Data Sources and Subprocessors

Where Cleanlist’s business contact data comes from, and who processes data on our behalf to run the service. Referenced by the Privacy Policy and by section 6 of the DPA.

Last Modified: September 6, 2026

Contracted business data providers

These are the providers Cleanlist holds a direct contract with. A lookup walks them in cost order and stops at the first accepted answer, which is what the waterfall is.

ProviderData supplied
AnymailfinderWork email lookup
CrustdataPerson and company records, firmographics
DatagmaWork email, direct dial
EmailableEmail verification: syntax, DNS and mailbox checks
FindymailWork email, profile URL resolution
HunterWork email, domain search
IcypeasWork email lookup
LeadMagicWork email, direct dial, mobile
ProspeoWork email, direct dial
WizaPerson records, work email, direct dial

On the “25+ providers” figure used elsewhere on this site. Both numbers are true and they count different things. Cleanlist holds direct contracts with the ten above. Several of those providers are themselves aggregators that resolve a lookup across their own upstream sources, so a single Cleanlist request can reach more than 25 distinct data sources in total. The nine are who we contract with and who we hold to the representations below. The 25+ is the reach of the waterfall.

Processing regions are not listed per row. Where a transfer leaves the European Economic Area or the United Kingdom it is covered by section 7 of the DPA, and the current region for a named vendor is available on request.

Cleanlist requires each provider to represent that it holds the rights and lawful bases needed to supply the data, that it gives any legally required notice, that it supports individual rights, and that it honours applicable suppression requirements. Cleanlist does not operate a web crawler and does not build its own contact database by copying web pages.

Subprocessors

These vendors process data on Cleanlist’s behalf to operate the service. Each is under contract with data protection obligations no less protective than those in our DPA, and each processes only for the purpose named.

SubprocessorPurpose
RailwayApplication hosting for the Cleanlist API
VercelMarketing site hosting and delivery
NeonManaged Postgres database
Azure Blob StorageFile, import and export storage
Temporal CloudWorkflow orchestration for enrichment jobs
ClerkAuthentication and session management
StripePayment processing and billing
ResendTransactional and lifecycle email delivery
BrevoBulk marketing email
IntercomCustomer support messaging and help centre
PostHogProduct analytics
SentryError monitoring and diagnostics
AttioCleanlist's own CRM, holding account and prospect records
OpenAIAI features a customer enables. Contractually barred from training on the content.
AnthropicAI features a customer enables. Contractually barred from training on the content.

Changes and notice

Cleanlist reconciles this page against the providers and vendors actually in production every quarter, and whenever one is added or removed. Under section 6 of the DPA, customers receive notice before a new subprocessor begins processing Customer Data, and may object on reasonable data protection grounds.

To be notified of changes, or to ask a question about a specific provider, write to support@cleanlist.ai.

If your details are in here

If your business contact details appear in Cleanlist and you want to know what we hold, correct it, have it deleted, or object to the processing, you do not need an account and you do not need to contact any of the providers above first. Write to support@cleanlist.ai. The Individual Rights and Suppression sections of the Privacy Policy explain what happens next.

Ask about any of these.

Questions about a provider, a subprocessor, or a transfer mechanism go to the privacy address and get a real answer.