GDPR compliance

Last updated: July 30, 2026

This page covers the data you extract about businesses — which is the sensitive part, and where responsibility is shared between us.

What is collected, and what is not

mySearch only collects professional information that businesses have made public themselves, on their Google listing and on their own website: company name, address, business phone number, contact email, opening hours, rating and reviews.

No data about private individuals is collected. Email addresses that look personal rather than professional are not the target of the engine, and review authors are never extracted.

Who is responsible for what

We are the controller for your customer account. You are the controller for the prospecting you carry out with the extracted data: it is you who decide who to contact, with what message and how often.

This matters practically: an objection from a prospect must be handled by you, in your own systems. The suppression list exists for that — a business added to it never comes back in your exports.

Legal basis for B2B prospecting

In Europe, prospecting a business at its professional contact details generally relies on legitimate interest, provided the message concerns that business's professional activity.

Three obligations come with it, and they are yours: state where you obtained the data, offer a simple way to object in every message, and honour that objection without delay. Our exports include the source of every email precisely so that the first point is easy to satisfy.

Rights of the businesses extracted

A business that wants its data removed from our systems can write to contact@mysearch.gg. We remove it and add it to a global exclusion list so that it is not extracted again.

We will pass the request on to you if their data has already been exported to you, but only you can delete it from your own tools.

Security

Data is hosted in the European Union. Access is isolated per organisation at the database level: a query issued on behalf of one organisation cannot read another's rows, even if the application layer were compromised.

API keys are stored as a hash. Passwords never reach our servers in clear text.

Contact

For any question about this document, write to contact@mysearch.gg.

Publisher :
mySearch

This document describes how the service actually works. It has not been reviewed by a lawyer and does not replace legal advice tailored to your situation.

Back to home