Privacy
RampedUp Privacy Center
RampedUp provides business-to-business information services using professional and company information. Our privacy program is designed to support responsible use of business contact data, data accuracy, transparency, and meaningful privacy rights. Where the GDPR applies to a particular processing activity, RampedUp relies principally on legitimate interests under Article 6(1)(f), subject to the safeguards described below.
Find the privacy law that applies to you
Pick a jurisdiction and we will show the principal comprehensive privacy law that applies there, the framework RampedUp works under for it, and the statutory text on publicly available information where one is on file. 194 countries, plus every US state and the District of Columbia.
Jurisdiction lookup
245 jurisdictions · 51 US states and DC · 194 countries
- Framework
- Principal comprehensive / general privacy law(s)
- On publicly available information
Select a country to see the law that applies. Choosing United States adds a second menu for the state.
What this is. It names the principal comprehensive privacy law for the jurisdiction you pick and, where we hold it, the statutory language on publicly available information. It is not legal advice, and a jurisdiction may have sectoral laws beyond the one named here.
Privacy laws, one page each
What each framework gives you, and how a request is handled under it.
Data Privacy Framework
Our U.S. Department of Commerce certification, DPF ID 7816, what we use the data for and what we do not.
GDPR
Articles 14.2(f), 15.1 and 15.3: the source of the data, the categories we hold, who it is disclosed to, and how to exercise your rights.
CCPA
California residents: our broker registration, the public-data exclusion, DROP, and non-discrimination.
The nature of the data we process
RampedUp focuses on professional and business contact information used in B2B contexts. Typical data elements may include an individual’s name, job title, employer, business contact details, professional profile information, and related company information.
The information is generally derived from publicly accessible professional and business sources, including company websites, press releases, professional directories, public business records, and other sources where individuals or organizations have made professional information available.
All data subjects are professionals, and the use of their contact data is restricted to business purposes. The privacy impact is minimal, and the interests of both RampedUp and its clients (e.g., promoting products/services) are legitimate and reasonable. We do not intentionally collect special-category data or information about minors.
Legitimate business interest impact assessment
RampedUp evaluates legitimate-interest processing using the established three-part framework: identifying a legitimate interest, assessing whether the processing is necessary for that interest, and balancing that interest against the rights, freedoms, and reasonable expectations of the individual.
Several characteristics of RampedUp’s processing are relevant to that balance: the information is professional rather than private in nature; it is typically made publicly available in a business context; its use is limited to business-information purposes; and individuals are provided mechanisms to access, correct, or request removal of information.
Data Processing Addendum (DPA)
RampedUp’s Data Processing Addendum sets out how we handle personal data when providing its services to Subscribers. It clarifies two roles:
- RampedUp Data
- RampedUp’s global B2B contact and company data. RampedUp and the Subscriber act as independent Controllers.
- Subscriber Personal Data
- Data that the Subscriber uploads or sends for enrichment, appending, or other processing. The Subscriber is the Controller/Business and RampedUp acts as a Processor/Service Provider.
The DPA outlines how RampedUp aligns with GDPR, CCPA, and other privacy laws while clearly allocating responsibilities between RampedUp and the Subscriber for compliance, security, and individual privacy rights.
The current Data Processing Addendum was last updated . It runs to 21 pages and includes Schedules 1 and 2, the Standard Contractual Clauses governing cross-border transfers of European Personal Data.
Download the DPA — PDF, 21 pages Read the Purpose statement / DPA
Data Privacy Framework and international transfers
RampedUp is an active participant in the Data Privacy Framework (DPF) program, which is administered by the International Trade Administration (ITA) within the U.S. Department of Commerce.
RampedUp evaluates cross-border transfer obligations separately from the question of whether a particular processing activity falls within GDPR territorial scope. Where an applicable transfer mechanism or contractual safeguard is required, RampedUp’s privacy and contractual processes are intended to support the relevant transfer requirements.
The DPF Program enables eligible U.S.-based organizations to certify their compliance pursuant to the EU-U.S. DPF and, as applicable, the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. DPF. Our certification can be found on their website here.
Cookies and website visitors
This section is about visitors to rampedup.ai, which is a different thing from the contact data described above. Nothing here loads, and no cookie below is set, until you accept them on the banner — declining leaves nothing to clean up, because nothing ran.
| Cookie | Set by | What it is for | Retention |
|---|---|---|---|
| vv_visitor_id | Website visitor analytics | A first-party identifier that recognises a returning browser. | 30 days |
| vv_sess_id | Website visitor analytics | Groups the pages viewed in a single visit. | Session |
| vvPD | Website visitor analytics | Holds the page data collected during the visit. | 30 days |
| vv_cookieconsent_status | Website visitor analytics | Records the consent state the analytics script reads before it runs. | 30 days |
| hubspotutk, __hstc, __hssc, __hssrc | HubSpot | Associates a form submission or a live chat conversation with the same visitor, so a reply goes to the right thread. | Per HubSpot’s cookie policy |
| Third-party cookies | Datarade | Set by datarade.ai when the review-rating widget in the footer loads. | Per Datarade’s cookie policy |
The website visitor analytics script is served from fe.sitedataprocessing.com. When it runs it sends the page address, page title, query string, referring anchor, screen resolution, the time of the request and the two identifiers above to that provider. It does not read anything you type into a form.
HubSpot is a sub-processor and is covered by the Data Processing Addendum. Its cookies are set when you load a page carrying a form or the chat widget.
Changing your mind. Use Cookie settings at the foot of any page to reopen the banner. Declining stops anything further from loading; cookies already set are cleared by removing rampedup.ai site data in your browser, which we cannot do on your behalf.
Do not sell — Subject Access Request portal
RampedUp is registered with several states within the United States as a data broker.
| Jurisdiction | Registration number | Registry |
|---|---|---|
| California | 538248 | California Privacy Protection Agency (CPPA) Data Broker Registry |
| Oregon | 00344 | Oregon Department of Consumer and Business Services, Division of Financial Regulation |
| Texas | 20250186 | Texas Secretary of State |
| Vermont | 0409326 | Vermont Secretary of State |
In compliance with the laws of California, Texas, Vermont, and Oregon, the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, RampedUp commits to provide, correct, limit, or eliminate data associated with Individuals or Organizations by completing the Subject Access Request form.
Open the Subject Access Request portal
Security controls, retention and deletion, breach handling and the registry detail behind these numbers are on the data security page.
