Done-for-you list cleaning
Free check on your list

Legal

Privacy Policy

This policy was last updated on 19 August 2026. It does not constitute legal advice.

Who we are

Datuma is a UK-based contact data cleaning service operated from datuma.co.uk. This policy covers the datuma.co.uk website, the free check, and the work we run for you. Where an account was already set up for you in the Datuma portal, it covers that too. For the technical controls that back this policy, see our Security page. For all privacy queries, contact support@datuma.co.uk.

What data we collect via the website

When you contact us, ask for a check, or become a customer, we collect:

  • Your name
  • Your work email address
  • Your organisation name
  • What you tell us in the message, including a call slot preference where you give one
  • The contact spreadsheet you send us for processing (which may include names, email addresses, phone numbers, job titles, LinkedIn URLs, and organisation names).

We also collect standard server and analytics information (request logs, page views, approximate location from IP) to operate and secure the site.

The forms on this website are protected by Cloudflare Turnstile, an anti-abuse check that tells us a form was completed by a person rather than a script. To do that, Cloudflare processes your IP address and signals about your browser when the form page loads. It runs only on the pages that carry a form. Cloudflare states that it uses these signals solely to detect and block automated visits, not to identify, profile or target individuals, and that it also uses them to improve its own bot detection.

What data we process during enrichment

When a contact spreadsheet is processed (for a free check, or for a paying client), minimal identifiers from each row (name, email, LinkedIn URL where present) are sent to our contact-data enrichment provider for lookup. The provider returns professional and organisational data, which is scored by Datuma and written back into the result.

Depending on the features enabled for a given account, enrichment may also include:

  • Business email validation: a deliverability check on a business email address, returned as a status (for example, verified or undeliverable).
  • Personal mobile number: where this feature is enabled, a personal mobile number associated with a business contact, together with the date it was found and the category of source.
  • Phone number verification: where this feature is enabled, a liveness check on a phone number in the file you sent us, returned as a status (for example, live and reachable).

For paying clients, the enriched records are held in the account we run the work in and retained under the Datuma Client Agreement. That account sits in the same European Union environment as every other, in a logically separated tenancy enforced at the database row level, which is the arrangement described in our Data Processing Terms.

Where enriched contact data comes from

Some contact details in an enriched record (including business email deliverability status and, where enabled, a personal mobile number) are not collected from the individual directly. They are sourced from third-party contact-data providers. These providers collect information that is publicly available or has been made public by the individual, or obtain it from suppliers who have confirmed a lawful right to share it.

On request, we will tell an individual the category of source for a given record and, where available, the immediate source of that record. Individuals can ask us to access, correct, or delete their data, or object to its processing, using the contact details below.

Data retention

  • The file you send us: deleted 30 days after it enters our systems, by a scheduled sweep that runs daily across all accounts. It does not wait for a request from you.
  • The contact records derived from your file: kept while we are working together, so that a later check can be compared with an earlier one. There is no automatic deletion after a fixed period. They are deleted when you ask us to, and when our engagement ends.
  • The result files we produce for you: kept while we are working together. There is no automatic deletion after a fixed period. They are deleted when you ask us to, and when our engagement ends.
  • Personal mobile numbers: where this feature is enabled for an account, a personal mobile number is re-verified or expired on a 90-day cycle and is purged alongside the rest of the contact record.
  • Free check data: a free check runs in a working account we create for it. The whole account, including the file you sent, the records derived from it and the result files, is erased 7 days after the last thing happens in it: 7 days after we run the check, or 7 days after the file arrives if we never run it. That happens automatically, whether or not anyone asks, and it cannot be reversed. It is shorter than every other period on this page, and it applies to the whole account rather than to a single file.
  • Enrichment API provider: retains the minimal lookup identifiers for the term of the agreement and deletes them within 60 days of termination, under its published data processing terms.
  • Email-verification provider: retains email addresses sent for deliverability validation solely to perform the check, and deletes them on termination. Results are stored only in your isolated records in Datuma's EU environment.
  • Phone-verification provider: where phone verification is enabled, phone numbers sent for a liveness check are retained by the provider solely to perform the check, for up to 30 days. On termination all data is deleted under the DPA. Results are stored only in your isolated records in Datuma's EU environment.
  • Paying clients: retention is governed by the Datuma Client Agreement, not by this policy. Their records are held in the European Union in a logically separated tenancy, on the same infrastructure described above.

Third-party processors

We rely on the following infrastructure partners to deliver the service and the website:

  • Supabase: PostgreSQL database hosting, EU region.
  • Google Workspace: hosts our business email. A file sent to us by email, and any written instruction or correspondence, is received and stored in our mailbox until we delete it (Irish contracting entity; no data region is configured for our account, so mailbox content may be processed where the provider or its sub-processors maintain facilities, under its transfer instruments).
  • Contact-data enrichment provider: professional and organisational data enrichment. It processes the lookup identifiers we send on our instructions, as our sub-processor (EU SCCs Module 3, processor to processor, with the UK Addendum), and acts as a controller in its own right for the results it compiles and returns from its own database (Module 1).
  • Email-verification provider: email deliverability validation for business addresses (EU region).
  • Phone-verification provider: mobile number liveness validation, where this feature is enabled (UK-domiciled, under DPA).
  • Resend: transactional email delivery for results and notifications, including the email that returns finished files. A US provider: we send from its Ireland region, but it stores account data, message metadata and logs in the US whatever region is selected.
  • Language-model provider (diagnostics only): where a processing run fails, and only where this diagnostic feature is switched on for our account, a short diagnostic summary (identifiers, the error message, counts, recent log lines; no contact records) is sent to draft an internal diagnosis for our operator. Its published position for its programming interface is that inputs and outputs are deleted within 30 days of receipt, subject to four exceptions it publishes: a service with longer retention under the customer’s control, a separately agreed retention arrangement, retention needed to enforce its usage policy, and retention required by law. Where its automated systems flag a submission as a usage policy violation it retains inputs and outputs for up to two years, and classification scores for up to seven. That is its published position and not a commitment given to us.
  • GoCardless: Direct Debit mandate setup and recurring payment collection for paying clients. A UK-regulated payment institution acting as a controller in its own right, not our sub-processor: it receives the billing contact and bank details of the organisation that pays us, never a customer file or any record derived from one.
  • Netlify: website hosting for datuma.co.uk.
  • Cloudflare: Turnstile anti-abuse check on the forms on this website, processing visitor IP address and browser signals (US provider under Cloudflare's data processing addendum, certified under the EU-US Data Privacy Framework including the UK Extension).
  • Plausible Insights OÜ (Estonia): website and portal page analytics. Cookieless, no contact data, IP addresses hashed transiently and not retained (European Union).

See /subprocessors for the current sub-processor list, and our Data Processing Terms for the contractual annex stating each provider's location and transfer mechanism.

Cookies

datuma.co.uk uses a minimal set of cookies. We do not set third-party tracking or advertising cookies. Any cookies used are strictly essential for the site and its forms to function.

Your rights

Under UK and EU data protection law, you have the following rights in relation to personal data we hold about you:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to data portability
  • Right to object to processing
  • Right to restrict processing

To exercise any of these rights, email support@datuma.co.uk.

Legal basis for processing

  • Free check: legitimate interest in evaluating the product on data you have chosen to send us, together with your request to run the check.
  • Contact data enrichment: legitimate interest in helping business customers maintain accurate business contact data, balanced against the rights and reasonable expectations of the individuals concerned. Individuals can object to this processing at any time using the contact details below.
  • Paying clients: performance of the contract set out in the Datuma Client Agreement.
  • Website operation and security: legitimate interest in running a secure, functioning site.

International transfers

Where personal data is transferred outside the UK or the European Economic Area, transfers take place under EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) supplemented by a UK International Data Transfer Addendum, or under the EU-US Data Privacy Framework where a provider holds a current certification. Our contact-data enrichment provider receives lookup identifiers as our processor, under the Module 3 (processor to processor) clauses with the UK Addendum; the results it returns from its own database come back under the Module 1 (controller to controller) clauses. The full transfer position for each provider is stated in Annex 1 of our Data Processing Terms.

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top of this page shows when it last changed. Material changes will be reflected here before they take effect.

Contact

For any privacy or data protection query, email support@datuma.co.uk.