Skip to content
TruePointTruePointData

Trust

How we source data, and what we refuse to collect.

Every field we store is attributable to a class of source. This page says which sources those are, what falls outside our scope entirely, and how to get your own record removed.

Where our data comes from

Every field we store is tagged with the class of source it came from. A field we cannot attribute does not enter the graph at all — not as an unattributed value, not as a best guess.

  • Public web pages: company sites, career pages and public job postings, crawled directly, respecting robots.txt and rate-limited to be a polite visitor.
  • Public and official registries, filings and announcements.
  • Licensed data from vendors, under the terms of those licences.
  • Corrections and confirmations contributed by TruePoint users about records they are already working with — always on an explicit, revocable opt-in, always logged against the contribution.
  • Verification signals: whether an address we published actually delivered.

What we never collect

The scope is business-contact data: who someone is at work, what they do there, and how to reach them there. Everything outside that is out of scope by design rather than by omission.

  • No special-category data, ever — health, beliefs, politics, sexuality, biometrics, trade-union membership.
  • No personal-life data: home addresses, personal social accounts, family details.
  • No data about minors.
  • No message content. Where a customer connects a mailbox or a dialer, we take structured outcome metadata — whether a message bounced, whether a call connected — and never the contents.

If your data is in here

You can ask what we hold about you, correct it, or have it removed. You do not need an account, and you do not need to be a customer.

  • Write to privacy@truepoint.in from any address, and say which record is yours.
  • Removal is a suppression, not a hide. A suppressed person stops being returned by search, by enrichment and by exports — there is no flag any customer can set to get them back.
  • Suppression propagates across the graph and into future deliveries. Files already delivered to a customer are outside our reach, which is why suppression at our egress is the control that matters.

What customers get in writing

  • A data processing agreement and a current sub-processor list.
  • Per-field provenance in the API response itself, so an audit does not depend on us answering an email.
  • Deletion confirmation covering the data we hold, on request.