GDPR Compliance

EfficientPIM is committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR).

1. What is GDPR?

The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union (EU) and the European Economic Area (EEA).

GDPR aims to give individuals control over their personal data and to unify data protection regulations across Europe. It applies to any organization that processes personal data of individuals in the EU/EEA, regardless of where the organization is located.

Key Principles of GDPR

GDPR is built on several key principles that must be followed when processing personal data:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

2. Our Commitment to GDPR

EfficientPIM is committed to protecting your personal data and complying with GDPR requirements. We have implemented appropriate technical and organizational measures to ensure GDPR compliance.

Our GDPR compliance program includes:

  • Regular privacy impact assessments
  • Data protection by design and by default
  • Comprehensive staff training on data protection
  • Regular audits of our data processing activities
  • Clear procedures for handling data subject requests
  • Robust security measures to protect personal data

3. Data We Process

In the context of our email scraping service, we may process the following types of personal data:

  • Contact Information: Email addresses, names, company information
  • Account Information: Registration details, login credentials (encrypted)
  • Usage Data: IP addresses, browser information, search queries
  • Payment Information: Payment method details (processed securely by third parties)

Publicly Available Data

Please note that the email addresses we scrape are publicly available information from websites. We do not access or process private email accounts or personal communications.

5. Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

Request a copy of the personal data we hold about you

Right to Rectification

Request correction of inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data in certain circumstances

Right to Restrict Processing

Limit how we process your personal data in certain situations

Right to Data Portability

Receive your personal data in a machine-readable format

Right to Object

Object to processing based on legitimate interest or direct marketing

6. Data Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

  • SSL/TLS encryption for data in transit
  • Encryption for data at rest
  • Access controls and authentication systems
  • Regular security assessments and penetration testing
  • Secure data centers with restricted access
  • Incident response procedures
  • Employee confidentiality agreements

We regularly review and update our security measures to ensure they remain effective against evolving threats.

7. International Data Transfers

As a global service, we may transfer personal data outside the EU/EEA. We ensure such transfers are protected by:

  • Adequacy decisions by the European Commission
  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs)
  • Specific derogations under GDPR

We have implemented appropriate safeguards to ensure your personal data remains protected during international transfers.

8. Data Breach Notification

We have established procedures to detect, investigate, and report data breaches. In the event of a personal data breach, we will:

  • Assess the risk to individuals' rights and freedoms
  • Notify the relevant supervisory authority within 72 hours (where required)
  • Inform affected individuals without undue delay (if the breach poses a high risk)
  • Implement measures to prevent future breaches

What Constitutes a Breach

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

9. Making a GDPR Request

To exercise your GDPR rights, please contact us using the information below. We will respond to your request within 30 days.

10. Contact Information

GDPR Inquiries

If you have any questions about our GDPR compliance or want to exercise your rights, please contact us at:

Email: [email protected]

We will acknowledge receipt of your request within 5 business days and provide a full response within 30 days.

Data Protection Officer

If you have specific concerns about how we process your personal data, you can also contact our Data Protection Officer at the same email address with "DPO" in the subject line.

Last updated: November 20, 2025