whats-best.ai
Search Sign in

Lead Generation

Vainu

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 1 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Vainu.io Software Oy · www.vainu.com

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

Vainu, a company-data platform from Vainu.io Software Oy of Helsinki, draws on Nordic patent and registration office records and publishes country counts — Denmark 862k, Finland 1.3m, Norway 1.1m, Sweden 1.9m — with a stated daily refresh. The bench scores it highest on CRM sync and export, 6 to 7: native connectors to five CRMs, per-field update rules, hourly rechecks, change webhooks and a REST API with JSONL streaming. The weakest band is visitor identification, 0 to 2 — we found no public information on identifying companies behind website visits, and scores differ on whether the 72 company-change event types count as a substitute. Data coverage spreads 4 to 6, turning on the fact that published counts stop at the Nordics, the Data product carrying only an unquantified 'Global' option. Pricing transparency runs 3 to 4: Vainu for Prospecting and Vainu for CRM publish 'Starting at 3,500€/ year +200€ / one-time onboarding fee' and 'Starting at 4,200€/ year +750€ / one-time onboarding fee', but we found no public information on seat, contact or VAT costs, so a real invoice is not computable.

Report an error

Speaks for it

  • Native connectors to HubSpot, Salesforce, Pipedrive, Dynamics 365 Sales and Superoffice, with per-field update rules and updates reversible on request
  • Documented REST API spanning search, enrichment, export, change tracking and JSONL streaming across the whole database
  • Published per-country company counts for Denmark, Finland, Norway and Sweden, with a stated daily refresh and company data drawn from patent and registration offices
  • Named source categories — patent and registration offices, public officials, company websites, press releases — with legitimate interest stated as the lawful basis and a dedicated privacy notice for people in the database
  • Two tiers publish annual starting prices and one-time onboarding fees, and the 12-month auto-renewing subscription and 60-day cancellation notice are stated plainly

Report an error

Held against it

  • We found no public information on identifying companies behind website visits or on third-party intent signals
  • We found no public information on coverage of Germany, Austria or Switzerland beyond an unquantified 'Global' option on the Data product
  • We found no public information on seat costs, contact or export allowances, or VAT treatment, so the annual invoice cannot be computed from public pages
  • Customers become data controllers the moment they export, and we found no public information on a do-not-contact list or checks against do-not-call registers
  • The privacy policy states data may be transferred to and stored outside the EEA, and we found no public information on hosting location or subprocessors

Report an error

Best for

  • Your pipeline targets the Nordic markets, where the published company counts are Denmark 862k, Finland 1.3m, Norway 1.1m and Sweden 1.9m
  • Your team runs HubSpot, Salesforce, Pipedrive, Dynamics 365 Sales or Superoffice and wants native, field-level syncing with hourly rechecks
  • You build on an API and want to stream the database as JSONL or subscribe to change webhooks
  • You want timing signals on target accounts — 72 event types such as funding rounds and key hires landed as CRM tasks or Slack notifications

Report an error

Avoid if

  • You need to know which companies visit your own website — visitor identification scored 0 to 2, and the signals on the pages are company-change events, not visits
  • Your pipeline depends on quantified coverage of Germany, Austria or Switzerland — we found no public information beyond an unquantified 'Global' option
  • You must budget before talking to sales — published prices are starting points without seat, contact or VAT figures, on a 12-month auto-renewing subscription with 60-day notice
  • You expect the vendor to carry the outreach compliance load — on export you become the data controller, and we found no public information on suppression lists or do-not-call checks

Report an error

The scores

Coverage, accuracy & freshness

Show reasoning
How this is scored

How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.

0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.

3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.

5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.

8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.

10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.

Report an error

The SDR Team Lead

Per-country counts are published for the Nordics — Denmark 862k, Finland 1.3m, Norway 1.1m, Sweden 1.9m — with a stated daily refresh, 9M+ contacts, 700+ data fields, and company data drawn from patent and registration offices, which is more than a headline count. But my team sells into DACH, and the only coverage beyond the Nordics is an unquantified "Global" label on the data tier; we found no public information on German, Austrian or Swiss coverage, on any email verification method, or on a bounce or credit-back guarantee. 1 2 4 5

Report an error

The RevOps Manager

Country-level counts exist for Denmark, Finland, Norway and Sweden, with company data drawn from national Patent and Registration offices and public officials, refreshed daily. However, we found no public information on DACH or broader EU coverage in numbers, on how contact data is verified, or on any bounce or credit-back guarantee. 1 2 4 5

Report an error

The Data Protection Officer

Per-country counts for Denmark, Finland, Norway and Sweden, daily refresh, and company data drawn from patent and registration offices are documented. But I found no public information on coverage of the German-speaking markets, on any verification method for the nine million contacts, or on a bounce or credit-back guarantee that would make inaccuracy the vendor's cost. 1 2 4 5

Report an error

The ABM Marketer

Company coverage is stated country by country — Denmark 862k, Finland 1.3m, Norway 1.1m, Sweden 1.9m — refreshed daily and drawn from patent and registration offices, which is exactly the register-based profile I want for Nordic accounts. But we found no public information on DACH coverage beyond the word "Global" on the Data product, no email verification method, and no bounce or credit-back guarantee, so accuracy rests on 550+ data points described as traceable to source with no vendor cost when a record is wrong. 1 2 4 5

Report an error

The DACH Sales Director

Coverage is stated country by country, but only for Denmark, Finland, Norway and Sweden — for Germany, Austria and Switzerland I found no public information beyond an unspecified 'Global' option on one tier. Refresh is daily and company data is drawn from the patent and registration offices, which I respect, but we found no public information on email verification, an accuracy methodology, or credit-back terms for bad contacts. 1 2 4 5 6

Report an error

The Skeptic

Per-country company counts for the four Nordic markets, a stated daily refresh, and company data drawn from patent and registration offices are genuinely documented. But we found no coverage figures for DACH or any EU market beyond an unquantified 'Global' tier, no verification method for the 9M+ contact emails and phone numbers, and no bounce or credit-back terms anywhere on the captured pages. 1 2 4 6

Report an error

Data sources & lawful basis

Show reasoning
How this is scored

Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.

0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.

3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.

5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.

8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.

10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.

Report an error

The SDR Team Lead

Sources are named — patent and registration offices, public officials, company websites, press releases — with legitimate interest stated as the basis for company-related personal data and a dedicated privacy notice for the people in the register, plus listed data-subject rights and an email route for removal. Removal is a request to a privacy inbox rather than a self-service process, and we found no public information on a balancing test being summarised, on people being notified when added, or on source and collection date being available per contact record. 3 4

Report an error

The RevOps Manager

Source categories are named concretely (registration offices, public officials, company websites, press releases), legitimate interest is stated as the basis, and a dedicated database privacy statement gives listed people access, rectification, objection and erasure rights with retention mirroring the original source. We found no public information on an Art. 14 notification practice, a published balancing assessment, or permanent suppression of objected records, and removal runs through a privacy email address rather than self-service. 3 4 5

Report an error

The Data Protection Officer

Sources are named concretely — registration offices, public officials, company websites — with legitimate interest stated as the basis, a dedicated privacy notice for the people in the database, a named Data Privacy Officer, and a retention design that mirrors removal from the original source. What I do not see is an Article 14 practice informing people when they are added, a published balancing test, or a self-service removal route — the listed person must email, and I found no public information on suppression being permanent across the dataset. 3 4

Report an error

The ABM Marketer

Sources are named — patent and registration offices, public officials, company websites, press releases — legitimate interest is stated for company-related personal data, and a dedicated database privacy notice gives listed people erasure and objection rights via privacy@vainu.io. What I did not find is an Art. 14 notification practice, a published balancing test, or a self-service removal route beyond an email address, so provenance sits at named categories rather than traceable per record. 3 4

Report an error

The DACH Sales Director

The lawful basis is stated openly — legitimate interest for company-related personal data — the source categories are named (registration offices, public officials, company websites, press releases), and a dedicated privacy statement gives the people in the database erasure and objection rights via privacy@vainu.io. We found no public information on an Art. 14 notification practice when a person is added, on a published balancing test, or on per-contact source traceability, so I stop short of the higher marks. 3 4

Report an error

The Skeptic

The database privacy statement names its sources — patent and registration offices, public officials, company websites, press releases — states legitimate interest as the basis for EU records, and lists data-subject rights with a named privacy officer. What it does not give is a self-service exit: removal runs through a request to privacy@vainu.io. We found no public balancing test and no practice of informing people when they are added. 3 4

Report an error

Visitor identification & intent signals

Show reasoning
How this is scored

Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.

0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.

3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.

5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.

8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.

10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.

Report an error

The SDR Team Lead

The closest thing on the pages is company-change signal — funding rounds, key hires, 72 event types landing as CRM tasks or Slack alerts — which is timing intelligence, not visitor identification. We found no public information on identifying companies behind website visits, on intent topics, or on any tracking script and its consent position. 1 6

Report an error

The RevOps Manager

We found no public information on identifying companies behind website visits, on any tracking script, or on a consent position for one. The nearest signals are change-based events (a funding round, a key hire, 72 event types) delivered as CRM tasks or Slack notifications, which are not visit-based identification. 1 6

Report an error

The Data Protection Officer

The pages describe company-change triggers such as funding rounds and key hires, but I found no public information on identifying the companies behind website visits, on any tracking script and its consent position, or on cookieless or consent-mode operation. The only cookie statement concerns Vainu's own website, not a product feature for customers. 1 3

Report an error

The ABM Marketer

We found no public information on website visitor identification — no reverse-IP product, no cookie or consent-mode statements, nothing on the TDDDG position for a tracking script. What the pages do show is warm-signal alerting on company change: 72 event types like funding rounds and key hires landing as a CRM task or Slack notification on a schedule I set, which keeps owners informed but never tells me which of my 300 accounts actually walked the site. 1 6

Report an error

The DACH Sales Director

We found no public information on website visitor identification or intent tracking — nothing on reverse-IP company matching, and nothing on consent for a tracking script under TDDDG. The nearest capability is event triggers: 72 event types such as funding rounds and key hires delivered as CRM tasks or Slack notifications — a timing signal, not visitor identification or third-party intent. 1 6

Report an error

The Skeptic

We found no public information on identifying companies behind website visits or on intent signals from any third-party source. The closest things on the pages are event triggers — 72 company-change event types landing as CRM tasks — and a cookie statement covering only Vainu's own website and marketing. 1 3 6

Report an error

Prospecting workflow & outreach rules

Show reasoning
How this is scored

Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.

0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.

3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.

5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.

8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.

10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.

Report an error

The SDR Team Lead

The filter set is genuinely strong for finding the right buyer — financial, group-structure, social-media and event filtering, 72 event types, alerts routed to CRM or Slack. What happens once the list exists is left with us: the policy says customers become data controllers on export, and we found no public information on a global suppression or do-not-contact list, on country-aware flagging of German contacts, or on checks against national do-not-call registers. 1 2 4 6

Report an error

The RevOps Manager

Filtering goes well past firmographics (technologies, financials, group structures, event data) with alerting on 72 event types and decision-maker phone and email data, and the database privacy statement is explicit that customers become data controllers on export. We found no public information on a suppression or do-not-contact list, on per-country outreach handling or do-not-call register checks, or on any guidance for cold outreach rules in the main EU markets. 1 2 4 6

Report an error

The Data Protection Officer

Firmographic and financial filters, seventy-two event types and CRM-routed alerts are described, and I credit Vainu for stating plainly that a customer who exports becomes the controller — that is more honesty than most of this category shows. However, I found no public information on a suppression or do-not-contact list, on numbers checked against national do-not-call registers, or on guidance for cold-outreach consent rules in the main EU markets. 2 4 6

Report an error

The ABM Marketer

Filtering is strong — advanced financial, group structure, social media and event-data filters, plus alerts whenever a new company matches my criteria — but we found no public information on a suppression or do-not-contact list, do-not-call register checks, or cold-outreach guidance for German and other EU markets. The database privacy statement makes me the data controller the moment I export, which leaves the UWG risk squarely on my desk. 2 4 6

Report an error

The DACH Sales Director

Filtering and triggers are genuinely strong — technographics, event data, financial and group-structure filters, alerts on new matching companies — but the compliance load sits with the customer: on export the customer becomes the data controller, and I found no public information on a do-not-contact list, checks against do-not-call registers, or guidance on cold outreach rules in the German-speaking markets. A tool handing my reps phone numbers for decision-makers with nothing on UWG §7 leaves the legal risk on my desk. 1 2 3 4

Report an error

The Skeptic

The search side is deep — financial, technographic, group-structure and event filters with alerts on new matches. But nothing on the pages addresses what the buyer may lawfully do with exported decision-maker contacts: we found no public information on a do-not-contact or suppression list or on cold-outreach guidance per market, and the database privacy statement makes the customer the data controller the moment data is exported. 1 2 4

Report an error

CRM sync, enrichment & export

Show reasoning
How this is scored

Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.

0 — Manual CSV export only; no CRM integration and no API.

3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.

5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.

8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.

10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.

Report an error

The SDR Team Lead

Native connectors to HubSpot, Salesforce, Pipedrive, Dynamics 365 and Superoffice with per-field update rules (fill only when empty, always overwrite, only on a new account), reversible updates, an hourly recheck of matched CRM records, and an API that streams the whole database as JSONL with change webhooks — this is the strongest area on the pages. For the top scores we found no public information on stated API limits or per-call credit costs, on propagating deletions when a person objects, or on which data may be kept after cancellation. 2 5 6

Report an error

The RevOps Manager

Native connectors to HubSpot, Salesforce, Pipedrive, Dynamics 365 Sales and Superoffice with per-field rules (fill only when empty, always overwrite, only on a new account), reversible updates on request, hourly re-matching of CRM accounts, contact updating, and a documented API with change webhooks and streaming export — this is a connector built by people who have seen a CRM. We found no public information on deletions or objections propagating into synced records, on API credit costs, or on what the buyer may keep after cancellation; the only exit-relevant term is the 12-month auto-renewing subscription with 60-day notice. 1 2 5 6

Report an error

The Data Protection Officer

Native connectors to five CRMs with per-field update rules, reversible updates, hourly rechecking and change webhooks make scheduled re-enrichment real, and the API spans search, enrichment, export and change tracking. I found no public information on deletions or objections propagating into synced records, on per-call API costs, or on what the customer may keep after the subscription ends. 2 5 6

Report an error

The ABM Marketer

Native connectors to HubSpot, Salesforce, Pipedrive, Dynamics 365 Sales and Superoffice with per-field update rules — fill only when empty, always overwrite, or only on a new account — hourly rechecks, change webhooks and an Enrichment Agent pushing custom points into CRM fields give a real system-of-record feel. Missing toward the top end: no published per-call or credit costs, no statement that an objection or deletion propagates into my synced records, and retention after cancellation is addressed only by the note that I become controller of what I export. 2 4 5 6

Report an error

The DACH Sales Director

This is the strongest part: native connectors to HubSpot, Salesforce, Pipedrive, Dynamics and Superoffice with field-level rules (fill when empty, overwrite, skip) and reversible updates, an hourly recheck against the database, change webhooks, and a REST API with search, enrichment, export, change tracking and JSONL streaming. What keeps me below the top: no evidence that objections or deletions propagate into synced records, no published cost per API call, and no statement of what exported data a customer may keep once the subscription ends. 2 4 5 6

Report an error

The Skeptic

Native connectors to five CRMs with per-field write rules, an hourly recheck of matched accounts, and an API with streaming, batch jobs and change webhooks go well past a one-way push. We found no public information on propagating deletions or objections into synced records, no API cost schedule beyond free-trial limits, and nothing on what happens to exported data when the 12-month subscription ends. 2 5 6

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.

0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.

3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.

5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.

8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.

Report an error

The SDR Team Lead

The contracting entity and controller is Vainu.io Software Oy in Helsinki with a named Data Privacy Officer, and data protection agreements or EU standard contractual clauses are named as transfer safeguards — but the policy itself states that data may be transferred to and stored at a destination outside the EEA. We found no public information on where the database is hosted or which subprocessors see it, which is what I would need before putting EU contacts into it. 3 4

Report an error

The RevOps Manager

The contracting entity and controller is Vainu.io Software Oy in Helsinki with a named Data Privacy Officer, but the privacy policy states data may be transferred to and stored at a destination outside the EEA, and we found no public information on hosting location, subprocessors or data partners, or certification. Standard contractual clauses are named as the transfer safeguard. 3 4

Report an error

The Data Protection Officer

The controller is Vainu.io Software Oy of Helsinki with a named Data Privacy Officer, and transfers outside the EEA are at least acknowledged with European standard contractual clauses named as a safeguard. But hosting location is unstated, subprocessors and data partners are unnamed, and I found no public information on where this database of people who never chose Vainu is actually processed. 3 4

Report an error

The ABM Marketer

The controller and contracting entity are Finnish with a named Data Protection Officer, the company data comes from Nordic public registers, and transfers outside the EEA are disclosed with EU standard contractual clauses named as the safeguard. We found no public information on where the service is hosted, on the ownership structure, or on any subprocessor list, so the chain beyond the register sources stays dark. 3 4

Report an error

The DACH Sales Director

Vainu.io Software Oy is a Finnish contracting entity and controller with a named Data Privacy Officer, and SCCs or Data Protection Agreements are named as transfer safeguards — a decent European footing. But the captured pages state that data may be transferred to and stored outside the EEA without naming destinations or infrastructure, and we found no public information on hosting location or a subprocessor list, which for a database of European business contacts is thin. 3 4

Report an error

The Skeptic

The controller is the Finnish company with a named privacy officer, which is the right starting point. But we found no public information on where the data is hosted or which subprocessors and data partners see it, and the privacy policy states that data may be transferred to and stored outside the EEA, with safeguards described only as possibly including EU standard contractual clauses. 3 4

Report an error

Pricing transparency

Show reasoning
How this is scored

Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.

0 — No public prices at all; every tier is a sales conversation.

3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.

5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.

8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.

10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.

Report an error

The SDR Team Lead

Two tiers carry real public numbers — Vainu for Prospecting starting at 3,500€/year plus a 200€ one-time onboarding fee, and Vainu for CRM starting at 4,200€/year plus 750€ — with a 12-month auto-renewing subscription and 60-day cancellation notice stated. But the starting-at framing hides the seat math, the data tier is customized pricing for large data volumes, and we found no public information on per-seat costs, contact or credit allowances, or VAT treatment, so an invoice for a team of eight cannot be computed from the pages. 2 5

Report an error

The RevOps Manager

Two annual floors are public — "Starting at 3,500€/ year +200€ / one-time onboarding fee" for Prospecting and "Starting at 4,200€/ year +750€ / one-time onboarding fee" for CRM — but we found no public information on per-seat costs, included contact or export volumes, or VAT treatment, and the Data tier is "Customized pricing for large data volumes" with Vainu View by quote. A real invoice is not computable from public pages. 2 5

Report an error

The Data Protection Officer

Annual starting prices and one-time onboarding fees are public for two plans, together with the twelve-month auto-renewal and sixty-day notice. But seats, contact allowances, exports and API usage are unpriced, the data plan is customized pricing only, and I found no public information on VAT treatment — the real annual invoice cannot be derived from the public pages. 2 5

Report an error

The ABM Marketer

Two annual floors are public — "Starting at 3,500€ / year +200€ / one-time onboarding fee" for Prospecting and "Starting at 4,200€ / year +750€ / one-time onboarding fee" for CRM — with 12-month auto-renewal and 60-day notice stated, which is more than most in this category. But both figures say starting at, Vainu View is "ask for quote", the Data product is "Customized pricing for large data volumes", and we found no public information on seat costs, export limits or VAT treatment, so the real invoice stays a sales conversation. 2 5

Report an error

The DACH Sales Director

Two products carry public starting prices — 3,500€/year plus a 200€ one-time onboarding fee for prospecting, 4,200€/year plus 750€ for CRM — with the 12-month auto-renewing term and 60-day cancellation notice stated plainly. But 'starting at' with no per-seat cost, no per-contact or credit price, no VAT treatment, and a fully customized third tier means I cannot compute the real annual invoice for a sales team from public pages. 2 5

Report an error

The Skeptic

Two tiers publish annual starting prices — 'Starting at 3,500€/ year +200€ / one-time onboarding fee' and 'Starting at 4,200€/ year +750€ / one-time onboarding fee' — with the 12-month auto-renewal and 60-day notice stated. But we found no public information on seat costs or contact and export allowances at those prices, the data tier is 'Customized pricing', Vainu View is quote-only, and the API is priced only as a free trial with unspecified limits, so the real annual invoice is not computable. 2 5

Report an error

European sovereignty — proven facts

1 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (6)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.vainu.com Checked 22 Sep 2026 Details →
  2. 2 Pricing page www.vainu.com Checked 22 Sep 2026 Details →
  3. 3 Privacy policy www.vainu.com Checked 22 Sep 2026 Details →
  4. 4 Privacy policy www.vainu.com Checked 22 Sep 2026 Details →
  5. 5 CRM sync, enrichment & export — found from sitemap www.vainu.com Checked 1 Oct 2026 Details →
  6. 6 CRM sync, enrichment & export — found from sitemap www.vainu.com Checked 1 Oct 2026 Details →