Trust & compliance
How EnvoAPI handles data
One page collecting the service levels we publish, the roles each party holds under GDPR and CCPA/CPRA, and where every commitment is written down. Each row links into the governing clause, not a summary of it.
- 47API endpoints
- <1.8sAvg response time
- 99.95%Uptime · last 90 days
Roles
Who holds which role, per data lane
GDPR and CCPA/CPRA obligations attach to roles, and the role differs by which data is moving. The Terms and the Privacy Policy draw the same three-way split.
Customer Data you submit
For data you submit for processing through the Services, EnvoAPI acts as your processor, service provider, or equivalent role to the extent required by applicable law. Where a Data Processing Addendum is required, the DPA in Appendix A of the Terms applies.
Public Professional Data we compile
For public professional data EnvoAPI independently collects, compiles, and makes available, EnvoAPI may act as an independent controller or business. Individuals can request access, correction, deletion, suppression, or opt-out.
Output Data after receipt
For your use of Output Data after receipt, you act as an independent controller or business. Lawful basis, privacy notices, data subject requests, and opt-out handling for that use are yours to maintain.
The register
Where each commitment is written down
EnvoAPI does not hold third-party certifications today, so this page names none. What it lists instead is binding: each row below is a clause of the Terms of Service or the Privacy Policy, linked at the clause.
- Data Processing AddendumTerms · Appendix AApplies and is incorporated by reference wherever EnvoAPI processes Customer Personal Data as a processor or service provider — subprocessor terms, assistance duties, and deletion on termination included.
- GDPR legal basesPrivacy PolicyThe legal bases relied on where the GDPR, UK GDPR, or similar laws apply, stated per processing purpose.
- California notice (CCPA/CPRA)Privacy PolicyThe notice for California residents, including the categories collected and the rights the CCPA/CPRA provides.
- Security measuresPrivacy PolicyTechnical and organizational measures: encryption in transit, access and authentication controls, logging and monitoring, vulnerability management, and incident response procedures.
- International transfersPrivacy PolicyWhere a transfer mechanism is required, lawful mechanisms such as Standard Contractual Clauses or adequacy decisions are used.
- Retention periodsPrivacy PolicyHow long each category of personal data is kept, and what determines the period.
- Opt-out and suppressionPrivacy PolicyHow individuals in Public Professional Data request access, deletion, or opt-out — and the suppression list that keeps an honored request honored.
- Responsible Use PolicyTerms · Appendix BWhat the Services must not be used for: harassment, unlawful spam, unlawful surveillance, discrimination, and the rest of the prohibited-use list.