This policy governs every lead list delivered by mailzy.us. It sits under the Terms of Service and works alongside the Acceptable Use Policy. Buying a list means you accept these rules.
What we deliver
Business-to-business contact records: company name, website, role, business email address, and public firmographic attributes. Records are compiled from publicly accessible sources and licensed data providers.
- We do not knowingly sell consumer (B2C) personal data.
- We do not sell special-category data (health, biometrics, political opinions, religion, sexual orientation, trade-union membership).
- We do not sell financial account numbers, government IDs, or passwords.
Sourcing
Data is gathered from public company websites, public professional directories, public registries, and third-party providers who represent that they collected the data lawfully. We do not bypass paywalls, authentication, or technical access controls that a source has put in place to prevent collection.
Accuracy and no guarantee
- Contact data decays. We target reasonable freshness but make no warranty of accuracy, deliverability, or fitness for a particular campaign.
- Verification, where offered, is a syntax and mail-server check, not a guarantee that a person still holds a role.
- We do not guarantee reply rates, meetings, or revenue.
- Replacement and refund rules for short or failed deliveries are in the Refund Policy.
Your role under data-protection law
Once a list is delivered, you become an independent data controller for those records. You are responsible for:
- Establishing a lawful basis for your outreach - typically legitimate interest for B2B contacts, assessed and documented by you.
- Sending a privacy notice to data subjects where required (for example, GDPR Article 14 notice at first contact).
- Honouring access, correction, objection, and deletion requests you receive.
- Checking local rules before mailing. Some jurisdictions require prior consent even for business addresses.
mailzy.us cannot and does not provide a lawful basis on your behalf.
Anti-spam obligations
Every message you send using our data or our mailboxes must:
- Accurately identify the sender, the sending company, and a valid physical postal address.
- Use truthful subject lines and headers - no spoofed domains, no forged From addresses.
- Include a working, one-click opt-out and honour it within 10 business days (immediately, in practice).
- Be relevant to the recipient's professional role.
- Comply with CAN-SPAM, CASL, GDPR/ePrivacy, UK PECR, the Australian Spam Act, and any other law that applies where the recipient sits.
Prohibited uses
- Reselling, sublicensing, republishing, or redistributing a list, in whole or in part.
- Uploading lists to a public repository, shared drive, or third-party data marketplace.
- Using data for consumer marketing, political campaigning, debt collection, harassment, doxxing, or scams.
- Enriching a list to build a competing data product.
- Using data for credit, employment, insurance, or housing eligibility decisions (this is not FCRA-compliant data).
Licence
You receive a non-exclusive, non-transferable, internal-use licence for your own outbound campaigns. The licence terminates automatically on breach of this policy, and you must delete the data.
Suppression and removal requests
Anyone can ask to be removed from our source database by emailing hello@mailzy.us with the email address or domain in question. We suppress within 30 days and keep a hash of the address purely to prevent re-collection. We cannot recall records already delivered to a customer, so we also notify affected customers of their obligation to suppress.
Enforcement
Confirmed spam complaints, blacklistings, or breaches of this policy can result in immediate suspension of lead-list access and mailboxes, without refund, and disclosure to affected providers where legally required.