GDPR Notice
Last updated: 13 July 2026
We are a United States company, and many of our customers and many of the people in our B2B database are in the EU, the UK, Switzerland, or the wider EEA. That means the GDPR and UK GDPR apply to us, and this notice explains how we meet them. It supplements the Privacy Policy.
1. Controller or processor?
It depends on the data, and the distinction matters:
- We are the controller of our customer account data and of the B2B contact records in our own database.
- We are the processor of the data you upload into the platform — your lists, your campaigns, your CRM records. You are the controller of that, and you decide who gets contacted. Our Data Processing Addendum governs that relationship.
2. Legal basis for B2B contact data
We process business contact data under Article 6(1)(f) — legitimate interests. The interest is business-to-business commercial communication; the data is limited to the professional sphere; and we have carried out a balancing test against the rights of the individuals concerned. That assessment is available on request.
Legitimate interests is not a blank cheque. It carries a duty to be transparent, to make objection easy, and to stop when someone objects. We do all three, and we do not require an account or an identity check to honour an objection.
3. Your rights
You have the right to: access the personal data we hold about you; rectify it if it is wrong; erase it; restrict or object to our processing (including an absolute right to object to direct marketing); data portability; and to withdraw consent where we rely on it.
To exercise any of them, email legal@govarova.com from the address concerned, or use the removal form. We respond within one month, extendable by two months for complex requests, and we will tell you if we need the extension. There is no charge.
4. International transfers
Our infrastructure is in the United States, so personal data from the EEA, the UK, and Switzerland is transferred there. We rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, and the Swiss addendum) as the transfer mechanism, supported by a transfer impact assessment and technical measures including encryption in transit and at rest.
A copy of the SCCs we use is available on request.
5. Data Processing Addendum
If you are a customer and you need a signed DPA — which you probably do if you are processing EU or UK personal data through our platform — our standard DPA is at /legal/dpa and is incorporated into the Terms of Service automatically. Email legal@govarova.com if you need a countersigned copy.
6. Sub-processors
The current list, and how to be notified of changes, is at /legal/subprocessors.
7. Breach notification
Where a personal data breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours of becoming aware of it, and we notify affected individuals without undue delay where the risk is high. Where we act as your processor, we notify you without undue delay so that you can meet your own deadline.
8. Complaining
Tell us first — legal@govarova.com — and we will try to put it right. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office) at any time, and you do not have to come to us first.
9. Contact
All GDPR matters: legal@govarova.com.
Randoye LLC, a Wyoming limited liability company, trading as Govarova.
30 N Gould St, Ste 5275
Sheridan, WY 82801
United States
legal@govarova.com
We are a fully remote company. The address above is our registered address for legal correspondence; we do not operate a public office and cannot receive visitors.