Data Sources and Subprocessors
Where Cleanlist’s business contact data comes from, and who processes data on our behalf to run the service. Referenced by the Privacy Policy and by section 6 of the DPA.
Last Modified: September 6, 2026
Contracted business data providers
These are the providers Cleanlist holds a direct contract with. A lookup walks them in cost order and stops at the first accepted answer, which is what the waterfall is.
| Provider | Data supplied |
|---|---|
| Anymailfinder | Work email lookup |
| Crustdata | Person and company records, firmographics |
| Datagma | Work email, direct dial |
| Emailable | Email verification: syntax, DNS and mailbox checks |
| Findymail | Work email, profile URL resolution |
| Hunter | Work email, domain search |
| Icypeas | Work email lookup |
| LeadMagic | Work email, direct dial, mobile |
| Prospeo | Work email, direct dial |
| Wiza | Person records, work email, direct dial |
On the “25+ providers” figure used elsewhere on this site. Both numbers are true and they count different things. Cleanlist holds direct contracts with the ten above. Several of those providers are themselves aggregators that resolve a lookup across their own upstream sources, so a single Cleanlist request can reach more than 25 distinct data sources in total. The nine are who we contract with and who we hold to the representations below. The 25+ is the reach of the waterfall.
Processing regions are not listed per row. Where a transfer leaves the European Economic Area or the United Kingdom it is covered by section 7 of the DPA, and the current region for a named vendor is available on request.
Cleanlist requires each provider to represent that it holds the rights and lawful bases needed to supply the data, that it gives any legally required notice, that it supports individual rights, and that it honours applicable suppression requirements. Cleanlist does not operate a web crawler and does not build its own contact database by copying web pages.
Subprocessors
These vendors process data on Cleanlist’s behalf to operate the service. Each is under contract with data protection obligations no less protective than those in our DPA, and each processes only for the purpose named.
| Subprocessor | Purpose |
|---|---|
| Railway | Application hosting for the Cleanlist API |
| Vercel | Marketing site hosting and delivery |
| Neon | Managed Postgres database |
| Azure Blob Storage | File, import and export storage |
| Temporal Cloud | Workflow orchestration for enrichment jobs |
| Clerk | Authentication and session management |
| Stripe | Payment processing and billing |
| Resend | Transactional and lifecycle email delivery |
| Brevo | Bulk marketing email |
| Intercom | Customer support messaging and help centre |
| PostHog | Product analytics |
| Sentry | Error monitoring and diagnostics |
| Attio | Cleanlist's own CRM, holding account and prospect records |
| OpenAI | AI features a customer enables. Contractually barred from training on the content. |
| Anthropic | AI features a customer enables. Contractually barred from training on the content. |
Changes and notice
Cleanlist reconciles this page against the providers and vendors actually in production every quarter, and whenever one is added or removed. Under section 6 of the DPA, customers receive notice before a new subprocessor begins processing Customer Data, and may object on reasonable data protection grounds.
To be notified of changes, or to ask a question about a specific provider, write to support@cleanlist.ai.
If your details are in here
If your business contact details appear in Cleanlist and you want to know what we hold, correct it, have it deleted, or object to the processing, you do not need an account and you do not need to contact any of the providers above first. Write to support@cleanlist.ai. The Individual Rights and Suppression sections of the Privacy Policy explain what happens next.
Ask about any of these.
Questions about a provider, a subprocessor, or a transfer mechanism go to the privacy address and get a real answer.