GDPR compliant data cleaning starts with not uploading the file
The strongest thing we can say about your data is that the browser demo never receives it. Below is exactly what happens to a file, what we hold on a paid plan, how long we keep it and what we will never do with it.
What this page is not
There is no certification badge on this page. We are not going to display a SOC 2 or ISO 27001 logo we have not earned. What follows is what we actually do.
Your file is read on your own machine
The cleaning engine on this site is JavaScript. When you drop a CSV, the browser reads it from your disk into its own memory and works there.
No upload
There is no request carrying your file. You can confirm it: open the network tab, load a file, and watch that nothing goes out.
No storage
Nothing is written to a server, and nothing is kept between visits. Closing the tab ends it.
No account needed
The demo asks for nothing, so there is nothing to link a file to a person even in principle.
What is handled once a file is processed for you
Bigger files, scheduled runs and connectors need a server, so on a paid plan a file does leave your machine. These are the rules that apply to it.
| Area | What we do |
|---|---|
| In transit | TLS on every connection. There is no unencrypted route into the service. |
| At rest | Encrypted storage for uploaded files and for the change logs produced from them. |
| Retention | Processed files are deleted on a schedule once a run completes. Enterprise sets its own retention window. |
| Deletion on request | Email us and your account data and stored files are removed. No retention clause overrides that. |
| Access | Access to production is limited to the people who operate it, and it is authenticated, not shared. |
| Sub-processors | Hosting, email delivery and payment processing are provided by third parties. That list is available on request and is disclosed in a DPA. |
| Training | Customer files are never used to train any model. See the section below. |
We do not sell your data and we do not train on it
Not to advertisers, not to data brokers, not to a model. Your contact list is your asset and the only reason we ever touch it is to give it back to you in better shape.
GDPR, and what you can expect from us
If you clean a customer list, you are the controller of that personal data and we are a processor acting on your instruction. That relationship is what a data processing agreement describes, and we sign one on request as part of the Enterprise plan.
In practice the browser demo removes most of the question. If the file never leaves your computer, there is no transfer, no processor and no third country involved. That is the single most useful privacy property this tool has, which is why it is the default rather than an option.
For an account you hold with us, you can ask what we store, ask for a copy, ask for a correction, or ask for the lot to be deleted. Write to app@datauntangler.com and it is handled by a person.
What we collect for an account
An email address, and the technical details every web service records: an IP address and a browser string, kept for security and abuse handling.
What we never collect
A file you cleaned in the demo, because it is never sent. No advertising trackers and no third party analytics that follow you off this site.
Reporting a problem
If you find a security issue, email us with the detail and we will confirm receipt. Please give us time to fix it before publishing.
Enterprise controls
SSO, roles and permissions, audit log export and a custom retention window are part of the Enterprise plan.
The safest way to evaluate it is the one that needs no approval
The demo runs in your browser on your own file. Nothing is uploaded, so nothing has to be signed off first.
No card required. Your file never leaves your computer.