Coupon code copied!

Privacy &Security

GDPR-aligned processing AES-256 encryption at rest TLS 1.2/1.3 in transit Least-privilege access SCC-based transfers DPA available on request No data sold, ever Corporate insurance coverage

Our approach to data protection

We are committed to protecting personal data and complying with applicable data protection laws, including the GDPR and other privacy laws, where it applies.

We apply core data protection principles: data minimization, purpose limitation, storage limitation, integrity, and confidentiality when designing and operating our services. In practice, this means we only collect the data we genuinely need, use it strictly for the purposes you’d expect, keep it no longer than necessary, and protect it with strong technical and organizational safeguards.

We process personal data only as necessary to provide, maintain, secure, support, and improve our services.

Depending on the activity, we may act as either a data processor or a data controller:

  • As a processor: when we process personal data on behalf of a business customer, including data about that customer’s authorized users or leads, we follow the customer’s documented instructions and the applicable agreement.

The customer remains responsible for determining the purposes and lawful basis of the relevant processing activities, including the collection, use, and communication of lead data through the Dripify platform.

  • As a controller: for certain activities, such as managing customer accounts, providing support, maintaining security, or meeting legal and administrative obligations, we act as a controller.

We do not sell or rent your data, and we do not use it to train AI models. Your lead data stays in your account. We do not pool it into a shared database or make it available to other Dripify customers. We use it only to run the campaigns you set up.

Data Processing Agreement

We make a Data Processing Agreement (DPA) available to customers who require one. 

The DPA covers our respective data protection roles and responsibilities, the categories of personal data we process, the purposes of processing, our security measures, subprocessors, international data transfers, how we assist with data subject requests, and how customer personal data is deleted or returned.

Customers can request the applicable DPA by contacting our support team via chat or at support@dripify.com.

Privacy rights and data requests

We support the exercise of applicable privacy rights in accordance with our role under data protection laws.

Where we process personal data on your behalf as a business customer, we act as a processor. In these cases, you remain responsible for responding to data subject requests, and we provide reasonable assistance where required by applicable law and our agreement with you. 

If we receive a request relating to personal data we process on your behalf, we may redirect the requester to you or otherwise handle the request in accordance with applicable law, your instructions, and our contractual obligations.

Where we act as a controller for specific processing activities, individuals may exercise applicable privacy rights, including the right to access, correct, delete, restrict, object to, or request portability of their personal data (subject to applicable legal conditions and limitations).

Privacy-related requests may be submitted by chat or by email at support@dripify.com. We may need to verify the requester’s identity before processing the request.

Subprocessors

We work with trusted third-party service providers to support the operation, hosting, security, communications, payment processing, analytics, and improvement of our platform. Where a provider processes customer personal data on our behalf, that provider acts as a subprocessor.

We maintain a structured list of subprocessors, review the role of each one, and, where required, put appropriate contractual arrangements and data protection requirements in place. 

Customer personal data is shared with subprocessors only where reasonably necessary to provide, secure, support, or improve our services.

Our current subprocessor list is available upon request by contacting our support team at support@dripify.com.

Security measures

We apply technical and organizational measures designed to protect customer personal data against unauthorized access, disclosure, alteration, loss, destruction, or other unlawful processing. 

Where applicable, these include:

Hosting
infrastructure on Amazon Web Services

Cloud-level network access
controls, including AWS Security Groups

Edge-level traffic
filtering and protection through Cloudflare

Encryption of data in transit
using TLS 1.2/1.3, where applicable

Encryption of data at rest
using AES-256

Role-based access
controls and access rights based on the principle of least privilege

Regular review
of access permissions

Logging
Access and activity logging across relevant platform infrastructure

Monitoring
of systems and network activity

Separation of customer data
through technical and organizational isolation controls

Confidentiality
obligations for personnel with access to customer personal data

Training
Security and GDPR-related personnel training

Endpoint protection
measures for employee devices

Internal security review
and data handling practices

Access to customer personal data is restricted to authorized personnel who need it for legitimate business purposes, including platform operation, customer support, security, maintenance, and legal or contractual obligations. 

We also apply appropriate contractual and data protection requirements to relevant service providers where required by law.

Data management and retention

We retain personal data only for as long as reasonably necessary,  for example, to provide our services, maintain security, comply with legal obligations, resolve disputes, enforce agreements, or support legitimate business operations.

Unless a different retention period is required by law, an applicable agreement, or the nature of the processing activity itself, we generally retain customer personal data for no longer than three years after the customer’s last use of our services. 

Different categories of information may have different retention periods depending on their purpose, legal requirements, contractual obligations, and operational needs.

Where we act as a processor, deletion or return of customer personal data follows the customer’s documented instructions, the applicable agreement, and applicable law. 

Following termination of our services or a valid customer request, applicable customer personal data is deleted or returned accordingly. 

We apply secure deletion and handling procedures designed to reduce the risk of unauthorized recovery, access, or continued processing after deletion.

International data transfers

Some of the service providers we work with may process personal data outside the European Economic Area (EEA) or the country where the relevant customer or individual is located.

Where an international transfer requires additional safeguards under applicable data protection law, we take steps to put an appropriate transfer mechanism in place. 

Depending on the circumstances, the process may include adequacy decisions, Standard Contractual Clauses (SCCs), or other lawful transfer mechanisms, along with transfer assessments and supplementary measures where appropriate.

Where we act as a processor, international transfers of customer personal data are handled in line with the applicable agreement, applicable data protection law, and the customer’s documented instructions.

Security Incident Management

We maintain internal procedures to identify, assess, escalate, investigate, and respond to security incidents. 

Where a security incident involving customer personal data triggers notification obligations under applicable privacy laws and/or our contractual commitments, we provide the required notifications accordingly. 

We also review incidents afterward to identify appropriate corrective or preventive measures.

Service reliability

We understand that our customers rely on Dripify to run ongoing outreach and sales workflows. 

We maintain internal procedures for platform availability, incident classification and escalation, support handling, system monitoring, and scheduled maintenance.

We continuously work to maintain the availability, security, and reliable operation of our services, but, as with any online service, we cannot guarantee uninterrupted availability.

Insurance

We maintain corporate insurance coverage appropriate to our business operations and risk profile. 

This may include professional liability, cyber and network-related risks, and general business liability, subject to the terms, conditions, exclusions, and limits of the relevant policies.

For more on how we collect, use, and protect personal data, please see our Privacy Policy and Terms of Service.