Legal

Data processing, explained.

Who does what with personal data, in GDPR terms. Last updated 30 July 2026.

Roles

For list data you upload, you are the controller and ListFunnel is the processor: we process addresses and resolved attributes solely on your instructions to provide the product.

For your own account data (login email, billing), ListFunnel is the controller.

What processing happens

Storage and organization of your lists; validation lookups (DNS/MX queries per domain); identity resolution via the enrichment providers configured for your workspace; computation of segments and analytics inside your workspace.

No processing for our own purposes: no cross-customer pooling, no model training on your lists, no resale.

Subprocessors

Current subprocessors are listed at /legal/subprocessors with their roles. We'll update that page before adding any new one.

Security & deletion

Encryption in transit (TLS) and at rest (Cloudflare D1). Workspace isolation per customer. Deletion of a list or workspace removes the underlying data immediately.

Your obligations as controller

Have a lawful basis for the lists you upload (consent or legitimate interest), honor data-subject requests (we'll assist — privacy@listfunnel.ai), and don't upload special-category data; ListFunnel is built for professional contact data only.

Formal DPA

A signable GDPR Data Processing Agreement (with SCCs where relevant) is available for paid workspaces — request it at legal@listfunnel.ai. This page is orientation, not the contract.