TL;DR
lemlist follows GDPR regulations by storing data in the EEA, using only publicly available information, requiring user consent for contact exports, and providing tools to help users implement opt-out mechanisms. All data stays on French servers hosted by OVH. Users act as data controllers while lemlist acts as the processor. Recipients can unsubscribe when an unsubscribe link is included in the email, or they can request deletion by contacting [email protected].
What This Is
GDPR (General Data Protection Regulation) compliance means lemlist handles personal data according to European privacy laws. This protects both lemlist users and the people they contact through campaigns.
lemlist operates as a data processor under GDPR, while users are data controllers responsible for ensuring their outreach complies with privacy regulations.
Why This Matters
GDPR compliance protects you from legal risks when running cold outreach campaigns. Non-compliance can result in significant fines and damage to your business reputation.
For recipients, GDPR gives them control over their personal data. They can request deletion, understand how their data is used, and opt out of communications. lemlist's compliance framework respects these rights while enabling effective outreach.
How lemlist Ensures GDPR Compliance
Data Storage and Residency
All lemlist data is stored within the European Economic Area (EEA) on servers located exclusively in France and hosted by OVH. No personal data is exported outside the EEA, ensuring full compliance with GDPR data residency requirements.
Public Information Only
lemlist's database contains only publicly available information from LinkedIn profiles, including:
Names
Job titles and positions
Company names
Employment history
Email addresses and phone numbers are not stored in the database unless explicitly provided by users during contact enrichment.
User Consent and Transparency
When users export contacts using lemlist credits, they explicitly agree to follow lemlist's privacy and sending policies. This consent mechanism ensures:
Users understand their responsibilities as data controllers
Data is used responsibly and within GDPR guidelines
Users provide recipients with a clear opt-out mechanism (for example, by including an unsubscribe link) where required
lemlist provides an in-app GDPR certification setting where users confirm their data collection follows GDPR principles.
Unsubscribe Links (Recommended)
lemlist allows users to include an unsubscribe link in their emails, and it is strongly recommended to do so to support GDPR/CAN-SPAM compliance and good sending practices. When an unsubscribe link is included and a recipient clicks it, they're removed from that campaign and cannot be contacted again by that user.
Data Processing Agreement (DPA)
lemlist offers a Data Processing Agreement that defines the relationship between lemlist (processor) and users (controllers). The DPA is available for review and signing online at lemlist's official website.
How to Request Data Deletion
If you want your information removed from lemlist's database, you have two options:
Option 1: Contact lemlist Privacy Team
Send an email to [email protected]
Include your full name and the email address you want removed
Specify if you're making a GDPR data subject request
lemlist will verify your request and confirm removal via email
Option 2: Contact the Sender Directly
If you received an email from a lemlist user, you can contact them directly to request removal from their contact list. Depending on how the sender configured their email, the message may include sender information and an unsubscribe link.
What Happens After Your Request
lemlist verifies the request follows GDPR requirements
Your data is removed from the database
You receive confirmation via email once deletion is complete
How Contact Enrichment Works
When users spend credits to enrich contacts, lemlist searches for email addresses using:
Common email format patterns (e.g., [email protected])
Email verification to confirm addresses are valid
Partner databases for additional contact information
This process respects privacy by using non-intrusive methods and only providing verified contact information to users who've agreed to GDPR-compliant use.
Additional Resources
For more information about lemlist's data practices:
Review the Privacy Policy for detailed data handling procedures
Access the Data Processing Agreement for GDPR-related clauses
Important: GDPR is just one privacy regulation. Other laws like CAN-SPAM (US), CASL (Canada), and PECR (UK) may also apply to your outreach. Laws vary by country, so consult legal professionals familiar with your target markets to ensure full compliance.
