Data Sourcing & Lawful Basis

Where contact data originates, the lawful basis relied on, what we refuse to supply, and how records are validated and suppressed.

Why this document exists

Anyone evaluating a contact-data supplier should be able to answer one question before buying: where did this data come from, and was it lawfully obtained? A supplier that cannot answer that question in writing should not be used. This document is our answer.

Sources we use

  • Publicly available business registries, licensing bodies and official company filings.
  • Business directories, trade association listings and publicly published company contact pages.
  • Data licensed from third-party providers under a written contract that warrants lawful collection and the right to sub-license.
  • Records supplied by publishers and list owners who collected them directly with notice to the individual.
  • Our own research, verification and enrichment work on the above.

Sources we refuse

  • Breached, leaked, hacked or otherwise unlawfully obtained datasets.
  • Data scraped in breach of a platform's terms of service or a technical access control.
  • Records obtained from a supplier who cannot evidence the right to supply them.
  • Special-category data under GDPR Article 9 — health, biometric, genetic, racial or ethnic origin, political opinions, religious belief, trade-union membership, sex life or sexual orientation.
  • Financial account numbers, card data, government identifiers, passwords or credentials.
  • Data relating to children, or data knowingly collected from a minor.

Lawful basis

For business-contact records in jurisdictions applying the GDPR or a comparable regime, we rely on legitimate interests under Article 6(1)(f) for the supply of business contact information to a business recipient for a business purpose, supported by a legitimate interests assessment held on file.

For consumer records, we supply only where the originating source can evidence an appropriate lawful basis, and we pass the recorded basis and source description through to the customer with the delivery so the customer can carry out its own assessment.

Where a market requires prior opt-in consent for the intended contact method — for example marketing email to individuals in much of the EEA and the UK, or SMS in several jurisdictions — the customer must confirm the intended use before delivery, and we will decline the order where the requested use is not compatible with the recorded basis.

Transparency to individuals

GDPR Article 14 requires that where personal data is not collected from the individual directly, the individual is informed. Our Your Data Rights document is the standing privacy notice for individuals whose data appears in a dataset we supply, and it is publicly reachable without an account.

Customers who use supplied data for their own campaigns take on their own Article 14 notice obligations for that processing.

Suppression and do-not-call screening

We maintain a global suppression list. Any individual who asks to be removed is added to it, and their record is excluded from all future deliveries to every customer.

Suppression is applied at delivery time, not at order time, so a record removed between order and delivery is not delivered.

  • We do not screen against every national do-not-call or preference register on the customer's behalf, because access to most registers is licensed to the calling party, not the data supplier.
  • The customer must register with and screen against the applicable register in each destination — for example the US National DNC Registry, the UK TPS and CTPS, or an equivalent national scheme — before calling.
  • Where a register is accessible to us and the customer requests it in writing, screening can be quoted as a separate service.

Accuracy, age and validation

No contact dataset is fully accurate. Records decay continuously as people change roles, numbers and addresses. We do not represent that any dataset is complete, current or error-free.

Each delivery states the collection or refresh window for the records supplied. Syntactic validation and duplicate removal are applied before delivery. Where a delivered file materially fails the agreed specification, the Refund Policy and the Service Levels document set out the replacement process.

Retention

Source datasets are retained only while there is a lawful basis and an operational need. Suppression records are retained indefinitely by design, because deleting them would cause a suppressed individual to reappear in a future dataset.

Related pages

Support is available through WhatsApp, Telegram and email. Payments are accepted in cryptocurrency only.