GDPR Compliance

Last updated: October 2, 2026

We take data protection seriously. This page explains how Anymail Finder (AMF Internet Services Limited) complies with the EU General Data Protection Regulation (GDPR) and similar privacy laws, including the UK GDPR.

1. Our GDPR Commitment

The General Data Protection Regulation (GDPR) and the UK GDPR set the standards for how personal data of EU and UK residents must be collected, processed, and protected.

We maintain policies, procedures and contractual safeguards designed to support our compliance with applicable data protection laws, and review them regularly. This includes:

2. Data Controller and Processor Roles

Anymail Finder may act as both a data controller and a data processor, depending on the context:

As a customer, you act as controller of the personal data you process through Anymail Finder or, where you process that data on behalf of your own customer, as that customer's processor; in the latter case Anymail Finder acts as your subprocessor, as described in our DPA.

When acting as a processor, we only process personal data on your documented instructions and in accordance with our Data Processing Addendum (DPA).

3. Data Processing Addendum (DPA)

We provide a Data Processing Addendum (DPA) that forms part of our Terms of Service and your agreement with us. It defines our obligations as a data processor under Article 28 of the GDPR, including:

You can request a signed copy of our DPA by emailing team@anymailfinder.com.

4. Data Hosting and Transfers

We host our infrastructure on Amazon Web Services (United States) and Hetzner Online GmbH (Germany).

When personal data is transferred from the EEA to a country that is not covered by an applicable adequacy decision, we rely on the EU Standard Contractual Clauses (SCCs) and AWS's Data Processing Addendum and any supplementary measures required by applicable law. For restricted transfers from the UK, we use the UK International Data Transfer Addendum to the EU SCCs as described in our Data Processing Addendum.

We also carry out applicable transfer risk assessments and implement supplementary safeguards where required by law for transfers of personal data outside the EEA and the UK.

We apply the same security and privacy measures to data wherever it is hosted, and we regularly review our infrastructure to minimize transfers outside the EEA where possible.

5. Data Security

We implement and maintain appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, in accordance with Article 32 of the GDPR.

Our security controls include, among others:

These measures are reviewed and updated regularly to ensure a high level of data protection and service integrity.

6. Data Retention and Deletion

You may also request deletion of your data at any time by contacting team@anymailfinder.com. Verified deletion requests are normally processed within 48 working hours.

7. Data Subject Rights

Depending on the circumstances and the legal basis for the processing, individuals ("Data Subjects") may have rights under the GDPR and UK GDPR to:

We provide two ways for individuals to exercise these rights:

  1. Opt-out / Blacklist: Individuals can block future lookups of their domain or email address by using our opt-out tool. Once submitted, the address or domain is added to our internal suppression list and is suppressed from future search results. A request to suppress an entire domain must be made by a person authorised to act for that domain. Individuals may also ask us, after we have verified their identity where appropriate, which customer account searched for their address, and we treat an objection to our continued use of their business contact information in accordance with applicable data protection laws, using the same suppression process.
  2. Direct request: Individuals may contact us at team@anymailfinder.com to request access, correction, or deletion of their personal data. Verified requests are typically processed within 48 working hours.

8. Data Shared with Subprocessors

We assess our subprocessors and require appropriate contractual data protection and security obligations from them. These partners help us deliver our service, manage customer relationships, and operate our business securely.

Our main subprocessors include:

Each subprocessor provides GDPR-compliant data processing terms, and we regularly review their security and privacy practices. We maintain an up-to-date list of subprocessors and notify customers of intended changes to subprocessors, with an opportunity to object on reasonable data protection grounds in accordance with our Data Processing Addendum (DPA).

9. Privacy Policy and Data Protection Officer (DPO)

We maintain a detailed Privacy Policy describing how we collect, use, and protect your data.

Anymail Finder has appointed a Data Protection Officer (DPO) responsible for overseeing GDPR compliance and managing data protection inquiries.

Contact our DPO: team@anymailfinder.com

10. Data Breach Notification

In the unlikely event of a personal data breach, we will:

We also comply with applicable legal obligations to notify supervisory authorities and, when required, affected data subjects.

11. Updates to This Statement

We may update this GDPR statement from time to time to reflect legal, technical, or operational changes. Significant updates will be communicated directly to customers and published on this page with an updated "Last updated" date.

AMF Internet Services Limited
Registered in the UK, number 10586048
team@anymailfinder.com