Regulatory frameworks

Where we stand today. We describe ourselves as compliant, never certified for frameworks we do not yet hold.

EU GDPR / UK GDPR Designed to comply

Our policies and controls are designed to comply with EU Regulation 2016/679, the UK GDPR, and the Irish Data Protection Act 2018. Backed by a signable DPA, records of processing, and documented technical and organisational measures.

SOC 2 Type II Working towards

We are preparing for a SOC 2 Type II examination. The report will be made available under NDA on completion.

Documents

Available to download directly - no request needed. Our full Records of Processing, detailed security measures, and Legitimate Interests Assessment are available to customers on request, and a future SOC 2 report will be shared under NDA.

Subprocessors

The vendors that help us run the service - each name links to that vendor's own trust page. Each is bound by a written contract with data-protection terms; transfers outside the EEA/UK rely on SCCs / UK IDTA, and the EU-US Data Privacy Framework where certified.

SubprocessorPurposeRegion
VercelApplication and website hosting, edge deliveryUS (EU edge)
SupabaseApplication database and authenticationEU
ClerkUser authentication and identityUS
StripeBilling and payment processingEU / US
Microsoft AzureCloud infrastructure for data servicesEU / US
Google Cloud / BigQueryData warehouse and processingEU / US
FullEnrichBusiness-contact enrichmentEU / US
People Data LabsBusiness-contact enrichmentUS
CrustdataBusiness-contact enrichment (professional-profile sourced)US
ComposioIntegration layer for pushing data to connected toolsUS
ResendTransactional and notification emailUS
ZeptoMail (Zoho)Transactional emailEU
UpstashManaged Redis cache for session and chat stateEU / US
ZohoScheduling, analytics and business operationsEU
PostHogProduct analyticsEU
Microsoft ClarityAnonymised session analytics (marketing site)US

See the full subprocessor list with transfer mechanisms, or download it as a PDF.

How we protect your data

A summary of our technical and organisational measures (Article 32 GDPR). Full detail is available under NDA.

Tenant isolation

Each customer's data is scoped by organisation and enforced at the database layer with row-level security.

Encryption

TLS in transit and encryption at rest across all data stores.

Secrets management

No plaintext secrets in code or config; managed secret stores with a documented rotation programme.

Change control

Changes ship through peer-reviewed, risk-tiered pull requests; direct pushes to production are blocked; automated security scanning runs on every change.

Monitoring and audit

Application and infrastructure logging, an administrative audit trail, and system-health monitoring with alerting.

Access control

Least-privilege, need-to-know access provisioned and removed on role change or exit; personnel bound by confidentiality.

What we collect and how long we keep it

Business-context data onlyWork email, role, and direct-dial for professionals. No special-category data is intentionally processed.
Data locationPrimary production systems are hosted within the European Economic Area. Some subprocessors operate in the US under recognised transfer mechanisms (below).
90-day retention on contact dataEnriched business-contact personal data is automatically anonymised 90 days after enrichment.
Lawful basisLegitimate interest (Article 6(1)(f)) for business-contact processing, documented in a Legitimate Interests Assessment.
International transfersTransfers outside the EEA/UK rely on the EU Standard Contractual Clauses / UK IDTA, and the EU-US Data Privacy Framework where certified.
Your rightsIndividuals may request access, rectification, erasure, restriction, portability, or object to processing in accordance with applicable data protection law. We respond within one calendar month. Contact compliance@marketsizer.io.
Incident responseAffected controllers notified within 48 hours; the Irish Data Protection Commission within 72 hours where applicable.
Artificial intelligenceWe use AI to help users analyse data and generate insights. Customer data is not used to train foundation models unless explicitly agreed in writing.

Questions about any of this? Email compliance@marketsizer.io.

What we process, at a glance

A plain-language summary of our processing activities. Our full Records of Processing Activities (Article 30) are available to customers on request.

CategorySummary
PurposeDelivering the MarketSizer platform - GTM intelligence, company and contact data, scoring, and outreach support.
Data subjectsCustomer users and business contacts (individuals in professional roles at prospect companies).
Data typesBusiness contact information, authentication data, and usage logs. No special-category data.
RetentionCustomer account data retained during the subscription; enriched contact data anonymised after 90 days.
Processing locationsPrimarily the EEA, with approved international transfers where applicable (SCCs / UK IDTA).

Company information

MarketSizer is operated by Tamcalc Limited, an Irish private company limited by shares incorporated under the Companies Act 2014. Two independent identifiers - our CRO registration and D-U-N-S Number - let you verify that we exist.

Registered companyTamcalc Limited (trading as MarketSizer)
CRO registration738699
D-U-N-S Number986144356
Registered officeGreyfort, Cruagh Road, Rathfarnham, Dublin, D16 DE92, Ireland
Country of incorporationIreland
Governing lawIreland
Primary data protection authorityIrish Data Protection Commission

Regulatory jurisdiction

Tamcalc Limited is incorporated in Ireland and regulated under Irish company law. As an EU-established controller and processor, our primary supervisory authority for data protection matters is the Irish Data Protection Commission (DPC). UK GDPR obligations are supported where applicable, and international transfers use recognised mechanisms such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where required.

Contact

Explore more

Find out who's evaluating in your market right now
before your competitors do.

30 minutes. No commitment. We'll show you the accounts actively evaluating in your market today.

No credit card · Tailored to your ICP · Live data, not a slide deck