Trust & Compliance

EU data residency, GDPR-native, no U.S. transfer.

Built and operated from the French Alps. Every prospect record, email, and reply stays in the EU — under GDPR, with the legal, technical, and organizational controls your security team asks about on day one.

Our security posture

Common questions

The 6 questions EU security teams ask before signing

Is your data really EU-only, or is it backhauled to the U.S.?

Yes, EU-only. Database in Frankfurt. Application servers in Frankfurt and Paris. No copies leave the EU.

What’s your GDPR lawful basis for processing prospect data?

Legitimate interest under Art. 6(1)(f) for B2B outreach; consent for any marketing-class activity. DPA available on request; we publish a sub-processor register.

Are you SOC 2 certified?

Our controls are mapped to SOC 2 Type 1 and we are actively working toward an audit report. We are not yet certified — we don’t claim to be.

What happens to my data if I cancel?

Account data is deleted within 30 days per our privacy policy; we can provide a deletion certificate on request.

Can a Lanceva employee read my prospect list or my emails?

Only authorized on-call engineers via a short-lived, audited break-glass workflow. MFA required; sessions are logged.

Where do my emails actually land — through your infrastructure or a third party?

Outbound mail goes through the Polsia email proxy (EU-resident). We do not relay through U.S.-based ESPs.

Start Free Trial →