Licensing business contact data comes with real regulatory responsibility, for us as the data provider and for you as the organization using it. This page lays out, in plain terms, which frameworks we align our sourcing and handling practices with, what those frameworks actually require, and where the responsibility shifts to you once data is in your hands. We would rather be specific and direct about this than make a vague blanket compliance claim that does not hold up to scrutiny.
For the formal legal text governing your use of our site and services, see our Privacy Policy and Terms of Service. This page is meant to explain our practices in accessible language alongside those documents, not replace them.
For contacts based in the European Union and UK, our sourcing and processing practices are aligned with core GDPR principles: lawful basis for processing, data minimization, and purpose limitation. We source business contact data under legitimate interest as a lawful basis where applicable, consistent with GDPR guidance on B2B business contact information.
We are not a certifying body, and GDPR does not offer third-party certification in the way some frameworks do, so we do not claim formal GDPR certification. What we can provide is documentation of our data handling practices and a compliance report on request, so your legal or procurement team can evaluate our practices directly rather than taking a badge at face value. Full detail on data subject rights and how to exercise them is in our GDPR policy.
For California-based contacts, our practices are aligned with CCPA requirements around data transparency, the right to know what data we hold, and the right to opt out of sale or sharing of personal information. If you are a California resident and want to know what data we hold on you, or want a record removed, our team can process that request directly. Full detail is in our CCPA policy.
All business contact data we license is compiled and delivered in a manner consistent with CAN-SPAM Act requirements on our end, meaning we do not knowingly compile data through deceptive means and we honor removal requests promptly. That said, CAN-SPAM compliance for the actual email campaigns you send using this data, accurate sender identification, a working unsubscribe mechanism, and honoring opt-outs within the required window, is your responsibility as the sender once the data is delivered. We are glad to advise on best practices, but we cannot guarantee compliance for campaigns we do not control. Full detail is in our CAN-SPAM policy.
This is worth stating clearly because it is a common point of confusion. Our healthcare contact databases, covered in more detail on our Physicians Email Database page, contain professional practice information for licensed providers: name, specialty, practice affiliation, and business contact details. They are sourced from public licensing and registration records such as CMS NPPES and state medical boards.
They do not contain protected health information, meaning no patient records, diagnoses, treatment history, or any data tied to an individual patient. HIPAA governs protected health information specifically, so it does not apply to this type of business-to-business contact data. If your use case involves anything touching actual patient data, that falls outside what we provide and would need to be handled under a different regulatory framework entirely.
If an individual contacts us directly requesting removal from our database, we honor that request and suppress the record from future licensing. If you are a client and one of your contacts asks to be removed, let our team know and we will process the suppression on our end as well, so the record does not resurface in a future list.
We want to be upfront rather than optimistic here. Compliance with data privacy and anti-spam regulation depends heavily on how licensed data is actually used, which is outside our control once delivered. We provide accurately sourced, well-documented data and can supply compliance reporting on our own sourcing practices, but we do not and cannot guarantee regulatory compliance for your specific use case. That determination depends on your industry, your jurisdiction, how you use the data, and your organization’s own legal obligations. If you have a use case with unusual regulatory sensitivity, we would recommend involving your legal counsel before launch.
Is your data GDPR compliant?
Our sourcing and handling practices are aligned with GDPR principles for business contact data. We do not hold formal third-party GDPR certification, since GDPR itself does not offer one, but we provide documentation on request.
Can someone ask to be removed from your database?
Yes. Contact our team with the individual’s details and we will suppress the record from future licensing.
Do you sell the same list to competing companies?
Our databases are licensed to multiple clients rather than sold exclusively to one buyer per record, similar to most B2B data providers. If exclusivity matters for your use case, raise it with our team directly.
Who is responsible for CAN-SPAM compliance on my campaigns?
You are, as the sender. We ensure our data is sourced and delivered in a manner consistent with CAN-SPAM on our end, but campaign-level compliance, including working unsubscribe links and honoring opt-outs, is your responsibility.
For details on how our data is sourced and verified, see our Data Methodology page. For the full legal text, see our Privacy Policy, GDPR, CCPA, and CAN-SPAM pages, or contact our team with specific compliance questions.
501 Silverside Rd, Suite 105 Wilmington, DE 19809, USA