ExportFinder

Privacy Policy

Last updated: August 31, 2026

1. Roles, controller and processor

ExportFinder is a brand of PDQ Company IT-Consulting GmbH.

PDQ Company IT-Consulting GmbH

Dammstrasse 16

6300 Zug

Switzerland

Commercial Register No.: CH-170.4.007.243-9

UID: CHE-113.654.513

Email: info@exportfinder.ch

This Privacy Policy applies to exportfinder.ch, related subdomains, the ExportFinder platform, account areas, customer communications, meeting booking and related business activities. For Customer Prospect Data, the relevant customer’s privacy information and instructions apply in addition to the processor information in this Policy.

PDQ as controller for its own activities. PDQ Company IT-Consulting GmbH ("PDQ") is the controller for personal data that PDQ processes for its own independent purposes, including operation of the ExportFinder website, customer-account administration, contracting, invoicing, support, security, analytics, meeting booking and PDQ’s own business communications.

Customer as controller for prospect and campaign data. When a customer uses ExportFinder to research, identify, enrich, analyse, organise, store or communicate with that customer’s business prospects or contacts ("Customer Prospect Data"), the customer determines the purposes and essential parameters of that processing and acts as the controller. PDQ processes Customer Prospect Data on behalf of and according to the customer’s documented instructions and acts as processor, unless a specific processing activity is expressly agreed or legally required to be treated differently.

Separation of roles. PDQ’s controller role for its own website, customer and corporate operations does not make PDQ the controller of Customer Prospect Data. PDQ does not independently determine the commercial purpose for which a customer uses Customer Prospect Data.

2. Applicable law

These Terms, the use of ExportFinder, and the contractual relationship between the Customer and PDQ Company IT-Consulting GmbH are governed exclusively by the substantive laws of Switzerland, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods (CISG).

To the extent legally permissible, the exclusive place of jurisdiction for all disputes arising out of or in connection with ExportFinder, these Terms, or the contractual relationship between the parties shall be Zug, Switzerland.

Mandatory provisions of applicable law that cannot legally be excluded or modified remain unaffected.

3. Who this policy concerns

This Privacy Policy may concern:

  • visitors to our website;
  • registered users and account administrators;
  • customers and potential customers;
  • business contacts and representatives of companies;
  • prospective customers, distributors, partners or other professional contacts whose data is processed through customer-directed B2B research activities;
  • people who communicate with us or book meetings; and
  • other individuals whose professional data is processed in connection with the ExportFinder service.

4. Categories of personal data

Depending on the context, we may process the following categories of information:

Identification and contact data: name, business email address, business telephone number, company, professional role, job title and related contact details.

Account and authentication data: account identifiers, login information, authentication events, session information, device information and other information required to secure and administer user accounts.

Customer and contractual data: subscription information, service configuration, company information, correspondence, invoices, payment references and records relating to our customer relationship.

Professional and B2B data: employer, position, department, company website, public professional profile, company location, industry, company size, business contact details and other professional or company attributes relevant to a commercial relationship.

Search and service data: target markets, search criteria, company filters, product or service descriptions, research requests, generated results, notes and other information supplied or generated when using ExportFinder.

Communications data: emails, meeting requests, support requests, replies, communication history and opt-out or suppression status.

Technical and usage data: IP address or derived approximate location, browser and device information, operating system, referrer, pages or functions used, timestamps, application events, security logs and cookie or similar identifiers.

Public web content: publicly accessible business information and webpage content retrieved for research, matching and analysis.

We do not intentionally collect sensitive personal data for B2B lead-generation purposes and ask users not to submit such information unless it is strictly necessary and lawful.

5. Sources of personal data

The source of personal data depends on PDQ’s role in the relevant processing.

For PDQ’s own controller activities, we may obtain personal data directly from you, from our customer relationship, from our website and service interactions, and from service providers used for account administration, analytics, security, communications and support.

For Customer Prospect Data, the customer may provide data directly or instruct ExportFinder to retrieve, verify, enrich or analyse professional information from sources selected or permitted by the customer, including:

  • publicly accessible websites, company pages, business directories, professional profiles and registers;
  • commercial B2B data and enrichment providers, including Prospeo;
  • web research and extraction services, including Firecrawl;
  • customer-supplied lists, search criteria and company information; and
  • information generated through the customer’s use of ExportFinder.

Where Customer Prospect Data is obtained indirectly, the customer, as controller, is responsible for determining and providing any transparency information required by applicable law. PDQ supports the customer in meeting such obligations to the extent required of a processor and agreed in the applicable data-processing terms.

6. Purposes of processing

PDQ’s own controller purposes. PDQ processes personal data for its own independent purposes where necessary to:

  • operate, secure and improve the ExportFinder website and platform;
  • create, authenticate and administer customer and user accounts;
  • manage contracts, subscriptions, customer support, meetings and customer relationships;
  • send service, transactional and PDQ’s own lawful business communications;
  • perform analytics, security monitoring, fraud prevention and troubleshooting;
  • issue invoices, process bank-transfer information and meet accounting, tax and legal obligations; and
  • establish, exercise or defend legal claims.

Customer-controlled purposes. For Customer Prospect Data, PDQ does not determine the customer’s business-development purpose. The customer decides why the data is processed and instructs ExportFinder to carry out one or more technical processing activities such as:

  • B2B company and market research;
  • identifying and matching companies or professional contacts against customer-defined criteria;
  • enriching and verifying professional business-contact information;
  • AI-assisted research, classification, summarisation, ranking and lead qualification;
  • storing, organising and managing prospect records within the customer’s workspace; and
  • transmitting customer-authorised communications through available communication features.

The customer remains responsible for the purpose, lawfulness and essential parameters of these processing activities.

7. Customer-controlled B2B prospect research, enrichment and outreach

ExportFinder is a B2B research and workflow tool through which customers may instruct PDQ to process professional information concerning companies and business contacts.

The customer ultimately decides what is done with Customer Prospect Data. The customer determines the commercial objective and essential parameters of the processing, including the target market, company or role criteria, search parameters, which results or contacts it wishes to use, the intended lawful basis, whether and through which channel a contact is approached, the content and timing of any campaign, the frequency of communications, the retention period and the customer’s downstream use of the resulting data.

PDQ executes the customer’s instructions. ExportFinder may retrieve, combine, verify, structure, rank, enrich, analyse, store and transmit Customer Prospect Data using the technical tools and subprocessors described in this Policy. These implementation choices support delivery of the service and do not transfer the customer’s responsibility for determining the purpose and essential means of the processing to PDQ.

The customer is responsible for legality of its instructions and outreach. This includes determining and documenting an appropriate legal basis, providing required transparency notices, respecting access/deletion/objection rights, and complying with applicable direct-marketing, telecommunications, competition and anti-spam rules in each relevant jurisdiction, including any consent or existing-customer requirements.

Sending through ExportFinder does not change the controller. Where a customer selects recipients, determines the message or campaign parameters and instructs or authorises transmission, the customer remains the controller and responsible principal for that outreach; PDQ performs the transmission and related technical processing on the customer’s behalf.

No independent reuse by PDQ. PDQ does not use Customer Prospect Data for an unrelated PDQ marketing purpose, resell it as PDQ’s own prospect database, or independently decide that a particular customer prospect should be contacted. If PDQ separately processes information about the same person for PDQ’s own independent relationship or lawful corporate purpose, that is a separate processing activity for which PDQ acts as controller.

PDQ may refuse, suspend or limit instructions that appear unlawful, abusive or inconsistent with the contract or applicable law. Exercising such compliance and security controls does not by itself mean that PDQ determines the customer’s commercial purpose.

8. AI-assisted processing — Anthropic Claude

We use the Anthropic Claude API directly to provide AI-assisted functionality. Depending on the feature, information sent to Claude may include company information, publicly available business information, Customer Prospect Data, search criteria, user-provided information and text retrieved for research.

Where Claude is used on Customer Prospect Data, the customer determines the research or business purpose and the relevant task or criteria. PDQ invokes Claude as part of the technical processing performed on the customer’s instructions. Anthropic may act as a subprocessor or service provider for that processing under the applicable contractual arrangements.

Claude may be used for company and market analysis, classification, matching, summarisation, research, lead qualification and generation of business insights. We seek to minimise personal data submitted to AI systems and do not intentionally submit sensitive personal data unless necessary, lawful and within the customer’s instructions.

We use Anthropic’s commercial API offering. Anthropic states that inputs and outputs from its commercial products and API are not used to train its models by default unless the customer explicitly opts into an applicable programme or provides qualifying feedback. Anthropic may retain API data in accordance with its commercial service settings and policies.

9. Web research and crawling — Firecrawl

We use Firecrawl to retrieve, crawl and structure publicly accessible web content for research and analysis. When used for Customer Prospect Data, Firecrawl is invoked to perform retrieval requested or configured by the customer through ExportFinder.

Depending on a request, Firecrawl may process URLs, webpage content, metadata and professional information publicly displayed in a business context. PDQ configures the technical retrieval process but does not independently determine the customer’s commercial purpose for collecting or using the resulting information.

10. Data enrichment and verification — Prospeo

We use Prospeo, operated by Defastra Tech Inc., to find, enrich and verify B2B contact information. For customer workflows, PDQ queries or submits information to Prospeo on the customer’s instructions in order to return requested enrichment or verification results.

Prospeo may process names, employers, professional roles, business email addresses, telephone numbers, public professional profiles and company attributes. Prospeo maintains its own B2B dataset and may act as an independent controller for that underlying dataset. PDQ’s use of Prospeo to fulfil a customer instruction does not make PDQ the controller of Prospeo’s independent source dataset.

11. Accounts and authentication — Clerk

We use Clerk for user authentication and account management. Clerk may process information such as name, email address, account identifiers, login and authentication information, IP address, device information, session identifiers and security events. Clerk generally acts as a processor for customer/end-user data and may act as an independent controller for certain Clerk account or service information under its own privacy terms.

12. CRM and meeting booking — HubSpot

We use HubSpot for PDQ’s own customer relationship management and meeting booking. For these activities, PDQ is controller and HubSpot generally acts as our processor/service provider.

If a customer elects to synchronise Customer Prospect Data with a HubSpot-connected workflow supported by ExportFinder, that processing is carried out on the customer’s instructions and HubSpot may act as a subprocessor for that customer-controlled processing, subject to the applicable configuration and contractual terms.

Where HubSpot forms, scheduling pages, tracking technologies or other HubSpot components are embedded in our website, HubSpot may also receive technical information and information submitted through those components.

13. Email delivery — Mailgun

We use Mailgun / Sinch Email for email delivery. This includes PDQ service and transactional emails and, where enabled, transmission of communications that a customer instructs or authorises ExportFinder to send to that customer’s selected business contacts.

For customer campaigns, the customer determines the recipients, purpose, content or campaign parameters, lawful basis and whether the communication should be sent. PDQ and Mailgun perform the technical transmission on the customer’s behalf. Use of Mailgun or ExportFinder’s sending functionality does not transfer the customer’s controller responsibility to PDQ.

Mailgun may process sender and recipient addresses, message headers, message content, delivery events, IP addresses, bounce and complaint information, suppression data and other technical delivery information. Mailgun provides EU and US processing regions; the region applicable to our sending domain depends on our account and domain configuration. Limited account-level information may be processed globally by the provider.

14. Hosting, network security and infrastructure

Google Cloud — core cloud infrastructure, application hosting, data storage, databases, backups and related technical services.

  • Data involved: Application and customer data, configuration data, database records, logs and other data necessary to operate the service.

  • Additional information: Our core application and database hosting is located in Switzerland. Google Cloud operates the Zurich region (europe-west6).

  • Cloudflare — DNS, content delivery, network performance, website security, bot/DDoS protection and related edge services.

  • Data involved: IP addresses, request metadata, security events, device/browser information and website traffic data.

  • Additional information: Because Cloudflare operates a global network, requests may be processed through infrastructure in multiple jurisdictions in accordance with Cloudflare’s contractual and privacy arrangements.

15. Google Analytics, Tag Manager and consent technologies

We use Google Analytics 4 (GA4) to understand how our website is used and to improve performance and user experience. We also use Google Tag Manager to manage website tags and Google Consent Mode to communicate applicable consent choices to Google technologies.

Depending on the user’s settings and the applicable consent status, Google Analytics may process device and browser characteristics, pages viewed, interactions, referral information, approximate geographic information and online identifiers. Google states that individual IP addresses from users in Switzerland, the EU/EEA and the United Kingdom are not logged or stored in Google Analytics and are discarded after use for coarse geographic derivation.

Non-essential analytics and similar technologies are used only in accordance with applicable consent and objection requirements. Users can change their cookie or privacy preferences through the available consent settings and through browser controls.

16. Cookies and similar technologies

We and our providers may use cookies, local storage, pixels, SDKs and similar technologies. Some technologies are strictly necessary for authentication, security, session management, load balancing or core website functions. Others are used for analytics and service improvement.

For visitors in Switzerland, we provide information about non-essential tracking and an appropriate means to object or manage preferences. Where the applicable law requires prior consent — including in relevant EU/EEA contexts and for processing that otherwise requires consent — non-essential technologies are activated only after the required choice has been made.

17. Billing and bank-transfer payments

ExportFinder is invoiced and paid by bank transfer. We process billing contact information, invoice data, amounts due, payment references, bank-transfer confirmations and accounting records as necessary to administer the customer relationship and comply with accounting and tax obligations.

Banks and financial institutions involved in a transfer process payment information under their own legal and regulatory obligations and generally act as independent controllers for their processing.

18. Legal bases where the GDPR applies

PDQ’s own controller processing. Where the GDPR applies to processing for PDQ’s own independent purposes, PDQ relies on one or more of the following legal bases:

  • Contract (Art. 6(1)(b) GDPR): where processing is necessary to enter into or perform a contract, including providing ExportFinder to customers and customer support.
  • Legitimate interests (Art. 6(1)(f) GDPR): including operating and improving ExportFinder, maintaining customer and business relationships, securing our systems, preventing abuse and establishing or defending legal claims. We assess these interests against the rights and reasonable expectations of affected individuals.
  • Consent (Art. 6(1)(a) GDPR): where PDQ requests consent, including for certain cookies, analytics or PDQ marketing activities. Consent can be withdrawn at any time for future processing.
  • Legal obligation (Art. 6(1)(c) GDPR): where processing is necessary to meet accounting, tax, regulatory or other legal obligations.

Customer Prospect Data. For Customer Prospect Data processed by PDQ as processor, the customer/controller is responsible for identifying, establishing and documenting the applicable legal basis and for satisfying any additional requirements that apply to its intended use or outreach. PDQ does not rely on PDQ’s own legitimate interests to determine the customer’s prospecting or campaign purpose.

A data-protection legal basis does not by itself remove separate requirements that may apply to electronic marketing communications.

19. Service providers, subprocessors and recipients

We use service providers to operate ExportFinder. For PDQ’s own controller processing, these providers generally process data for PDQ under the applicable contractual arrangement. For Customer Prospect Data, providers used to perform customer-directed processing may act as subprocessors or other service providers in the processing chain, subject to the applicable DPA, subprocessor terms and service configuration.

Relevant providers and recipients may include:

  • Google Cloud — hosting and cloud infrastructure;
  • Cloudflare — network, security and content-delivery services;
  • Anthropic — Claude API for AI-assisted processing;
  • HubSpot — CRM and meeting scheduling;
  • Mailgun / Sinch Email — email delivery;
  • Prospeo / Defastra Tech Inc. — B2B enrichment and verification;
  • Firecrawl / SideGuide Technologies, Inc. — public web retrieval and crawling;
  • Clerk, Inc. — authentication and user management;
  • Google — Analytics, Tag Manager and Consent Mode;
  • banks, accountants, tax advisers, legal advisers and other professional advisers where necessary; and
  • public authorities, courts or other recipients where disclosure is required or permitted by law.

20. International data transfers

Our core application and database hosting is located in Switzerland. However, several technology providers used by ExportFinder are headquartered in or operate from the United States, the European Union, Canada and other jurisdictions. Personal data may therefore be processed outside Switzerland.

Where data is transferred to a country that is not recognised as providing an adequate level of protection, we use or rely on appropriate safeguards as required by applicable law. Depending on the provider and transfer, these may include the Swiss-U.S. Data Privacy Framework, the EU-U.S. Data Privacy Framework, recognised standard contractual clauses adapted for Swiss law, data-processing agreements, contractual confidentiality and security obligations, and supplementary technical or organisational measures.

Because provider infrastructures and subprocessors can change, the specific countries involved may vary over time. More detailed information about a particular transfer or safeguard can be requested from us at info@pdqcompany.com.

21. Retention

PDQ’s own controller data. PDQ retains its own customer, account, website, support, security and corporate records only for as long as reasonably necessary for the relevant purpose, subject to legal retention requirements and legitimate needs such as security and legal claims.

  • Customer and account information is generally retained for the duration of the customer relationship and for an appropriate period afterwards.
  • Invoices, accounting records and relevant supporting documentation are generally retained for ten years where required by Swiss accounting law.
  • Security and technical logs are retained for periods proportionate to security, troubleshooting and audit needs.

Customer Prospect Data. Customer Prospect Data is stored and retained to provide the service on the customer’s instructions and according to the customer’s configuration, contractual retention settings and applicable DPA. The customer determines the business retention purpose and is responsible for instructing deletion, correction, restriction or continued retention where required. PDQ does not retain Customer Prospect Data for an unrelated PDQ business-development purpose after the relevant customer processing ends, except where limited retention is required by law, security needs, backup cycles or the applicable processor agreement.

Third-party providers may apply technical backup or retention periods subject to our configuration, contracts and their applicable service terms.

22. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration and disclosure. Measures may include access controls, authentication, encryption in transit, infrastructure security controls, logging, monitoring, backups, least-privilege access, vendor assessments and contractual data-protection obligations.

No internet-based service can guarantee absolute security. Users are responsible for protecting their own account credentials and for notifying us promptly if they suspect unauthorised account access.

23. Your rights

Depending on the law applicable to you and the circumstances, you may have rights to:

  • obtain information about processing of your personal data;
  • access personal data concerning you;
  • request correction of inaccurate or incomplete data;
  • request deletion or destruction of personal data where applicable;
  • object to certain processing, including direct marketing;
  • request restriction of processing where applicable;
  • receive certain personal data in a portable format where the legal conditions are met;
  • withdraw consent at any time for future processing where processing is based on consent; and
  • raise concerns with the competent data-protection authority.

Where PDQ is the controller, you can exercise applicable rights by contacting info@pdqcompany.com. We may request information reasonably necessary to verify your identity and locate the relevant data.

Where the relevant data is Customer Prospect Data, the ExportFinder customer is the controller and is ultimately responsible for deciding and responding to the request. If a request is sent to PDQ, we may identify the relevant customer, forward or refer the request to that customer and provide the technical assistance required of us as processor. PDQ does not independently decide the customer’s lawful basis, retention purpose or response to a data-subject request, except to the extent PDQ has a separate legal obligation.

Rights can be subject to statutory exceptions, competing rights and legal retention obligations. In Switzerland, you may also contact the Federal Data Protection and Information Commissioner (FDPIC / EDÖB). Where the GDPR applies, you may have the right to lodge a complaint with the competent EU/EEA supervisory authority.

24. Customer as controller; PDQ as processor

Controller responsibility remains with the customer. For Customer Prospect Data, the customer is the party that decides why the processing takes place and the essential parameters of how the data will be used. The customer therefore acts as controller and remains ultimately responsible for its processing instructions and use of the resulting data.

Customer Prospect Data includes professional contact and company-related personal data that a customer supplies to ExportFinder or instructs ExportFinder to locate, retrieve, enrich, verify, analyse, rank, organise, store or use for customer-authorised communications.

Customer decisions include, in particular: the customer’s commercial objective; target countries and markets; company, industry, seniority and role criteria; search and qualification criteria; which contacts or results to select; the lawful basis and transparency approach; whether, when and how to contact a prospect; communication content and frequency; opt-out handling; retention; export; and any downstream use.

PDQ acts on documented instructions. PDQ processes Customer Prospect Data only to provide ExportFinder and perform the processing operations instructed or configured by the customer, subject to the agreement, DPA and applicable law. Customer use of product controls, searches, filters, workflows and campaign authorisations may constitute documented instructions within the scope agreed with PDQ.

Technical implementation remains with PDQ. PDQ may determine non-essential technical and organisational means needed to provide a secure and functional service, such as infrastructure architecture, security controls, APIs, algorithms, technical workflows, routing, storage technology and approved subprocessors. Those implementation decisions do not authorise PDQ to determine an independent commercial purpose for Customer Prospect Data.

Customer compliance obligations. The customer is responsible for ensuring that its instructions and use of ExportFinder are lawful, including the validity of any legal basis, required notices, consent requirements, direct-marketing and anti-spam rules, suppression/objection handling and data-subject rights. The customer must not instruct PDQ to perform processing that the customer itself is not permitted to perform.

PDQ assistance. PDQ provides reasonable processor assistance with security, data-subject requests, deletion/export functions and other obligations as required by applicable law and the DPA. PDQ may refuse or suspend unlawful instructions and may process limited information where independently required to comply with law, maintain security or establish legal claims.

No independent commercial use. PDQ does not sell, repurpose or use Customer Prospect Data for PDQ’s own unrelated marketing or independent prospecting. At the end of the relevant processing relationship, Customer Prospect Data is returned or deleted according to the contract, DPA, customer instructions and applicable legal requirements.

This allocation of roles reflects the intended operation of ExportFinder. The legal classification of a specific processing activity always depends on the actual facts and applicable law.

25. Automated processing and profiling

ExportFinder uses automated tools and AI to classify companies, enrich information, rank or match business opportunities, structure research and assist with lead qualification. Where these activities involve Customer Prospect Data, they are performed for the customer-defined purpose and under the customer’s instructions.

The customer determines the criteria, intended use and business consequences of the output and remains controller for any customer-directed profiling or subsequent decision. PDQ does not use ExportFinder to make its own independent decisions about customer prospects.

ExportFinder is not intended for solely automated decisions about individuals that produce legal effects or similarly significant effects. It must not be used for decisions concerning consumer credit, insurance eligibility, employment, housing or other similarly high-impact individual decisions unless expressly supported and lawfully implemented.

26. Children

ExportFinder is a professional B2B service and is not directed to children. Customer-directed B2B research and lead-generation workflows must not be used to intentionally collect personal data relating to children.

27. Required disclosures and corporate transactions

For data for which PDQ is controller, we may disclose personal data where reasonably necessary to comply with applicable law, respond to a legally binding request, protect the security or integrity of our services, investigate misuse or fraud, protect our rights or those of others, or establish, exercise or defend legal claims. For Customer Prospect Data, disclosures are made on the customer’s instructions, through approved subprocessors, or where PDQ is independently required by law to disclose information.

Personal data may also be transferred in connection with a merger, financing, restructuring, acquisition, sale of assets or similar corporate transaction, subject to applicable data-protection requirements.

28. Changes to this Privacy Policy

We may update this Privacy Policy when our services, technology, providers, processing activities or applicable legal requirements change. The current version will be published on our website and the “Last updated” date will indicate the latest revision. Where required, we will provide additional notice of material changes.

29. Contact

PDQ Company IT-Consulting GmbH — ExportFinder
Dammstrasse 16, 6300 Zug, Switzerland
Email: info@exportfinder.ch

Legal Notice

Liability for Content

The contents of this website have been prepared with the greatest possible care. However, PDQ Company IT-Consulting GmbH does not guarantee the accuracy, completeness, or timeliness of the information provided.

Liability for External Links

This website may contain links to external third-party websites over whose content PDQ Company IT-Consulting GmbH has no control. Responsibility for the content of linked websites lies solely with their respective providers or operators.

Copyright

The content and works published on this website are subject to applicable copyright law. Any reproduction, modification, distribution, or other use beyond the limits permitted by copyright law requires the prior written consent of the respective rights holder.