4)) the Customer instructs ListPlus not to use certain features, data providers or sources for its workspace; ListPlus enforces this instruction technically.

(3) The Customer gives further instructions in text form to support@listplus.ai. ListPlus may refuse instructions that go beyond the agreed scope of services or carry them out for reasonable remuneration.

(4) ListPlus informs the Customer without delay if, in its opinion, an instruction infringes data protection law, and may suspend carrying it out until the Customer confirms or changes it.

§ 4 Customer obligations

The Customer ensures that

The Customer informs ListPlus without delay if it detects errors or irregularities in the processing.

§ 5 Confidentiality

ListPlus ensures that all persons authorised to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Only persons who need access to provide the Service, support or fix incidents are given access to Customer Data.

§ 6 Technical and organisational measures

(1) ListPlus takes the technical and organisational measures described in Annex 2 under Art. 32 GDPR to ensure a level of security appropriate to the risk.

(2) The measures are subject to technical progress. ListPlus may replace them with equivalent or better measures; the level of security must not fall below the agreed level.

§ 7 Sub-processors

(1) The Customer gives ListPlus general authorisation to engage sub-processors. The sub-processors engaged when the contract is concluded are listed in Annex 3 and are deemed approved.

(2) ListPlus informs the Customer in text form at least 30 days before engaging a new or replacing an existing sub-processor (e.g. by email or by updating Annex 3 with notice by email). The Customer may object to the change within this period in text form for a valid data protection reason. If the parties cannot agree, the Customer may terminate the user agreement with effect from the date the sub-processor is engaged. [TO CHECK: special rule for the short-notice replacement of a data provider that fails or discontinues its service.]

(3) ListPlus contractually binds each sub-processor to data protection obligations that substantially correspond to those in this DPA. ListPlus is liable to the Customer for the sub-processor's compliance with these obligations under Art. 28(4) GDPR.

(4) Ancillary services ListPlus uses from third parties without those third parties having access to Customer Data (e.g. telecommunications, payment processing for ListPlus itself) are not sub-processing within the meaning of this DPA.

§ 8 Transfers to third countries

Customer Data is processed outside the EU/EEA only if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision (e.g. the EU-U.S. Data Privacy Framework) or the EU Standard Contractual Clauses (Module 3, processor to processor) that ListPlus concludes with the respective sub-processor. The Service is hosted in the EU region Frankfurt; the sub-processors concerned and the respective safeguard are listed in Annex 3.

§ 9 Assisting the Customer

(1) ListPlus assists the Customer with appropriate technical and organisational measures in responding to data subject requests. The Service enables the Customer to view, export, correct and delete Customer Data itself; the workspace's Block List flags records of people who are not to be contacted. If a data subject objects to ListPlus, ListPlus enters their identifier as a hash into a cross-customer suppression list so that they are no longer retrieved from data providers, recorded as a research hit or monitored through the Service; records the Customer already holds are unaffected and are for the Customer to handle.

(2) If a data subject contacts ListPlus directly, ListPlus forwards the request to the Customer without delay where the Customer can be identified, and does not answer it itself unless the Customer instructs it to or the law requires it.

(3) Taking into account the nature of processing and the information available, ListPlus assists the Customer in complying with the obligations under Art. 32 to 36 GDPR (security, notifications, data protection impact assessment, prior consultation).

(4) ListPlus may charge reasonable fees based on effort for assistance that goes beyond the features of the Service and is not caused by a breach by ListPlus.

§ 10 Personal data breaches

ListPlus notifies the Customer of a breach affecting Customer Data without undue delay after becoming aware of it, where possible within 48 hours. The notification contains, as far as known, the information under Art. 33(3) GDPR; missing information is provided later. ListPlus takes the necessary measures to secure the data and mitigate possible adverse effects without delay. Notifying supervisory authorities and data subjects is the Customer's responsibility.

§ 11 Deletion and return

(1) During the term of the contract, the Customer can export and delete Customer Data itself at any time. Certain data is deleted automatically after the periods stated in the Privacy Policy (section 11).

(2) After the user agreement ends and the account is deleted, ListPlus deletes the Customer Data unless there is a legal obligation to retain it. Copies in backups at the hosting provider are overwritten at the end of the backup cycle [TO CHECK: backup periods, currently up to 30 days].

(3) Data is returned through the Service's export feature before deletion.

§ 12 Evidence and audits

(1) On request, ListPlus provides the Customer with all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. Up-to-date self-assessments, the description of measures in Annex 2 and certificates and audit reports of sub-processors (e.g. the hosting provider's ISO 27001 or SOC 2) will normally suffice as evidence.

(2) The Customer may carry out further audits, including inspections, at most once per calendar year after giving reasonable notice (at least 30 days) during normal business hours, itself or through an auditor bound to confidentiality who does not compete with ListPlus, unless a supervisory authority requires more or there is a specific reason. Each party bears its own costs.

§ 13 Liability

Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the Terms (§ 14 of the Terms) and the indemnification under § 15 of the Terms apply. As a processor, ListPlus is only liable for damage caused where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to the Customer's lawful instructions.

§ 14 Term and final provisions

(1) This DPA applies for the term of the user agreement and beyond for as long as ListPlus processes Customer Data.

(2) In the event of conflicts between this DPA and the Terms, this DPA prevails in matters of data protection.

(3) ListPlus may change this DPA under the procedure in § 16 of the Terms, in particular to adapt it to changes in the law or in sub-processors. § 7 takes precedence for sub-processors.

(4) The laws of the Federal Republic of Germany apply. To the extent permitted by law, the place of jurisdiction is the registered office of airrange software GmbH.

(5) Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.

Annex 1: Subject matter and scope of processing

Nature and purpose of processing

Storing, checking, cleaning, enriching, searching, researching, transmitting and exporting contact and company lists as part of the Service under the Terms, including querying external data providers and publicly available sources with the Retrieval Tools and processing by AI models to the extent described in the Privacy Policy (section 12).

Categories of data subjects

Categories of personal data

Duration

For the term of the user agreement; deletion under § 11.

Annex 2: Technical and organisational measures

Annex 3: Sub-processors

Part A: Sub-processors

These providers process customer data on our behalf under Art. 28 GDPR. “Switch off” names the workspace policy switch with which the customer stops transfers to this provider for its workspace.

Service providerServiceData transmittedSeat / locationThird-country safeguardCustomer can switch off
Vercel Inc.Running the application, file storage for lists and imports, queues for background work, web analytics and speed insights, AI gateway (access to the model “Jev”)All data of the application; connection data on every request (IP address, browser)Covina, California, USA — Hosting, file storage and queues in the EU region FrankfurtEU-U.S. Data Privacy Framework; Standard Contractual Clauses in the data processing agreementno
Redis Ltd. (Redis Cloud)The application's database: workspaces, lists, working data, cachesAll data of the applicationSeat: Mountain View, California, USA — Database in Frankfurt (AWS eu-central-1), transport TLS-encrypted — [TO CHECK: Confirm the data processing agreement and encryption at rest]Processing in the EU; Standard Contractual Clauses for support access from third countriesno
Pusher Ltd.Live status updates in the browser (import done, enrichment running, new hits)Events about operations; for small changes the changed cell valuesLondon, United Kingdom — [TO CHECK: Confirm the cluster location]Adequacy decision for the United Kingdomno
Pipedream, Inc.Connections to CRM systems and spreadsheets (OAuth credentials, forwarding of calls); internal notifications about account, list and payment eventsRecords the customer exchanges with a connected system; from events the user id, e-mail address, list name and row count and a summary of the payment event (customer, e-mail, amount, plan)San Francisco, California, USA — [being replaced] — [TO CHECK: The service is being discontinued; notifications move to n8n, the replacement for connections is open]Standard Contractual Clausesyes (connections)
Postmark (ActiveCampaign, LLC)Receiving e-mails forwarded to the Inbox address @in.listplus.ai; sending workspace invitations and pipeline digest mails from notifications@listplus.aiForwarded e-mails in full (sender, subject, body, attachments); the invitee's address and the inviter's name; per digest entry name, position, companyChicago, Illinois, USA — [TO CHECK: Sign the data processing agreement; shorten retention at the provider (default 45 days)]Standard Contractual Clausesyes (inboxEmail, pipelineEmail)
OpenAILanguage models for commands, checks, AI columns, column recognition on import, recognition of contacts in the Inbox, mapping of unknown webhook fields, AI research; transcription of dictationsThe excerpt the task needs (section “AI processing” of the privacy policy); requests are not stored at the provider (store: false) and not used for trainingOpenAI Ireland Ltd., Dublin, Ireland (contracting entity for the EU) / OpenAI, L.L.C., San Francisco, USA — [TO CHECK: Confirm the contracting entity (Ireland/USA) and the Data Processing Addendum]EU-U.S. Data Privacy Framework; Standard Contractual Clauses in the Data Processing Addendumyes (ai)
Groq, Inc.Fast language model for short single calls: understanding a search query, role resolution, list titles, short Inbox entriesThe short text of the request (search description, signature line)Mountain View, California, USA — [TO CHECK: Confirm the Data Processing Addendum and the no-training clause]Standard Contractual Clausesyes (ai)
TypeSafe AI (Modell „Jev“, über das AI Gateway von Vercel)Judgement model: seniority of job titles, kind of a LinkedIn position, pre-check of Inbox entries and webhook records, judge columnsThe values to judge (job titles, positions, up to 12 fields of a record); without storage at the provider (zero data retention)Seat: to be confirmed — [TO CHECK: Confirm seat, contracting entity and safeguard]Standard Contractual Clauses via Vercelyes (ai)
Apify Technologies s.r.o.Data collection platform: runs scrapers (“actors”) that read public pages — LinkedIn imports (Sales Navigator, employee lists, post reactions and comments, people search incl. by past employer), Crunchbase company pages, Reddit, X, Google Maps profiles, web traffic, contact details on websitesThe search URL, company URL, post URL, company name or research query — never the customer's listPrague, Czech Republic — [TO CHECK: Confirm the data processing agreement; third-party actors run on Apify's infrastructure]Processing in the EUyes (provider:apify)

Part B: Data providers and sources

On a lookup these providers receive only the search key (e.g. e-mail address, domain, LinkedIn URL, name and company or search filters), never the rest of the list. They are controllers of their own data; ListPlus is the tool with which the customer queries them. Whether they count as sub-processors or as independent recipients for the search key is being clarified with our lawyers.

Service providerServiceData transmittedSeat / locationThird-country safeguardCustomer can switch off
ProspeoB2B contact database (segment search), verified business e-mail addresses and phone numbers, company profiles, job changesSearch filters or the search key: LinkedIn URL, name and company, domainProspeo SAS, Paris, France — [TO CHECK: Confirm the seat]Processing in the EUyes (provider:prospeo)
FullEnrichBusiness e-mail address and phone number from name and company or LinkedIn URL (waterfall through 20+ sources)Name and company, domain or LinkedIn URLFullEnrich Corp., San Francisco, USAStandard Contractual Clauses according to the provider's privacy policyyes (provider:fullenrich)
CompanyEnrichCompany data from domain or company name (industry, size, location, website); workforce, decision makers, similar companiesDomain or company name; for person lookups name and companyCompany in Turkey — Servers, databases and backups in Finland — [TO CHECK: Clarify the safeguard for access from Turkey]Processing in the EU (Finland); Turkey without an adequacy decisionyes (provider:companyenrich)
HarvestAPIPublicly visible LinkedIn data: profile, company, profile search, posts and reactions, open jobs; the basis of the Watchlist alertsLinkedIn URL, name and company, post URLSeat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmedyes (provider:linkedin, alerts)
Enrich.soPublicly visible LinkedIn profile data from a URL (fallback when HarvestAPI does not answer)LinkedIn URLSeat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmedyes (provider:linkedin)
MillionVerifierChecking whether an e-mail address is deliverableThe e-mail addressGBD Software as a Service Private Limited Company, Budapest, HungaryProcessing in the EUyes (provider:millionverifier)
Serper (Google-Suche)Google search results: LinkedIn profile URL for name and company, company website, news, web search of the AI research, confirmation of recognised contacts in the InboxThe search term (e.g. name and company)Serper, seat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmedyes (provider:serper)
Hacker News (Suche über Algolia)Public stories and comments on Hacker News including user names, for the AI researchOnly the search term, never data from customer listsAlgolia, Inc., San Francisco, USA — public interface without an accountNo contract; only the search term is transmittedno
Öffentliche Quellen (über Apify gelesen)Publicly visible pages a scraper reads at the customer's request; the platforms are not our contracting partners, the customer observes their termsThe URL or search calledLinkedIn, Crunchbase, Reddit, X, Google Maps, Similarweb, arbitrary websitesNot applicable (retrieval of public pages)yes (provider:apify, source:reddit, source:twitter, source:linkedin, source:people, source:sources)

Part C: Recipients chosen by the customer

Systems the customer transfers data to because it connects or names them itself. The customer is the controller of that transfer; they are listed for completeness.

Service providerServiceData transmittedSeat / locationThird-country safeguardCustomer can switch off
Verbundene Systeme des KundenImport from and export to systems the customer connects; pipeline targetsThe records the customer transfersHubSpot, Salesforce, Pipedrive, Google Sheets, Airtable, Notion, lemlist (via Pipedream); Instantly, Smartlead, Attio, Close, Slack (with the customer's key)The customer is the controller of this transferyes (connections)
Eigener Webhook-Endpunkt des KundenPipeline target “endpoint”The records the customer transfersNamed by the customerThe customer is the controller of this transferno
Die eigene KI des Kunden (Agent-API, MCP, Recherche-Link)Reading and writing lists and research through an AI system the customer connectsWhat the connection exposes (columns, sublists, actions)Chosen by the customer, e.g. ChatGPT, Claude, own agentsThe customer is the controller of this transferyes (agentApi)

Open points per provider are marked [TO CHECK] in the table; the current version of this annex is published at listplus.ai/en/subprocessors. Not in this annex: providers that process only the users' account, contract and billing data (privacy policy, section 15).

3. Service providers and data sources

Last updated: 8 October 2026

This list is Annex 3 of our data processing agreement (listplus.ai/en/dpa) and the “Recipients” section of our privacy policy in one — generated from a single source so that there are never two versions. Changes of sub-processors are announced to customers 30 days ahead (DPA § 7).

“Customer can switch off” names the workspace policy switch with which a workspace owner stops transfers to this provider for its workspace.

Part A: Sub-processors

These providers process customer data on our behalf under Art. 28 GDPR. “Switch off” names the workspace policy switch with which the customer stops transfers to this provider for its workspace.

Service providerServiceData transmittedSeat / locationThird-country safeguardCustomer can switch off
Vercel Inc.Running the application, file storage for lists and imports, queues for background work, web analytics and speed insights, AI gateway (access to the model “Jev”)All data of the application; connection data on every request (IP address, browser)Covina, California, USA — Hosting, file storage and queues in the EU region FrankfurtEU-U.S. Data Privacy Framework; Standard Contractual Clauses in the data processing agreementno
Redis Ltd. (Redis Cloud)The application's database: workspaces, lists, working data, cachesAll data of the applicationSeat: Mountain View, California, USA — Database in Frankfurt (AWS eu-central-1), transport TLS-encrypted — [TO CHECK: Confirm the data processing agreement and encryption at rest]Processing in the EU; Standard Contractual Clauses for support access from third countriesno
Pusher Ltd.Live status updates in the browser (import done, enrichment running, new hits)Events about operations; for small changes the changed cell valuesLondon, United Kingdom — [TO CHECK: Confirm the cluster location]Adequacy decision for the United Kingdomno
Pipedream, Inc.Connections to CRM systems and spreadsheets (OAuth credentials, forwarding of calls); internal notifications about account, list and payment eventsRecords the customer exchanges with a connected system; from events the user id, e-mail address, list name and row count and a summary of the payment event (customer, e-mail, amount, plan)San Francisco, California, USA — [being replaced] — [TO CHECK: The service is being discontinued; notifications move to n8n, the replacement for connections is open]Standard Contractual Clausesyes (connections)
Postmark (ActiveCampaign, LLC)Receiving e-mails forwarded to the Inbox address @in.listplus.ai; sending workspace invitations and pipeline digest mails from notifications@listplus.aiForwarded e-mails in full (sender, subject, body, attachments); the invitee's address and the inviter's name; per digest entry name, position, companyChicago, Illinois, USA — [TO CHECK: Sign the data processing agreement; shorten retention at the provider (default 45 days)]Standard Contractual Clausesyes (inboxEmail, pipelineEmail)
OpenAILanguage models for commands, checks, AI columns, column recognition on import, recognition of contacts in the Inbox, mapping of unknown webhook fields, AI research; transcription of dictationsThe excerpt the task needs (section “AI processing” of the privacy policy); requests are not stored at the provider (store: false) and not used for trainingOpenAI Ireland Ltd., Dublin, Ireland (contracting entity for the EU) / OpenAI, L.L.C., San Francisco, USA — [TO CHECK: Confirm the contracting entity (Ireland/USA) and the Data Processing Addendum]EU-U.S. Data Privacy Framework; Standard Contractual Clauses in the Data Processing Addendumyes (ai)
Groq, Inc.Fast language model for short single calls: understanding a search query, role resolution, list titles, short Inbox entriesThe short text of the request (search description, signature line)Mountain View, California, USA — [TO CHECK: Confirm the Data Processing Addendum and the no-training clause]Standard Contractual Clausesyes (ai)
TypeSafe AI (Modell „Jev“, über das AI Gateway von Vercel)Judgement model: seniority of job titles, kind of a LinkedIn position, pre-check of Inbox entries and webhook records, judge columnsThe values to judge (job titles, positions, up to 12 fields of a record); without storage at the provider (zero data retention)Seat: to be confirmed — [TO CHECK: Confirm seat, contracting entity and safeguard]Standard Contractual Clauses via Vercelyes (ai)
Apify Technologies s.r.o.Data collection platform: runs scrapers (“actors”) that read public pages — LinkedIn imports (Sales Navigator, employee lists, post reactions and comments, people search incl. by past employer), Crunchbase company pages, Reddit, X, Google Maps profiles, web traffic, contact details on websitesThe search URL, company URL, post URL, company name or research query — never the customer's listPrague, Czech Republic — [TO CHECK: Confirm the data processing agreement; third-party actors run on Apify's infrastructure]Processing in the EUyes (provider:apify)
PostHog Inc. (EU-Cloud)Usage events of the application (which feature was used when), pseudonymousEvent name and properties, a pseudonym of the account (hash), plan, workspace hash; no names, e-mail addresses or list contents; can be switched off per account and per workspaceSan Francisco, California, USA — EU cloud in FrankfurtProcessing in the EU; Standard Contractual Clauses in the data processing agreementyes (telemetry)
Axiom, Inc.Server logs and browser error reports for troubleshootingLog lines of the application; on browser errors the error text, stack and page (without user id and without query string)San Francisco, California, USA — [TO CHECK: Confirm seat, data location and retention period]Standard Contractual Clausesno
Chatwoot Inc.Support chat in the application; first answers by an AI assistant that reads only approved help textsUser id, name, e-mail address and chat messages; only after clicking the chat buttonWilmington, Delaware, USA — [TO CHECK: Confirm the data processing agreement]Standard Contractual Clausesyes (supportChat)
Hanko GmbHSign-in: e-mail address with one-time code or Google login; sessions (30 days)E-mail address, user id, sign-in method, timestampsKiel, GermanyProcessing in the EUno
Google LLC (Anmeldung mit Google)Confirming the sign-in when the user chooses “Sign in with Google”E-mail address and Google account id; Google learns that the person signs in to ListPlusMountain View, California, USAEU-U.S. Data Privacy Frameworkno
Stripe Payments Europe, Ltd.Payments, invoices, VATName, e-mail address, billing address, VAT id, payment data (only at Stripe)Dublin, IrelandStandard Contractual Clauses for transfers to Stripe, Inc. (USA)no
Attio Ltd. (CRM)Account e-mails: stores the e-mail address at sign-up and sends the welcome e-mailE-mail addressLondon, United KingdomAdequacy decision for the United Kingdomno
Amazon Web Services EMEA SARL (DynamoDB)User record: e-mail address and purchased planE-mail address, planLuxembourg — Frankfurt (eu-central-1)Processing in the EUno

Part B: Data providers and sources

On a lookup these providers receive only the search key (e.g. e-mail address, domain, LinkedIn URL, name and company or search filters), never the rest of the list. They are controllers of their own data; ListPlus is the tool with which the customer queries them. Whether they count as sub-processors or as independent recipients for the search key is being clarified with our lawyers.

Service providerServiceData transmittedSeat / locationThird-country safeguardCustomer can switch off
ProspeoB2B contact database (segment search), verified business e-mail addresses and phone numbers, company profiles, job changesSearch filters or the search key: LinkedIn URL, name and company, domainProspeo SAS, Paris, France — [TO CHECK: Confirm the seat]Processing in the EUyes (provider:prospeo)
FullEnrichBusiness e-mail address and phone number from name and company or LinkedIn URL (waterfall through 20+ sources)Name and company, domain or LinkedIn URLFullEnrich Corp., San Francisco, USAStandard Contractual Clauses according to the provider's privacy policyyes (provider:fullenrich)
CompanyEnrichCompany data from domain or company name (industry, size, location, website); workforce, decision makers, similar companiesDomain or company name; for person lookups name and companyCompany in Turkey — Servers, databases and backups in Finland — [TO CHECK: Clarify the safeguard for access from Turkey]Processing in the EU (Finland); Turkey without an adequacy decisionyes (provider:companyenrich)
HarvestAPIPublicly visible LinkedIn data: profile, company, profile search, posts and reactions, open jobs; the basis of the Watchlist alertsLinkedIn URL, name and company, post URLSeat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmedyes (provider:linkedin, alerts)
Enrich.soPublicly visible LinkedIn profile data from a URL (fallback when HarvestAPI does not answer)LinkedIn URLSeat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmedyes (provider:linkedin)
MillionVerifierChecking whether an e-mail address is deliverableThe e-mail addressGBD Software as a Service Private Limited Company, Budapest, HungaryProcessing in the EUyes (provider:millionverifier)
Serper (Google-Suche)Google search results: LinkedIn profile URL for name and company, company website, news, web search of the AI research, confirmation of recognised contacts in the InboxThe search term (e.g. name and company)Serper, seat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmedyes (provider:serper)
Hacker News (Suche über Algolia)Public stories and comments on Hacker News including user names, for the AI researchOnly the search term, never data from customer listsAlgolia, Inc., San Francisco, USA — public interface without an accountNo contract; only the search term is transmittedno
Öffentliche Quellen (über Apify gelesen)Publicly visible pages a scraper reads at the customer's request; the platforms are not our contracting partners, the customer observes their termsThe URL or search calledLinkedIn, Crunchbase, Reddit, X, Google Maps, Similarweb, arbitrary websitesNot applicable (retrieval of public pages)yes (provider:apify, source:reddit, source:twitter, source:linkedin, source:people, source:sources)

Part C: Recipients chosen by the customer

Systems the customer transfers data to because it connects or names them itself. The customer is the controller of that transfer; they are listed for completeness.

Service providerServiceData transmittedSeat / locationThird-country safeguardCustomer can switch off
Verbundene Systeme des KundenImport from and export to systems the customer connects; pipeline targetsThe records the customer transfersHubSpot, Salesforce, Pipedrive, Google Sheets, Airtable, Notion, lemlist (via Pipedream); Instantly, Smartlead, Attio, Close, Slack (with the customer's key)The customer is the controller of this transferyes (connections)
Eigener Webhook-Endpunkt des KundenPipeline target “endpoint”The records the customer transfersNamed by the customerThe customer is the controller of this transferno
Die eigene KI des Kunden (Agent-API, MCP, Recherche-Link)Reading and writing lists and research through an AI system the customer connectsWhat the connection exposes (columns, sublists, actions)Chosen by the customer, e.g. ChatGPT, Claude, own agentsThe customer is the controller of this transferyes (agentApi)

4. Notice for the people in the data

Last updated: 8 October 2026

You are probably reading this because a company contacted you and named ListPlus as its source, or because you want to know what ListPlus has to do with your data. Here it is, as briefly as possible.

What ListPlus is — and is not

ListPlus (listplus.ai) is a tool of airrange software GmbH, Sperberweg 7, 82152 Krailling, Germany, with which companies check, complete and research their contact lists. ListPlus has no database of people of its own. When a customer looks a person up or completes a field, ListPlus asks specialised data providers or public sources at that moment and shows the customer the result.

For these lookups we act on behalf of the respective customer (processor, Art. 28 GDPR). The customer is responsible for looking you up, using your data and contacting you. Who that was you can see from the message you received; we may not and cannot tell you from our own knowledge if the customer is not identifiable.

Which data can be retrieved

Only data related to your professional role: name, position, company and its details (industry, size, location), business e-mail address and whether it is deliverable, business phone number, the address of your LinkedIn profile, location, and publicly visible profile details and public posts or reactions when a customer explicitly retrieves them. No private data, no special categories (health, religion, political opinion).

Where the data comes from

From data providers that run their own databases of business contacts (for example Prospeo, FullEnrich, CompanyEnrich, MillionVerifier), and from publicly accessible sources (for example LinkedIn, company websites, Google search, Crunchbase, Hacker News, Reddit, X) that a service reads at the customer's request. The complete, current list with the providers' seats is at listplus.ai/en/subprocessors, Part B. The providers are responsible for their own databases; information about those you obtain from them.

Who receives the data and how long it stays

The result of a lookup is seen only by the customer who triggered it; it is stored in that customer's workspace until they delete it. Results are not shared between customers. We additionally keep a cache per customer for at most 30 days so that the same lookup is not paid twice. Nobody can search for people on ListPlus without an account.

The legal basis for the lookup is the customer's legitimate interest (Art. 6(1)(f) GDPR) in finding business contacts and keeping accurate business data, limited to the professional context. Whether the customer may contact you beyond that depends on its own legal basis and on unfair-competition law; that is the customer's responsibility.

Your rights — and what we do

Objection (Art. 21 GDPR). Write to support@listplus.ai with your business e-mail address or the address of your LinkedIn profile. We enter both as a checksum (not in plain text) into a suppression list that applies to all customers: your data is then no longer retrieved from providers through ListPlus, no longer recorded as a research hit and no longer monitored. One limit we have to name: if a customer searches only with your name and company, we learn e-mail address and profile only when the provider answers; we then do not store the result, but the provider has seen the request.

Access, rectification, erasure (Art. 15 to 17 GDPR). These rights are directed at the customer who uses your data; if your request reaches us, we forward it to the customer where identifiable and answer what we know ourselves. The data providers delete your data in their own databases themselves; their contact details are in the provider list.

Complaint (Art. 77 GDPR). Our supervisory authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

Everything else, in particular how we handle the data of website visitors and customers, is in our privacy policy at listplus.ai/en/privacy.

5. Privacy policy

Last updated: 8 October 2026

This privacy policy informs you under Articles 13 and 14 of the General Data Protection Regulation (GDPR) which personal data we process when operating the website listplus.ai and the ListPlus application (listplus.ai/app, including the Outlook add-in and the Agent API), for which purposes, on which legal basis, and which rights you have.

1. Controller

airrange software GmbH
Sperberweg 7
82152 Krailling
Germany
Phone: +49 (0)89 28741023
Email: support@listplus.ai
Commercial register: Amtsgericht München, HRB 271683
Managing Director: Stephan Methner

For any data protection question and to exercise your rights, contact us at support@listplus.ai.

2. Data protection officer

[TO CHECK: whether a data protection officer must be appointed is under review. Once appointed, their contact details will be listed here.] Until then, please send data protection requests to support@listplus.ai.

3. Overview: our role in processing your data

Depending on your relationship with ListPlus, we process your data in different roles:

4. Visiting the website and hosting

The website and the application are hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA); servers and file storage are located in the EU region Frankfurt am Main. When you open a page, Vercel processes technically necessary connection data: IP address, date and time, requested URL, referrer, browser and operating system information and status codes (server log files).

Purpose: delivering the website, stability, security and abuse prevention. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working service). Retention: server log files are deleted after [PLACEHOLDER: Vercel log retention, e.g. X days] unless needed longer to investigate a security incident.

Although servers and file storage are in the EU, data may also be transferred to the USA by Vercel itself, as Vercel is a US company and uses subprocessors. Vercel is certified under the EU-U.S. Data Privacy Framework; in addition we have concluded a data processing agreement with Standard Contractual Clauses with Vercel (see sections 15 and 16).

5. Cookies, local storage and analytics

We do not use advertising or tracking cookies, and no cookies from ad networks or social networks. We use the following cookies and entries in your browser's local storage (localStorage):

NameTypePurposeDuration
NEXT_LOCALECookie (first-party)Stores the language you chose for the website and the application1 year
hankoCookie (first-party, domain .listplus.ai)Session token after sign-in; signing in is not possible without itUntil sign-out or session expiry (max. 30 days)
lp-split-lists, lp-split-inbox, lp-split-pipelines, lp-split-saved, lp-split-segment, lp-split-researchCookie (first-party)Remembers whether and how wide each view's left column (e.g. the lists sidebar) is shown in the application1 year
Application settings (e.g. userLanguage, column views, last opened list, search history, panel state, research runs executed in the tab)localStorageStores your settings and work state locally in the browser; this data does not leave your browserUntil you clear it in your browser
hanko-auth-flow-statelocalStorageIntermediate state of the sign-in flowUntil sign-in completes
lp-first-views, lp-signup-trackedlocalStoragePrevents the same browser being counted more than once as a “first visit” or “sign-up” in usage measurement; contains no user identifier (only view names or the account's creation date)Until you clear it in your browser
lp-chatwoot-identified and cookies/storage of the chat widget (e.g. cw_conversation)localStorage / cookie (Chatwoot)Operating the support chat in the application dashboard (section 9); only set after you click the chat buttonup to 12 months [TO CHECK: verify duration in the browser]

Legal basis: storing and reading this information on your device is based on Section 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) where it is strictly necessary to provide the service you explicitly requested (sign-in, language setting, application settings, support chat). The chat widget is only loaded once you click the chat button. The subsequent processing is based on Art. 6(1)(b) GDPR (user agreement) or Art. 6(1)(f) GDPR. [TO CHECK: classification of lp-first-views/lp-signup-tracked under Section 25 TDDDG.]

Reach measurement, usage events and error logs

Website: we use Vercel Web Analytics and Vercel Speed Insights to measure reach and page speed. These services work without cookies and without cross-device profiles. They record pages visited, referrer, approximate country-level location, device type, browser and operating system, and load times; to distinguish visits, a hash derived from request data is used and discarded daily.

Application: which features are used when, we count with PostHog (PostHog Inc., EU cloud in Frankfurt). Each event carries a pseudonym of your account (a hash of the user ID, not reversible), the plan, a hash of the workspace, the event and its properties (e.g. “list created”, “enrichment started”, the number of rows) — never names, email addresses or the contents of your lists. PostHog sets no cookies for us and records no sessions. You can switch usage measurement off in your account settings; a workspace owner can switch it off for all members (workspace policy). Independently of that, we keep daily counters without any personal reference (how often a feature was used).

Error logs: logs of our servers and error reports from the browser (error text, stack, the page visited without query parameters, browser) are sent to Axiom (Axiom, Inc., USA) [TO CHECK: seat, data location and retention period]. Error reports contain no user ID.

Purpose: improving the website and application, error analysis. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in designing our service to meet demand and in running it reliably). Recipients: Vercel Inc., PostHog Inc., Axiom, Inc. (see section 15).

Third-party content your browser loads

In a few places your browser loads content directly from third parties, which thereby learn your IP address: explainer videos on the application's start page from Wistia (only after a click), map tiles from OpenStreetMap in the contact view (with the coordinates of the company shown, not yours), icons from jsDelivr, and profile pictures of people directly from LinkedIn or the data provider. Legal basis: Art. 6(1)(f) GDPR.

Stripe payment pages

When you subscribe to a plan or buy credits, you are redirected to a Stripe payment page (checkout.stripe.com or the Stripe customer portal). Stripe's privacy notice applies there; Stripe sets its own cookies there, among other things for fraud prevention.

6. Registration, sign-in and user account

To use ListPlus you create an account with your email address. You sign in with your email address and a one-time passcode we send you by email, or with “Sign in with Google”; we do not store a password. The sign-in service is operated for us by Hanko GmbH, Kiel, Germany (hosted in the EU); a session lasts 30 days. If you choose to sign in with Google, Google LLC (USA) confirms your identity and sends us your email address and your Google account ID; Google learns that you sign in to ListPlus (third-country safeguard: EU-U.S. Data Privacy Framework). We process your email address, optionally your name, an internal user ID, the sign-in method, the times of registration and sign-in, and technical session data.

Purpose: setting up and securing your account. Legal basis: Art. 6(1)(b) GDPR (contract or pre-contractual steps). Retention: for the duration of the user relationship; after the account is deleted, the data is deleted unless statutory retention obligations apply.

7. Providing the application and performing the contract

When you use ListPlus, we process your account data, your plan, your credit balance and its transactions (purchases, usage per action, refunds), settings, the lists, folders and saved contacts you create, API connections and their execution logs, as well as technical logs for error analysis and abuse detection.

Purpose: providing the contractual services, billing credits, security and abuse prevention (e.g. rate limits). Legal basis: Art. 6(1)(b) GDPR; for security and abuse prevention Art. 6(1)(f) GDPR.

For a fast working data store we use Redis Cloud (Redis Ltd.), hosted in the Frankfurt region (AWS eu-central-1). For live status updates in the browser (e.g. “import finished”) we use the realtime service Pusher (Pusher Ltd.) [TO CHECK: seat/cluster]; it transmits event and status information about your operations.

Through workflows (webhooks) at the service Pipedream, Inc. (USA; the service is currently being replaced by an automation service operated in the EU, see section 15) we receive internal notifications about events in our service: sign-up, sign-in, sign-out and deletion of an account (user ID, email address, sign-in method), lists created and deleted (list ID, user ID, list name, import type and row count, no list content), and a summary of the events of our payment provider Stripe (event type, customer and transaction IDs, the payer's email address, amount, currency, status, plan — no payment instruments, no billing address). Of these notifications, only your email address is stored permanently, as follows:

Purpose: managing your account and plan, and sending the welcome email to get you started. Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement). The welcome email is purely a greeting and onboarding message about your account, not advertising. We only send newsletters or promotional emails with your explicit consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.

Workspaces and invitations

You work in workspaces. Lists, Watchlist, Inbox, research runs, pipelines and connected systems belong to the workspace and every member sees them; plan and credits belong to the workspace owner. Whoever invites a member triggers an email to the invited address with the inviter's name and the workspace name, sent via Postmark (section 14) from notifications@listplus.ai; an invitation expires after 14 days. The owner can switch features and data providers off for all members in the workspace policy; the current policy can be viewed in the workspace settings and exported as a text file. Legal basis: Art. 6(1)(b) GDPR; for the invitation email to a person not yet registered, Art. 6(1)(f) GDPR (the inviter's interest in working together).

8. Payments and invoices

Subscriptions and credit packs are processed by Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). Stripe processes name, email address, billing address, VAT ID where given, and payment data, and calculates VAT. We do not receive full card or account details from Stripe, only customer and payment status information and invoices.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(c) GDPR (tax and commercial law obligations). Retention: we keep accounting records for the statutory periods (Section 147 AO, Section 257 HGB: 8 years for vouchers, 10 years for books and annual accounts). For certain purposes of its own (e.g. fraud prevention, regulatory obligations) Stripe is itself a controller.

9. Support by email and chat

When you contact us by email (support@listplus.ai) or via the chat widget in the application dashboard, we process your message, your contact details and, for signed-in users, your user ID, name and email address so we can match your account. The chat widget is provided by Chatwoot Inc. [TO CHECK: address], USA; the data is processed on servers in the USA. The widget is only loaded once you click the chat button in the application dashboard — no data is sent to Chatwoot before that. Chat replies may first come from an AI assistant that only draws on approved help articles; you can ask to be handed to a person at any time.

Legal basis: Art. 6(1)(b) GDPR where your request concerns the contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering requests). Retention: until the request is fully resolved, then [PLACEHOLDER: e.g. 24 months] for traceability, unless statutory retention obligations apply.

10. Connections to other systems

When you connect a CRM, spreadsheet or other tool (e.g. HubSpot, Salesforce, Pipedrive, Google Sheets, Airtable, Notion, Lemlist, Stripe, or as an import source Apollo, Phantombuster, Intercom, Zoom, Calendly), the connector service Pipedream, Inc. (San Francisco, USA) manages the login credentials (OAuth) on our behalf; ListPlus itself does not store them. Requests to and transfers into the connected system run wholly or partly through Pipedream's proxy service; the transferred records pass through Pipedream's servers. Which data is transferred is determined by your actions (import, export, pipeline target); a reference list reloads from its source regularly at your request. Destinations you connect with your own API key (e.g. Instantly, Smartlead, Attio, Close, Slack, your own webhook endpoint) we reach directly; we store the key encrypted. Legal basis: Art. 6(1)(b) GDPR; section 11 applies to the content.

Your own AI: Agent API, MCP and research link

You can connect an AI system of your choice (e.g. ChatGPT, Claude or your own agents) to ListPlus through a connection per list (REST at listplus.ai/d/…, MCP at listplus.ai/mcp/…) or through a research link (listplus.ai/r/…). That AI system then reads and writes what the connection exposes (columns, sublists, permitted actions); every call is logged with action, rows, credits and duration (90 days [TO CHECK]). The provider of that AI system is your recipient, not our service provider: which data it receives and how it treats it is determined by your choice of provider and the scope of the connection. The access key is part of the address path and therefore appears in the access logs of our hosting provider.

11. Customer data: ListPlus as processor

Personal data that customers process in ListPlus — such as lists from file imports, imports from LinkedIn or connected systems, enrichment results, saved contacts and Inbox entries — is processed by us on behalf of and on the instructions of the customer (Art. 28 GDPR). The customer is the controller of this data and of its use, for example for sales outreach. Data subjects should address their requests to the company using their data; if such a request reaches us, we forward it to the customer where possible.

The data processing agreement (DPA) at listplus.ai/dpa applies and is part of the user agreement for customers on every plan. A signed copy is available on request at support@listplus.ai.

Retention: lists are stored until the customer deletes them; deletion is immediate and permanent. Some areas are deliberately time-limited: Inbox entries are deleted 14 days after arrival, shared result links stop working 7 days after they were created, AI research runs are deleted 1 to 7 days after they start (the user's choice; a run that hands its hits to a list, 30 days), profiles that were only viewed (not saved or enriched) drop out of “Recently viewed” after 30 days without further activity, and a pipeline’s history (records sent to a destination the customer chose, with the destination’s response) is deleted 30 days after sending. Watchlist entries, contacts from the Outlook add-in and form submissions stay until the customer deletes them.

Deleting the account: you delete your account yourself in the settings (“Delete account”). We then delete your account, every workspace you own with all its lists, files, pipelines, inboxes, research runs and watchlists, your personal data in our database, your pseudonym at PostHog with its events and your support contact at Chatwoot with its conversations; running subscriptions are cancelled. What remains: invoices and the customer record at Stripe (statutory retention), data you created in workspaces owned by others (it belongs to that workspace), logs at the hosting and logging providers until they expire (without user ID), the message history at the email service (45 days), and the cross-customer caches without personal reference. A 30-day marker prevents a still-valid sign-in session from recreating the account.

12. AI processing

ListPlus uses AI models to understand commands, check and judge data, fill AI columns, detect columns on import, recognise Inbox entries and webhook records, transcribe dictation and run research. The calls are made exclusively from our servers, never from your browser; the AI provider receives the part of the data the task needs — for checks only distinct values, for the features named below also whole texts or records:

Providers: OpenAI (language models and transcription; requests are sent with the “do not store” setting and, according to the provider, not used for training) [TO CHECK: contracting entity Ireland/USA], Groq, Inc. (USA; a fast model for short single calls) and TypeSafe AI (judgement model “Jev”, connected through the AI Gateway of Vercel Inc., without storage at the provider) [TO CHECK: seat]. Seat, data location and safeguard per provider are in section 15. A workspace owner can switch all AI features off for the workspace (workspace policy); no AI provider is called then. Legal basis: for customer data we act as processor (section 11); otherwise Art. 6(1)(b) GDPR. No automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR takes place; AI results (including judgements such as seniority or a “fit” score in research) are suggestions that the user reviews and applies. The research fit score describes how well a hit matches the customer's search description; a workspace owner can switch this rating off (workspace policy), after which no hit is rated.

13. Data providers and data enrichment (information under Art. 14 GDPR)

ListPlus lets customers search for, complete and verify business contact and company data. This data does not come from ListPlus itself — ListPlus owns no contact database of its own — but is retrieved at the moment of the request from specialised data providers or from publicly available sources. If your business contact data has been retrieved through ListPlus, this section informs you about the processing.

Categories of data

Name, job title and seniority, company and company data (industry, size, location, website, funding, technologies), business email address and its deliverability status, business phone number and, where applicable, mobile number, LinkedIn profile URL, location, and publicly visible profile details (e.g. career history, past employers) as well as public posts, comments or reactions where a customer retrieves them. In AI research, in addition: the source (URL), a short piece of evidence (e.g. the comment that led to the hit) and an estimate of how well the person matches the search description (“fit”, 0–100, with a reason).

Sources

The data comes from data providers that run their own databases of business contacts — Prospeo (contact database, email and phone), FullEnrich (email and phone), CompanyEnrich (company data), MillionVerifier (deliverability), HarvestAPI and Enrich.so (publicly visible LinkedIn data), Serper (Google search results) — and from publicly accessible sources that a service reads at the customer's request: LinkedIn (search results, employee lists, posts, comments and reactions, profile search including by past employer), Crunchbase company pages, Reddit, X, Hacker News (search via Algolia, only the search term), Google Maps profiles, web traffic estimates and arbitrary websites, also to find contact details. These public sources are read by the data collection platform Apify (Prague) with third-party programs (“actors”); the platforms themselves are not our contracting partners. The complete, current list with seat, data transmitted and safeguard is at listplus.ai/en/subprocessors, Part B.

The data providers are responsible for their own data sets; information on their processing is available in their respective privacy notices. A workspace owner can switch individual providers and sources off for the workspace (workspace policy).

Purposes, recipients and legal basis

The data is retrieved when a customer triggers a specific search or enrichment and is provided only to that customer, who uses it for their own business purposes (e.g. sales, maintaining CRM data). We send the data provider only the search key needed for the lookup (e.g. email address, domain, LinkedIn URL, name and company, or search filters), never the rest of the customer's list. The legal basis is Art. 6(1)(f) GDPR: the legitimate interest of the customer and of ListPlus lies in finding business contacts and maintaining accurate business data; it is limited to data in a professional context. Personal enrichment results (email addresses, phone numbers, job titles) are not shared between customers. For retrievals a customer triggers, we act as that customer's processor (DPA § 2). [TO CHECK: allocation of controller/processor roles when retrieving third-party data, see lawyer notes L29.]

Watchlist: monitoring contacts

This feature is switched off by default in every workspace; only the owner can switch it on, after a notice of their responsibility (the time is recorded). A customer can then have individual contacts on their Watchlist monitored: weekly or daily, ListPlus reads the person's public LinkedIn profile (via HarvestAPI) and checks whether position or employer changed or new posts appeared; an AI model classifies the kind of position. Events are stored in the customer's workspace and can be handed to a pipeline of the customer. This is a recurring observation of specific people; it happens only when the customer explicitly sets it up, the customer is the controller for it, and a workspace owner can switch it off. Anyone who objects to the monitoring (section “Your rights”) is no longer retrieved.

Outlook add-in

If a customer uses the Outlook add-in, it sends the name and email address of the correspondent currently opened to ListPlus, which retrieves data about them as in an enrichment and stores them in an “Outlook Contacts” list of the workspace until the customer deletes them.

Retention

Results added to a customer's list are stored until the customer deletes them (section 11). Lookup results about people are cached only in the respective customer's workspace to avoid duplicate lookups: 30 days from the workspace's last lookup. Company data for a domain (name, industry, size, location, website, technologies, funding, address and phone of the headquarters — no details about people) is kept in a company cache shared across customers for 30 days from retrieval; a workspace can switch off contributing to this cache.

Your rights

You have the rights listed in section 18, in particular the right to object to the processing of your data at any time. To do so, contact support@listplus.ai. Where a customer processes your data in its own lists or contacts you, that customer is the controller; your objection to direct marketing should then be addressed to that customer. A short version of this information addressed to you is at listplus.ai/en/contact-data-notice. An objection is entered into a suppression list that applies to all customers: your data is then no longer retrieved through ListPlus.

14. Email receiving and sending (Postmark)

Users can forward emails to a personal address at @in.listplus.ai so that ListPlus recognises contact details in them (e.g. from signatures, vCards or calendar invitations). These emails are received via the Postmark service (ActiveCampaign, LLC, formerly Wildbit, USA). Postmark accepts the email and passes its content to us as structured data (JSON). We process sender, recipient, subject, body and supported attachments of the forwarded email; third-party data contained in it is processed by us as the user's processor (section 11). To recognise contacts, the content is sent to AI providers (section 12).

Through the same service we send, from notifications@listplus.ai, workspace invitations (the invitee's address, the inviter's name, the workspace name) and, when a customer sets up a pipeline with the “Email” target, digest mails to members of the workspace with the name, position and company of each entry and a link to its contact card (the links work for 30 days). Sign-in codes are sent by the sign-in service (section 6), not by Postmark. A workspace owner can switch the Inbox address and pipeline emails off.

Legal basis: Art. 6(1)(b) GDPR (providing the feature the user uses). Third-country transfer: we base the transfer to Postmark in the USA on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). [TO CHECK: data processing agreement with Postmark still to be signed.] Retention: Postmark keeps messages for 45 days by default [TO CHECK: planned shortening of this period]. Inbox entries are deleted automatically on our side 14 days after arrival; contacts the user saves or adds to a list are kept.

14a. List webhooks and forms

A customer can set up a webhook per list (an address at listplus.ai/i/…) to which other systems send records, and publish a form (listplus.ai/f/…) that visitors of the customer's website fill in. We process the data arriving this way as the customer's processor (section 11); the customer is the controller towards the data subjects and informs them. Records pass through the queues of our hosting provider; unknown field names and, on request, a spam check go to AI models (section 12); doubtful records can be held back in the customer's Inbox.

For a form we store, per submission, the page it is embedded in, with a consent checkbox the consent and its time, and for two minutes a shortened hash of the visitor's IP address to limit mass submissions; we serve the fonts ourselves, no third-party content is loaded. The form's consent text is a suggestion to the customer, not legal advice. Legal basis: Art. 6(1)(b) GDPR towards the customer; for abuse limitation Art. 6(1)(f) GDPR.

15. Recipients and subprocessors

We only pass on personal data where this is necessary for the purposes described. Within our company, only people who need access for their tasks have it. We use the following service providers:

Part A: Sub-processors

Service providerServiceData transmittedSeat / locationThird-country safeguard
Vercel Inc.Running the application, file storage for lists and imports, queues for background work, web analytics and speed insights, AI gateway (access to the model “Jev”)All data of the application; connection data on every request (IP address, browser)Covina, California, USA — Hosting, file storage and queues in the EU region FrankfurtEU-U.S. Data Privacy Framework; Standard Contractual Clauses in the data processing agreement
Redis Ltd. (Redis Cloud)The application's database: workspaces, lists, working data, cachesAll data of the applicationSeat: Mountain View, California, USA — Database in Frankfurt (AWS eu-central-1), transport TLS-encrypted — [TO CHECK: Confirm the data processing agreement and encryption at rest]Processing in the EU; Standard Contractual Clauses for support access from third countries
Pusher Ltd.Live status updates in the browser (import done, enrichment running, new hits)Events about operations; for small changes the changed cell valuesLondon, United Kingdom — [TO CHECK: Confirm the cluster location]Adequacy decision for the United Kingdom
Pipedream, Inc.Connections to CRM systems and spreadsheets (OAuth credentials, forwarding of calls); internal notifications about account, list and payment eventsRecords the customer exchanges with a connected system; from events the user id, e-mail address, list name and row count and a summary of the payment event (customer, e-mail, amount, plan)San Francisco, California, USA — [being replaced] — [TO CHECK: The service is being discontinued; notifications move to n8n, the replacement for connections is open]Standard Contractual Clauses
Postmark (ActiveCampaign, LLC)Receiving e-mails forwarded to the Inbox address @in.listplus.ai; sending workspace invitations and pipeline digest mails from notifications@listplus.aiForwarded e-mails in full (sender, subject, body, attachments); the invitee's address and the inviter's name; per digest entry name, position, companyChicago, Illinois, USA — [TO CHECK: Sign the data processing agreement; shorten retention at the provider (default 45 days)]Standard Contractual Clauses
OpenAILanguage models for commands, checks, AI columns, column recognition on import, recognition of contacts in the Inbox, mapping of unknown webhook fields, AI research; transcription of dictationsThe excerpt the task needs (section “AI processing” of the privacy policy); requests are not stored at the provider (store: false) and not used for trainingOpenAI Ireland Ltd., Dublin, Ireland (contracting entity for the EU) / OpenAI, L.L.C., San Francisco, USA — [TO CHECK: Confirm the contracting entity (Ireland/USA) and the Data Processing Addendum]EU-U.S. Data Privacy Framework; Standard Contractual Clauses in the Data Processing Addendum
Groq, Inc.Fast language model for short single calls: understanding a search query, role resolution, list titles, short Inbox entriesThe short text of the request (search description, signature line)Mountain View, California, USA — [TO CHECK: Confirm the Data Processing Addendum and the no-training clause]Standard Contractual Clauses
TypeSafe AI (Modell „Jev“, über das AI Gateway von Vercel)Judgement model: seniority of job titles, kind of a LinkedIn position, pre-check of Inbox entries and webhook records, judge columnsThe values to judge (job titles, positions, up to 12 fields of a record); without storage at the provider (zero data retention)Seat: to be confirmed — [TO CHECK: Confirm seat, contracting entity and safeguard]Standard Contractual Clauses via Vercel
Apify Technologies s.r.o.Data collection platform: runs scrapers (“actors”) that read public pages — LinkedIn imports (Sales Navigator, employee lists, post reactions and comments, people search incl. by past employer), Crunchbase company pages, Reddit, X, Google Maps profiles, web traffic, contact details on websitesThe search URL, company URL, post URL, company name or research query — never the customer's listPrague, Czech Republic — [TO CHECK: Confirm the data processing agreement; third-party actors run on Apify's infrastructure]Processing in the EU
PostHog Inc. (EU-Cloud)Usage events of the application (which feature was used when), pseudonymousEvent name and properties, a pseudonym of the account (hash), plan, workspace hash; no names, e-mail addresses or list contents; can be switched off per account and per workspaceSan Francisco, California, USA — EU cloud in FrankfurtProcessing in the EU; Standard Contractual Clauses in the data processing agreement
Axiom, Inc.Server logs and browser error reports for troubleshootingLog lines of the application; on browser errors the error text, stack and page (without user id and without query string)San Francisco, California, USA — [TO CHECK: Confirm seat, data location and retention period]Standard Contractual Clauses
Chatwoot Inc.Support chat in the application; first answers by an AI assistant that reads only approved help textsUser id, name, e-mail address and chat messages; only after clicking the chat buttonWilmington, Delaware, USA — [TO CHECK: Confirm the data processing agreement]Standard Contractual Clauses
Hanko GmbHSign-in: e-mail address with one-time code or Google login; sessions (30 days)E-mail address, user id, sign-in method, timestampsKiel, GermanyProcessing in the EU
Google LLC (Anmeldung mit Google)Confirming the sign-in when the user chooses “Sign in with Google”E-mail address and Google account id; Google learns that the person signs in to ListPlusMountain View, California, USAEU-U.S. Data Privacy Framework
Stripe Payments Europe, Ltd.Payments, invoices, VATName, e-mail address, billing address, VAT id, payment data (only at Stripe)Dublin, IrelandStandard Contractual Clauses for transfers to Stripe, Inc. (USA)
Attio Ltd. (CRM)Account e-mails: stores the e-mail address at sign-up and sends the welcome e-mailE-mail addressLondon, United KingdomAdequacy decision for the United Kingdom
Amazon Web Services EMEA SARL (DynamoDB)User record: e-mail address and purchased planE-mail address, planLuxembourg — Frankfurt (eu-central-1)Processing in the EU

Part B: Data providers and sources

On a lookup these providers receive only the search key (e.g. e-mail address, domain, LinkedIn URL, name and company or search filters), never the rest of the list. They are controllers of their own data; ListPlus is the tool with which the customer queries them. Whether they count as sub-processors or as independent recipients for the search key is being clarified with our lawyers.

Service providerServiceData transmittedSeat / locationThird-country safeguard
ProspeoB2B contact database (segment search), verified business e-mail addresses and phone numbers, company profiles, job changesSearch filters or the search key: LinkedIn URL, name and company, domainProspeo SAS, Paris, France — [TO CHECK: Confirm the seat]Processing in the EU
FullEnrichBusiness e-mail address and phone number from name and company or LinkedIn URL (waterfall through 20+ sources)Name and company, domain or LinkedIn URLFullEnrich Corp., San Francisco, USAStandard Contractual Clauses according to the provider's privacy policy
CompanyEnrichCompany data from domain or company name (industry, size, location, website); workforce, decision makers, similar companiesDomain or company name; for person lookups name and companyCompany in Turkey — Servers, databases and backups in Finland — [TO CHECK: Clarify the safeguard for access from Turkey]Processing in the EU (Finland); Turkey without an adequacy decision
HarvestAPIPublicly visible LinkedIn data: profile, company, profile search, posts and reactions, open jobs; the basis of the Watchlist alertsLinkedIn URL, name and company, post URLSeat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmed
Enrich.soPublicly visible LinkedIn profile data from a URL (fallback when HarvestAPI does not answer)LinkedIn URLSeat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmed
MillionVerifierChecking whether an e-mail address is deliverableThe e-mail addressGBD Software as a Service Private Limited Company, Budapest, HungaryProcessing in the EU
Serper (Google-Suche)Google search results: LinkedIn profile URL for name and company, company website, news, web search of the AI research, confirmation of recognised contacts in the InboxThe search term (e.g. name and company)Serper, seat: to be confirmed — [TO CHECK: Confirm seat and safeguard]To be confirmed
Hacker News (Suche über Algolia)Public stories and comments on Hacker News including user names, for the AI researchOnly the search term, never data from customer listsAlgolia, Inc., San Francisco, USA — public interface without an accountNo contract; only the search term is transmitted
Öffentliche Quellen (über Apify gelesen)Publicly visible pages a scraper reads at the customer's request; the platforms are not our contracting partners, the customer observes their termsThe URL or search calledLinkedIn, Crunchbase, Reddit, X, Google Maps, Similarweb, arbitrary websitesNot applicable (retrieval of public pages)

Part C: Recipients chosen by the customer

Systems the customer transfers data to because it connects or names them itself. The customer is the controller of that transfer; they are listed for completeness.

Service providerServiceData transmittedSeat / locationThird-country safeguard
Verbundene Systeme des KundenImport from and export to systems the customer connects; pipeline targetsThe records the customer transfersHubSpot, Salesforce, Pipedrive, Google Sheets, Airtable, Notion, lemlist (via Pipedream); Instantly, Smartlead, Attio, Close, Slack (with the customer's key)The customer is the controller of this transfer
Eigener Webhook-Endpunkt des KundenPipeline target “endpoint”The records the customer transfersNamed by the customerThe customer is the controller of this transfer
Die eigene KI des Kunden (Agent-API, MCP, Recherche-Link)Reading and writing lists and research through an AI system the customer connectsWhat the connection exposes (columns, sublists, actions)Chosen by the customer, e.g. ChatGPT, Claude, own agentsThe customer is the controller of this transfer

We have concluded, or are concluding, data processing agreements under Art. 28 GDPR with service providers acting on our behalf. [TO CHECK: completeness of the agreements.] The current list with seat, data location and safeguard is published at listplus.ai/en/subprocessors; it is also Annex 3 of our data processing agreement. Beyond that, we only disclose data where we are legally obliged to (e.g. to authorities or tax advisers under statutory obligations).

16. Transfers to third countries

Some of the service providers listed are based outside the EU/EEA, in particular in the USA, or use subcontractors there. We host the application in the EU region Frankfurt but cannot rule out that data is transferred to third countries. Transfers only take place where there is an adequacy decision of the European Commission (e.g. for companies certified under the EU-U.S. Data Privacy Framework, Art. 45 GDPR) or appropriate safeguards are in place, in particular EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can request a copy of the safeguards at support@listplus.ai.

17. Retention at a glance

DataRetention
Account and usage dataFor the duration of the user relationship; deleted after account deletion
Lists and saved contactsUntil deleted by the customer or until account deletion
Inbox entries14 days after arrival
Forwarded emails at the receiving service Postmark45 days (provider default) [TO CHECK: planned shortening]
Shared result links7 days from creation
AI research runs1 to 7 days from start, the user's choice; 30 days when hits are handed to a list
Watchlist, Outlook contacts, form submissionsUntil deleted by the customer
Profiles only viewed (“Recently viewed”)30 days after last activity
Pipeline history (records sent and responses)30 days after sending
Cached lookup results about people (per workspace)30 days from the last lookup
Company cache (shared across customers, no personal reference)30 days from retrieval
Usage events (PostHog, pseudonymous)Until the account is deleted, at most [TO CHECK: period at PostHog]
Invoices and accounting recordsStatutory retention periods: vouchers 8 years, books 10 years
Server log files and error reports[PLACEHOLDER: periods at Vercel and Axiom]
Support requests[PLACEHOLDER]

We have no feature to restore deleted data. Technical backups at our hosting provider are overwritten according to its periods [TO CHECK: backup periods].

18. Your rights

You have the following rights towards us regarding your personal data:

Right to object (Art. 21 GDPR): where we process your data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. Where your data is processed for direct marketing, you can object at any time without giving reasons; the data will then no longer be processed for that purpose.

To exercise your rights, a message to support@listplus.ai is enough. We respond without undue delay and at the latest within one month (Art. 12(3) GDPR).

Right to lodge a complaint (Art. 77 GDPR): you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

19. Obligation to provide data

Providing your email address is required for registration; without it we cannot set up an account. Payment details are required to subscribe to a paid plan or buy credits. Otherwise you are under no obligation to provide us with data.

20. Data security

Every transmission — between your browser and us, between our servers and the database, and to every service provider — is encrypted (TLS). Files are stored encrypted at our hosting provider [TO CHECK: encryption at rest for Redis Cloud]. API and AI keys are used on the server only; access keys customers store for their own destinations are stored encrypted. Access to lists requires sign-in and is limited to the members of the respective workspace. ListPlus itself holds no security certification of its own; our hosting provider Vercel is certified to ISO 27001:2022, among others, and has a SOC 2 Type 2 report.

21. Changes to this privacy policy

We update this privacy policy when our service or the legal situation changes. The version published on this page applies.