This statement sets out where the data we supply comes from, the lawful basis on which we collect and disclose it, the checks we run before a record is supplied, and what a buyer is responsible for once it is delivered. It is written for the person doing supplier due diligence, not for marketing.
It applies to every customer on identical terms. Where we enter a written supply agreement, that agreement incorporates this statement by reference at the version in force on the date of supply. Superseded versions are archived and available on request, so you can always evidence the terms that applied when your data was delivered.
1. What We Supply, And Why It Is Personal Data
We supply business contact data: organisations, and named individuals in their professional capacity at those organisations, together with role, business email address, business telephone number and business address.
Where a record names an individual, it is personal data under the UK GDPR, and we treat it as such. The fact that data is about someone at work, or was publicly accessible when we collected it, does not take it outside data protection law. We say this plainly because suppliers who claim otherwise are the source of most buyer-side problems.
We do not supply consumer data, special category data, or data about individuals in a personal capacity.
2. Where The Data Comes From
Every record we supply is traceable to one of the following source classes, and the class is recorded against the record in the delivered file.
| Source class | What it provides | Method |
|---|---|---|
| Statutory registers | Company identity, number, registered office, incorporation date, officers, persons with significant control | Companies House public register, via its official API |
| Sector regulators and public bodies | Regulated-entity identity, registration status, site addresses, published contact details | Official published datasets and APIs, for example the Care Quality Commission, the Food Standards Agency, NHS organisation reference data, the Department for Education, and local planning authority portals |
| Published business listings | Trading name, trading address, business telephone, website, opening hours, category | Business listings published by the organisation itself on mapping and directory platforms |
| The organisation's own website | Business email addresses, named staff and roles, telephone numbers, as published by the organisation on its own pages | Automated retrieval of publicly accessible pages, respecting each site's robots directives |
| Licensed third-party providers | Named contacts, job titles, business email addresses, professional profile links | Commercial B2B data providers under licence, where that licence permits onward supply |
3. How Email Addresses Are Obtained
Business email addresses reach a delivered file by one of two routes, and the route is recorded against each record.
- Published. The address was published by the organisation itself, on its own website, in a public register, or in a business listing it controls.
- Pattern-derived and verified. Where an organisation publishes a consistent address format, we may derive a likely address for a named individual at that organisation's own domain, and then confirm it exists before supply. A derived address is never supplied unverified, and is always labelled as derived.
We do not supply personal email addresses, addresses obtained from breached or leaked datasets, or addresses obtained from any source we are not entitled to use.
4. Accuracy And Verification
Accuracy is a legal obligation under Article 5(1)(d) of the UK GDPR, not a quality nicety. Before supply:
- Every email address is checked against a third-party verification service, and the result and the date of that check are supplied with the record.
- Addresses returning an invalid or undeliverable result are removed, not supplied with a warning.
- Role-based addresses, such as info@ or enquiries@, are flagged as such so you can decide whether they fit your campaign.
- Company status is re-checked against the register at build time, so dissolved and closed entities are excluded.
- The date each record was captured is supplied, so you can judge freshness rather than take it on trust.
5. Corporate Subscriber Screening
This is the check that matters most for direct B2B email marketing, and it is the one most commonly skipped in this market.
Under regulation 22 of the Privacy and Electronic Communications Regulations 2003, unsolicited marketing email may be sent to a corporate subscriber without prior consent. A corporate subscriber is a limited company, a limited liability partnership, a public limited company, a Scottish partnership, or a corporate or public body. Sole traders and ordinary partnerships are individual subscribers, and consent is required to send them marketing email.
Any list of small businesses drawn from trade listings contains sole traders. We therefore match every record against the Companies House register before supply and record its entity type. Depending on what you have asked for, we either:
- supply only records confirmed as corporate subscribers; or
- supply the full set with each record labelled by entity type, so you can apply your own policy.
Which of the two applies is stated on the delivery note for your file. If you intend to run unsolicited email marketing, we recommend the first.
We do not claim this is opt-in data, and you should not describe it that way. The individuals in these files have not consented to receive marketing from you. Lawful use rests on the corporate subscriber position under PECR and on legitimate interests under the UK GDPR, both of which depend on the recipient being able to object easily and on that objection being honoured. A supplier who tells you their scraped or register-derived B2B list is "consented" or "opt-in" is describing something that does not exist.
6. Lawful Basis
We rely on legitimate interests, Article 6(1)(f) of the UK GDPR, for collecting business contact data and disclosing it to a buyer for business-to-business marketing. We have carried out and documented a Legitimate Interests Assessment covering the purpose test, the necessity test and the balancing test. A summary of that assessment is available to customers on request.
In summary: the interest is the supply of accurate business contact data so that suppliers of relevant products and services can reach the businesses that buy them; there is no less intrusive way to achieve it, because a business cannot be contacted without its contact details; and the impact on individuals is limited because the data concerns them in a professional capacity, is restricted to business contact points, is drawn from information already published or held on a public register, and carries an unconditional right to object which we act on across every brand we operate.
7. Transparency
Because we do not collect this data from the individual directly, Article 14 of the UK GDPR applies. Our own privacy information is published at b2bdatascout.co.uk/privacy and sets out the categories of data we hold, our sources, our purposes and the rights available.
Article 14 also applies to you as an independent controller once the data is in your hands. Where personal data is used to contact someone, the obligation is discharged at the latest in that first communication. In practice this means your first email must identify you and link to your own privacy notice. See section 9.
8. Suppression, Objections And Retention
- We operate a single suppression list across every brand, campaign and sending domain we run. One objection suppresses an address everywhere, permanently.
- Suppression is actioned within three working days and normally the same day.
- Records suppressed with us are excluded from all future supply. Suppression cannot reach data already delivered to you, which is why your own obligations in section 9 matter.
- We keep the minimum record needed to enforce a suppression, being the address itself, and use it for nothing else.
- We hold a record of what was supplied to whom and when, for the period needed to answer a rights request or a regulator, and to evidence the terms of supply.
- Requests for access, rectification, erasure or objection can be made to hello@b2bdatascout.co.uk and are answered within one month.
9. Your Responsibilities As Recipient
We supply data to you as an independent controller. We are not your processor, you are not ours, and we are not joint controllers. Each of us is separately accountable for our own processing. That means the following are yours, and we cannot discharge them for you:
- Carry out your own Legitimate Interests Assessment for your campaign. Ours covers our supply, not your use. Yours turns on what you are selling and whether it is genuinely relevant to the recipient's role.
- Provide your own privacy information at first contact, satisfying Article 14. A single line and a link in the first email is the accepted route.
- Identify yourself clearly as the sender. Do not disguise the originating domain or use a misleading subject line.
- Offer a working opt-out in every message, and honour it promptly and permanently across all your sending.
- Respect the corporate subscriber boundary. If we supplied entity type rather than pre-screening, applying it is your decision and your responsibility.
- Keep the data secure, restrict access to staff who need it, and delete it when your purpose ends.
- Do not resupply. Data is licensed for your own use. It may not be resold, sublicensed, published, or transferred to another party, including a group company, without our written agreement.
- Tell us about objections you receive that relate to data we supplied, so we can suppress at source and stop the same record reaching anyone else.
- Do not use the data for consumer marketing, for automated calls, or for SMS marketing without the consent those channels require.
We withdraw access, without refund, from any customer we find using our data to send unsolicited bulk email to consumers or otherwise in breach of this statement.
10. What We Warrant, And What We Do Not
Precision here protects both of us. We warrant that, at the date of supply:
- the data was obtained from the source classes described in section 2, and lawfully so;
- we are entitled to supply it to you for the purpose agreed;
- each record carries the source, capture date, entity type and verification result stated on the delivery note;
- the file has been screened against our suppression list;
- no record was obtained from a breached, leaked or unlawfully acquired dataset, or in knowing breach of a third party's terms of use.
We do not warrant that the individuals named have consented to receive marketing, because they have not. We do not warrant that your intended use is lawful, because that depends on your campaign, your basis and your process, none of which we control. We do not warrant uninterrupted accuracy after the date of supply, because business contact data decays and no supplier can honestly promise otherwise.
11. Security And Location
Data is processed in the United Kingdom and delivered to you over an access-controlled channel to a named recipient. We do not transfer supplied data outside the UK without a lawful transfer mechanism. Access within our business is limited to those who need it to build and deliver a file.
12. Evidence Supplied With Every Delivery
Compliance claims are worth little without record-level evidence, so every file supplied under this statement carries its own. Alongside the data you receive a short delivery note stating the file, the date, the record count, the sources used, the screening applied, and the verification date. The file itself carries the following fields on every row:
| Field | What it tells you |
|---|---|
source | Which source class in section 2 the record came from |
source_ref | The register number, listing or page the record is traceable to |
captured_date | When we collected it |
entity_type | Limited company, LLP, sole trader, partnership, public body, or unmatched |
email_origin | Published, or pattern-derived and verified |
email_verified_date | When the address was last confirmed deliverable |
13. Complaints
If you believe data we supplied has been misused, or you have received a message you object to, write to hello@b2bdatascout.co.uk. We investigate every report and reply with what we found and what we changed.