Loading

RepuFix Legal

Privacy Policy

Effective date: April 7, 2026 · Last updated: April 7, 2026

This Privacy Policy explains how RepuFix ("RepuFix", "we", "our", or "us") collects, uses, stores, and protects information when you access or use the RepuFix platform at repufix.io (the "Service"). By using the Service, you acknowledge you have read and agree to this Policy. If you do not agree, you must discontinue use immediately.

1. Who We Are and Scope

RepuFix is a data conditioning and analysis platform. It is not an email sender, campaign manager, CRM, or outreach tool. RepuFix enables users to upload their own lead data for the purposes of cleaning, deduplication, scoring, classification, verification, and simulation analysis.

This Policy applies to all users of the Service, including individuals and businesses located in the United States, Canada, the European Union, the United Kingdom, and all other jurisdictions. This Policy governs all personal data processed by RepuFix in connection with the Service.

RepuFix acts as a Data Processor with respect to lead data uploaded by users, and as a Data Controller with respect to account data and operational data we collect directly from users. For further information on these roles, please refer to our Data Processing Agreement.

2. Information We Collect

2.1 Account and Registration Data

When you create an account, we collect your name, email address, organization name (if provided), billing information (processed via third-party payment processors), and any preferences or settings you configure. This information is used to manage your account, process payments, and communicate with you about the Service.

2.2 Uploaded Lead Data

The Service allows you to upload files containing lead data, which may include email addresses, full names, company names, job titles, domains, source identifiers, and any other fields included in your CSV or imported dataset. This data is owned entirely by you. We process it solely to perform the cleaning, classification, scoring, verification, and simulation functions you request. We do not use this data for any other purpose.

2.3 Derived and Processed Data

As part of normal operation, RepuFix generates derived data from your uploaded lead data. This includes quality scores, classification flags (e.g., free email domain, role account, duplicate status), verification results, deliverability estimates, and simulation outputs. This derived data is attributed to your account and is treated with the same protections as your uploaded data.

2.4 Usage and Activity Logs

We automatically collect information about how you interact with the Service, including pages visited, features used, actions taken (e.g., importing a list, running a clean, exporting a segment), timestamps, error logs, and session duration. This data is used to maintain, improve, and protect the Service.

2.5 Device, Network, and Browser Data

We collect technical information including IP address, browser type and version, operating system, device identifiers, referring URLs, and time zone. This data is used for security monitoring, fraud detection, and service improvement. IP addresses may be used to approximate geographic location at the country or region level.

2.6 Communications

If you contact us via email, support portal, or any other channel, we retain the content of your communications and our responses. We use this information to respond to inquiries, resolve disputes, and improve our support quality.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, and maintain the Service, including processing lead data uploads, running cleaning and classification algorithms, executing verification requests via third-party APIs, and generating simulation outputs.
  • To authenticate users and maintain the security of accounts.
  • To process credits, billing transactions, and subscription management.
  • To communicate with you about account activity, service updates, security alerts, and support requests.
  • To monitor and analyze usage patterns for the purpose of improving performance, identifying bugs, and developing new features.
  • To detect, investigate, and prevent fraudulent transactions, abuse, or other violations of our Terms of Service.
  • To comply with applicable legal obligations, respond to lawful requests from government authorities, and enforce our agreements.
  • To fulfill contractual obligations to you under our Terms of Service and any applicable Data Processing Agreement.

We do not use your data for advertising. We do not sell, rent, or license your data to third parties. We do not use your uploaded lead data to train machine learning models, large language models, or any artificial intelligence system. This prohibition applies permanently and unconditionally.

4. Data Ownership

You retain full ownership of all lead data you upload to the Service. RepuFix acquires no ownership interest, intellectual property right, or license in your lead data beyond what is strictly necessary to deliver the Service to you.

Derived data (scores, classifications, flags, simulation outputs) generated from your lead data is also owned by you. You may export it at any time and request its deletion subject to the data retention terms below.

You represent and warrant that you have all necessary rights, consents, and lawful bases to upload the lead data you provide to RepuFix, and that doing so does not violate any applicable law, third-party rights, or contractual obligation.

5. Third-Party Service Providers

RepuFix engages certain third-party service providers to operate the Service. These providers are contractually bound to process your data only as necessary to perform their designated functions and to maintain appropriate security measures.

5.1 Email Verification API Providers

When you request email verification, email addresses from your uploaded dataset are transmitted to one or more third-party email verification API providers. These providers perform technical deliverability checks (syntax validation, DNS/MX record lookup, SMTP verification, and catch-all detection). Verification results are returned to your account. Verification providers may retain query data as described in their own privacy policies. RepuFix endeavors to use providers with privacy-protective data handling practices.

5.2 Cloud Infrastructure and Hosting

The Service is hosted on cloud infrastructure provided by third parties, which may include Vercel, Amazon Web Services, or equivalent providers. Your data is stored on servers that may be located in the United States or other countries. These providers are bound by data processing agreements and industry-standard security certifications.

5.3 Payment Processing

Payment information is processed by third-party payment processors. RepuFix does not store full payment card numbers. Payment processors operate under their own privacy policies and applicable PCI-DSS standards.

5.4 Analytics

We use PostHog for privacy-safe product analytics, and it runs only after you explicitly accept analytics via our consent banner. You may reject, or withdraw a prior acceptance at any time, and essential features continue to work either way. Session recording, session replay, heatmaps, surveys, and autocapture are disabled; we do not call identify() and do not send your email, uploaded lead data, or search queries to analytics. URLs are reduced to route shapes with an allowlisted set of query parameters. Error and security monitoring (Sentry) is separate from product analytics and is subject to the personal-data scrubbing described above; we do not use Vercel Analytics.

A current list of subprocessors is maintained and available upon request. We will provide reasonable notice before adding new subprocessors that materially affect the processing of your data.

6. Data Retention

We retain your account data for as long as your account remains active. If you close your account, we will delete or anonymize your account data within 90 days, except where retention is required by applicable law, fraud prevention obligations, or unresolved billing disputes.

Uploaded lead data and derived data (scores, flags, classifications) are retained for as long as you maintain them in the Service. You may delete individual lists, leads, or segments at any time through the interface. Deleted data is permanently removed from production systems within 30 days. Backup retention: encrypted backups may retain copies of deleted data for up to 90 days following deletion from production, after which they are purged from all backup systems.

Usage logs and technical records are retained for up to 12 months for security and operational purposes, after which they are deleted or anonymized.

To request the deletion of your data, contact us at privacy@repufix.io. We will acknowledge your request within 5 business days and complete the deletion within 30 days, subject to any legally required retention exceptions.

7. Your Rights and Choices

7.1 GDPR Rights (EU/EEA/UK Users)

If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:

  • Right of Access — Request a copy of the personal data we hold about you.
  • Right to Rectification — Request correction of inaccurate or incomplete data.
  • Right to Erasure — Request deletion of your personal data ('right to be forgotten').
  • Right to Restriction of Processing — Request that we limit the processing of your data in certain circumstances.
  • Right to Data Portability — Receive your data in a structured, machine-readable format.
  • Right to Object — Object to processing of your data for certain purposes, including profiling.
  • Right to Withdraw Consent — Where processing is based on consent, withdraw that consent at any time.
  • Right to Lodge a Complaint — File a complaint with your national data protection supervisory authority.

Our legal bases for processing your account and operational data include: contract performance (to deliver the Service you have subscribed to), legitimate interests (security, fraud prevention, service improvement), and compliance with legal obligations. For lead data uploaded by you, our legal basis as processor is your documented instruction as controller.

7.2 CCPA Rights (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete your personal information, the right to opt out of the sale or sharing of personal information (note: RepuFix does not sell or share personal information as defined under CCPA), and the right to non-discrimination for exercising your rights.

To exercise your CCPA rights, contact us at privacy@repufix.io. We will verify your identity before processing requests.

7.3 Canadian Users (PIPEDA / Law 25)

Canadian users are protected under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. You have the right to access your personal information, request correction of inaccuracies, and withdraw consent for processing where consent is the legal basis. Contact us at privacy@repufix.io to exercise these rights.

8. International Data Transfers

RepuFix operates globally and may process your data in the United States and other countries where our infrastructure and subprocessors are located. If you are located in the EU/EEA or UK, your data may be transferred to and processed in countries that do not have the same level of data protection as your home country.

Where such transfers occur, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Agreement (IDTA), or other lawful transfer mechanisms. For transfers to verification API providers, we ensure that data transfer agreements are in place or that providers are certified under applicable frameworks.

You may request information about the specific mechanisms used to protect your data in international transfers by contacting privacy@repufix.io.

9. Security

RepuFix implements reasonable and industry-standard technical and organizational security measures designed to protect your data against unauthorized access, disclosure, alteration, or destruction. These measures include, where applicable, encryption of data in transit using TLS, access controls and authentication requirements, regular security assessments, and monitoring for unauthorized access.

No security system is impenetrable. RepuFix cannot guarantee the absolute security of your data. In the event of a data breach that affects your personal data, we will notify you and applicable regulatory authorities as required by law.

You are responsible for maintaining the security of your account credentials. You should use a strong, unique password, enable multi-factor authentication where available, and notify us immediately at security@repufix.io if you suspect unauthorized access to your account.

10. Regulatory Compliance Responsibilities

RepuFix processes lead data on your behalf as a data processor. You are solely responsible as the data controller for ensuring that your collection, use, and processing of lead data — and any subsequent outreach you conduct using that data — complies with all applicable laws and regulations, including but not limited to:

  • CAN-SPAM Act (United States): You are responsible for ensuring that any commercial email sent using leads processed through RepuFix complies with the CAN-SPAM Act, including accurate header information, non-deceptive subject lines, a valid physical postal address, a functional unsubscribe mechanism, and prompt honoring of opt-out requests.
  • CASL (Canada): You are responsible for ensuring that any commercial electronic messages sent to Canadian recipients comply with Canada's Anti-Spam Legislation (CASL), including obtaining express or implied consent as required, providing sender identification, and including an unsubscribe mechanism in every message.
  • GDPR (EU/EEA/UK): You are responsible for ensuring a lawful basis for processing any personal data contained in your lead lists, for honoring data subject rights requests, and for ensuring that any transfer or use of lead data complies with GDPR requirements applicable to you as controller.
  • Other applicable laws: You are responsible for compliance with all other applicable privacy, data protection, electronic communications, and anti-spam laws in the jurisdictions where you operate and where your leads are located.

RepuFix does not guarantee that use of the Service ensures compliance with any of the above regulations. The Service is a data conditioning tool only. Compliance with applicable law remains your obligation.

11. Children's Privacy

The Service is intended exclusively for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected information from a minor, we will take steps to delete that information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, where the changes are material, provide notice via email or prominent display within the Service. Your continued use of the Service after any such change constitutes acceptance of the updated Policy.

13. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to conflict of law principles. For users in the EU/EEA/UK, this does not affect your statutory rights under applicable data protection legislation.

14. Contact Us

For privacy-related inquiries, data subject rights requests, or questions about this Policy, contact us at:

RepuFix — Privacy Team

Email: privacy@repufix.io

For EU/EEA data protection matters, you may also contact your local supervisory authority.