Trust & compliance

How EnvoAPI handles data

One page collecting the service levels we publish, the roles each party holds under GDPR and CCPA/CPRA, and where every commitment is written down. Each row links into the governing clause, not a summary of it.

Roles

Who holds which role, per data lane

GDPR and CCPA/CPRA obligations attach to roles, and the role differs by which data is moving. The Terms and the Privacy Policy draw the same three-way split.

  • Customer Data you submit

    For data you submit for processing through the Services, EnvoAPI acts as your processor, service provider, or equivalent role to the extent required by applicable law. Where a Data Processing Addendum is required, the DPA in Appendix A of the Terms applies.

    Terms · Data protection

  • Public Professional Data we compile

    For public professional data EnvoAPI independently collects, compiles, and makes available, EnvoAPI may act as an independent controller or business. Individuals can request access, correction, deletion, suppression, or opt-out.

    Privacy Policy · Roles

  • Output Data after receipt

    For your use of Output Data after receipt, you act as an independent controller or business. Lawful basis, privacy notices, data subject requests, and opt-out handling for that use are yours to maintain.

    Terms · Data protection

The register

Where each commitment is written down

EnvoAPI does not hold third-party certifications today, so this page names none. What it lists instead is binding: each row below is a clause of the Terms of Service or the Privacy Policy, linked at the clause.

Questions

Ask about data handling

Evaluating EnvoAPI for a procurement or privacy review? Send the question — or read the two documents this page indexes in full.

Terms of Service · Privacy Policy · Live service levels at /status