Skip to content
Trust centre

What we hold, and what we will not claim

How does Cuvy handle personal data under GDPR and CCPA?

Cuvy holds contact details for people at work: an address, a job title, an employer, with the source and the date it was seen on every row. A request to be removed is honoured within 30 days, from anyone, customer or not. Nothing is resold, and nothing is ever sent from your account. Cuvy holds no third-party security certification today, and says so rather than implying one.

What is held
Business contact data
Every row shows
Source and date seen
Removal
Within 30 days, for anyone
Certifications
None held today
DPA
Available on request

50 addresses free every month · no card

Last updated

What is in it

Working life, and nothing either side of it

The boundary is easier to describe by what is absent than by what is present.

What Cuvy deals in is people at work: an address, a name, a job title, an employer, sometimes a company domain. What it does not hold is anything about a person outside that — no postal addresses, no consumer profiles, no browsing history, and none of the special categories the GDPR lists. There is no way to search this product for someone as a private individual, because there is nothing in it that describes them as one.

One case is worth naming rather than glossing. Recruiting searches can return a personal address, because that is often the only one a candidate reads, and it costs no extra credit. It carries the same source, the same date and the same removal route as everything else, and it is offered to the customer who ran the search rather than published anywhere.

Where a source is about an organisation rather than a person — domain registration records, for instance — it stays in the company directory and never becomes a person row. That distinction is enforced in the product rather than by convention, and it is the reason a company record cannot be turned into somebody's inbox by accident.

Behaviour

Four things that are true of every row and every run

Not principles. Each one is either happening or it is not, and each is checkable from your own account.

A removal is finished within 30 days
Anyone can ask, customer or not, about their own details. The record comes out, and it stays out — the address is kept on a suppression list so a later refresh of the same source cannot quietly put it back.
One source and one date on every row
Every address shows where it was seen and when. That is what makes an outbound list answerable: if somebody asks where you got their address, the answer is on the row rather than reconstructed from memory.
Your lists are never sold
Your lists are yours: the names, the tags, the notes and the columns you imported are never sold, licensed or handed to another customer, and a CSV you upload is used for the job you asked for and never joins what other customers can search. What is separate is an address Cuvy itself finds for you — on Free, Starter and Growth those join the shared index, and on Pro and Scale they do not. An address you supplied is never pooled on any plan.
Nothing is sent from your account
No messages, no connection requests, no profile views beyond the page you already opened. The extension never signs in from our side, and the only thing your prospects ever receive is what you send yourself.
What is not claimed

There is no certification, and no audit to imply one

Cuvy has completed no third-party security audit, holds no certificate against an international information-security standard, and appears on no transatlantic data-transfer scheme. There is no audit in progress either, and nothing on this site should be read as suggesting one. If a supplier gate in your organisation requires any of that, Cuvy does not pass it today, and knowing so now is worth more than a page of reassurance.

That paragraph is the most useful thing here precisely because it is the one nobody prints. Certification language is cheap to imply and expensive to check, and "enterprise-grade" appears on the websites of companies with no controls at all. When there is a report, this section will name it, say who issued it and give the date — and until then it will keep saying what it says now.

What exists in the meantime is documentation rather than attestation: a DPA you can sign, a privacy policy that describes real retention periods, a removal route with a number of days attached, and a questionnaire answered accurately, including the lines where the answer is unfavourable.

Removal

Getting a person out, in three steps

The same route whether the request comes from a customer, from someone who was contacted, or from a regulator acting for them.

  1. Write to the support address

    Send the email address you want removed to support@cuvy.io, with "removal" in the subject. You do not need an account, you do not need to explain why, and you will not be asked to create one to make the request.

    No account needed
  2. We find every row that matches

    Including rows held under a former employer, and including any copy inside a Cuvy run that has already finished. Where a company record mentions the same address, that goes too. What we cannot reach is a copy a customer has already exported — the opt-out page sets out what that means.

    Former employers included
  3. It is gone, and it is suppressed

    You get confirmation in writing within 30 days, usually sooner. The address is added to a suppression list so that reloading the source it came from does not reintroduce it later.

    Confirmed in writing

California residents have a separate statutory route under the CCPA and CPRA, with its own wording and its own timescales. It reaches the same people and produces the same outcome, and the form of it is on the opt-out page. Requests to correct rather than delete a record go to the same address; a wrong job title is worth telling us about, because it is wrong for every customer who sees it.

Questions

What security reviewers and recipients ask

Is Cuvy certified against any security standard?

No. There is no completed third-party audit report, no certificate against an international information-security standard, and no listing under any transatlantic data-transfer scheme. Nor is there an audit under way that it would be honest to call in progress. If your questionnaire names a particular scheme, the answer on that line is no. When that changes, this page will say which one, who issued it and when.

Someone found my address through Cuvy. How do I get it out?

Email support@cuvy.io with the address and the word "removal" in the subject. It is taken out within 30 days and added to a suppression list so a later refresh of the original source cannot put it back. You do not need to be a customer, and you will not be asked for a reason or an account.

Is a work email address personal data?

Yes. Under the GDPR an address that identifies an individual is personal data whether or not it belongs to their employer, which is why there is a removal route at all and why every row carries its source. Anyone who tells you a work address falls outside the regulation is describing a convenience rather than the law.

Can the people I email tell that I used Cuvy?

No. Nothing is added to your message, there is no tracking pixel, no "found via" header and no notification to the person looked up. Cuvy stops at the file or the CRM push; the only thing your prospect sees is the email you wrote and the domain you sent it from.

Do the addresses Cuvy finds for us go into the index other customers search?

On Free, Starter and Growth, yes: an address Cuvy finds for your workspace joins the shared index, and that is part of what those plans are paid with. On Pro and Scale it does not. On every plan, an address you typed in or imported is yours and is never pooled — and neither are your list names, tags, notes or the fact that you were interested in anybody. It is stated here, on the plan card and in the terms, because a plan paid for partly in data has to say so before the card is entered rather than afterwards.

What happens to a list I upload for enrichment?

It runs the job you asked for and stays in your workspace. It is not added to the corpus other customers search, not used to fill anybody else's results, and not sold. Delete it from the web app when you are done, or ask support to remove it along with everything else in the account.