Legal · Privacy Policy

EnvoAPI Privacy Policy

This Privacy Policy explains how EnvoAPI collects, uses, discloses, sells, shares, retains, and protects Personal Data in connection with our websites, APIs, dashboards, documentation, enrichment services, batch-processing tools, customer support, marketing activities, and related products and services (collectively, the “Services”).

  • EffectiveJuly 29, 2026
  • Last updatedJuly 29, 2026
  • Sections27
On this page27 sections

This Privacy Policy explains how EnvoAPI LLC, a limited liability company organized under the laws of the State of Wyoming, United States (“EnvoAPI,” “we,” “us,” or “our”) collects, uses, discloses, sells, shares, retains, and protects Personal Data in connection with the Services.

This Privacy Policy applies to:

  1. visitors to our websites, documentation, landing pages, and online properties;
  2. customers, account administrators, developers, authorized users, prospects, vendors, and business contacts;
  3. individuals whose professional or company-related information may appear in Public Professional Data processed or made available through the Services; and
  4. individuals who contact us, request support, submit privacy requests, or otherwise interact with EnvoAPI.

This Privacy Policy is incorporated into and should be read together with our Terms of Service, Data Processing Addendum, Subprocessor List, Security Overview, and any applicable order form or written agreement.

EnvoAPI is a B2B public-professional-data enrichment API. EnvoAPI is not affiliated with, endorsed by, sponsored by, or approved by LinkedIn Corporation, Microsoft Corporation, or any other third-party platform, website, data source, marketplace, social network, search engine, or registry referenced in or through the Services. “LinkedIn” and related marks are trademarks of LinkedIn Corporation.

Public availability of information does not necessarily mean that the information is free from privacy, contractual, intellectual property, publicity, anti-spam, employment, consumer protection, or other legal restrictions. Customers are responsible for determining whether their use of the Services and Output Data is lawful for their purposes.

01Key definitions

“Account Data” means information associated with an EnvoAPI account, workspace, dashboard, API key, billing profile, or authorized user.

“Customer” means the business, organization, or other legal entity that uses or purchases the Services.

“Customer Data” means data, identifiers, URLs, search queries, files, batch records, instructions, and other information submitted to the Services by or on behalf of a Customer.

“Output Data” means data, records, responses, matches, enriched fields, company information, profile information, metadata, confidence scores, normalized URLs, and other results returned by the Services.

“Personal Data” or “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual, as defined by applicable privacy laws.

“Public Professional Data” means professional, business, company, role, profile, career, education, public web, public company, public URL, or similar data that EnvoAPI has a reasonable basis to believe is publicly available, provided by a Customer, licensed from third parties, derived from public sources, or otherwise lawfully available for the Services.

“Sensitive Data”means special category, sensitive, regulated, or high-risk information, including government identifiers, payment card data, protected health information, biometric identifiers, precise geolocation, children’s data, criminal history, account passwords, private messages, private contacts, union membership, political opinions, religious beliefs, racial or ethnic origin, sexual orientation, and other information treated as sensitive under applicable law.

02Our roles under privacy laws

Depending on the context, EnvoAPI may act as a controller, business, processor, service provider, contractor, or subprocessor.

2.1EnvoAPI as controller or business

EnvoAPI generally acts as a controller or business when we determine the purposes and means of processing Personal Data for our own business purposes, including when we process:

  • Account Data;
  • billing and payment records;
  • website, analytics, and cookie data;
  • sales, marketing, and support communications;
  • security, fraud-prevention, and abuse-prevention data;
  • Public Professional Data that we collect, license, organize, normalize, match, cache, index, or make available through the Services; and
  • suppression, opt-out, deletion, and compliance records.

2.2EnvoAPI as processor, service provider, or contractor

EnvoAPI may act as a processor, service provider, or contractor when we process Customer Data on behalf of a Customer under a written agreement, order form, or Data Processing Addendum.

In that context, the Customer is responsible for determining the purposes and lawful basis for the processing, providing required notices, obtaining required consents or permissions, honoring individual rights, and ensuring that Customer’s use of the Services complies with applicable law.

2.3Customer as independent controller or business

Once a Customer receives, stores, exports, combines, uses, contacts, profiles, scores, or otherwise acts on Output Data, the Customer generally acts as an independent controller or business for that processing. Customer’s privacy policy, notices, legal bases, opt-out processes, and compliance obligations apply to Customer’s use of Output Data.

2.4Data Processing Addendum

Where required by applicable law or by agreement, our Data Processing Addendum is available at Appendix A of our Terms of Service. If there is a conflict between this Privacy Policy and an executed DPA, the DPA controls for processing covered by the DPA.

03Personal Data we collect

We collect different categories of Personal Data depending on how you interact with EnvoAPI.

3.1Account, registration, and administrative data

When a Customer or authorized user creates an account, uses the dashboard, generates API keys, purchases credits, signs an order form, or manages a workspace, we may collect: name; business email address; business phone number; company name; job title or role; username; password or authentication credential, stored in hashed or protected form where applicable; workspace name; account settings; billing contact; tax or invoicing details; plan, credit balance, and subscription information; API keys, token metadata, and credential metadata; access permissions and user roles; support tickets and administrative messages; and contract, procurement, and security-review information.

3.2Customer Data submitted to the Services

Customers may submit Customer Data to the Services for matching, normalization, search, enrichment, verification, debugging, or support. Customer Data may include: profile URLs; company URLs; names; business email addresses; company domains; company names; job titles; locations; search terms; batch files; CRM identifiers; internal record IDs; webhook payloads; API parameters; error reports; logs; and other data provided by Customer through the Services.

Customers must not submit Sensitive Data unless EnvoAPI has expressly agreed in writing and the parties have implemented appropriate legal and security safeguards.

3.3Public Professional Data

The Services may process Public Professional Data relating to professionals, companies, organizations, and business contacts. Depending on the endpoint, plan, configuration, and data availability, Public Professional Data may include:

  • name;
  • professional profile URL;
  • normalized public profile identifier;
  • public profile image or avatar URL;
  • headline or professional summary;
  • current and past job titles;
  • current and past employers;
  • company name, domain, and profile URL;
  • company size, industry, type, location, and description;
  • professional location at city, region, or country level;
  • public education information;
  • public skills, certifications, languages, or professional interests;
  • public posts, public activity, or public engagement metadata, where applicable and where made available by a source;
  • public company affiliations and public work history;
  • public URLs and web references;
  • timestamps, source metadata, cache metadata, confidence scores, and matching metadata; and
  • derived or normalized fields, such as canonical URLs, company-domain matching, seniority, department, or role category.

EnvoAPI is designed for public professional and company data. We do not intentionally provide private messages, private contacts, account passwords, non-public account information, restricted data behind authentication walls, or data obtained by bypassing technical access controls.

3.4Website, device, usage, and log data

When you visit our websites, documentation, dashboard, APIs, or online properties, we may collect: IP address; device identifiers; browser type; operating system; referring and exit pages; pages viewed; documentation pages viewed; approximate location derived from IP address; request timestamps; API endpoint usage; response status codes; error logs; latency and performance metrics; usage volume; rate-limit events; account activity logs; security events; cookies, pixels, SDKs, and similar tracking technologies; and diagnostic, crash, and debugging information.

3.5Billing and payment data

We may collect billing and payment information, including: billing name; billing address; tax identification details where required; invoice details; payment method metadata; transaction history; subscription status; credit purchases; refunds, chargebacks, and disputes; and payment processor tokens or references.

We do not intentionally store full payment card numbers. Payment card information is typically processed by our payment processor.

3.6Communications, support, sales, and marketing data

When you communicate with us, request a demo, subscribe to updates, attend events, join a waitlist, complete forms, respond to surveys, or interact with our support or sales team, we may collect: name; business email address; company name; job title; business phone number; message contents; support attachments; call notes; meeting details; marketing preferences; event attendance information; lead-source information; CRM records; and communications history.

3.7Cookies and similar technologies

We may use cookies, pixels, local storage, session replay tools, analytics SDKs, and similar technologies to operate our websites and Services, remember preferences, authenticate users, secure accounts, measure performance, understand usage, improve documentation, support marketing, and, where enabled, deliver or measure advertising.

You can manage cookies through your browser settings. Some cookies are necessary for the Services to function and cannot be disabled without affecting core functionality.

3.8Information from third parties

We may receive Personal Data from third parties, including: Customers; authorized users; public websites and public online sources; search engines; company websites; public registries; public profile pages; data licensors and enrichment partners; analytics providers; advertising or attribution partners; fraud-prevention and security providers; payment processors; event partners; business partners; affiliates; and service providers.

04Sources of Public Professional Data

EnvoAPI may collect, license, receive, derive, normalize, or verify Public Professional Data from sources that may include:

  • publicly available professional profile pages;
  • publicly available company pages;
  • public company websites;
  • public directories and public registries;
  • public search results and public web pages;
  • customer-provided records;
  • third-party data providers or licensors;
  • publicly accessible business databases;
  • open web references;
  • user-submitted corrections or opt-out requests; and
  • derived or inferred metadata created through matching, normalization, deduplication, or enrichment logic.

We may not always identify every source used for a specific field, especially where data has been normalized, cached, deduplicated, licensed, updated over time, or derived from multiple public or third-party sources.

05How we use Personal Data

We use Personal Data for the following purposes.

5.1To provide and operate the Services

We use Personal Data to: create and manage accounts; authenticate users; issue and manage API keys; process API requests; match, normalize, enrich, and return Output Data; run batch jobs; process webhooks; maintain dashboards; provide documentation; deliver support; process payments; calculate credits and usage; manage subscriptions; issue invoices; maintain logs; and provide notices about the Services.

5.2To build, maintain, and improve Public Professional Data

We use Public Professional Data to: provide person and company enrichment; normalize public profile URLs; match professionals to companies; deduplicate records; update stale records; improve field accuracy; generate confidence scores; identify broken or changed URLs; improve data quality; maintain suppression lists; honor opt-out and deletion requests; and prevent reappearance of suppressed records.

5.3To improve and develop the Services

We may use Personal Data to: analyze usage patterns; debug errors; improve API reliability; improve matching and enrichment logic; improve documentation and onboarding; develop new endpoints and features; conduct product analytics; test performance; evaluate data quality; detect duplicate or inaccurate records; and create aggregated or de-identified statistics.

We do not use Customer Data to train foundation models for unrelated third-party products unless we have Customer’s permission or another lawful basis. We may use aggregated, de-identified, or anonymized data to understand service performance, improve reliability, and develop product features.

5.4To secure the Services and prevent abuse

We use Personal Data to: protect accounts and API keys; detect abuse, fraud, and suspicious activity; enforce rate limits; prevent credential theft; investigate security incidents; monitor availability and performance; prevent spam, scraping attacks, denial-of-service attacks, and misuse; enforce our Terms of Service and Acceptable Use restrictions; and protect the rights, safety, and security of EnvoAPI, Customers, individuals, and third parties.

5.5To communicate with Customers and prospects

We use Personal Data to: respond to inquiries; provide support; send administrative messages; send service notices; send invoices and billing notices; provide product updates; send security notices; conduct demos; manage sales opportunities; administer events; and send marketing communications where permitted by law.

You may opt out of marketing emails by using the unsubscribe link in the email or contacting us at [email protected]. We may still send transactional, security, legal, billing, and service-related messages.

5.6To comply with law and enforce rights

We use Personal Data to: comply with legal obligations; respond to lawful requests; maintain tax, accounting, and business records; verify and respond to privacy requests; maintain suppression and opt-out records; enforce contracts; resolve disputes; protect legal rights; conduct audits; and comply with sanctions, export-control, anti-corruption, and other compliance obligations.

07How we disclose Personal Data

We may disclose Personal Data as described below.

7.1Customers and authorized users

We disclose Output Data to Customers and their authorized users when they use the Services. Customers are responsible for their own use, storage, disclosure, and retention of Output Data.

7.2Service providers and subprocessors

We disclose Personal Data to service providers and subprocessors that help us operate the Services, including providers of: cloud hosting; infrastructure; databases; storage; content delivery networks; security monitoring; authentication; payment processing; billing; analytics; customer support; email delivery; CRM; sales operations; logging; error monitoring; data quality; compliance tooling; and professional services.

Our current subprocessor list is available on request at [email protected].

7.3Payment processors

Payment information may be processed by payment processors that act as independent controllers or processors depending on their role and applicable law. Their privacy policies apply to their processing of payment information.

7.4Customer-directed integrations

If a Customer connects EnvoAPI to a CRM, data warehouse, workflow tool, sales engagement tool, ATS, cloud storage bucket, webhook destination, or other integration, we may disclose Customer Data and Output Data to that integration as directed by Customer.

7.5Affiliates, corporate transactions, and business transfers

We may disclose Personal Data to our affiliates and in connection with a merger, acquisition, financing, reorganization, bankruptcy, due diligence process, sale of assets, transfer of business, or similar corporate transaction.

7.6Professional advisors

We may disclose Personal Data to lawyers, auditors, accountants, insurers, banks, consultants, and other professional advisors where reasonably necessary for business, legal, tax, accounting, insurance, compliance, or dispute-resolution purposes.

7.7Legal, safety, and compliance disclosures

We may disclose Personal Data where we believe disclosure is necessary or appropriate to: comply with law; respond to lawful requests, subpoenas, court orders, or legal process; enforce our Terms of Service, DPA, order forms, or other agreements; protect the rights, safety, security, and property of EnvoAPI, Customers, individuals, or third parties; investigate fraud, abuse, security incidents, or unlawful activity; prevent harm; or cooperate with regulators, law enforcement, or other authorities.

7.8With consent or direction

We may disclose Personal Data with your consent, at your direction, or as otherwise disclosed at the time of collection.

08Sale, sharing, and targeted advertising

Some US privacy laws use broad definitions of “sale,” “sharing,” or “targeted advertising.” These definitions may cover activities that do not involve selling data for money in the ordinary sense.

8.1Public Professional Data provided to Customers

Because EnvoAPI provides access to Public Professional Data and Output Data to business Customers for monetary or other valuable consideration, some disclosures of Personal Data through the Services may be considered a “sale” under certain US privacy laws.

If you are an individual whose Public Professional Data may be processed by EnvoAPI, you may opt out of the sale of your Personal Data by contacting us at [email protected]with the subject line “Do Not Sell or Share.”

8.2Website cookies and advertising

If we use advertising, retargeting, cross-context behavioral advertising, or similar technologies on our websites, those activities may be considered “sharing” or “targeted advertising” under certain privacy laws. You may manage cookie choices through your browser settings and, where required, through an applicable opt-out preference signal.

8.3No knowing sale or sharing of children’s data

The Services are designed for business and professional use and are not directed to children. We do not knowingly sell or share Personal Data of individuals under 16 years of age.

8.4Sensitive Personal Data

We do not intentionally sell Sensitive Data. We do not intentionally use Sensitive Data to infer characteristics about individuals.

09California notice at collection

This section applies to California residents and describes the categories of Personal Information we collect, the purposes for which we collect and use it, whether it may be sold or shared, and our general retention practices.

Category of Personal InformationExamplesSourcesPurposesSold or shared?Retention
IdentifiersName, business email, business phone, profile URL, company domain, account ID, API key metadata, IP addressYou, Customers, public sources, service providers, data licensorsProvide Services, enrichment, authentication, support, billing, security, compliancePublic Professional Data may be sold to Customers; website identifiers may be shared if advertising cookies are enabledSee Section 14
Customer records / commercial informationBilling details, plan, credit purchases, invoices, transaction records, support historyYou, Customers, payment processorsBilling, account administration, tax, fraud prevention, supportNot sold as standalone billing data; disclosed to service providersSee Section 14
Internet or other electronic network activityWebsite activity, dashboard usage, API logs, documentation pages, request metadata, cookies, device dataYour browser/device, Services, analytics providersOperate Services, analytics, security, debugging, marketing attributionMay be shared if advertising or cross-context behavioral advertising cookies are enabledSee Section 14
Geolocation dataApproximate location derived from IP address; public professional location at city/region/country levelYour browser/device, public sources, Customers, data licensorsSecurity, analytics, enrichment, regional compliance, account protectionPublic professional location may be sold to Customers as part of Public Professional DataSee Section 14
Professional or employment-related informationJob title, company, work history, professional headline, company affiliation, public profile metadataPublic sources, Customers, data licensors, business contactsEnrichment, matching, company research, CRM hygiene, product qualityMay be sold to Customers as Public Professional DataSee Section 14
Education informationPublic education information, certifications, professional qualificationsPublic sources, Customers, data licensorsEnrichment, matching, professional profile contextMay be sold to Customers as Public Professional DataSee Section 14
InferencesSeniority, department, role category, confidence scores, match scores, derived company metadataEnvoAPI processing, public sources, Customer Data, data licensorsMatching, enrichment, deduplication, data qualityMay be sold to Customers as part of Output DataSee Section 14
Audio, electronic, or visual informationSupport-call recordings, meeting recordings, public profile image URLs, screenshots submitted for supportYou, Customers, public sources, support toolsSupport, training, quality, enrichment where public profile image URLs are availablePublic profile image URLs may be sold to Customers as Public Professional Data; support recordings are not soldSee Section 14
Sensitive Personal InformationAccount login credentials; payment-related information handled by payment processors; limited security dataYou, authentication providers, payment processorsAccount security, payment processing, fraud prevention, legal complianceNot intentionally sold or shared; not used to infer characteristicsSee Section 14

We collect and use Personal Information for the business and commercial purposes described throughout this Privacy Policy, including Sections 5, 7, and 8.

We may disclose Personal Information to the categories of recipients described in Section 7, including Customers, service providers, subprocessors, payment processors, professional advisors, affiliates, integration providers, and legal or compliance recipients.

10Privacy rights

Depending on where you live and the laws that apply, you may have some or all of the rights described below.

10.1Rights that may apply

You may have the right to:

  • request access to Personal Data we process about you;
  • request a copy or portability of certain Personal Data;
  • request correction of inaccurate Personal Data;
  • request deletion of Personal Data;
  • opt out of sale, sharing, targeted advertising, or certain profiling;
  • limit certain uses or disclosures of Sensitive Data;
  • object to processing based on legitimate interests;
  • restrict certain processing;
  • withdraw consent where processing is based on consent;
  • appeal a denied privacy request where applicable;
  • lodge a complaint with a data protection authority; and
  • not be discriminated against for exercising privacy rights.

10.2How to exercise your rights

You may submit a request by:

Please include enough information for us to understand, verify, and respond to your request. For requests relating to Public Professional Data, helpful information may include your name, current or former company, professional profile URL, relevant public URLs, business email address, and the specific right you wish to exercise.

10.3Verification

We may need to verify your identity before responding to certain requests. Verification may include asking you to confirm control of an email address, provide relevant profile URLs, provide account information, confirm information already in our records, or complete another reasonable verification step.

We will not use information provided for verification for unrelated purposes.

10.4Authorized agents

Where applicable, you may authorize another person or entity to submit a privacy request on your behalf. We may require proof of authorization and may ask you to verify your identity directly with us unless prohibited by law.

10.5Appeals

If we deny your request and applicable law gives you an appeal right, you may appeal by replying to our decision email or contacting [email protected]with the subject line “Privacy Request Appeal.”

10.6Requests involving Customer-controlled data

If your request relates to Personal Data that we process on behalf of a Customer, we may refer your request to the Customer, ask you to contact the Customer directly, or assist the Customer in responding, depending on our role, the DPA, and applicable law.

10.7Limits and exceptions

Privacy rights are subject to legal limits and exceptions. We may decline or limit a request where permitted by law, including where we cannot verify the request, where the request conflicts with legal obligations, where retention is required for security or compliance, or where the request is excessive, unfounded, or adversely affects the rights and freedoms of others.

11Public Professional Data requests and opt-outs

If you are an individual whose Public Professional Data may be processed by EnvoAPI, you may request access, correction, deletion, suppression, or opt-out by contacting [email protected].

11.1Suppression

When we honor a deletion or opt-out request, we may retain limited information in a suppression list to help prevent the same record from reappearing in the Services. Suppression records may include limited identifiers such as name, profile URL, hashed email, company, and request metadata.

11.2Effect of deletion or opt-out

Deletion or opt-out from EnvoAPI does not remove information from third-party websites, public sources, search engines, Customers’ systems, or other databases. Customers may have already received Output Data before we processed your request. Where required by law and feasible, we may notify relevant Customers or restrict future availability of suppressed records through the Services.

11.3Corrections

If you believe Public Professional Data returned by EnvoAPI is inaccurate, you may request correction. We may ask for supporting information, such as a current public profile URL or company page. We may also choose to suppress a record instead of correcting it where correction is not practical or where suppression better protects your rights.

11.4Source platform controls

If information appears on a third-party platform or public website, you may need to update your settings, remove the information, or submit a request directly to that third party. EnvoAPI does not control third-party platforms or public websites.

12Global Privacy Control and opt-out preference signals

Where required by law, we honor legally recognized opt-out preference signals, such as Global Privacy Control, for browser-based website activity.

If our website uses technologies that qualify as sale, sharing, or targeted advertising, a recognized opt-out preference signal will be treated as an opt-out for that browser or device. Because browser-based signals may not identify a person across all API records, accounts, devices, browsers, or Public Professional Data records, requests relating to Public Professional Data should also be submitted by emailing [email protected].

13Marketing choices

You may opt out of marketing emails by clicking the unsubscribe link in our emails or contacting us at [email protected]. We may continue to send administrative, transactional, billing, security, legal, and service-related communications.

If you receive outreach from a Customer that used EnvoAPI, you should contact that Customer directly to exercise unsubscribe, opt-out, deletion, or other rights relating to that Customer’s communications or systems.

14Retention

We retain Personal Data for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Our retention periods depend on the type of data, sensitivity, context, Customer settings, contractual obligations, legal obligations, security needs, and operational requirements.

Typical retention periods may include:

Data categoryTypical retention period
Account DataFor the life of the account, plus a reasonable period after closure for legal, security, backup, and business-record purposes
Billing, tax, and transaction recordsAs required for tax, accounting, audit, and legal obligations, typically up to seven (7) years
API logs and request metadataTypically 30–180 days, unless needed longer for security, abuse prevention, debugging, billing, compliance, or legal reasons
Customer batch filesTypically 7–90 days after processing, unless Customer configures longer retention or support/legal needs require it
Customer support recordsTypically 2–5 years after resolution, unless required longer for legal or business reasons
Public Professional Data caches and indexesRetained and updated for as long as needed to provide the Services, maintain data quality, comply with law, honor rights, and maintain suppression lists
Suppression, deletion, and opt-out recordsRetained as long as necessary to honor the request and prevent reappearance of suppressed records
Marketing recordsUntil you opt out, the data is no longer needed, or we delete it under our retention practices
Security logsTypically 90 days–2 years, depending on risk, legal needs, and security requirements
BackupsDeleted or overwritten according to backup schedules, typically within 30–180 days, subject to legal holds and technical constraints

We may retain de-identified, anonymized, or aggregated information that cannot reasonably identify an individual.

15Security

We implement reasonable technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access.

These measures may include, as appropriate: encryption in transit; encryption at rest where applicable; access controls; authentication controls; role-based permissions; logging and monitoring; vulnerability management; network security controls; backup and recovery controls; least-privilege access; employee confidentiality obligations; incident response procedures; vendor security reviews; and internal policies and training.

No method of transmission, storage, or processing is completely secure. Customers are responsible for securing their own accounts, API keys, integrations, Customer Applications, systems, and Output Data.

If you believe you have discovered a security vulnerability or account compromise, contact us at [email protected].

16International transfers

EnvoAPI may process and store Personal Data in countries other than the country where you live, including the United States and other jurisdictions where EnvoAPI, its affiliates, service providers, or subprocessors operate.

Where required, we use appropriate transfer safeguards, which may include adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum, transfer risk assessments, contractual safeguards, and technical and organizational measures.

We do not claim participation in the EU-U.S. Data Privacy Framework, UK Extension, or Swiss-U.S. Data Privacy Framework unless expressly stated in a separate certification notice published by EnvoAPI.

17Automated processing and profiling

The Services may use automated matching, normalization, deduplication, classification, scoring, and enrichment logic to return Output Data, confidence scores, role categories, company matches, seniority labels, and similar metadata.

EnvoAPI does not use the Services to make employment, credit, housing, insurance, healthcare, education, criminal justice, government-benefit, or other legally significant decisions about individuals. Customers must not use the Services or Output Data as the sole or determinative basis for legally significant decisions where prohibited or restricted by law or our Terms of Service.

Where applicable law gives you rights relating to automated decision-making or profiling, you may contact us at [email protected].

18Children’s privacy

The Services are intended for business and professional use and are not directed to children. We do not knowingly collect, sell, or share Personal Data of children under 16 years of age. If you believe a child’s Personal Data has been provided to EnvoAPI, contact us at [email protected].

19Customer responsibilities

Customers are responsible for their own privacy compliance when using the Services and Output Data. Customers must:

  • provide all required privacy notices;
  • identify and maintain an appropriate legal basis for processing;
  • obtain any required consents or permissions;
  • honor opt-outs, unsubscribe requests, deletion requests, suppression requests, and other rights;
  • comply with anti-spam, electronic communications, employment, consumer protection, privacy, data protection, and other applicable laws;
  • use Output Data only for lawful B2B purposes permitted by our Terms of Service;
  • avoid prohibited uses, including harassment, doxing, unlawful surveillance, spam, discrimination, regulated eligibility decisions, and consumer reporting;
  • maintain appropriate security controls;
  • not submit Sensitive Data unless expressly authorized in writing; and
  • ensure that Customer Applications and integrations comply with applicable law and the Customer’s agreements with EnvoAPI.

20Data broker and public data laws

Depending on our activities and applicable law, EnvoAPI may be considered a data broker, data provider, or similar entity in certain jurisdictions. Where required, we will maintain applicable registrations, notices, opt-out mechanisms, deletion mechanisms, and other compliance processes.

Where EnvoAPI is required to register as a data broker in a jurisdiction, information about the applicable registration is available on request at [email protected].

21Region-specific information

21.1EEA, UK, and Switzerland

If you are located in the EEA, UK, or Switzerland, you may have rights to access, correct, delete, restrict, object to processing, request portability, withdraw consent, and lodge a complaint with a supervisory authority.

Controller contact: [email protected]

EnvoAPI has not appointed a Data Protection Officer, an EU representative, or a UK representative. Data protection inquiries should be directed to the controller contact above.

Where EnvoAPI has not obtained Personal Data directly from you, the categories of sources are described in Sections 3 and 4, and the categories of Personal Data, purposes, recipients, legal bases, retention periods, and rights are described throughout this Privacy Policy.

21.2California

California residents may have the right to know, access, delete, correct, opt out of sale or sharing, limit certain uses of Sensitive Personal Information, and not be discriminated against for exercising their rights.

You may exercise these rights by emailing [email protected]with the subject line “Privacy Request” or “Do Not Sell or Share.”

We do not knowingly sell or share Personal Information of individuals under 16. We do not intentionally use Sensitive Personal Information to infer characteristics.

21.3Other US states

Residents of certain US states may have rights to access, delete, correct, opt out of targeted advertising, opt out of sale, opt out of certain profiling, request portability, and appeal a denied request. You may exercise applicable rights by emailing [email protected].

21.4Canada, Australia, and other regions

Depending on where you live, you may have additional rights under local privacy laws. We will respond to requests as required by applicable law.

22Third-party websites, platforms, and services

The Services may reference, link to, integrate with, or process information associated with third-party websites, platforms, applications, public sources, or services. EnvoAPI does not control and is not responsible for the privacy practices, content, availability, accuracy, terms, policies, or security of third-party services.

Your use of third-party services is governed by the applicable third party’s terms and privacy policies.

23Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The “Last updated” date above indicates when this Privacy Policy was last revised.

If we make material changes, we will provide notice as required by law, which may include posting a notice on our website, sending an email, providing dashboard notice, or updating this page. Your continued use of the Services after the updated Privacy Policy becomes effective means that you acknowledge the updated Privacy Policy, where permitted by law.

24Contact us

For privacy questions, requests, or concerns, contact us at:

EnvoAPI LLC
A Wyoming limited liability company, United States
Privacy, security, and support requests: [email protected]
Contact form: https://envoapi.com/contact

Appendix AQuick notice for individuals in Public Professional Data

EnvoAPI provides B2B public professional and company-data enrichment services. We may process publicly available professional information, such as name, professional profile URL, current company, job title, work history, public business location, public education information, public skills, company information, source metadata, and matching confidence scores.

We use this information to provide business Customers with enrichment, matching, normalization, data-quality, and company-research services. Some disclosures of this information to Customers may be considered a “sale” under certain US privacy laws.

You may request access, deletion, correction, suppression, or opt-out by contacting [email protected].

Appendix BQuick notice at collection for Customers and website visitors

When you use EnvoAPI as a Customer, website visitor, developer, or business contact, we may collect identifiers, contact information, account information, billing information, device data, usage logs, cookies, support communications, and security data.

We use this information to provide the Services, authenticate users, issue API keys, process payments, provide support, secure the Services, improve the product, send service communications, conduct business development, and comply with law.

We may disclose this information to service providers, subprocessors, payment processors, analytics providers, security providers, professional advisors, affiliates, authorities where required, and integrations you configure. Website identifiers may be shared for advertising or analytics purposes where such technologies are enabled.

You may manage cookies through your browser settings and exercise privacy rights by emailing [email protected].

Appendix CCustomer privacy notice language

Customers may use the following sample language in their own privacy notices, subject to legal review and adaptation to the Customer’s actual use case:

We may use third-party business data providers and enrichment services, including EnvoAPI, to help us maintain accurate business contact and company information, match professional profiles to companies, update CRM records, improve data quality, conduct B2B sales or recruiting operations, and understand our business relationships. These providers may process publicly available professional information, business contact information, company information, profile URLs, job titles, employment history, and related metadata. You may contact us to exercise your privacy rights regarding our use of this information.

This sample language is provided for convenience only and does not constitute legal advice. Customers remain responsible for their own privacy notices, legal bases, consents, opt-outs, and compliance obligations.

Your data

Questions about your privacy?

Contact us about how EnvoAPI handles Personal Data, or exercise a privacy right relating to Public Professional Data.