You're the controller for that request
You decide who to contact through ListPlus, so you answer access, erasure and objection requests yourself, not ListPlus.
Privacy & GDPR
Roles, hosting locations, named subprocessors, retention periods and how to request a DPA — the specifics behind ListPlus's data handling.
You decide who to contact; ListPlus processes your list data on your behalf under a DPA.
Application and files run on Vercel in Frankfurt; the working data cache is in Frankfurt too.
A data processing agreement is available for every plan — email support@listplus.ai.
For the contact data in your lists, the two roles are kept separate.
A tool, not a database. The customer is the controller and in control, on the server. One provider list with every name. A notice and a suppression list for the people in the data. And a section on what is still open — we write that down too.
The same text opens the data protection package.
A data protection officer who objects to one provider or one feature does not have to reject the product.
Everything a data protection officer asks for in one printable page: the workspace switches, the DPA with its annexes, every provider with seat and safeguard, the notice for the people in the data, and the privacy policy. Customers generate the same package with their own switches from the workspace settings — or send it as a 30-day link.
Opens in the browser; print or download from there.
Application, files and the working data cache are hosted in the Frankfurt region.
Each subprocessor handles one part of the product and receives only what that part needs. The complete list with safeguards and the policy switch per provider is at listplus.ai/en/subprocessors.
| Subprocessor | Purpose | Data received | Seat / location |
|---|---|---|---|
| Vercel | Hosting, application runtime, file storage | Your lists, uploaded files, usage data | Hosting region Frankfurt (EU); may transfer data to the US under its DPA |
| Redis Cloud (Redis Ltd.) | Working data cache for fast reads | A cached copy of your list data | Hosting region AWS eu-central-1 (Frankfurt); seat on request |
| Vercel Analytics / Speed Insights | Product usage and performance analytics | Page-view and performance data | on request |
| Algolia | Hacker News search in AI Research | Your research query | on request |
| Hanko | Authentication — sign-in and one-time login codes | Your email address | on request |
| Pusher | Realtime status updates (import, enrichment) | Account-scoped event and status data | on request |
| Stripe | Subscription and credit-pack payments | Billing and payment details | on request |
| Postmark | Inbound e-mail for the Inbox feature | E-mails forwarded to your Inbox address | on request |
| Pipedream | OAuth for connected apps (HubSpot, Salesforce, Pipedrive, Google Sheets, Airtable, Notion, Lemlist, Stripe); sign-up and payment workflows | Login credentials for connected apps (held by Pipedream, not ListPlus); account, list and payment event notifications — of these, only your email address is passed on and stored (CRM and user database) | on request |
| Attio (CRM) | Account e-mails: stores your email address at sign-up and sends the welcome e-mail | Your email address only | London, UK (hosting region on request) |
| AWS DynamoDB (Amazon Web Services) | User record for your account and purchased plan | Your email address and the plan you bought | Frankfurt, Germany (EU) |
| OpenAI, Groq; Vercel AI Gateway (value-classification model) | AI model providers for AI commands, checks, AI Column, AI Research and Inbox recognition | Text sent by ListPlus's AI features — never a whole list | on request |
| Prospeo | Person and company contact lookups (Segment Search and more) | Search filters, or the identifier being looked up (LinkedIn URL, name + company, domain) | on request |
| FullEnrich | Person contact lookups (email ↔ profile) | An email address, or a name + company | San Francisco, California, USA |
| CompanyEnrich | Company detail lookups | A domain, company name, or email | Legal entity: Turkey. Compute, databases and backups: Finland |
| MillionVerifier | Email verification | An email address | Hungary |
| HarvestAPI (fallback: Enrich.so) | LinkedIn profile, company and search data | A LinkedIn URL, or a name + company | on request |
| Apify (runs third-party scraping actors: HarvestAPI, Freshdata, Crunchbase and others) | LinkedIn imports; Crunchbase company data; optional AI Research sources (Reddit, X; BuiltWith currently not available) | A search, company or post URL, a company name, or a research query | on request |
| Serper (Google search) | Web search — finding a LinkedIn URL or company website, AI Research web search | The search query | on request |
| Chatwoot | In-app support chat | Your name, email address and chat messages | on request |
Some subprocessors may process data outside the EU; those transfers are covered by data processing agreements. A full subprocessor list with exact locations is available on request from support@listplus.ai.
Your lists stay until you delete them. A few places are deliberately temporary.
| What | Kept for |
|---|---|
| Lists | Until you delete them — no automatic expiry |
| Inbox entries | 14 days after arrival |
| Shared result links | 7 days from creation — opening the link does not extend it |
| Background AI Research runs | 7 days from when you start them |
| Recently viewed profiles (Person Search) | 30 days of no further activity — contacts saved to a folder or enriched don't expire |
| Search result sessions (Segment Search, Person Search) | 30 days, sliding — renewed each time you reopen them |
| LinkedIn lookup cache (profile, company, search) | 30 days |
| Provider lookup cache (Prospeo, FullEnrich, Crunchbase) | 7 days, per user — only lookups that returned data |
| Repeated Segment Search | 30 days |
| Company data cache (by domain) | Shared across all customers, no fixed expiry |
| AI classification cache | 30 days for confident results |
| Email verification cache | 7 days |
| Inbound e-mail at the provider (Postmark) | on request |
Each AI feature receives only the data it needs for that one job.
Available for every plan — Basic, Pro and Premium. Email your company name to support@listplus.ai and it's sent to you to sign; there's no self-service download in the app today. ListPlus itself holds no security certification of its own (no ISO 27001, SOC 2 or similar). Vercel, ListPlus's hosting provider, holds its own certifications, including SOC 2 Type 2 and ISO 27001:2022 — that's Vercel's certification, not ListPlus's, covering Vercel's infrastructure.
That request is addressed to you, not to ListPlus — but ListPlus gives you what you need to answer it.
You decide who to contact through ListPlus, so you answer access, erasure and objection requests yourself, not ListPlus.
The number badge in the sparkles column at the right edge of a row opens the record panel, where each enrichment result is headed with its provider, for example "Prospeo · Contact".
Select the row and use the selection bar's ⋯ menu → Delete (saved automatically; Undo brings it back). This removes it from that list only — not other lists, your watchlist, the Inbox, an export, or a CRM you already pushed it to.
DPA requests, the full subprocessor list with exact locations, backup and retention questions at ListPlus's providers, or the full subprocessor list is published at listplus.ai/en/subprocessors; deleting your entire account is self-service in Settings → Profile — all go through support.
support@listplus.ai
On Vercel, in the EU region Frankfurt. The working data cache (Redis Cloud) is also in Frankfurt, on AWS eu-central-1.
You are. ListPlus processes that data on your behalf under a DPA, but you decide who to contact and why.
No, not ListPlus itself. Vercel, its hosting provider, holds its own certifications, including SOC 2 Type 2 and ISO 27001:2022 — that covers Vercel's infrastructure, not a ListPlus certification.
Yes, for every plan. Email support@listplus.ai with your company name and it's sent to you to sign.
No. AI commands see your instruction and column structure; AI checks and AI Column see only distinct values; enrichment providers see only the identifier being looked up.
No, you do — you're the controller for that outreach. The record panel's provider badge on each row shows the source you need.
Lists are kept until you delete them. A few places are temporary by design: Inbox (14 days), shared result links (7 days from creation), research runs (1 to 7 days, 30 with hand-off to a list), lookup caches about people (30 days per workspace) and a shared company cache without personal data (30 days).
Try the sample list or bring your own starting point.