GDPR
Last updated: January 2026
Social Intents, LLC ("Social Intents", "we", "us") is committed to supporting compliance with the EU General Data Protection Regulation (GDPR) and the UK GDPR for CapyScout (the "Service"). This page summarizes our roles, your responsibilities as a customer, and how individuals can exercise their rights. It supplements our Privacy Policy.
1. Roles: controller and processor
For account and billing data of our customers, Social Intents acts as a data controller. When you submit email addresses and context to be enriched, Social Intents generally acts as a data processor on your behalf, and you are the controller responsible for having a lawful basis to process that data. For the compilation of business contact information from public and third-party sources, we may act as an independent controller.
2. Lawful basis
Processing of professional contact data through the Service typically relies on legitimate interests in providing business-to-business intelligence, balanced against the rights and freedoms of the individuals concerned. As our customer, you are responsible for ensuring you have an appropriate lawful basis for the data you submit and for the outreach or decisions you make using our results.
3. Data subject rights
Individuals in the EU, UK, and comparable jurisdictions may request to:
- Access the personal data we hold about them.
- Correct inaccurate data or complete incomplete data.
- Erase their data ("right to be forgotten").
- Restrict or object to processing, including profiling.
- Receive their data in a portable format.
To make a request, use our data request form or contact us via socialintents.com. We will respond within the timeframes required by law, typically within one month. If we processed the data on behalf of a customer, we will refer or assist that customer as controller.
4. Data processing terms
Where Social Intents processes personal data on your behalf, our processing is governed by a data processing agreement (DPA) that includes GDPR-required terms, confidentiality, security measures, sub-processor obligations, and assistance with data subject requests. Customers who require a signed DPA can request one through the contact channel above.
5. International transfers
Personal data may be transferred to and processed in the United States and other countries. Where required, we rely on appropriate safeguards, such as the European Commission's standard contractual clauses, together with supplementary measures.
6. Sub-processors
We use vetted sub-processors for hosting, enrichment, payments, and analytics. Each is bound by contractual data protection obligations. A current list of sub-processors is available on request.
7. Security and breach notification
We maintain technical and organizational measures appropriate to the risk, including encryption in transit, hashing of secrets and API keys, and access controls. In the event of a personal data breach, we will notify affected customers without undue delay as required by GDPR.
8. Contact
For GDPR requests, use our data request form. For DPAs, our list of sub-processors, or questions about our data practices, contact Social Intents, LLC via socialintents.com.