Privacy & GDPR

Privacy & GDPR at ListPlus

Roles, hosting locations, named subprocessors, retention periods and how to request a DPA — the specifics behind ListPlus's data handling.

You control outreach

You decide who to contact; ListPlus processes your list data on your behalf under a DPA.

EU hosting

Application and files run on Vercel in Frankfurt; the working data cache is in Frankfurt too.

DPA on request

A data processing agreement is available for every plan — email support@listplus.ai.

Roles

You are the controller. ListPlus is the processor.

For the contact data in your lists, the two roles are kept separate.

You (the controller)
You decide who to contact, why, and on what legal basis. That responsibility stays with you.
ListPlus (the processor)
ListPlus processes your list data on your behalf — storage, enrichment, checks — under a data processing agreement (DPA), available on request.
Our position

How we see our role — written for your data protection officer.

A tool, not a database. The customer is the controller and in control, on the server. One provider list with every name. A notice and a suppression list for the people in the data. And a section on what is still open — we write that down too.

Read our position

The same text opens the data protection package.

Your controls

What you can switch off.

A data protection officer who objects to one provider or one feature does not have to reject the product.

Workspace policy
The workspace owner switches off, for everyone in the workspace: single data providers (Prospeo, FullEnrich, CompanyEnrich, LinkedIn data, e-mail verification, Google search, scrapers), AI features, Watchlist alerts, the Inbox e-mail address, the Agent API, connected systems, pipeline e-mails, the support chat, usage events, or contributing to the shared company cache. Off means no data reaches that provider — enforced on the server, not only hidden in the UI. The policy exports as a text file for your review.
Published provider list
Every sub-processor, data provider and source with seat, data received, safeguard and the switch that stops it, at listplus.ai/en/subprocessors — the same list as Annex 3 of the DPA, generated from one source.
For the people in the data
A notice addressed to them at listplus.ai/en/contact-data-notice, and a global do-not-retrieve list: someone who objects is no longer looked up through ListPlus, for any customer.
One click

The data protection package, before you sign up.

Everything a data protection officer asks for in one printable page: the workspace switches, the DPA with its annexes, every provider with seat and safeguard, the notice for the people in the data, and the privacy policy. Customers generate the same package with their own switches from the workspace settings — or send it as a 30-day link.

Open the sample package

Opens in the browser; print or download from there.

Hosting & locations

EU hosting, Frankfurt region.

Application, files and the working data cache are hosted in the Frankfurt region.

Application & file storage
Vercel, EU region Frankfurt. Runs ListPlus and stores your lists and uploaded files.
Working data cache
Redis Cloud, hosted on AWS eu-central-1 (Frankfurt), for fast reads while you work in a list.
Cross-border transfers
Some processing — AI features, enrichment lookups — is done by subprocessors outside the EU. Those transfers are covered by data processing agreements.
Subprocessors

Who processes data on ListPlus's behalf.

Each subprocessor handles one part of the product and receives only what that part needs. The complete list with safeguards and the policy switch per provider is at listplus.ai/en/subprocessors.

SubprocessorPurposeData receivedSeat / location
VercelHosting, application runtime, file storageYour lists, uploaded files, usage dataHosting region Frankfurt (EU); may transfer data to the US under its DPA
Redis Cloud (Redis Ltd.)Working data cache for fast readsA cached copy of your list dataHosting region AWS eu-central-1 (Frankfurt); seat on request
Vercel Analytics / Speed InsightsProduct usage and performance analyticsPage-view and performance dataon request
AlgoliaHacker News search in AI ResearchYour research queryon request
HankoAuthentication — sign-in and one-time login codesYour email addresson request
PusherRealtime status updates (import, enrichment)Account-scoped event and status dataon request
StripeSubscription and credit-pack paymentsBilling and payment detailson request
PostmarkInbound e-mail for the Inbox featureE-mails forwarded to your Inbox addresson request
PipedreamOAuth for connected apps (HubSpot, Salesforce, Pipedrive, Google Sheets, Airtable, Notion, Lemlist, Stripe); sign-up and payment workflowsLogin credentials for connected apps (held by Pipedream, not ListPlus); account, list and payment event notifications — of these, only your email address is passed on and stored (CRM and user database)on request
Attio (CRM)Account e-mails: stores your email address at sign-up and sends the welcome e-mailYour email address onlyLondon, UK (hosting region on request)
AWS DynamoDB (Amazon Web Services)User record for your account and purchased planYour email address and the plan you boughtFrankfurt, Germany (EU)
OpenAI, Groq; Vercel AI Gateway (value-classification model)AI model providers for AI commands, checks, AI Column, AI Research and Inbox recognitionText sent by ListPlus's AI features — never a whole liston request
ProspeoPerson and company contact lookups (Segment Search and more)Search filters, or the identifier being looked up (LinkedIn URL, name + company, domain)on request
FullEnrichPerson contact lookups (email ↔ profile)An email address, or a name + companySan Francisco, California, USA
CompanyEnrichCompany detail lookupsA domain, company name, or emailLegal entity: Turkey. Compute, databases and backups: Finland
MillionVerifierEmail verificationAn email addressHungary
HarvestAPI (fallback: Enrich.so)LinkedIn profile, company and search dataA LinkedIn URL, or a name + companyon request
Apify (runs third-party scraping actors: HarvestAPI, Freshdata, Crunchbase and others)LinkedIn imports; Crunchbase company data; optional AI Research sources (Reddit, X; BuiltWith currently not available)A search, company or post URL, a company name, or a research queryon request
Serper (Google search)Web search — finding a LinkedIn URL or company website, AI Research web searchThe search queryon request
ChatwootIn-app support chatYour name, email address and chat messageson request

Some subprocessors may process data outside the EU; those transfers are covered by data processing agreements. A full subprocessor list with exact locations is available on request from support@listplus.ai.

Retention

How long data is kept.

Your lists stay until you delete them. A few places are deliberately temporary.

WhatKept for
ListsUntil you delete them — no automatic expiry
Inbox entries14 days after arrival
Shared result links7 days from creation — opening the link does not extend it
Background AI Research runs7 days from when you start them
Recently viewed profiles (Person Search)30 days of no further activity — contacts saved to a folder or enriched don't expire
Search result sessions (Segment Search, Person Search)30 days, sliding — renewed each time you reopen them
LinkedIn lookup cache (profile, company, search)30 days
Provider lookup cache (Prospeo, FullEnrich, Crunchbase)7 days, per user — only lookups that returned data
Repeated Segment Search30 days
Company data cache (by domain)Shared across all customers, no fixed expiry
AI classification cache30 days for confident results
Email verification cache7 days
Inbound e-mail at the provider (Postmark)on request
What the AI sees

Never the whole list.

Each AI feature receives only the data it needs for that one job.

AI commands (Prompts panel)
Your instruction, column names and types and the row count — not cell values, unless the command needs to judge values, in which case only the distinct values of the relevant columns are sent.
AI checks & AI Column
Only the distinct (unique) values of the column(s) involved, never full rows. A 10,000-row list with a few hundred unique job titles sends a few hundred combinations, not ten thousand rows.
Enrichment providers
Only the identifier needed for that lookup — an email, a domain, a LinkedIn URL, a name and company, or a company name — never your other columns.
AI Research
Your research description, or one person's known identity details — never the rest of your list.
Inbox recognition
The text of an entry you paste or forward (email body and supported attachments), to recognise the contacts in it.
Import column detection
A sample of your file's first rows (10%, 50–200 rows) with real cell values, plus the distinct values of gender, country and yes/no columns from the whole file — on every import, to suggest column types.
Where this runs
All of this happens on ListPlus's servers, never in your browser.
DPA / AVV

A data processing agreement, on request.

Available for every plan — Basic, Pro and Premium. Email your company name to support@listplus.ai and it's sent to you to sign; there's no self-service download in the app today. ListPlus itself holds no security certification of its own (no ISO 27001, SOC 2 or similar). Vercel, ListPlus's hosting provider, holds its own certifications, including SOC 2 Type 2 and ISO 27001:2022 — that's Vercel's certification, not ListPlus's, covering Vercel's infrastructure.

Request a DPA
Data-subject requests

Someone asks where you got their data, or wants it deleted.

That request is addressed to you, not to ListPlus — but ListPlus gives you what you need to answer it.

You're the controller for that request

You decide who to contact through ListPlus, so you answer access, erasure and objection requests yourself, not ListPlus.

The source of a value

The number badge in the sparkles column at the right edge of a row opens the record panel, where each enrichment result is headed with its provider, for example "Prospeo · Contact".

Removing a row

Select the row and use the selection bar's ⋯ menu → Delete (saved automatically; Undo brings it back). This removes it from that list only — not other lists, your watchlist, the Inbox, an export, or a CRM you already pushed it to.

Contact

Questions about your data?

DPA requests, the full subprocessor list with exact locations, backup and retention questions at ListPlus's providers, or the full subprocessor list is published at listplus.ai/en/subprocessors; deleting your entire account is self-service in Settings → Profile — all go through support.

Email support@listplus.ai

support@listplus.ai

Good to know.

Where is ListPlus hosted?

On Vercel, in the EU region Frankfurt. The working data cache (Redis Cloud) is also in Frankfurt, on AWS eu-central-1.

Who is the controller for the contacts in my lists?

You are. ListPlus processes that data on your behalf under a DPA, but you decide who to contact and why.

Does ListPlus hold ISO 27001 or SOC 2 certification?

No, not ListPlus itself. Vercel, its hosting provider, holds its own certifications, including SOC 2 Type 2 and ISO 27001:2022 — that covers Vercel's infrastructure, not a ListPlus certification.

Can I get a DPA / AVV?

Yes, for every plan. Email support@listplus.ai with your company name and it's sent to you to sign.

Does an AI model ever see my whole list?

No. AI commands see your instruction and column structure; AI checks and AI Column see only distinct values; enrichment providers see only the identifier being looked up.

Someone asked where I got their data — does ListPlus answer that?

No, you do — you're the controller for that outreach. The record panel's provider badge on each row shows the source you need.

How long is my data kept?

Lists are kept until you delete them. A few places are temporary by design: Inbox (14 days), shared result links (7 days from creation), research runs (1 to 7 days, 30 with hand-off to a list), lookup caches about people (30 days per workspace) and a shared company cache without personal data (30 days).

Start with anything. End with contacts that are ready.

Try the sample list or bring your own starting point.