Data security and privacy are core principles at Dropcontact. Our services are designed to comply with applicable data protection regulations, including the General Data Protection Regulation (GDPR), and are governed by documented security policies, contractual safeguards, and independent audits. Dropcontact applies privacy by design and by default, ensuring that security and data protection are embedded throughout the lifecycle of our services.
Dropcontact is the only B2B contact data enrichment solution to have been audited by the CNIL, France’s data protection authority, widely regarded as one of the most stringent worldwide. The audit included full access to Dropcontact’s servers, stored data, and source code.
Key legal documents:
Depending on the context, Dropcontact acts as:
The emails and data provided by Dropcontact are processed in full compliance with the General Data Protection Regulation (GDPR).
Unlike most solutions on the market, Dropcontact does not use or store any contact database, whether purchased, scraped, or contributed by users. Our proprietary algorithms generate results in real time using only first name, last name, and company name as input. The result is generated dynamically, and we don’t retain or reuse any contact data after processing. We don’t sell leads: instead, we enrich the contact data you already have.
All processing is done on European servers, and no personal data is stored. This ensures maximum compliance, transparency, and security while also keeping the information fresh, accurate, and achieving a high data enrichment rate.
Dropcontact processes professional (B2B) contact data only. Categories of personal data processed include:
Dropcontact does not process sensitive personal data as defined under Article 9 of the GDPR.
Personal data is processed solely for the performance of the contracted services, including:
Processing is carried out strictly in accordance with the documented instructions of the data controller.
Our service’s overall security is governed by our Information Security Policy, which encompasses access management for IT infrastructure, encryption key management, system and software updates, security network configurations, and incident management.
Dropcontact implements appropriate technical and organizational security measures, including:
These measures are designed to preserve the confidentiality, integrity, and availability of personal data.
Yes. Dropcontact undergoes an annual external security audit: CASA Validation Report. The audit includes:
Audit documentation may be made available upon request and subject to confidentiality obligations.
Personal data processed by Dropcontact is hosted on servers located within the European Union. Dropcontact relies on infrastructure providers with servers in the EU.
Yes. Dropcontact uses a single authorized sub-processor, contractually bound to provide appropriate security and data protection guarantees:
Customers are informed in advance of any planned changes to sub-processors and have the right to object within the timeframe defined in the DPA.
In the event of a personal data breach, Dropcontact:
This process is defined in the Dropcontact DPA.
Dropcontact is not currently certified under ISO/IEC 27001 or SOC 2. However, Dropcontact undergoes an annual independent security audit: CASA Validation Report. This audit covers:
In addition, Dropcontact relies exclusively on Amazon Web Services (AWS) as its infrastructure provider. AWS is fully compliant with internationally recognized security standards, including ISO/IEC 27001 and SOC 2 (Type II). No other third-party infrastructure providers are involved in the delivery of the service. Dropcontact’s security program is designed in alignment with industry best practices reflected in these standards, and its security posture is continuously reviewed and improved through regular audits and internal controls.
Dropcontact assists data controllers, where applicable, in responding to requests to exercise data subjects’ rights, including:
Requests received directly by Dropcontact are forwarded to the relevant data controller without delay.
For data protection and privacy-related inquiries, Dropcontact can be contacted at: data@dropcontact.io
Try Dropcontact free and see the difference on your own contacts.