Skip to main content
folup
Product Pricing Blog
Login Start free trial
Product Pricing Blog Login Start free trial

GDPR

Effective date: 2 September 2026

On this page

  1. 1. What This Notice Covers
  2. 2. Controller, Processor & Our Representative
  3. 3. Legal Basis, Activity by Activity
  4. 4. Candidates: Where We Got Your Data
  5. 5. Exercising Your Rights
  6. 6. Supervisory Authorities & Complaints
  7. 7. Sub-processors & Transfers
  8. 8. Data Processing Agreement
  9. 9. Security & Breach Notification

1. What This Notice Covers

This notice supplements our Privacy Policy for people in the European Economic Area, the United Kingdom, and Switzerland. It does not repeat the Privacy Policy — that document already sets out what we collect, why, who receives it, and how long we keep it, and it applies to you in full. This page adds only what the GDPR specifically requires on top.

Where folup stands. folup is a United States business and does not currently market its services in the EU or the UK. We recognise that our customers are recruiters, and that some of the candidates they contact will be located there. Where that happens we apply GDPR standards to those candidates’ data, whether or not we are strictly obliged to.

2. Controller, Processor & Our Representative

Who we are. Folup LLC, a limited liability company formed in Florida, United States, trading as folup.

When we are a controller. For your account, billing, and usage data, and for any business e-mail address folup itself locates or verifies, we decide how the data is used and we are the controller.

When we are a processor. For candidate records a customer imports from their own systems, that customer decides why and how the data is used. They are the controller and we act on their instructions. Section 2 of the Privacy Policy sets this split out in more detail.

Article 27 representative. A controller outside the EU must designate a representative inside it where Article 3(2) applies — that is, where the controller offers goods or services to people in the Union, or monitors their behaviour there. We have concluded that neither limb applies to folup, and we have not designated one. Our reasoning, so you can judge it rather than take it on trust:

  • We do not offer services to people in the EU or UK. folup is sold to United States recruiters, priced in dollars, and not marketed, advertised, or localised for any EU or UK market. Under the EDPB’s guidance, a website merely being reachable from the Union is expressly not enough to meet this limb.
  • We do not monitor behaviour in the EU or UK. folup can track whether an outreach message was opened or a link clicked, and that tracking is switched off for any recipient we have reason to believe is in the EEA or the UK. No behavioural data about them is collected, so none can be reused to make decisions about them. Detecting that someone replied is not behavioural monitoring — it is receiving mail.

We will revisit this the moment either fact changes. If we begin marketing in the EU or UK, or extend engagement tracking to people there, we will designate representatives and name them in this section before doing so. In the meantime reach us directly at hello@folup.ai, and if you think this conclusion is wrong in your case, say so — we will engage with the argument rather than stand on it.

3. Legal Basis, Activity by Activity

The GDPR requires us to identify a lawful basis for each thing we do, not one basis for everything:

  • Running your folup account — performance of a contract, Article 6(1)(b). We cannot provide the Service you subscribed to without it.
  • Taking payment — performance of a contract, Article 6(1)(b), and our legal obligation to keep tax records, Article 6(1)(c).
  • Finding and verifying a candidate’s business e-mail address — legitimate interests, Article 6(1)(f). See Section 4 for the balancing we have applied.
  • Sending outreach and detecting replies — performance of our contract with you; for the candidate receiving it, our customer’s legitimate interests in professional recruitment.
  • Drafting messages with AI — performance of a contract, Article 6(1)(b). No candidate data is used to train any model, as Section 7 of the Privacy Policy confirms.
  • Keeping accounts secure and investigating abuse — legitimate interests, Article 6(1)(f).
  • Website cookies — the cookies we set are strictly necessary to run the Service, so no consent is required for them. We run no analytics or tracking cookies at present; Section 13 of the Privacy Policy explains what would change if we did.

Where we rely on legitimate interests you have an absolute right to object, and where we rely on consent you can withdraw it at any time without giving a reason.

4. Candidates: Where We Got Your Data

If you have received a message sent through folup, you never gave us your details yourself. Article 14 entitles you to know how we got them, and here it is.

The source. Either a folup customer imported your details from their own records — a CSV they exported, their applicant-tracking system, or manual entry — or folup’s lookup feature located and verified a business e-mail address for you through specialist business contact-data providers, which compile business e-mail addresses from public and commercial sources. We can tell you which provider supplied a particular record if you ask us about your own data.

What we hold. Workplace details only: your name, a business e-mail address, your employer, your job title, and a link to a public professional profile. We do not seek out home addresses, personal e-mail accounts, or any special-category data under Article 9.

Why we think this is fair. Relying on legitimate interests requires us to weigh our interest against yours. Ours is operating a recruiting tool. Yours is not being contacted about work you did not ask to hear about. We have tried to keep that balance honest by limiting ourselves to workplace contact details, never contacting you at a personal address, putting an unsubscribe link in every message, and removing you on request without argument or delay. If you think we have the balance wrong in your case, tell us — you do not have to justify an objection.

When we tell you. Article 14 requires notice at the latest when we first contact you. Every outreach message sent through folup links to this notice, so the first time you hear from a folup user you also learn where the data came from and how to stop it.

Getting removed. E-mail hello@folup.ai. We will delete the data folup controls and add you to a suppression list so you are not looked up again. If a customer imported you, they control that copy: we will tell you who they are, pass your request on, and delete ours. Section 12 of the Privacy Policy covers this too.

5. Exercising Your Rights

Your rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent are listed in Section 11 of the Privacy Policy. This section is about the mechanics.

  • How. E-mail hello@folup.ai. There is no form to fill in.
  • How long. Within one month. If a request is genuinely complex we may extend by a further two months, and we will tell you why before the first month is up.
  • Cost. Free. We will not charge you and we will not ask you to justify the request.
  • Identity. We may ask for enough information to be confident you are who you say you are — usually just replying from the address concerned. We will not demand identity documents for a routine request.
  • If a customer is the controller. We will tell you that, name them, and forward your request, rather than leaving you to work out who to ask.
  • If we refuse. We will explain why, and tell you that you can complain to a supervisory authority or go to court.

6. Supervisory Authorities & Complaints

You can complain to a data protection authority at any time, and you do not have to raise it with us first — though e-mailing us is usually faster.

We have no lead supervisory authority. folup has no establishment in the EU, so the GDPR’s one-stop-shop mechanism does not apply to us and no single authority takes the lead. That works in your favour: complain to the authority for the country where you live or work, and it has jurisdiction. The European Data Protection Board lists every national authority. In the UK, that is the Information Commissioner’s Office.

7. Sub-processors & Transfers

folup operates from the United States, and every sub-processor below processes data there. If you are in the EEA, the UK, or Switzerland, your data will be transferred to the United States.

  • Vercel — website and application hosting (United States).
  • Stripe — payment processing (United States).
  • Anthropic — AI drafting, contractually barred from training on our data (United States).
  • Sanity — blog content management. No user or candidate data reaches it.

Transfer mechanism. We rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved. You can ask us for a copy of the relevant terms.

Changes. If we add or replace a sub-processor that handles personal data, we will update this list before the change takes effect and e-mail customers on paid plans.

8. Data Processing Agreement

Where folup acts as your processor, Article 28 requires a written agreement between us. Our Data Processing Agreement is published in full and incorporates the Standard Contractual Clauses. You do not need to sign it — it forms part of our Terms of Service and applies automatically whenever we process personal data on your behalf. If your organisation needs a countersigned copy for its records, e-mail hello@folup.ai.

9. Security & Breach Notification

Section 10 of the Privacy Policy describes the measures we take. In summary: data is encrypted in transit and at rest, mailbox connection tokens are encrypted at rest, and access to production data is limited to what is needed to run the Service.

If something goes wrong. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as Article 33 requires. Where the risk is high, we will tell affected people directly and without undue delay, and we will say plainly what happened rather than minimising it.

folup

Finds the e-mail LinkedIn won’t give you, then follows up from your own inbox.

Follow up. Get replies.

Coming soon

Product

  • Features
  • Pricing
  • How We Compare
  • FAQ
  • Chrome Extension Coming soon

Company

  • About
  • Contact
  • Blog

Legal

  • Privacy Policy
  • Terms of Service
  • GDPR
  • DPA

© 2026 Folup LLC. All rights reserved.

hello@folup.ai