Lead Generation
Kaspr
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by KASPR SAS · www.kaspr.io
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Kaspr is a lead-generation contact database from KASPR SAS of Paris, collected through a LinkedIn browser extension users must synchronise with LinkedIn. Strongest is pricing transparency, at 6 to 7: Free at €0, Starter at €59 and Business at €99 per user per month are public with credit allowances per data type, export limits, VAT treatment and notice periods. Data provenance scores 4, with sources named — LinkedIn, Whois, GitHub, data partners — plus a Personal Data Charter and opt-out form. Weakest is visitor identification at 1: the only trace is an 'Intent data' line in the Enterprise feature list. Data coverage holds at 3 on headline counts alone — 500m+ phone numbers and email addresses, 200m+ profiles — and credits are neither refundable nor exchangeable. Sovereignty scores spread from 4 to 6 and prospecting compliance from 1 to 2: judges crediting the Paris controller, published subprocessors and Standard Contractual Clauses scored against those weighing US processors in the chain and residency pledged only 'as far as possible' within UK/EU/EEA — a range the bench logged without flagging a genuine disagreement.
Speaks for it
- Published prices for every tier from Free €0 to Starter €59 and Business €99 per user per month, with credit allowances per data type, export limits, VAT treatment and notice periods
- Database sources named — LinkedIn, Whois, GitHub and data partners — with a Personal Data Charter, an opt-out form and a one-month rights-response commitment
- Paths out of the tool via transfer to compatible CRMs, CSV enrichment, Zapier, dialers and Salesforce enrichment at Enterprise
- A named controller, KASPR SAS, a simplified joint-stock company registered with the RCS of Paris, publishing subprocessors and citing Standard Contractual Clauses for providers outside the UK/EU/EEA
- A free tier with no credit card required, carrying 15 B2B email credits, 5 phone credits and 5 direct email credits per month
Held against it
- Visitor identification sits at 1, its only public trace being the two-word 'Intent data' line in the Enterprise feature list
- Coverage rests on headline counts — 500m+ phone numbers and email addresses, 200m+ profiles — and we found no public information on per-country or DACH coverage, verification method or refresh cadence
- Credits are neither refundable nor exchangeable, expire at the end of the subscription period with the captured pages giving different figures on roll-over, and 'unlimited' is capped at 10,000 credits per account per month in the terms
- Termination permanently deletes the workspace with all contacts and credits, user-transmitted data becomes and remains KASPR's property even after account deletion, and we found no plain statement on keeping exported contacts after cancellation
- We found no public information on the lawful basis for database records, a suppression or do-not-contact list, or cold-outreach guidance for EU markets
Best for
- You want to test B2B contact enrichment before spending — the Free tier is €0 per user per month with no credit card required
- You buy on published, predictable pricing — per-user tier prices, credit allowances by data type and annual export limits are public from Free to Business
- Your team prospects through LinkedIn and needs contact data pushed onward to a compatible CRM, via Zapier, CSV or dialers
Avoid if
- You need website-visitor identification or in-market intent signals — ask the vendor: the public pages we read do not show it
- You must document lawful basis and outreach compliance up front — beyond a 'GDPR aligned' badge, we found no public information on suppression lists, do-not-call checking or cold-outreach guidance for EU markets
- You need country-level coverage certainty — DACH or EU — before committing, since only headline counts are public and credits are neither refundable nor exchangeable
- You need to keep your data after cancellation — termination permanently deletes the workspace and user-transmitted data remains the vendor's property
The scores
Coverage, accuracy & freshness
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
The only coverage figures are headline counts — 500m+ phone numbers and email addresses and 200m+ profiles — with no country, region or industry breakdown, so I cannot tell what a DACH or EU pipeline would actually look like. We found no public information on a verification method or refresh cadence behind the word "verified", and no bounce or credit-back terms. 1 2
The RevOps Manager
Five hundred million plus phone numbers and emails and 200m+ profiles are headline counts and nothing more; we found no public information on country-level coverage, verification method or refresh cadence — the policy fixes profile retention at five years from initial collection with no word on re-verification — and the terms state credits are 'neither refundable nor exchangeable', so bad data stays the buyer's cost. 1 3 4
The Data Protection Officer
The pages give headline figures only — 500m+ phone numbers and email addresses and 200m+ profiles described as verified and compliant, with nothing behind the word verified. We found no public information on per-country or DACH coverage, a verification method, a refresh cadence, or a bounce guarantee. 1
The ABM Marketer
The homepage's headline counts — 500m+ verified phone numbers and email addresses, 200m+ profiles — are all the pages give, with a G2 star rating standing in for accuracy evidence. We found no public information on per-country or DACH coverage, a verification method, or a refresh cadence, and the terms state credits are neither refundable nor exchangeable, so there is no credit-back for bad data. 1
The DACH Sales Director
Headline numbers only — "500m+ verified and compliant phone numbers and email addresses" and "over 200m+ profiles" — and we found no public country breakdown, so I cannot tell a Mittelstand prospect what this actually covers in Germany, Austria or Switzerland. We found no public information on verification method or refresh cadence, and the sources named are social networks and directories (LinkedIn, Whois, GitHub, data partners) rather than official registers. 1 3
The Skeptic
Headline counts only — "500m+ verified and compliant phone numbers and email addresses" and "200m+ profiles" on the homepage, with "verified" asserted and nothing behind it. We found no public information on per-country coverage, a DACH or European breakdown, how records are verified, or any refresh cadence; and the terms state credits are "neither refundable nor exchangeable", so an inaccurate record is the buyer's cost, not the vendor's. 1 4
Data sources & lawful basis
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
Source categories are named — LinkedIn, Whois, GitHub and data partners — and there is a Personal Data Charter, an opt-out form and a one-month response commitment, which is more than most vendors show. But we found no public information on the legal basis for EU records, no balancing, and no Art. 14 notification practice, so the homepage's "GDPR aligned" badge stands on its own. 3 4 1
The RevOps Manager
Sources are named — LinkedIn, Whois, GitHub, data partners — and the LinkedIn browser extension is disclosed as integral to the product, with an opt-out form from sharing with customers and a Personal Data Charter for the people in the database. But we found no public information on the legal basis claimed for those records, any balancing test behind it, or whether people are notified when they are added. 3 4 1
The Data Protection Officer
Sources are named concretely — LinkedIn, Whois, GitHub and data partners — alongside a Personal Data Charter, an opt-out form stopping sharing with customers, and a one-month rights response, with collection running through a LinkedIn browser extension users must install. We found no public statement of the legal basis for the database records, no Art. 14 notification practice, and no balancing test. 1 2 3 4
The ABM Marketer
The privacy policy names its source categories — social networks such as LinkedIn, Whois, GitHub and data partners — and backs them with a Personal Data Charter, an opt-out form for people in the database and a named controller, KASPR SAS. We found no public information on the lawful basis or any balancing test for those records, and while the terms make a LinkedIn-syncing browser extension integral to the product, the pages leave its contribution to the database undescribed. 3 4 1
The DACH Sales Director
Sources are named more concretely than usual — LinkedIn, Whois, GitHub and data partners — and the people listed get a Personal Data Charter, an opt-out form, a privacy contact, multilingual policy and a one-month response commitment. But we found no public information on the legal basis claimed for the database records, on any balancing, or on notifying people when they are added, and the homepage "GDPR aligned" badge sits there without explanation. 3 1
The Skeptic
The privacy notice does name its sources plainly — LinkedIn, Whois, GitHub and data partners — and there is a Personal Data Charter, an opt-out form for people in the database, and a one-month response commitment. But we found no public information on the lawful basis for holding those records, no legitimate-interest assessment, and no practice of notifying people when they are added; collection runs through a browser extension that members must synchronise with their LinkedIn account, disclosed as a mechanism with no balancing shown. 2 3 4
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
The only trace of intent is a two-word "Intent data" row on the Enterprise plan, with nothing on what it is or how it is sourced. We found no public information on website visitor identification, the level at which visitors are identified, or any consent position for a tracking script. 2
The RevOps Manager
The only trace of intent anywhere is the phrase 'Intent data' in the Enterprise feature list; we found no public information on website visitor identification, how any intent signal is collected, or the product's consent position for tracking. 2
The Data Protection Officer
The only public trace of anything in this area is Intent data listed as an Enterprise feature line. We found no public information on company- or person-level visitor identification, any tracking script, or a position on consent under the TDDDG. 2
The ABM Marketer
The only trace of buying intent anywhere is the two words "Intent data" on the Enterprise feature list, with no source, method or alerting described; we found no public information on website visitor identification, any tracking script, or a consent position for one. For an account-based motion this is a contact database, not an in-market signal I can act on while it is warm. 2
The DACH Sales Director
The only trace is an "Intent data" line in the Enterprise feature list, with no method, source or consent position behind it. We found no public information on website-visitor identification, on any tracking script, or on how the vendor treats consent for such tracking under German telecom-privacy rules. 2
The Skeptic
The single trace is the phrase "Intent data" in the Enterprise feature list — no source, method or consent position captured with it. We found no public information on website-visitor identification, on how any intent signal is generated, or on any position regarding consent for tracking scripts. 2
Prospecting workflow & outreach rules
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
What is evidenced is a LinkedIn extension, contact groups and enrichment automations — I found no firmographic, technographic or job-title search filters on the captured pages, which matters because filters are how my team finds the right buyer at all. We found no public information on cold-outreach guidance for EU markets, a do-not-contact or suppression list, or do-not-call checking, so the legal risk sits entirely with the customer. 4 2 1
The RevOps Manager
You get contact groups, export credits and a dashboard for managing leads, and the licence is restricted to internal business use — but we found no public information on cold-outreach guidance by market, a suppression or do-not-contact list, do-not-call register checks, or opt-outs syncing back to the database; 'Enterprise-level compliance' appears as a feature row with no description. 4 2 1
The Data Protection Officer
The pages show a dashboard with lead management, contact groups and automations, plus export credits, but nothing on what the buyer may lawfully do with the contacts. We found no public information on outreach guidance for EU markets, a suppression or do-not-contact list, country-aware flags, or do-not-call checking. 1 2 4
The ABM Marketer
The dashboard with automations, contact groups, bulk enrichment and export credits gives real list handling, and the licence restricts use to internal business purposes. We found no public information on search filters, a do-not-contact or suppression list, checks against do-not-call registers, or any guidance on cold outreach rules in the main EU markets — the legal risk sits entirely with me. 1 2 4
The DACH Sales Director
The workflow evidenced is a LinkedIn extension plus a dashboard with automations, contact groups, bulk enrichment and export credits — but we found no public information on do-not-contact lists, country-aware flags for German contacts, or any guidance on what the buyer may lawfully send under UWG §7. The only compliance signal is an unexplained "Enterprise-level compliance" label in the Enterprise tier. 2 4
The Skeptic
The workflow on display is a LinkedIn extension that reveals contact data, a dashboard with automations and contact groups, and paid export credits — and beyond a "GDPR aligned" badge on the homepage, we found no public information on what the buyer may lawfully do with those contacts. We found no public information on a suppression or do-not-contact list, country-aware handling, or guidance on cold-outreach rules in the main EU markets; the terms address the customer's own conduct (scraping and bulk API use prohibited) while outreach rules go unstated. 1 2 4
CRM sync, enrichment & export
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
Transfer to compatible CRMs, CSV enrichment, Zapier, dialers and a Salesforce enrichment feature at Enterprise give real paths out of the tool, and export credits are defined as a type. But we found no public information on field mapping, deduplication, sync direction or API documentation (access is upon request), and on cancellation the terms say the workspace is permanently deleted while transmitted data becomes and remains the vendor's property — nothing on what my team may keep. 4 2
The RevOps Manager
CRM connectivity amounts to transferring contact details 'to the customer relationship management (CRM) solutions it uses, if these are compatible', plus Zapier, dialers, CSV enrichment and API access upon request; we found no public information on field mapping, deduplication or scheduled re-enrichment, and Salesforce enrichment appears only as an Enterprise line item. The exit terms are the part I would be cleaning up for years: termination permanently deletes the workspace and everything attached to it, and all data the user transmitted 'shall become and remain the property of KASPR, even after the account has been deleted' — nothing states what the customer may keep. 4 2
The Data Protection Officer
Transfer of contact details to compatible CRM solutions, CSV enrichment, Zapier and dialers are stated, with API access upon request and bulk API use prohibited; the terms say the workspace is permanently deleted on termination and user-transmitted data remains the vendor's property. We found no public information on field mapping, deduplication, bidirectional sync, or whether exported contacts may be kept after cancellation. 2 4
The ABM Marketer
Contacts can be pushed to compatible CRMs, enriched by CSV, wired through Zapier and dialers, and an API is available on request — though the terms cap use at 10,000 credits per account per month, treat API use of unlimited credits as abusive, and name Salesforce enrichment only at Enterprise. On exit the workspace and all its contacts and credits are permanently deleted, and everything the customer transmitted becomes and remains the vendor's property even after account deletion, which is a harsh exit clause I would want negotiated before signing. 2 4
The DACH Sales Director
One-way transfer of contact details to compatible CRMs, Salesforce enrichment at Enterprise, CSV enrichment, Zapier and dialers are listed, but the API sits behind "upon request" with no published limits or credit costs. We found no public statement on whether exported contacts may be kept after cancellation — and the terms state that data the user transmits becomes and remains Kaspr's property even after account deletion. 4 2
The Skeptic
Contact transfer to "compatible" CRM solutions, CSV enrichment, Zapier and dialers appear in the plan comparison, with API access only "Upon Request" and any use of unlimited credits through APIs expressly treated as abusive. We found no public information on field mapping, deduplication or bidirectional sync; on exit, the workspace with all contacts and credits is permanently deleted, user-transmitted data "shall become and remain the property of KASPR", and there is no plain statement on whether exported contacts may be kept after cancellation. 2 4
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
The controller is KASPR SAS in Paris, named on the vendor's own pages with RCS registration, transfers outside the EEA are acknowledged with Standard Contractual Clauses, and a subprocessor list is published. That said, the list names US processors in the chain (Google and HubSpot for analytics, Stripe, ActiveCampaign) and we found no public information on named hosting infrastructure, the identity of the data partners, or the ownership picture after the acquisition. 3 4
The RevOps Manager
The controller and contracting entity are named on the vendor's own pages — KASPR, a simplified joint-stock company in Paris — and the privacy policy names its processors (OVH, MongoDB, Google, HubSpot, Stripe, ActiveCampaign, Sendinblue, Userback) with Standard Contractual Clauses for providers outside the UK/EU/EEA. But residency is promised only 'as far as possible' within the UK/EU/EEA, Google and HubSpot process analytics in the USA and HubSpot Inc. stores enquiry data, and we found no public information on a data processing agreement, where the database itself is hosted, or the ultimate ownership of the Paris entity. 3 4
The Data Protection Officer
KASPR SAS of Paris is the named contracting entity and controller, the subprocessor list is published with US processors named openly — Google, HubSpot, Active Campaign, Stripe — under Standard Contractual Clauses, and processing is as far as possible within UK/EU/EEA. Hosting of the contact database is not pinned to named infrastructure, and we found no public information on where the data partners sit or on any certification. 3 4
The ABM Marketer
A Paris-registered simplified joint-stock company is the named controller, and the privacy policy publishes subprocessors by purpose — OVH and MongoDB for account storage, Google and HubSpot in the USA for analytics, Stripe for payments — with Standard Contractual Clauses as the transfer safeguard. Residency is only hedged as "as far as possible" within the UK/EU/EEA rather than committed, the MongoDB group includes the US parent, and we found no public information on the vendor's own ownership, so I cannot fully clear the US Cloud Act question from these pages. 3 4
The DACH Sales Director
A French entity and controller registered with the RCS of Paris, a published subprocessor list and an SCC clause for third-country transfers give a real European base. But the region holding the contact database itself is not stated, data partners are unnamed, US processors (Google and HubSpot for analytics, Stripe, ActiveCampaign, the MongoDB group) sit in the chain, and ownership is unresolved on the captured pages. 3 4
The Skeptic
The contracting entity and controller are named as a Paris-registered SAS, subprocessors are listed, and Standard Contractual Clauses are cited for non-EU providers — but the chain includes Google, HubSpot Inc., Active Campaign LLC and Stripe in the USA and a MongoDB group naming its US parent. We found no public information on where the contact database itself is hosted, on the ownership structure, or on data residency beyond "as far as possible" processing within the UK/EU/EEA. 3 4
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
Tier prices, per-seat costs, credits per data type, export limits, credit expiry, minimum terms and VAT treatment are all public, which is more than most of this category manages. What keeps the annual invoice from being fully computable is that we found no public information on the price of additional credits or overage rates, API access is upon request, Enterprise is custom-priced, and the captured pages give different signals on rollover — a credits roll-over row on the pricing page while the terms state credits cannot be carried over. 2 4
The RevOps Manager
Tier prices, credit allowances by data type, export limits, monthly and annual terms, notice periods and prices in euros excluding VAT are all public, which is more than most of this category manages. Gaps keep the invoice from being fully computable: additional credits are purchasable at no published price, API access is 'Upon Request', Enterprise and its intent data are 'Custom', credits expire at period end without refund, and the captured pages give different figures for unlimited use — 'Unlimited B2B email credits' on the pricing page against 'a maximum limit of 10,000 credits per account per month applies' in the terms. 2 4
The Data Protection Officer
Free, Starter at €59 and Business at €99 per user per month are public with credits per data type, expiry at subscription end, euro prices excluding VAT, notice periods and payment terms. API access is upon request and unpriced, additional credits carry no published price, Enterprise is custom-priced, and the captured pages give different figures for credit roll-over. 2 4
The ABM Marketer
Free, Starter at €59 and Business at €99 per user per month are public with credits per data type, annual export limits, expiry at period end, VAT exclusion, notice periods and monthly auto-renewal stated, so most of the invoice is computable. API access is listed only as upon request, Enterprise is custom-priced, and we found no public information on the price of additional credits — and with credits neither refundable nor exchangeable, there is no refund rule for inaccurate data. 2 4
The DACH Sales Director
Three tiers are public — Free €0, Starter €59 per user per month, Business €99 per user per month — with credit allowances per data type, per-user pricing, VAT exclusion and credit expiry stated in the terms. But we found no public price for additional credits, API calls or the Enterprise tier, the terms cap "unlimited" credits at 10,000 per account per month, and the captured pages give different positions on rollover — a "Credits Roll Over" row on the pricing page against terms saying credits expire at the end of the subscription period. 2 4
The Skeptic
Credit allowances per tier and per data type are genuinely public — B2B email, phone, direct email and export limits for every plan from Free to Business at stated per-user prices, with VAT treatment, auto-renewal, notice periods and an "unlimited" cap of 10,000 credits per account per month documented in the terms. But the price of additional credits, API access and the Enterprise tier sit behind a request, credits are "neither refundable nor exchangeable" with no credit-back rule for inaccurate data, and the terms say credits expire at the end of each subscription period and cannot be carried over while the plan comparison carries a roll-over row whose values were not captured. 2 4
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in FR ⚠ unverified | 3/3 pts | 3 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 3 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. The terms page gives the registered office as 38 rather than 8 rue Dunois, though under the same Paris RCS number 843 898 396.
- Weak sourcing — Subprocessors. The policy elsewhere names further US providers — Stripe as payment processor plus HubSpot Inc. and Active Campaign LLC — and the help centre states 'Wir nutzen Intercom', so US exposure goes beyond the account-data storage layer.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 9 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 9 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (10)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.kaspr.io Checked 22 Sep 2026 Details →
- 2 Pricing page www.kaspr.io Checked 22 Sep 2026 Details →
- 3 Privacy policy www.kaspr.io Checked 22 Sep 2026 Details →
- 4 Terms of service www.kaspr.io Checked 22 Sep 2026 Details →
- 5 Coverage, accuracy & freshness — found from sitemap www.kaspr.io Checked 1 Oct 2026 Details →
- 6 Coverage, accuracy & freshness — found from sitemap help.kaspr.io Checked 1 Oct 2026 Details →
- 7 Prospecting workflow & outreach rules — found from sitemap www.kaspr.io Checked 1 Oct 2026 Details →
- 8 Prospecting workflow & outreach rules — found from sitemap help.kaspr.io Checked 1 Oct 2026 Details →
- 9 CRM sync, enrichment & export — found from sitemap help.kaspr.io Checked 1 Oct 2026 Details →
- 10 CRM sync, enrichment & export — found from sitemap help.kaspr.io Checked 1 Oct 2026 Details →