Epafi
The MachineEngineFeaturesPricingAbout
Sign inStart free
EPAFILegal

Privacy,in plain terms.

This policy tells you exactly what Epafi processes, why, and who touches it. No hedge words, no 'may include' lists. If something here is unclear, that is a bug — email us.

Effective · 2026-08-01Version · 3.2Reading time · 7 min

Contents

01What we process02Where data comes from03Who processes it with us04What we never do05Retention & deletion06Your rights07Contact & complaints
01

What we process

Epafi is contact data infrastructure. To run it, we process two distinct categories of data, and we never blur the line between them:

  • +Account data — your name, work email, company, and billing details. You give us this directly when you sign up.
  • +Workspace data — the contact records you import or push through the API: names, emails, phone numbers, employers, job titles, social profiles, tags, and any custom fields you create.
  • +Usage data — product telemetry such as feature usage, error logs, and performance timings. This contains no contact record content.

We do not collect data about your contacts’ behavior, we do not track your contacts across the web, and we do not enrich anyone you have not explicitly imported.

02

Where data comes from

Workspace data enters Epafi only through actions you take:

  • +File imports you run (CSV, vCard, LinkedIn or Google Contacts exports).
  • +Records you push through the REST API, CLI, or webhooks.
  • +Enrichment attributes returned by our data providers for records you chose to enrich.

If you import personal data about other people, you are responsible for having a lawful basis to do so — typically legitimate interest for B2B contact management. Section 6 and our GDPR page explain how we support your obligations.

03

Who processes it with us

We keep the sub-processor list short, named, and current. No anonymous "partners", no marketing pixels on workspace data.

ProcessorPurposeData touchedLocation
ClearbitContact & company enrichmentIdentifiers you submit for enrichmentUS
FullContactContact & company enrichmentIdentifiers you submit for enrichmentUS
Amazon Web ServicesHosting & storageAll workspace data (encrypted)EU (Frankfurt)
ClerkAuthenticationAccount credentials & session dataUS
StripeBillingPayment method & invoicesUS

Every sub-processor is bound by a data processing agreement with equivalent obligations. We announce changes to this list at least 14 days in advance to workspace owners.

04

What we never do

  • +Sell, rent, or broker your data or your contacts’ data — to anyone, in any form.
  • +Train shared or third-party ML models on your workspace data.
  • +Run advertising trackers on authenticated pages.
  • +Read your contact records for any purpose other than operating, securing, or debugging the service — and debugging access is logged and time-boxed.
  • +Keep data after you delete it, beyond the backup windows described below.
05

Retention & deletion

Workspace data lives until you delete it. Deleted records vanish from production immediately and from encrypted backups within 30 days. Merge undo history is kept for 30 days, then purged.

Closing your account deletes all workspaces you own after a 14-day grace period. Billing records are retained for the period required by tax law (typically 7 years) and contain no contact record content.

06

Your rights

Regardless of where you live, we extend the core GDPR rights to every user:

  • +Access — export everything we hold about you, from Settings → Export, self-serve.
  • +Rectification — correct any account data at any time.
  • +Erasure — delete records, workspaces, or your entire account, self-serve.
  • +Portability — full-fidelity CSV and JSON exports, no lock-in formats.
  • +Objection & restriction — write to privacy@epafi.app and we will act within 30 days.

If your contacts exercise their rights against you, our API and UI give you the tools to honor them — including record-level deletion that propagates to backups on the schedule above.

07

Contact & complaints

Privacy questions, requests, or DPA inquiries: privacy@epafi.app. Our data protection contact is listed on the GDPR page.

If you are in the EU/EEA and believe we have not resolved a concern, you have the right to lodge a complaint with your local supervisory authority. We would rather fix the problem — write to us first.

Questions about this document? legal@epafi.app — we answer legal mail within two business days.

Epafi

Contact data infrastructure for teams that can’t afford a messy CRM.

All systems operational

Product

  • Features
  • The engine
  • Pricing
  • CLI

Company

  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Security
  • GDPR

Epafi

© 2026 EPAFI — ALL RIGHTS RESERVED

MADE FOR CLEAN DATA