GDPR Compliance

Last updated: January 14, 2026

1. Our Commitment to GDPR

SendItFast AI ("Company", "we", "our", "us") is committed to protecting the privacy and security of personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws. This page provides comprehensive information about how we handle personal data and your rights as a data subject.

We have implemented appropriate technical and organizational measures to ensure that personal data is processed lawfully, fairly, and transparently, and we continuously review and update our practices to maintain compliance.

─────────────────────────────────────────────────

2. Data Controller Information

SendItFast AI is the data controller for personal data collected through our Service. This means we determine the purposes and means of processing personal data.

Contact Details:
SendItFast AI
Email: privacy@senditfast.ai

Data Protection Officer:
Email: dpo@senditfast.ai

─────────────────────────────────────────────────

3. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the GDPR. We are committed to facilitating the exercise of these rights and will respond to your requests within one month, as required by law.

3.1 Right of Access (Article 15)

You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to the personal data and the following information:

  • The purposes of the processing
  • The categories of personal data concerned
  • The recipients or categories of recipients to whom the personal data has been or will be disclosed
  • The envisaged period for which the personal data will be stored, or the criteria used to determine that period
  • The existence of automated decision-making, including profiling, and meaningful information about the logic involved

Upon request, we will provide you with a copy of your personal data free of charge. For any further copies, we may charge a reasonable fee based on administrative costs.

3.2 Right to Rectification (Article 16)

You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

You can update most of your account information directly through your account settings. For other corrections, please contact us.

3.3 Right to Erasure ("Right to Be Forgotten") (Article 17)

You have the right to obtain the erasure of personal data concerning you without undue delay where one of the following grounds applies:

  • The personal data is no longer necessary for the purposes for which it was collected or processed
  • You withdraw consent and there is no other legal ground for the processing
  • You object to the processing and there are no overriding legitimate grounds
  • The personal data has been unlawfully processed
  • The personal data must be erased to comply with a legal obligation

Please note that this right is not absolute. We may retain certain data where we have a legal obligation or legitimate basis to do so.

3.4 Right to Restriction of Processing (Article 18)

You have the right to obtain restriction of processing where one of the following applies:

  • You contest the accuracy of the personal data, for a period enabling us to verify the accuracy
  • The processing is unlawful and you oppose erasure and request restriction instead
  • We no longer need the personal data but you require it for legal claims
  • You have objected to processing pending verification of our legitimate grounds

3.5 Right to Data Portability (Article 20)

You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format. You also have the right to transmit that data to another controller without hindrance from us, where the processing is based on consent or a contract and is carried out by automated means.

3.6 Right to Object (Article 21)

You have the right to object, on grounds relating to your particular situation, to processing of personal data concerning you which is based on legitimate interests. We shall no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.

Where personal data is processed for direct marketing purposes, you have the right to object at any time to processing for such marketing, including profiling to the extent that it is related to such direct marketing.

3.7 Right Not to Be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except where the decision is necessary for a contract, authorized by law, or based on your explicit consent.

3.8 Right to Withdraw Consent

Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

─────────────────────────────────────────────────

4. Legal Basis for Processing

We process personal data only when we have a valid legal basis to do so. The legal bases for our processing activities include:

4.1 Performance of Contract (Article 6(1)(b))

Processing necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes:

  • Creating and managing your account
  • Processing your uploaded data to provide the Service
  • Processing payments and managing subscriptions
  • Providing customer support

4.2 Legitimate Interests (Article 6(1)(f))

Processing necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your fundamental rights and freedoms. Our legitimate interests include:

  • Improving and developing our Service
  • Ensuring the security of our Service and preventing fraud
  • Analyzing usage patterns to enhance user experience
  • Marketing our products and services (subject to your preferences)

4.3 Consent (Article 6(1)(a))

Where you have given explicit consent to the processing of your personal data for one or more specific purposes. You may withdraw consent at any time.

4.4 Legal Obligation (Article 6(1)(c))

Processing necessary for compliance with a legal obligation to which we are subject, such as:

  • Tax and accounting requirements
  • Regulatory compliance obligations
  • Responding to lawful requests from public authorities

─────────────────────────────────────────────────

5. Data Processing Activities

5.1 Account Data

Data Processed: Name, email address, profile information
Purpose: Account creation, authentication, and service delivery
Legal Basis: Performance of contract
Retention: Duration of account plus reasonable period for backup and legal compliance

5.2 User-Uploaded Data (Prospect Data)

Your Role: When you upload prospect data or contact lists, you act as the data controller for that data. We act as a data processor on your behalf.
Our Obligations: We process this data only according to your instructions and in accordance with our Data Processing Agreement.
Legal Basis: Performance of contract
Retention: Automatically deleted 30 days after processing

5.3 Usage Data

Data Processed: Service usage patterns, feature usage, performance data
Purpose: Service improvement, troubleshooting, analytics
Legal Basis: Legitimate interests
Retention: Aggregated and anonymized data may be retained indefinitely

5.4 Transaction Data

Data Processed: Transaction records, subscription information
Purpose: Payment processing, accounting, compliance
Legal Basis: Performance of contract, legal obligation
Retention: 7 years (as required by law)

─────────────────────────────────────────────────

6. International Data Transfers

Your personal data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country.

When we transfer personal data outside the EEA, UK, or Switzerland, we ensure that appropriate safeguards are in place to protect your personal data, including:

  • Adequacy Decisions: Transfers to countries that have received an adequacy decision from the European Commission
  • Standard Contractual Clauses (SCCs): We use the European Commission's Standard Contractual Clauses to protect data transferred outside the EEA
  • Supplementary Measures: Additional technical and organizational measures as needed to ensure an essentially equivalent level of protection

You may request a copy of the safeguards we have put in place by contacting us at privacy@senditfast.ai.

─────────────────────────────────────────────────

7. Data Sources and Research Methods

7.1 Online Research Approach

SendItFast may conduct online research to enrich prospect data using publicly available information from multiple sources. Our research methods are designed to:

  • Access only information that is publicly accessible without circumventing technical protection measures or authentication barriers
  • Respect rate limits, robots.txt directives, and platform terms of service
  • Aggregate and analyze information without circumventing technical protection measures
  • Provide insights similar to what a human researcher could compile from public sources
  • Comply with applicable data protection laws and regulations

The Service provides aggregated insights from publicly available sources. Not all data sources listed below may be used for every research query. The selection of data sources depends on the nature of the research request and the availability of publicly accessible information.

7.2 Data Sources Used for Online Research

We may use publicly available information from the following categories of sources:

  • Professional networks (e.g., LinkedIn)
  • Social media platforms (e.g., Reddit, Twitter/X, Instagram, Facebook)
  • Business intelligence sources (e.g., Pitchbook, Crunchbase, AngelList)
  • Sales intelligence platforms (e.g., Apollo, ZoomInfo, Clearbit)
  • Data enrichment services (e.g., Clay, Firecrawl, D7)
  • News media and publications (e.g., TechCrunch, Bloomberg, Medium, Substack)
  • Regulatory filings and public records (e.g., SEC)
  • Technology platforms (e.g., G2, Capterra, Hacker News, BuiltWith)

All online research is conducted using lawful means that respect platform terms of service and do not circumvent technical protection measures or authentication barriers.

7.3 API-Integrated Sub-Processors

We engage trusted third-party sub-processors with formal API integrations to assist in providing our Service. These sub-processors are bound by contractual obligations to process personal data in accordance with the GDPR and our instructions.

CategoryPurposeData Location
Cloud InfrastructureHosting, storage, and computingEU and USA (with SCCs)
Database ServicesData storage and managementEU region available
Payment ProcessingSecure payment handlingEU and USA (PCI-DSS compliant)
Email ServicesTransactional email deliveryUSA (with SCCs)
AnalyticsService monitoring and improvementUSA (with SCCs)
AuthenticationUser identity and access managementEU and USA (with SCCs)

7.4 Data Enrichment Services

For certain services, we may use data enrichment services that provide additional context and information. These services may be accessed via API integration or through lawful online research methods. Examples include:

  • Contact information and professional data (e.g., Apollo, ZoomInfo, Clearbit, Hunter, Lusha)
  • Company data and firmographics (e.g., Clay, Firecrawl, D7)
  • Business intelligence and funding data (e.g., Pitchbook, Crunchbase, AngelList)

7.5 Public Records and Regulatory Filings

We may access publicly available records and regulatory filings, which are in the public domain and accessible without restriction. Examples include:

  • SEC filings and financial disclosures
  • Other government and regulatory records
  • Public company information and disclosures

7.6 Comprehensive Data Source List

The following is a comprehensive list of data sources that may be used for online research. Not all sources may be utilized for every query, and use of specific sources depends on nature of research request and availability of publicly accessible information.

SourceCategory
LinkedInProfessional Network
PitchbookBusiness Intelligence
ClayData Enrichment
ApolloSales Intelligence
RedditSocial Media
GlassdoorProfessional Platform
YouTubeSocial Media
ThreadsSocial Media
InstagramSocial Media
FacebookSocial Media
MediumPublishing Platform
SubstackPublishing Platform
G2Business Platform
TechCrunchNews Media
D7Data Enrichment
Hacker NewsTechnology Platform
FirecrawlData Enrichment
ZoomInfoSales Intelligence
HunterContact Intelligence
LushaContact Intelligence
ClearbitData Enrichment
BuiltWithTechnology Platform
OwlerBusiness Intelligence
SECRegulatory Filings
CapterraBusiness Platform
AngelListBusiness Platform
BloombergNews Media
CrunchbaseBusiness Intelligence

7.7 Legal Basis for Data Sources

The legal basis for accessing and using data from these sources varies by category:

API-Integrated Services: Accessed via formal API integration with contractual agreements ensuring appropriate data protection and compliance with applicable regulations.

Online Research Services: Accessed using publicly available information through lawful means that respect platform terms of service. All online research is conducted without circumventing technical protection measures or authentication barriers.

─────────────────────────────────────────────────

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to satisfy any legal, regulatory, accounting, or reporting requirements. Our retention periods are as follows:

Data CategoryRetention PeriodBasis
Account DataDuration of account + 30 daysContract performance
Uploaded Files30 days after processingContract performance
Usage Logs90 days (raw), indefinite (aggregated)Legitimate interests
Transaction Records7 yearsLegal obligation
Security Logs12 monthsLegitimate interests
Support Communications3 years after resolutionLegitimate interests

─────────────────────────────────────────────────

9. Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data at rest (AES-256) and in transit (TLS 1.2+)
  • Access controls and authentication mechanisms
  • Regular security assessments and penetration testing
  • Employee training on data protection and security
  • Incident response procedures
  • Regular backups and disaster recovery capabilities

─────────────────────────────────────────────────

10. Data Processing Agreement

For customers who process personal data using our Service, we offer a Data Processing Agreement (DPA) that meets the requirements of Article 28 of the GDPR. The DPA includes:

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Categories of personal data and data subjects
  • Rights and obligations of the controller and processor
  • Technical and organizational security measures
  • Sub-processor engagement terms
  • Data subject rights assistance
  • Audit rights

To request our DPA, please contact legal@senditfast.ai.

─────────────────────────────────────────────────

11. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (where required)
  • Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms
  • Document all breaches, including the facts, effects, and remedial actions taken
  • Notify our customers without undue delay if the breach involves data processed on their behalf

─────────────────────────────────────────────────

12. Supervisory Authority

If you are located in the EEA, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities can be found at the European Data Protection Board website.

We encourage you to contact us first so that we can address your concerns directly. We are committed to resolving any issues related to our processing of your personal data.

─────────────────────────────────────────────────

13. Exercising Your Rights

To exercise any of your rights under the GDPR, please contact us at:

Email: privacy@senditfast.ai
Data Protection Officer: dpo@senditfast.ai

When submitting a request, please provide:

  • Your name and email address associated with your account
  • The specific right you wish to exercise
  • Any relevant details to help us locate your data

We will respond to your request within one month. If your request is complex or we receive a large number of requests, we may extend this period by up to two additional months, in which case we will notify you.

─────────────────────────────────────────────────

14. Changes to This Page

We may update this GDPR information page from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting an updated version on our website and updating the "Last updated" date.

─────────────────────────────────────────────────

15. User Responsibility and No Warranty

15.1 Your Sole Responsibility

By using the Service and providing personal data, you acknowledge that you are solely and exclusively responsible for:

  • All decisions and actions taken based on information or output from the Service
  • Verification of accuracy, completeness, and suitability of all information before use
  • Compliance with all applicable laws and regulations in your jurisdiction
  • Outcomes and consequences of using the Service in your business operations
  • Protection of your own data, accounts, and systems
  • Any risks associated with using AI-powered data processing services

15.2 No Warranties or Guarantees

SendItFast AI provides no warranty, guarantee, or assurance of any kind regarding:

  • The accuracy, completeness, or reliability of any processing, output, or services
  • The suitability for any specific purpose or requirement
  • The correctness of data processing operations or results
  • The performance or functionality of the Service
  • That errors will be corrected or issues resolved
  • That security measures will prevent all incidents or breaches

All services are provided on an "AS IS" basis without warranties of any kind, either express or implied. SendItFast AI expressly disclaims all warranties, including but not limited to merchantability, fitness for a particular purpose, title, and non-infringement.

Even in the event of errors, omissions, inaccuracies, or defects in any processing, output, or services, SendItFast AI shall have no liability of any kind.

15.3 No Legal Recourse

You agree to waive all rights to bring any claim, lawsuit, action, or proceeding against SendItFast AI in connection with or arising from your use of the Service or provision of personal data.

Your sole and exclusive remedy for any dissatisfaction is to discontinue using the Service.

You release, waive, and forever discharge SendItFast AI from all claims, demands, causes of action, losses, damages, costs, expenses, or liabilities of any kind related to the Service or data processing.

Copyright © 2026 SendItFast AI. All rights reserved. This document is provided for informational purposes. Redistribution, modification, or commercial use without authorization is prohibited.