Skip to content

Privacy Policy

Last updated: June 26, 2026

Data Enrich OS ("we", "us") provides a lead intelligence and data enrichment platform. This policy explains what data we process, why, and the choices you have. We designed the product to be compliance-first: provenance is recorded on every enriched field, and opt-out requests are enforced on every export.

Template notice: this document is a good-faith starting point and should be reviewed by qualified legal counsel for your jurisdiction before public launch.

1. Data we process

We process two broad categories of data:

  • Account data — your name, work email, hashed password, workspace name, and audit/usage logs needed to operate your account.
  • Customer-provided data — the company and contact records you upload or enrich. You are the controller of this data; we process it on your behalf as a processor.

2. How enrichment data is sourced

Enriched fields come from official, licensed provider APIs and from publicly available business pages where you enable safe extraction. We do not scrape login-walled platforms, bypass access controls, or use rotating proxies. Each enriched value carries a provenance record indicating its source.

3. Legal bases (GDPR)

  • Performance of a contract — to provide the service you sign up for.
  • Legitimate interests — B2B contact data processing for sales intelligence, balanced against data-subject rights and subject to opt-out.
  • Consent — where required for specific processing, recorded as a consent event.
  • Legal obligation — to honor opt-out / Do-Not-Contact and erasure requests.

4. Opt-out & data-subject rights

Individuals may request access, correction, deletion, or suppression of their data. The platform maintains opt-out and Do-Not-Contact lists; matching records are excluded from exports and flagged for removal. To exercise rights, contact privacy@divineastromedia.com or use the in-app compliance tools.

5. Sub-processors

We use a limited set of sub-processors (e.g., hosting, database, and the enrichment providers you choose to enable with your own keys). A current list is available on request. Live provider calls are off by default and only occur when you explicitly enable them.

6. Data retention

Account data is retained for the life of your account. Customer-provided data is retained until you delete it or close your workspace. Audit logs are retained for a rolling period for security and compliance.

7. Security

We use signed sessions, scrypt password hashing, role-based access control, security headers, and an append-only audit log. Outbound and live calls are gated off by default. See our Security & Compliance page for details.

8. International transfers

Where data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses). Enterprise customers can request data-residency options.

9. Changes & contact

We may update this policy; material changes will be announced in-app or by email. Questions: privacy@divineastromedia.com.