Trust Centre

One place for everything we publish about privacy, security, and the legal terms behind HeadshotMarketing. If you are evaluating us, this is the page to send to your legal, security, or procurement team.

Compliance status

Here is exactly what is true today — no more, no less.

GDPR / CCPA posture

Published

A DPA with processing-details and subprocessor annexes, documented data-residency options, and a subject-rights request workflow are live today. See the Privacy Policy and DPA above for the full detail.

SOC 2 Type II

Target state — not yet earned

We have not engaged an accredited auditor for a SOC 2 Type II examination. This is a real gap for regulated enterprise buyers, not a certification we hold. When the attestation is earned, the report will be published here.

Policies & documentation

Each document below is the current, published version.

Privacy Policy

What personal data we collect, why we collect it, how long we keep it, and the rights you hold over it under GDPR, UK GDPR, DPDP, and US state privacy law.

Read the Privacy Policy

Terms of Service

The agreement that governs your use of HeadshotMarketing.

Read the Terms

Security

How we protect accounts and customer data: encryption, RBAC, authentication, multi-tenant isolation, and coordinated disclosure.

Review our security posture

Data Processing Addendum (DPA)

Our GDPR/CCPA-aligned processor terms, with annexes covering processing details, technical/organisational measures, and subprocessors — for customers who need a signed DPA.

View the DPA

Subprocessors

Every third party that may process customer data on our behalf, what they do, and where they operate.

See the subprocessor list

Cookies

The cookies and similar technologies we set, what each one is for, and how to change your choices.

Read the Cookie Policy

Data Residency

Customer data is stored in India by default. International transfers rely on Standard Contractual Clauses, the UK IDTA, and Swiss FDPIC-approved terms; contract-level data localisation is available on request.

Read the data residency section

Data Subject Requests

Exercise your access, correction, deletion, portability, or objection rights over your personal data by emailing our Privacy Office.

Email the Privacy Office

How we think about trust

The commitments the product is built around today.

RBAC on every operation

Every GraphQL query and mutation carries an explicit permission check, enforced at the platform gateway edge. There is no ambient "read everything" role.

Multi-tenant isolation

Every workspace’s contacts, campaigns, and assets are isolated from every other workspace by default.

Encrypted in transit and at rest

All traffic is TLS-encrypted end to end. Stored data is encrypted at rest, and the most sensitive fields (third-party OAuth credentials) use field-level encryption on top of that.

Auditable by design

Every campaign, send, and approval is recorded with the actor and timestamp, so you can reconstruct exactly who did what and when.

The principles above describe how the product is built and operated today — they are not claims to hold any third-party certification. Certification status, when it changes, will be published on this page.

Questions we haven't answered?

Security questionnaires, data processing agreements, and vendor reviews all go to the same place. Tell us what you need and we will route it to the right person.