This Privacy Policy sets out the data processing practices of The Data Business Ltd (“The Data Business”). Please note that all data thus captured will be used and held in accordance with the requirements of the Data Protection Act 2018.
The Data Business is a data management business operating across the B2B sector. The Data Business helps its clients to better manage their data through a variety of services which, include:
Since August 2026, these services also include automated data enrichment carried out through our proprietary software “EntrIQ”, and the sale of pre-built, ready-to-use datasets.
The Data Business is the controller in respect of the activities described in this policy, save where the section “Our Role: Controlling and Processing Personal Data” states otherwise, and if you have any requests concerning your personal data or any queries regarding how we handle your data, you can contact our Data Protection Officer via:
The Data Business Email: info@the databusiness.net
The Data Business Post: Data Protection Officer, The Data Business Ltd, Mill Studio, 17A Stour Street, Canterbury, CT1 2NR.
The Data Business Telephone: +44 (0)1227 463817
We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:
The role we play in respect of your personal data depends on which service is involved:
Data enrichment services: where we enrich, cleanse or otherwise process data that a client has supplied to us for that purpose, we act as a processor on that client’s behalf, under the terms of our contract and data processing agreement with them. In this scenario, the client remains the controller, and this policy does not override the client’s own privacy notice to you. Any request you make to us about this data will ordinarily be referred to the relevant client.
Pre-built datasets: where we compile, hold and sell our own datasets (including data sourced from publicly available sources, licensed third-party providers, or client-supplied data we have been given rights to reuse), particularly through our “EntrIQ” service, we act as the controller of that data, and the remainder of this policy applies to it in full.
Much of the personal data we hold as a controller has not been collected from you directly. In line with our obligations under Article 14 of UK GDPR, we set out below where it comes from and what it consists of.
Categories of data: typically business contact details such as name, job title, employer, business address, business email address and business telephone number, together with data appended through enrichment such as company size, sector, seniority banding or similar business classifications.
Sources: this data is obtained from (a) publicly available sources, such as company websites, public filings and directories; (b) licensed third-party data providers; and (c) clients who have supplied data to us with the rights to include it in datasets we compile and sell. We do not knowingly process special category data as part of these datasets.
Legal basis: we rely on legitimate interests as the legal basis for compiling, enriching and selling this data, on the basis that it consists of business contact details processed for business-to-business purposes.
Our “EntrIQ” software carries out automated processing to enrich records, for example by appending, inferring or standardising fields such as company size, industry classification or seniority banding based on existing data. This is a form of profiling.
This processing does not produce decisions with legal or similarly significant effects on individuals, and it is not “solely automated decision-making” within the meaning of Article 22 UK GDPR. You have the right to object to this profiling at any time: see “Right to object” below.
We would like to use your personal data to send you details of products or services that we offer that we have identified as likely to be of interest to you. We will only send you information in line with the preferences you indicated when you provided the personal data.
If at any point, you would like to opt-out of receiving communications from us, or would like to change the channels (such as email or post) that we use to contact you, please contact our Data Protection Officer (all details included above).
In carrying out our business including our obligations to you, we may use sub-contractors. These will be mailing houses, email broadcasters, marketing agencies. We will ensure that they respect your privacy and abide by all data protection laws.
In addition, as part of our “EntrIQ” service, personal data may be sold or licensed to business clients as part of pre-built datasets. Once purchased, those clients act as independent data controllers of the data they have bought, and their own use of it is governed by their own privacy policy, not this one. We take reasonable steps to satisfy ourselves that clients purchasing data intend to use it lawfully and for legitimate business purposes, and our terms of sale restrict resale or unlawful use, but we cannot control a buyer’s subsequent processing once the data has been lawfully transferred.
Your personal information may be transferred to, and processed by our trusted data management suppliers. We have therefore taken appropriate safeguards to ensure that your personal information will remain protected in accordance with this Privacy Notice. These include implementing the European Commission’s Standard Contractual Clauses for international transfers of personal information, which require all companies to protect personal information they process from the EEA in accordance with European Union data protection law.
We will keep your personal data in connection with the services/products you have bought for 3 years after the last purchase. We need to retain this data for our own accounting purposes and for legal and tax purposes.
In terms of personal data that we use for marketing, we will keep this data for as long as we are able to market to you and if you withdraw your consent or opt-out of marketing communications, we will keep your contact details only to ensure that we do not contact you again for marketing purposes.
Data submitted to us by clients for enrichment is retained only for as long as necessary to perform the enrichment service and for a short period afterwards to resolve any queries, after which it is deleted or returned in accordance with our contract with the client.
Data held within our pre-built datasets is reviewed and refreshed on a rolling basis; records are kept for as long as we reasonably consider them accurate and commercially current, and are removed or corrected where they are found to be inaccurate, out of date, or where an individual has exercised their rights under this policy.
You have rights in respect of your personal data. We will need to confirm your identity before we can consider your request so, if you wish to exercise any of these rights, we will need to receive your request via either a business email address or by post on company headed paper. In both cases confirming your name, job titles, company name, address, telephone and business email address.
The right to be informed – you have the right to be told about the collection and use of the personal data you provide. This privacy policy sets out the purpose for which we process your personal data, how long we will keep your data, who we will share your data with. If you have any questions on how and why we process your data please contact the DPO. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-be-informed
Right of access – you have the right to know whether we are processing your personal data, and to a copy of that data. We would need as much information as possible to enable us to locate your data. We will respond to your request within 28 days of receipt of your request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-of-access
Right to rectification – you have the right to have any incorrect personal data corrected or completed if it is incomplete. You can make this request verbally or in writing. We will need as much information as possible to enable us to locate your data. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-rectification
Right to erasure – this right, often referred to as the right to be forgotten allows you to ask us to erase personal data where there is no valid reason for us to keep it. We will look at any request and inform you of our decision within 28 days of receiving the request. Where you ask us to erase your data, we will also remove it from any dataset we hold for sale going forward. We are not able to recall data already sold to a client prior to your request, but we will not include your data in any future sale. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure
Right to restrict processing – you have the right to ask us to restrict processing of your data. We will look at any request and inform you of our decision within 28 days of receiving the request. If you want to exercise this right, please contact the DP at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-restrict-processing
Right to data portability – you have the right to move, copy or transfer your personal data from one IT environment to another. This right applies to data that you have provided to us and that we are processing on the legal basis of consent or in the performance of a contract and that processing is by automated means. We will respond to your request within 28 days of receipt of your request. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability
Right to object – you have the right to object to our processing of your personal data based on (i) legitimate interests, or for the performance of a task in the public interests/exercise of official authority (including profiling); (ii) direct marketing (including profiling); and (iii) for purposes of scientific/historical research and statistics.
(i) Legitimate interests/legal task – your objection should be based on your situation. We can continue to process the data if we can demonstrate compelling legitimate grounds which override your interests. This includes objections to our enrichment or inclusion of your data within datasets offered for sale, which we process on the basis of legitimate interests – see “Where We Get Personal Data From” above. (ii) Direct marketing – you have an absolute right to ask us to stop processing for the purposes of direct marketing. We will action your request as soon as possible. (iii) Scientific/historical research and statistics – your objection should be based on your situation. If we are conducting research where the processing is necessary for the performance of a public task, we can refuse to comply with your objection. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-object
Rights relating to automated decision making including profiling – you have the right in respect of automated decision making, including profiling. Where we carry out solely automated decision making, including profiling, which has legal or similarly significant effects on you, we can only do this if it is in connection with a contract with you, we have a right under law or you have provided your explicit consent. We will tell you if this happens and tell you how you can request human intervention or challenge the decision. If you want to exercise this right, please contact the DPO at the contact details above. If you want to know more about this right, the ICO has more guidance on their website: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/rights-related-to-automated-decision-making-including-profiling
Where we process your personal data based on your consent you have the right to withdraw that consent at any time without reason. You can opt-out by using the unsubscribe/opt-out in any marketing we send you and you can contact the DPO at the contact details above.
If you are unhappy with any aspect of our handling of your data you can make a complaint to the Information Commissioner’s Office – https://ico.org.uk/concerns
Where you engage us to provide data cleansing, enrichment or consultancy services, we need certain personal data (such as contact and account details) to perform that contract. Without it, we will not be able to provide the service. Provision of data for our own pre-built datasets is not required from you directly – see ‘Where We Get Personal Data From’ above.
A cookie is a small piece of information sent by a web server to a web browser, which enables the server to collect information from the browser. Find out more about cookies on http://www.allaboutcookies.org. We use cookies to identify you when you visit this website and to keep track of your browsing patterns and build up a demographic profile.
Our use of cookies also allows registered users to be presented with a personalised version of the site, carry out transactions and have access to information about their account. Most browsers will allow you to turn off cookies. If you want to know how to do this please look at the menu on your browser, or look at the instruction on http://www.allaboutcookies.org. Please note however that turning off cookies will restrict your use of our website.
Our website may contain links to other websites that are outside our control and are not covered by this Privacy Policy. If you access other sites using the links provided, the operators of these sites may collect information from you that will be used by them in accordance with their privacy policy, which may differ from ours.
This privacy policy is regularly reviewed and will be updated when necessary. If we make any significant changes to the policy we will communicate these to you.
Last updated: 4th August 2026
© Copyright 2026 thedatabusiness.net All rights reserved.*
Automated page speed optimizations for fast site performance