Source
Privacy policy — Lusha
Checked for Lusha on 22 Sep 2026
- Page
- https://www.lusha.com/legal/privacy-notice/
- Checked
- 22 Sep 2026, 06:56 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:ab3b6844a8e06437ee86144d61a761dfc3f5356361643c28961ee06293ee13bc
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Entity Report an error
“Lusha Systems Inc. is an incorporated company established in Delaware, with its registered office at 800 Boylston Street, Suite 1410, Boston, MA 02199 USA.”
-
Scope Report an error
“Lusha helps business customers (e.g. HR professionals, B2B professionals, sales professionals) validate, verify and find business contact information of relevant Contacts (as defined below) retained in Lusha’s B2B database (“Lusha B2B Database”, and “Services”).”
-
No sensitive data Report an error
“Lusha only collects Data to the extent necessary for the Services and does not collect sensitive data related to health, religious beliefs, political opinions, or ethnicity.”
-
ISO 27701 Report an error
“Lusha’s privacy practices are audited on a yearly basis by an independent third party and maintains ISO 27701 certification.”
-
DPA Report an error
“All processing activities on behalf of our Licensees are conducted in a lawful and secure manner, pursuant to Lusha’s Data Processing Addendum (“DPA”).”
-
Sources Report an error
“Our Community Program: Our community members may share Data of their professional business network with us, such as information found in their CRM database, email headers, email subjects, calendar meeting information such as meeting participants, meeting description, subject, and date and time of the meeting, which can include information about Contacts .”
-
Public sources Report an error
“Publicly available sources: We source the categories of data listed in section “3.1 Data about Contacts” from trusted data brokers and also use publicly available APIs to collect data from publicly available sources.”
-
Browser extension linkedin Report an error
“When an End User uses our browser extension while using LinkedIn, we read the minimum Data presented on the LinkedIn profile pages that the End User is browsing for providing the Service”
-
Auto complete email patterns Report an error
“Our proprietary algorithm scans publicly available sources and retrieves public information to understand standard corporate email patterns”
-
Integrations Report an error
“As part of the Services, Licensees may integrate Lusha with certain platforms (“Integrations”). When using Lusha’s Integrations, Data from Licensee’s CRM tools, email, browser extension (such as Chrome add-on) or other software will be transmitted to Lusha”
-
Stripe Report an error
“For End Users and Licensees that pay for the Services by credit cards, our service provider Stripe Inc. processes your payment information, while Lusha does not have direct access to it.”
-
No automated decision making Report an error
“Lusha does not use personal data for automated decision-making processes.”
-
Google limited use Report an error
“Lusha’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.”
-
Microsoft policy Report an error
“Further, Lusha’s use of the Microsoft API is subject to Microsoft’s privacy policies”
-
Transfer countries Report an error
“We may share information with third parties in the ways and for the purposes described above, including to overseas recipients, located in countries including the United States, the United Kingdom, Australia and Israel.”
-
Categories Report an error
“Such service providers include (i) hosting services providers, (ii) data analytics providers, (iii) payment processors, and (iv) security services providers.”
-
List published Report an error
“A full list of sub-processors, including their purpose, locations, and transfer method can be found here.”
-
Joint controllers social Report an error
“When you join Lusha’s Facebook group or fan page, Facebook and Lusha act as joint controllers. When you visit our LinkedIn Page, LinkedIn and Lusha act as joint controllers.”
-
Retention end users Report an error
“We retain your Data for the duration of your active account on Lusha. We may keep your Data for 3 years following the last activity in your account in order to comply with our legal and contractual obligations”
-
Deletion standard Report an error
“Lusha takes the appropriate and adequate measures to de-identify and/or dispose of all and any Data in a secure, timely, and lawful manner, in accordance with NIST 800-88 guidelines for media sanitization.”
-
Suppression list Report an error
“Note that we maintain a suppression list which may include personal data, for the sole purpose of ensuring that opt-out requests are respected and that your contact information no longer appears in the Lusha B2B Database in the future if you have opted-out.”
-
Subject rights Report an error
“Information and access to a copy of your Data: you may obtain confirmation as to whether or not your Data is processed by Lusha. As applicable you may get more information on the Data we hold and how your Data is processed, and get a copy of your Data.”
-
Public servants excluded Report an error
“so we have implemented measures to exclude contacts whom we determine are public servants or otherwise public figures”
-
Min age Report an error
“The products and services of Lusha are not targeted to or intended for children under the age of 18.”
-
Provider Report an error
“We are headquartered in the United States of America, and while our data is stored on Amazon Web Services in the United States of America, many of our data processing activities are carried out in other countries.”
-
EU UK transfer safeguards Report an error
“we make available appropriate safeguards such as the Standard Contractual Clauses approved by the European Commission or the United Kingdom International Data Transfer Agreement or Addendum (as applicable)”
-
Israel adequacy Report an error
“certain Lusha processing operations involve our affiliate Lusha Systems Ltd. and some of our staff are located in Israel, where there is an adequate level of protection of personal data according to the European Commission”
-
CCPA Report an error
“addresses the requirements under the California Consumer Privacy Act of 2018 (Cal. Civ. §§ 1789.100–1798.199) and the California Consumer Privacy Act Regulations by the Attorney General (the “CCPA“).”
-
Data sale disclosure Report an error
“In the preceding 12 months, we have sold the categories of personal data about Contacts identified in Section 3 above to our Licensees, who access this data through the Lusha B2B Database, in exchange for valuable consideration.”
-
Ad sharing Report an error
“In the preceding 12 months, we have shared the following categories of personal data for cross-context behavioral advertising purposes, through the use of advertising cookies and similar technologies on our website: identifiers (such as cookie identifiers and device identifiers), IP address, and internet or network activity information”
-
Gpc supported Report an error
“If you enable GPC in a supported browser or browser extension, we will treat that signal as a valid request to opt-out of the sale and sharing of personal information associated with that browser or device.”
-
Toll free line Report an error
“Call us toll-free at 1-866-I-OPT-OUT (1-866-467-8688) / Service Code 2001#”
-
Request volume 2024 Report an error
“Requests to know 7 7 0 < 1 day Requests to delete/opt-out 1119 1119 0 < 4 days Requests via email 10411 10411 0 < 15 days”
-
Entities joint controllers Report an error
“Lusha Systems Inc. and Lusha Systems Ltd. (a company incorporated in Israel with registered address at 132 Derech Menachem Begin,Tel Aviv 6701101) are joint controllers of your Data.”
-
AI recommendations Report an error
“including AI recommendations based on won deals and companies listed in the Licensees CRM”
-
No sale of licensee data Report an error
“We do not sell any Data or information shared with us by our paying Licensees unless they decide to join our Community Program.”
-
Copy request limit Report an error
“You may only request a copy of your data twice within a 12-month period.”
-
Google workspace email scanning Report an error
“When a Licensee connects their email account or calendar as an Integration, Lusha may scan and/or extract business contact details from the related contact lists and or meeting metadata”
2 facts read from this page are not shown because they could not be confirmed on the page as captured.
Scores citing this record
- The ABM Marketer Data sources & lawful basis
- The ABM Marketer Prospecting workflow & outreach rules
- The ABM Marketer European sovereignty
- The DACH Sales Director Data sources & lawful basis
- The DACH Sales Director European sovereignty
- The Data Protection Officer Data sources & lawful basis
- The Data Protection Officer European sovereignty
- The RevOps Manager Data sources & lawful basis
- The RevOps Manager Prospecting workflow & outreach rules
- The RevOps Manager European sovereignty
- The SDR Team Lead Coverage, accuracy & freshness
- The SDR Team Lead Data sources & lawful basis
- The SDR Team Lead Prospecting workflow & outreach rules
- The SDR Team Lead European sovereignty
- The Skeptic Data sources & lawful basis
- The Skeptic Prospecting workflow & outreach rules
- The Skeptic European sovereignty