This page explains how professional contact information enters Hunter’s database, what processing steps are involved, the legal basis for that processing, and the rights that individuals have over their data. It is intended to be read alongside our Privacy Policy and our How Hunter Uses AI page.
| Data controller | Hunter Web Services Inc. |
|---|---|
| Privacy contact | privacy@hunter.io |
| EU Representative | Instant EU GDPR Representative Ltd, Office 2, 12A Lower Main Street, Lucan Co. Dublin K78 X5P8, Ireland. Email: contact@gdprlocal.com |
| UK Representative | GDPR Local Ltd., 1st Floor Front Suite, 27–29 North Street, Brighton, England BN1 1EB. Email: contact@gdprlocal.com |
| EEA supervisory authority | EEA residents may lodge complaints with the supervisory authority in their country of residence. Hunter’s EU representative is available to facilitate engagement with supervisory authorities. |
| UK supervisory authority | Information Commissioner’s Office (ICO) – ico.org.uk |
1. Data types: collected and inferred
Every email address in Hunter’s database enters through one of two distinct pathways:
Collected emails
A collected email address is one that was directly present on a publicly accessible web page at the time our automated systems crawled it. Examples of sources include company websites, press releases, academic institution pages, professional directories, and similar publicly indexed content.
What is “publicly accessible”
“Publicly accessible” means any content that can be retrieved by an automated system visiting a URL without authentication. This includes:
- Visibly rendered content: email addresses displayed on a web page as text that a human visitor can read.
- Page source code: email addresses present in the HTML source code of a page, even if not visibly displayed to a human visitor. Web page source code is publicly accessible by default; any system that can visit the page can retrieve its source. If an email address is present in the source code of a public page (for example, in a mailto: link, a contact form parameter, or metadata), it is technically publicly accessible and may be collected by our crawler.
- Linked documents: email addresses present in publicly accessible documents linked from a page, such as PDF press releases or downloadable contact sheets.
If you are a website owner and you do not want Hunter’s crawler to collect data from your pages, you can instruct our crawler not to visit your site by adding the appropriate directives to your robots.txt file. Hunter’s crawler respects robots.txt instructions. More information is available at hunter.io/robot.
Note: robots.txt instructions apply to future crawls; they do not automatically remove data already collected from your pages.
Inferred emails (labeled: inferred)
An inferred email address is algorithmically generated by our systems based on the email format pattern observed for a given company domain.
How the process works
- Step 1 – Name identification: our systems identify individuals who are publicly associated with a company, typically from company web pages, press content, or professional directory listings. We do not access private accounts or non-public sources.
- Step 2 – Pattern application: our systems analyze the email format pattern used by the company’s domain and apply it to the individual’s name to generate a probable professional email address. We only generate an address where we have sufficient data from that domain to do so reliably. If the data is insufficient, no address is generated.
- Step 3 – Verification and labeling: the generated address is verified to confirm it is technically active. If verification fails, the address is discarded. Verified addresses are added to our database with an “Inferred” label.
2. Legal basis: legitimate interests under GDPR Article 6(1)(f)
Hunter uses “legitimate interests” as its legal basis under GDPR Article 6(1)(f). This means we have assessed that our business purpose, i.e. helping companies find and contact relevant professional counterparts, is a genuine commercial need, that processing professional contact data is necessary to achieve it, and that our interest does not outweigh the privacy rights of the individuals concerned.
We have conducted a formal Legitimate Interests Assessment for our data collection and inference activities. A summary is available on request at privacy@hunter.io. Full assessments are available to supervisory authorities upon request. In brief:
- Our legitimate interest is enabling B2B professionals to identify relevant business contacts.
- We collect and process only professional contact data from public sources, and only for legitimate B2B outreach purposes.
- We apply additional restrictions to inference, including exclusions for sensitive domain categories and a requirement for sufficient domain data, to ensure the processing remains proportionate.
- Where an individual objects to our processing, we act promptly. In the majority of cases, we will erase and suppress the data rather than seek to maintain it.
3. Restrictions on inference: excluded categories
We apply restrictions to the inference process that do not apply to the collection of publicly available addresses. We do not generate inferred email addresses for individuals or domains in the following categories:
- Previously opted-out individuals: the suppression list is checked before any inference is generated. Suppression blocks re-generation as well as re-collection; the address cannot re-enter our database through either pathway.
- Sensitive category domains under Article 9 GDPR: our systems utilize a curated exclusion list to prevent the generation of inferred addresses for organizations where domain membership might disclose protected characteristics. This framework is primarily focused on EU-based entities and encompasses five high-protection categories: religious organizations, political entities, trade unions, recovery or identity-centric patient groups, and LGBTQ+ identity associations.
- Low-confidence domains: domains where the observed email pattern is insufficiently consistent to generate a reliable inference. Inference is only applied where the pattern confidence score meets our minimum threshold.
- Explicit boundaries: our inference process is limited to email addresses on corporate domains. We do not infer or provide personal email addresses (e.g. on gmail.com, outlook.com, or similar consumer domains), home addresses, personal phone numbers, or any other attribute outside the professional contact sphere. These categories are excluded from our processing entirely.
4. Data accuracy and source disputes
We are committed to holding accurate data and to being honest when our records are uncertain or incomplete. If you believe that data held about you in our database is inaccurate, you have the right to rectification under Article 16 GDPR. We will investigate the specific record, including checking the claimed source URL against archived versions of the relevant page.
5. Retention and storage
We do not retain contact records indefinitely. The following controls apply:
- Re-verification: all records are subject to periodic re-verification on a rolling basis. Records failing re-verification are reviewed for removal.
- Data retention: we retain data for as long as the information, or the underlying name for inferred emails, is available on publicly accessible sources. When a source page is no longer accessible and we cannot verify the information from another public source, we review and remove the record. We process these removals on a rolling basis.
- Source delisting: for collected emails, where the source page is no longer publicly accessible and the address cannot be re-verified from another verified public source, the record is reviewed for removal.
6. What we do not do
- We do not expose contact data in public search engine results or on publicly indexable pages.
- We do not process professional email addresses for consumer advertising, behavioral profiling, or tracking purposes.
- We do not re-add suppressed addresses. Once your address is on our suppression list, through opt-out, erasure, or objection, it cannot re-enter our database through either collection or inference.
- We do not permit our platform to be used for bulk unsolicited commercial email. This is a condition of our Terms of Service and is enforced through account monitoring and suspension.
- We do not infer email addresses for individuals in excluded categories, as set out in Section 3.
7. Your rights
As an individual whose data may be held in Hunter’s database, you have the following rights under GDPR. All rights requests are processed within one calendar month.
| Your right | What it means and how to exercise it |
|---|---|
| Access (Art. 15) | Receive confirmation of whether we hold data about you, what data we hold, its source, the legal basis, retention period, and categories of recipients. Submit a request at hunter.io/claim or email privacy@hunter.io. |
| Erasure (Art. 17) | Permanent deletion of your data. We remove the record and add your address to our suppression list, blocking both re-collection and re-generation. Submit at hunter.io/claim. |
| Objection (Art. 21) | Object to our processing of your data where it is based on legitimate interests. If you object, we will assess whether our interests are overridden by yours. Where they are, we will stop processing and erase and suppress your data. Submit your objection at hunter.io/claim or email privacy@hunter.io. |
| Rectification (Art. 16) | Request correction of inaccurate data, including disputed source attribution. Email privacy@hunter.io with the details of the inaccuracy. |
| Restriction (Art. 18) | Request that we restrict (but not delete) processing while a dispute or objection is being assessed. |
| Supervisory authority complaint (Art. 77) | EEA residents: lodge a complaint with CNIL (France) as our lead supervisory authority, or your national data protection authority. UK residents: lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk. US residents: contact your state Attorney General. |
Questions: privacy@hunter.io · Effective date: May 2026 · Version 1.0