Hunter uses automated and AI-powered systems to build, validate, and maintain its database of professional contact information. This page explains how those systems work, what decisions they make autonomously, where human oversight applies, and how our AI use is governed under the EU AI Act and GDPR.
1. Overview of AI and automated systems at Hunter
Hunter uses AI and automated systems across two distinct contexts: (1) our own proprietary systems that build and maintain the Profile Database; and (2) third-party AI providers used for user-facing email features, content filtering, and database pipeline processing.
We rely on our legitimate business interest for processing personal data when using our proprietary automated systems. When deploying third-party AI systems, Hunter may act as a controller or a processor depending on the scope of work, as described in the sections below.
| System | Task |
|---|---|
| Web crawling (proprietary) | Automated systems visit public web pages and extract structured professional contact information. |
| Name detection and extraction (proprietary ML) | Machine learning models identify and extract names and organizational affiliations from text found on public web pages, turning web content into structured data. |
| Summarization and classification (proprietary AI) | Machine learning models extract keywords from web content and classify organizations and contacts for more accurate data segmentation. |
| Embeddings generation (proprietary AI) | Machine learning models build numeric representations of entities (contacts, companies) to enable similarity detection, identifying relationships between entities in our database. |
| Email format pattern recognition (proprietary ML) | Machine learning models analyze domain-level email patterns to enable address inference. |
| Email address inference (proprietary) | Machine learning models apply domain patterns to generate probable email addresses. |
| Email verification (proprietary) | Automated SMTP-level checks confirm address deliverability before database entry. |
| Service optimization (proprietary) | Automated systems and processes detect fraud, prevent abuse, improve search relevance, and enhance user experience. |
| Email writing assistance and personalization (optional) | Assists Hunter users in drafting and personalizing outreach email content. Hunter users are data controllers; Hunter acts as processor on user instructions. |
| Spam detection and content filtering | Analyzes AI-generated and user-triggered content for spam signals and harmful or prohibited attributes. Applies to AI-assisted email content and user-initiated checks. Hunter is the data controller for this processing. |
| Data pipeline / web data structuring | Transforms and structures public web data into usable metadata for the Profile Database. (Hunter as data controller.) |
| Discover / content discovery (optional) | Assists Hunter users in finding relevant contacts and companies via natural language queries. Hunter users are data controllers; Hunter acts as processor. |
2. Web crawling and data extraction
Hunter’s web crawlers are automated systems that visit publicly accessible URLs and extract structured data from page content. They identify patterns consistent with professional contact information, email addresses, names, job titles, company names, and store them with source metadata.
- Crawlers are limited to publicly accessible content. They do not access pages requiring authentication or use credentials to circumvent access controls.
- Crawlers respect robots.txt directives published by website owners. More information about Hunter’s crawler is available at hunter.io/robot.
- Where our crawler encounters private consumer data, such as a personal email address or personal phone number that is not associated with a professional context, it does not process it. Only professional contact data is collected.
- Individual crawl decisions are made automatically by scheduling systems.
The source pages from which crawlers collect data include company websites, professional directories, press releases, academic pages, and similar publicly indexed content. Crawled pages are not limited to EEA-hosted content.
3. Email format pattern recognition
Once email addresses have been collected for a domain, a pattern recognition model analyzes them to determine the email format convention in use at that company. Common patterns include firstname@, firstname.lastname@, f.lastname@, and similar.
The model produces a confidence score for each pattern based on the volume and consistency of observed collected addresses. This score:
- Is surfaced in the Domain Search interface and API, giving users visibility into pattern reliability.
- Must meet a minimum threshold before inference is applied; domains with insufficient data are excluded.
- Is recalculated as new collected data becomes available for a domain.
If a company changes its email format, for example following an acquisition or rebranding, the pattern confidence score for inferred contacts under the old format will fall. This triggers review and removal of affected records.
4. Structuring and organizing contact data
Hunter uses proprietary AI models and third-party AI providers to process and structure public web content into the organized professional profiles in our database. This includes classifying organizations by industry and business type, identifying professional names and job titles from web page content, and organizing contact records so that search results and company suggestions are accurate and relevant.
No additional personal data is collected for these purposes. This processing does not create new inferences about individuals’ personal characteristics; it organizes and relates information that is already in our database.
5. Email address inference
Email inference is the generation of a probable professional email address for an individual based on their name and their employer’s domain pattern.
5.1 What the inference system does and does not do
The inference system:
- Does: take a person’s name (from a public source) and a domain email pattern (derived from collected addresses) and generate a single probable email address.
- Does not: access private accounts, social profiles, or any non-public source to obtain the person’s name or any other input.
- Does not: use behavioral data, tracking signals, or inferences about personal characteristics, preferences, financial status, health, or any other attribute.
- Does not: combine inference with scoring, ranking, or profiling of the individual beyond the single deliverability check.
5.2 Is this profiling under GDPR Article 4(4)?
GDPR Article 4(4) defines profiling as “any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.”
Creating an email address based on your name and company pattern counts as “profiling” under GDPR, because it uses your personal information to infer something new about you. However, this type of profiling doesn’t trigger the stricter rules that apply to automated decisions about your job, credit, or access to services. The significance of the profiling characterization is that it engages the data subject’s right to object under Article 21(1) without needing to show significant effect, and the obligation to be transparent about the logic involved, both of which we address in this page and in the sourcing page.
5.3 Automated decision-making and GDPR Article 22
Article 22(1) GDPR restricts automated decision-making that produces “legal or similarly significant effects” for the individual without human intervention.
We assess that the generation of an inferred email address does not constitute a decision that produces legal or similarly significant effects within the meaning of Article 22(1). The output is a generated contact record for B2B prospecting purposes. It does not determine an individual’s access to employment, credit, services, or other legal rights. This is our current assessment, based on the EDPB guidelines on automated decision-making. The regulatory position in this area continues to develop, and we will update our approach accordingly. If you believe that an automated outcome relating to your data has had a significant effect on you, you can email us at privacy@hunter.io.
6. Verification: SMTP checks
Before entering the active database, every email address, collected and inferred, is verified to confirm it is active and capable of receiving mail. We communicate with the mail server associated with the address domain to carry out this check. No message is delivered during the process. Addresses that fail verification are not added to our database, or are removed if they were previously active.
7. EU AI Act compliance
The EU AI Act (Regulation (EU) 2024/1689) applies to AI systems placed on or put into service in the EU market. Hunter’s pattern recognition and email inference systems fall within the EU AI Act’s definition of an AI system.
7.1 Risk classification
We have assessed our AI systems under the EU AI Act risk classification framework:
| AI system | Our risk classification and rationale |
|---|---|
| Web crawling and data extraction | Not an AI system within the Act’s definition; automated rule-based crawling does not involve machine learning or inference. |
| Email format pattern recognition | Limited risk. This system analyzes collected data at the domain level to identify patterns. It does not make decisions about individuals and does not output content that interacts with them. |
| Email address inference | Limited risk. The system generates a data point about a named individual based on name and domain pattern. It does not determine access to services, employment, or credit. However, given that it generates content that is attributed to individuals, the transparency obligations in Article 50 of the EU AI Act apply. |
| SMTP verification | Not an AI system; automated technical check without a machine learning component. |
7.2 Transparency obligations
We assess our inference system as engaging these obligations in the following respects:
- The “Inferred” label applied to inferred contacts in the Hunter interface fulfills our obligation to signal to users that the information was AI-generated.
- This transparency page and the How Hunter Sources and Infers Data page together constitute our public disclosure of the logic and methodology of our inference system.
- We are monitoring guidance from the EU AI Office and will update our compliance approach accordingly.
8. Data quality controls for AI outputs
We apply the following quality controls beyond those applied to directly collected data:
- Pattern confidence threshold: inference is only applied where the domain pattern is established with sufficient consistency. Low-confidence domains are excluded.
- SMTP verification gate: all generated addresses must pass technical verification before entering the database. Unverified addresses are not added.
- Periodic re-verification: inferred records are subject to the same re-verification cadence as collected records. Pattern confidence is also recalculated as new data arrives.
- Complaint-driven review: where a data subject disputes an inferred address, we investigate the specific record and correct or remove as appropriate.
- Exclusion auditing: we periodically audit our exclusion category lists (sensitive domains) to ensure they are current and correctly applied.
9. Service optimization AI (fraud detection and abuse prevention)
Separately from the inference and verification pipeline, Hunter uses AI and automated systems for service optimization purposes. This affects Hunter users (account holders), not data subjects in the Profile Database.
These systems are used for:
- Fraud detection: automated systems monitor account activity and payment signals to identify and prevent payment fraud. In certain cases where automated signals are ambiguous, the relevant information is reviewed manually by our team.
- Abuse prevention: automated systems monitor usage patterns and account behavior to detect violations of our Terms of Service and applicable laws.
- Search relevance: AI improves the ranking and relevance of search results presented to Hunter users within the platform.
- User experience enhancement: automated systems analyze usage patterns and statistics to understand how features are used and identify improvements.
10. Third-party AI providers
Hunter integrates third-party AI providers for distinct processing purposes, each with a different legal relationship, data scope, and applicable safeguards. Current providers, the categories of data shared with each, and their location are listed at hunter.io/subprocessors, which is updated whenever a provider changes.
10.1 How we use third-party AI providers
We use AI models for distinct purposes, each with a different data relationship.
Optional user features (email writing, personalization, contact discovery): Hunter users are independent data controllers for this processing. When you use these features, you decide what data to submit and for what purpose. Hunter processes that data on your instructions only, as a processor. You are responsible for ensuring you have a lawful basis for any personal data you include.
Optional user features (contact discovery): Hunter’s Discover feature uses a third-party AI provider to help Hunter users find relevant contacts and companies via natural language queries. Hunter users are independent data controllers for this processing, and Hunter processes data on their instructions only, as a processor.
Spam detection and content filtering: Hunter uses a third-party AI provider to analyze content generated by AI writing features and to perform user-triggered content checks for spam signals and harmful or prohibited content. Hunter is the data controller for this processing. Its purpose is to protect recipients and prevent harmful content from being distributed through AI-assisted features.
Data pipeline processing: Hunter uses a third-party AI provider as part of its internal pipeline to process and structure public professional contact information for the Profile Database. Hunter is the data controller. The legal basis is legitimate business interest.
10.2 Email writing assistance and personalization – optional
Hunter users can optionally use a third-party AI provider to generate and personalize email content for their outreach campaigns. Hunter users are made aware that the writing assistant feature is an AI-powered tool.
Data transmitted to the provider for this purpose:
- User-written prompts and instructions;
- Email draft content submitted for improvement or revision;
- Context provided by the user (e.g. tone, style preferences);
- Campaign data including recipients’ names, job titles, and country (where the user’s campaign includes these fields);
- Email subject lines and message body content.
Hunter processes this data on user instructions only and does not use it for independent purposes.
10.3 Spam detection and content filtering
A third-party AI provider is used to analyze content generated by AI writing features, and to perform user-triggered content checks, for spam signals and for content that may be harmful, discriminatory, or that reveals sensitive personal attributes. This processing applies to AI-assisted email content and user-initiated checks. It does not automatically scan all campaign sends where no AI feature has been used. Data processed includes:
- Email subject lines and message body content;
- Recipients’ names and other personal data included in campaign messages.
The content filtering system is specifically designed to detect and block harmful, discriminatory, or illegal outputs, or those that reference protected categories under Article 9 GDPR, including health conditions, political opinions, sexual orientation, and religious beliefs, before they are presented to the user.
10.4 Public web data structuring – database pipeline
A third-party AI provider is used within Hunter’s internal data pipeline to transform and structure public web data pertaining to professional contact information into usable metadata for the Profile Database.
Data processed includes:
- Full names of professionals identified on public pages;
- Professional email addresses collected from public sources;
- Social media profile URLs associated with professional profiles.
10.5 Contact discovery
Hunter’s Discover feature uses a third-party AI provider to help Hunter users find relevant contacts and companies within their accessible data using natural language queries.
Data is transmitted to the provider for the following purposes:
- User-written natural language queries;
- Contact and company data returned from Hunter’s Profile Database that is relevant to the query;
- Context provided by the user to refine search results.
Hunter processes this data on user instructions only and does not use it for independent purposes. Hunter users are independent data controllers for this processing; Hunter acts as processor.
10.6 Lookalikes and Opportunities (optional)
Hunter users can optionally use AI to identify contacts and companies similar to their existing saved lists. When this feature is used, Hunter sends the user’s saved contacts and selected company lists to a third-party AI provider for similarity analysis. This feature operates on data the user has provided; Hunter processes it on user instructions as a processor.
This feature is in internal beta. The underlying provider and model may change during this period as we continue testing.
10.7 Safeguards common to all AI processing
- No model training on Hunter data: Hunter contractually requires that its AI providers not use any data processed through our integration for AI model training. Data is processed only to deliver the requested function.
- Retention limit: data is retained only as long as necessary for abuse monitoring purposes, after which it is deleted. Current retention periods by provider are listed at hunter.io/subprocessors.
- Data Processing Agreement: our agreements include processing only per Hunter’s documented instructions; confidentiality obligations; prohibition on training use; deletion upon service termination; GDPR Article 28-compliant sub-processor obligations; and appropriate security measures.
- Data minimization obligation: we send only the fields strictly necessary for each AI function. Hunter users should also apply data minimization when constructing prompts, and avoid submitting personal data that is not required for the AI task.
- Encryption in transit: all data transmitted to our AI providers is encrypted in transit.
10.8 AI accuracy limitation – hallucination disclaimer
AI language models can produce outputs that are inaccurate, incomplete, or misleading, a phenomenon known as “hallucination.” Email content generated by AI features may contain factual errors, incorrect personalization, or inappropriate language if not reviewed. Hunter users must review all AI-generated content before sending. Do not send AI-generated email content without human review. Hunter does not accept liability for harm caused by AI-generated content that has not been reviewed and approved by the user.
10.9 User controls for AI features
- Optional AI usage: AI-powered writing assistance can be turned off on a per-sequence basis within each campaign. Discover is available according to your subscription plan. If you want to opt out of all optional AI features across your account, contact privacy@hunter.io.
- API management: API integrations are permitted to access AI features only once explicitly authorized.
- Audit logging: AI feature usage is monitored and logged for accountability purposes.
- Data deletion: users can request deletion of data previously processed through AI features by contacting privacy@hunter.io.
10.10 Hunter user obligations when using AI features
Because Hunter users are independent data controllers for the campaign data they process through AI features, the following obligations apply:
- Users must hold a lawful basis under Article 6 GDPR (or applicable law) for processing the personal data of email recipients submitted to AI features.
- Users must not submit special category personal data (health, political opinions, sexual orientation, religious beliefs, etc.) to AI features unless they hold explicit consent under Article 9 GDPR for that specific processing.
- Users must not submit data they are not lawfully permitted to process. Hunter reserves the right to suspend accounts where unlawful data submissions are identified.
- Users remain responsible for reviewing all AI-generated content before use.
11. What we do not use AI for
- We do not use AI to infer personal characteristics, preferences, financial status, health information, political opinions, religious beliefs, sexual orientation, or any attribute other than a probable professional email address.
- We do not use AI to score, rank, or profile individuals in ways that affect their access to opportunities, services, or resources.
- We do not use AI to generate synthetic profiles attributed to real people, or to create content that impersonates individuals.
- We do not make solely automated decisions that produce legal or similarly significant effects for data subjects without human oversight.
- We do not use Hunter users’ contact search activity to train AI models, our own or third-party.
- We do not send special category personal data (Article 9 GDPR) to AI models. Our content filtering is specifically designed to detect and block outputs that reference such attributes.
12. Your rights in relation to AI processing
If AI systems, either Hunter’s own systems or third-party AI providers, have processed personal data about you, you have specific rights in addition to your general GDPR rights.
| AI-specific right | What it covers and how to exercise it |
|---|---|
| Right to information about AI logic (Art. 13/14 GDPR) |
You can request information about:
|
| Right to human review (Art. 22 GDPR) | If you believe an automated AI system has made a decision with legal or similarly significant effects concerning you, you have the right to: obtain human intervention in that decision; express your point of view; request an explanation of how the decision was reached; and contest the decision and request reconsideration. Contact privacy@hunter.io. |
| Right to opt out of AI features (Hunter users only) | Hunter users can: (i) turn off AI writing assistance on a per-sequence basis within each campaign; (ii) request a full account-level opt-out from all optional AI features by contacting privacy@hunter.io; (iii) request deletion of data previously processed through AI features by contacting privacy@hunter.io. |
Questions: privacy@hunter.io · Effective date: August 2026 · Version 1.0