Legal
Data processing, explained.
Who does what with personal data, in GDPR terms. Last updated 30 July 2026.
Roles
For list data you upload, you are the controller and ListFunnel is the processor: we process addresses and resolved attributes solely on your instructions to provide the product.
For your own account data (login email, billing), ListFunnel is the controller.
What processing happens
Storage and organization of your lists; validation lookups (DNS/MX queries per domain); identity resolution via the enrichment providers configured for your workspace; computation of segments and analytics inside your workspace.
No processing for our own purposes: no cross-customer pooling, no model training on your lists, no resale.
Subprocessors
Current subprocessors are listed at /legal/subprocessors with their roles. We'll update that page before adding any new one.
Security & deletion
Encryption in transit (TLS) and at rest (Cloudflare D1). Workspace isolation per customer. Deletion of a list or workspace removes the underlying data immediately.
Your obligations as controller
Have a lawful basis for the lists you upload (consent or legitimate interest), honor data-subject requests (we'll assist — privacy@listfunnel.ai), and don't upload special-category data; ListFunnel is built for professional contact data only.
Formal DPA
A signable GDPR Data Processing Agreement (with SCCs where relevant) is available for paid workspaces — request it at legal@listfunnel.ai. This page is orientation, not the contract.