Trust Centre
One place for everything we publish about privacy, security, and the legal terms behind HeadshotMarketing. If you are evaluating us, this is the page to send to your legal, security, or procurement team.
Compliance status
Here is exactly what is true today — no more, no less.
GDPR / CCPA posture
PublishedA DPA with processing-details and subprocessor annexes, documented data-residency options, and a subject-rights request workflow are live today. See the Privacy Policy and DPA above for the full detail.
SOC 2 Type II
Target state — not yet earnedWe have not engaged an accredited auditor for a SOC 2 Type II examination. This is a real gap for regulated enterprise buyers, not a certification we hold. When the attestation is earned, the report will be published here.
Policies & documentation
Each document below is the current, published version.
Privacy Policy
What personal data we collect, why we collect it, how long we keep it, and the rights you hold over it under GDPR, UK GDPR, DPDP, and US state privacy law.
Read the Privacy PolicySecurity
How we protect accounts and customer data: encryption, RBAC, authentication, multi-tenant isolation, and coordinated disclosure.
Review our security postureData Processing Addendum (DPA)
Our GDPR/CCPA-aligned processor terms, with annexes covering processing details, technical/organisational measures, and subprocessors — for customers who need a signed DPA.
View the DPASubprocessors
Every third party that may process customer data on our behalf, what they do, and where they operate.
See the subprocessor listCookies
The cookies and similar technologies we set, what each one is for, and how to change your choices.
Read the Cookie PolicyData Residency
Customer data is stored in India by default. International transfers rely on Standard Contractual Clauses, the UK IDTA, and Swiss FDPIC-approved terms; contract-level data localisation is available on request.
Read the data residency sectionData Subject Requests
Exercise your access, correction, deletion, portability, or objection rights over your personal data by emailing our Privacy Office.
Email the Privacy OfficeHow we think about trust
The commitments the product is built around today.
RBAC on every operation
Every GraphQL query and mutation carries an explicit permission check, enforced at the platform gateway edge. There is no ambient "read everything" role.
Multi-tenant isolation
Every workspace’s contacts, campaigns, and assets are isolated from every other workspace by default.
Encrypted in transit and at rest
All traffic is TLS-encrypted end to end. Stored data is encrypted at rest, and the most sensitive fields (third-party OAuth credentials) use field-level encryption on top of that.
Auditable by design
Every campaign, send, and approval is recorded with the actor and timestamp, so you can reconstruct exactly who did what and when.
The principles above describe how the product is built and operated today — they are not claims to hold any third-party certification. Certification status, when it changes, will be published on this page.
Questions we haven't answered?
Security questionnaires, data processing agreements, and vendor reviews all go to the same place. Tell us what you need and we will route it to the right person.