Submit a Data Subject Access Request (DSAR) through our Privacy Center to receive a copy of your personal information in Lusha’s database. Requests are processed within 30 days as required by law.
Your privacy comes first
All of our methods for collecting, processing, and storing data are designed to protect your personal information.
Data subject rights
Access your data
Edit your data
Right to erasure ("Right to be Forgotten")
Request deletion of your personal data through our self-serve Privacy Center. Deletion requests are processed within 30 days, and your data will be permanently removed from our systems.
CCPA consumer rights
California residents have additional rights, including:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information
- Right to non-discrimination for exercising CCPA rights
Data collection & usage
Data sources
- Lusha community: Verified business contacts shared by users
- Public records: Publicly available business information
- Third-party partners: Licensed data from compliant vendors
- Web scraping: Business information from company websites and professional networks
Data minimization
Lusha collects only business contact information necessary for B2B sales and marketing purposes. We do not collect:
- Sensitive personal information (health, financial, political)
- Consumer information (non-business contacts)
- Information about minors under 16
- Personal browsing history or behavior
Third-party vendor compliance
All data vendors must meet international privacy standards including:
- GDPR and CCPA compliance verification
- Regular vendor risk assessments
- Contractual privacy and security obligations
- Audit rights and compliance monitoring
Privacy controls & tools
Self-serve privacy center
24/7 access to submit privacy requests including:
- Data subject access requests (DSAR)
- Deletion requests
- Opt-out and suppression
- Profile verification and correction
No sales contact required. All requests are processed automatically when possible.
Do Not Call (DNC) screening
Automatic screening against major Do Not Call registries:
- US National Do Not Call Registry
- UK Telephone Preference Service (TPS)
- EU country-specific DNC lists
- Germany Do Not Call Register
Customer notification system
When a contact submits a deletion request, we automatically notify customers who have accessed that contact to ensure their CRM systems are updated for compliance.
Subprocessors & data sharing
Lusha works with carefully selected subprocessors who meet our security and privacy standards:
- Cloud infrastructure providers (AWS)
- Analytics and monitoring services
- Customer support platforms
- Payment processors
- Email service providers
The complete subprocessor list is available for download. We notify customers 30 days in advance of any new subprocessor additions.
Data retention & deletion
- Business contact data retained while relevant for B2B purposes
- Deleted data purged within 30 days from all systems
- Backup retention for disaster recovery (90 days maximum)
- Suppression list maintained permanently to honor opt-outs
- Customer usage data retained in accordance with retention policy
CCPA Compliant
GDPR Compliant
ISO 31700
SOC TYPE II