Done-for-you list cleaning
Free check on your list

Legal

Datuma Data Processing Terms

Version 1.0. Effective 7 August 2026.

These terms govern our processing of personal data contained in any file or record set you send us, or authorise us to retrieve, for a contact data quality check. They apply from the moment a file is accepted, including to a free check. They are the written contract required by Article 28(3) of the UK GDPR.

These terms are not legal advice, and they do not replace your own assessment of your lawful basis for sharing the data with us. Annexes: Annex 1, Sub-processors · Annex 2, Retention.

1. Who we are, and the roles of the parties

Us (the processor). DATUMA LTD, a company registered in England and Wales under company number 16428722, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Registered with the Information Commissioner's Office under registration number ZC209580. Contact for all matters under these terms: support@datuma.co.uk.

You (the controller). The organisation that sends us the file, or on whose instruction the file is sent, as identified in the documented instruction described in section 2.

The roles. You determine the purposes and means of the processing. We process the personal data only on your behalf and only on your instructions. We are your processor.

If you are acting for a client of your own. Where the records belong to a client of yours and you are handling them as that client's processor, you are engaging us as a sub-processor. In that case these terms apply between us and you, and you confirm that your own contract with your client permits you to engage us and that you have your client's prior specific or general written authorisation as required by Article 28(2). We accept the same data protection obligations towards you as your contract with your client places on you, to the extent those obligations relate to the processing described in section 3. You remain fully liable to your client for our performance. Tell us at the point of intake that you are acting for a client, so that the record shows it.

2. How these terms are accepted, and what sits alongside them

These terms are accepted in writing, electronically, before any file is accepted for processing. Acceptance is recorded with the accepting person's name, email address, organisation, the date and time, and the version of these terms accepted. Where you accept them by replying to us in writing, your reply is that record, and we keep it.

Each engagement also has a documented instruction: a short written record, given by you, that identifies you, confirms your authority to instruct us, describes the file, states what you are asking us to do with it, and states your retention choice. An instruction given by email or recorded on an order form satisfies this requirement, provided it can be saved. The ICO confirms that an instruction may be documented in any written form, including email, so long as there is a saved record of it.

These terms and the documented instruction together form the contract required by Article 28(3). Commercial matters (price, payment, scope of work, liability) are governed separately by our service terms and by the quote or order you accept. Where our service terms and these terms conflict on a data protection matter, these terms govern.

3. Details of the processing

Subject matterChecking, correcting and reporting on the quality of business contact records that you supply to us.
DurationFrom acceptance of a file until the data is deleted in accordance with section 4.7 and the retention statement that accompanies these terms.
Nature of the processingReceiving your file, by email or from a link you give us, and storing it; loading it into our systems and parsing it; identifying duplicate and conflicting records within it; validating business email addresses for deliverability; where you have asked for it and it is enabled for your account, validating mobile number liveness; attempting to establish whether the named individual is still in the role and organisation your record states, using third-party sources; scoring and classifying records; producing result files and a written report; reviewing and assembling those results by hand; returning them to you; and deleting the data.
Purpose of the processingSolely to perform the check you have instructed and to return the results to you. We do not use the personal data in your file for any other purpose. We do not sell it, licence it, share it with any party other than the sub-processors and the one instructed recipient listed in the annex, use it to build or enrich any product or dataset offered to others, or use it to train any machine learning model.
Type of personal dataBusiness contact data: name; business email address; job title or role; employer or organisation name; business telephone number; professional profile URL; and the other fields present in the file you send. Where you have asked for it and it is enabled for your account, a personal mobile number. Derived fields we produce, such as deliverability status, duplicate grouping, role verification outcome and a quality score.
Categories of data subjectYour business contacts, prospects, customers and CRM records: individuals acting in a professional or business capacity. Where you are acting for a client of your own, the data subjects are that client's business contacts.
Special category and criminal offence dataNone. You must not send us data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, data concerning health, sex life or sexual orientation, or data relating to criminal convictions or offences. If such data is present in a file, tell us before you send it.
Your obligations and rights as controllerYou determine what we do with the data and may change or withdraw your instructions at any time. You are responsible for the lawfulness of the processing you instruct, for the accuracy of what you send us, and for meeting your own transparency obligations to the individuals concerned. You may require us to delete or return the data at any time, may request the information described in section 4.8, and may object to a new sub-processor as described in section 4.4.

4. Our obligations

4.1 Processing only on your documented instructions

We process the personal data only on your documented instructions, including in relation to any transfer of personal data outside the United Kingdom, unless we are required to do otherwise by law. If we are required by law to process the data other than on your instructions, we will tell you before doing so unless the law prohibits us from telling you.

Your instructions are: these terms, the documented instruction for the engagement, the intake preferences you record with us (what the results should load into, whether evidence sits in the file or alongside it, and anything in the file we must never touch or add to), and anything else you tell us in writing.

If we think an instruction of yours breaches data protection law, we will tell you promptly and may pause the processing concerned until the point is resolved.

We do not determine the purposes or means of the processing. If we ever did, we would be a controller in respect of that processing and would carry a controller's liability for it.

4.2 Duty of confidence

Every person we allow to process the personal data is bound by a written commitment of confidentiality, or is already under a statutory duty of confidence. This covers our staff and any contractor, temporary worker or agency worker with access to the data. Confidentiality obligations survive the end of the engagement.

At the date these terms took effect, one named individual has access to customer data and no contractor has been given access. Any contractor engaged in future will sign a confidentiality undertaking before access is granted.

4.3 Security

We take appropriate technical and organisational measures to secure the personal data, as required by Article 32. The measures in place are:

  • Location. Your file and the records derived from it are held in the European Union, in Ireland, on our hosting platform's infrastructure. See the annex for the providers involved and section 5 for the limited cases where data leaves the UK and EU.
  • Data in transit, into our systems. Once your file is with us it is uploaded into our hosting platform over an enforced encrypted connection. A failed encryption negotiation fails the upload; it does not fall back to an unencrypted transfer.
  • Data in transit, between you and us. You send us your file, and we send your results back to you. Both legs normally travel by email, and email is not a channel either of us controls end to end. Mail servers ordinarily negotiate an encrypted connection and ours is configured to do so, but we do not claim more than that, because the guarantee is not ours to give. If you would rather your contact data did not travel as an email attachment, tell us at intake and we will agree an alternative: you send us a time-limited link from your own file store and we retrieve the file from there, and we return your results the same way. We ask for the file at one stated address, given to you directly, and we do not publish an intake address.
  • Data at rest. Encryption at rest is provided by our hosting platform, which states in its published security description that all customer data is encrypted at rest with AES-256 and in transit with TLS, and that access tokens and keys are additionally encrypted at the application level before being stored. We rely on that statement and we have not independently tested it.
  • Separation. Each customer's data is held in a logically separated tenancy, enforced at the database row level. Access to the processing functions is restricted to service credentials that are not issued to customers or to any third party.
  • Access to results. Links to result files are issued individually and are scoped to your account. A link sent to you by email expires 48 hours after it is sent; a link issued to you in the portal expires one hour after it is issued.
  • Access control. Access to customer data is limited to the individuals who need it to perform the check, and each is subject to section 4.2.
  • Logging. Processing activity and administrative actions are logged, including account erasure events.
  • Deletion by default. Raw uploaded files are deleted automatically on a schedule, as described in the retention statement, without waiting for a request from you.
  • Review. We review these measures and update them as the service changes.

We do not hold a security certification. We do not claim adherence to an approved code of conduct or certification scheme.

4.4 Sub-processors

You give us your general written authorisation to engage the sub-processors listed in the annex to these terms, and only for the purposes stated there for each of them.

If we intend to add or replace a sub-processor, we will give you at least 30 days' written notice before that sub-processor starts processing your data. You may object on reasonable data protection grounds within that period. If you object and we cannot offer you a reasonable alternative, you may terminate the engagement for the affected processing and we will delete or return the data under section 4.7 without penalty to you.

Where we engage a sub-processor, we put a written contract in place imposing data protection obligations that offer an equivalent level of protection for the personal data to those in these terms. We remain fully liable to you for the performance of each sub-processor's data protection obligations.

The current list, and the purpose and location of each sub-processor, is in the annex. It is also available at https://datuma.co.uk/subprocessors/.

One disclosure sits outside this section, and we state it here so the clause above cannot mislead by omission. The contact data enrichment provider described in section 5 processes the lookup identifiers we send it under its own published terms, as a controller in its own right rather than on our instructions. It is a recipient of personal data disclosed on your instruction, not our sub-processor, and the equivalent-protection commitment above does not describe it. The annex discloses it separately, with the data it receives and the transfer mechanism in force, and the notice and objection rights in this section apply to a change of that provider in the same way.

4.5 Data subjects' rights

We take appropriate technical and organisational measures to help you respond to requests from individuals exercising their rights, including access, rectification, erasure, restriction, portability and objection.

In practice this means: we can locate and export the records we hold for a named individual within your account; we can delete a record on your instruction; we record, per record, the category of source for any contact detail we did not receive from you; and we can tell you what we did to a given record and when.

If an individual contacts us directly about data we hold for you, we will not respond to the substance of the request. We will tell them to contact you, and we will tell you promptly.

4.6 Assisting you

Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations to keep personal data secure, to notify personal data breaches to the Information Commissioner's Office, to notify personal data breaches to affected individuals, to carry out data protection impact assessments where required, and to consult the Information Commissioner's Office where a data protection impact assessment indicates a high risk that cannot be mitigated.

Breach notification. We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data we process for you. The notification will describe, so far as we know it at the time: the nature of the breach, the categories and approximate number of records and individuals affected, the likely consequences, and the measures taken or proposed. Where we cannot provide all of that at once, we will provide it in phases without further undue delay.

4.7 Deletion and return at the end of the engagement

At the end of the engagement, at your choice, we will delete all the personal data we process for you, or return it to you and then delete our copies. If you do not tell us which you want, we will delete.

You may ask us to delete the data at any time, not only at the end of the engagement, and we will do so.

Deletion is carried out securely. Certain data is deleted automatically on a schedule whether or not you ask: the retention statement that accompanies these terms sets out what is deleted, when, and by which mechanism.

Backups. Deleting live data does not immediately remove it from system backups. Backup copies are held in the same environment, are not accessible to the service or used to serve requests, and are overwritten on the backup cycle. Any copy of your data remaining in a backup after deletion is put beyond use, and is removed on the next backup expiry cycle. The retention statement gives the current backup cycle. This reflects the ICO's stated position that where appropriate safeguards are in place, such as data being put beyond use, it may be acceptable for data not to be deleted from backups immediately, provided the retention period is appropriate and the data is deleted as soon as possible on the next deletion cycle.

We keep no copy of your file or your records after deletion, other than: records of the fact that processing occurred (dates, counts, the identity of the accepting person, the version of these terms accepted, and billing records), which contain no contact records of yours and which we keep because we are required to be able to demonstrate compliance and to keep accounting records.

4.8 Information, audits and inspections

We will make available to you all information necessary to demonstrate that the obligations of Article 28 have been met, and will allow for and contribute to audits and inspections carried out by you or by an auditor you appoint.

In practice, we expect most requests to be answered with information: this document, the annex, the retention statement, our security description, and a written answer to specific questions. If information is not sufficient for your purposes, you may audit us on reasonable prior written notice, no more than once in any twelve month period, except following a personal data breach affecting your data or where a supervisory authority requires it, in which case you may audit as often as is necessary. Audits take place during business hours, must not unreasonably disrupt our operations, and are at your cost unless the audit reveals a material breach of these terms by us.

5. International transfers

Your file and the records derived from it are held in the European Union, in Ireland. We do not transfer them outside the UK and EU except as set out in this section and in the annex.

Two of the transfers below concern the way your file reaches us and the way your results reach you, rather than the checking work itself. They are listed first because they are the ones a reader is most likely to assume do not exist.

The following are the only transfers that occur, each of them limited to the data described:

  • Your file reaching us, and our correspondence with you. Where you send us your file by email, and whenever you write to us, the message and anything attached to it is received and stored in our mailbox, which is hosted by the mail provider named in the annex. Where that provider processes or stores mailbox content outside the UK and EU, that is a transfer of whatever you put in the message, which may include your file. The annex states that provider's processing location and the transfer instrument in force. We delete the mailbox copy of your file once it is safely in our systems, and the retention statement says so. If you prefer this transfer not to happen, send us a link from your own file store instead, as described in section 4.3.
  • Your results reaching you. Result files are sent to you through the transactional email provider named in the annex, either as attachments or, where they are too large to attach, as a time-limited link. That provider therefore transmits the finished records we produced for you. Its processing location and transfer instrument are in the annex.
  • Support access to the hosting platform. Your data stays in Ireland, but the company that operates that platform is established in Singapore and its support function is provided by a group company in the United States. It follows that platform personnel outside the UK and EU may in principle be able to access data held in Ireland in the course of supporting the service. We record this because a reader who saw only "held in Ireland" would reasonably assume otherwise. The instrument covering it is in the annex.
  • Role and organisation verification. Where you instruct the identity layer, individual lookup identifiers (such as a professional profile URL, a name, and a company domain) are sent to our contact data enrichment provider, which is established in the United States. That provider processes the identifiers under its own published terms, as a controller in its own right rather than on our instructions: it is a recipient of the data, not our sub-processor, and section 4.4 and the annex record that distinction. The transfer is covered by the EU Standard Contractual Clauses (Decision (EU) 2021/914), Module 1 (controller to controller), with the UK International Data Transfer Addendum (ICO template version B1.0).
  • Mobile number liveness. Where you instruct the phone layer and it is enabled for your account, the telephone number alone, with no name or other contact detail attached, is checked against the destination telephone network. Destination networks and the intermediaries used to reach them may be located anywhere in the world. Only the number is transmitted. We do not claim that telephone number checks stay within the UK or EU.
  • Diagnostic assistance on a failed run. Where a run fails, a short diagnostic summary may be sent to a language model provider established in the United States to draft an internal diagnosis and a suggested reply for our operator. The summary contains the batch identifier, the account identifier, the uploaded file name, the recorded error message, record counts, and recent processing log lines. It does not contain contact records. See the annex for the scope limits and the residual risk we record honestly.

Business email deliverability validation is performed in the European Union.

Where a transfer requires it, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on another lawful transfer mechanism, as recorded in the annex for each entry.

6. Your obligations and warranties

You confirm and warrant that:

  1. You are authorised to instruct us in respect of the personal data you send us, and where the data belongs to a client of yours, that your contract with that client permits you to engage us as a sub-processor and that you hold the authorisation required by Article 28(2).
  2. You have identified a lawful basis under Article 6 for the processing you instruct, and where you rely on legitimate interests you have carried out and recorded the balancing assessment.
  3. You have met, or will meet, your transparency obligations to the individuals concerned under Articles 13 and 14, including in relation to any contact detail we source from a third party on your instruction.
  4. The personal data you send us contains no special category data and no criminal offence data, as described in section 3.
  5. You will not send us personal data relating to individuals under the age of 18, and you will not send us personal data outside the categories described in section 3.
  6. You have told us about any record or field in the file that we must not touch or add to, and about any individual in the file who has objected to processing or asked to be suppressed.

If any of these ceases to be true during the engagement, you will tell us without delay.

7. Changes to these terms

We may update these terms. Where a change materially affects your rights or our obligations, we will give you at least 30 days' notice before the new version applies to processing we carry out for you, and you may terminate the affected processing if you do not accept it. Each engagement records the version accepted, and that version governs the processing carried out under it.

8. Governing law

These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

9. Contact

For any matter under these terms, including a data subject request, a breach notification, an audit request, an objection to a sub-processor, or a request to delete your data, write to support@datuma.co.uk.

We are not required to appoint a statutory Data Protection Officer and have not appointed one. Responsibility for data protection matters sits with the director of DATUMA LTD, who is reached directly at support@datuma.co.uk.

Annex 1: Sub-processors

Annex 1 to the Datuma Data Processing Terms, version 1.0. Effective 7 August 2026.

These are the sub-processors Datuma engages to deliver the service. You give your general written authorisation to each of them, for the purpose stated. We will give you at least 30 days' notice before adding or replacing any of them, and you may object on reasonable data protection grounds.

# Sub-processor What it does with your data Data it receives Location of processing Transfer mechanism
1 Supabase Pte. Ltd. (Singapore), registered at 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513, operating on Amazon Web Services infrastructure Hosts the database, the application functions, the file storage and the account system. This is where your file and the records derived from it are held. All data in your file and everything derived from it Your data is stored in the European Union, in Ireland, and it is not moved out of Ireland to be processed. The company we contract with is established in Singapore, and its own group company Supabase, Inc. in the United States provides its support function, so the people who can reach the platform are not all in the UK or EU. We state this rather than let the Irish location imply otherwise. EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 where you are a controller and Module 3 where you are a processor, together with the UK International Data Transfer Addendum (ICO template version B.1.0). No Data Privacy Framework reliance is possible or claimed here, because the company we contract with is not US established.
2 Email verification provider Validates whether a business email address is deliverable. Business email addresses European Union data centre (EU API endpoint) UK International Data Transfer Addendum (ICO template B1.0) wrapping EU Standard Contractual Clauses 2021/914, Module 2 (controller to processor). Bilaterally executed 2026-06-23. Provider also registered under the EU-US Data Privacy Framework.
3 Phone verification provider Checks whether a mobile number is live, and its carrier and line type. Runs only where you instruct the phone layer and it is enabled for your account. The telephone number alone. No name or other contact detail is attached. Provider is UK domiciled. The lookup itself is not UK or EU contained: the bare number is queried against the destination telephone network, which may be located anywhere in the world. Controller and Processor Agreement, counter-signed 2026-06-26. Provider's own sub-processors: Amazon Web Services, Google, and any destination network or intermediary that must be queried.
4 Plus Five Five, Inc. (United States), trading as Resend, 2261 Market Street #5039, San Francisco, CA 94114 Sends the emails our systems generate. This includes the delivery email that hands your finished files back to you: the result files are attached to it, so this provider transmits the full contact records we produced for you. Where files are too large to attach, the email instead carries a time-limited link and the provider transmits the link, not the files. It also sends account and results-notification emails where you hold an account with us. The recipient's email address; the finished contact records where they are attached; contact names, employers and profile links where a digest is sent United States. We send from the provider's Ireland region, but the provider states that account data, message metadata, logs and API records are stored in the United States whatever region is selected. We state that rather than let the Ireland setting imply EU storage. EU Standard Contractual Clauses (Decision (EU) 2021/914), Modules 1, 2 and 3 as applicable, and the same clauses as amended by the UK Addendum for UK transfers. The provider also states it complies with the EU-US Data Privacy Framework and its UK Extension.
5 Google Cloud EMEA Limited (Ireland), 70 Sir John Rogerson's Quay, Dublin 2, for Google Workspace Hosts our business email. Where you send us your file by email, or send us your written instruction and acceptance, the message and any attachment are received and stored in our mailbox on this provider's systems until we delete them. It also carries our ordinary correspondence with you, and anything you write to support@datuma.co.uk, including a data subject request. Whatever you put in a message to us: your instruction, and where you send it by email, your file and the contact records in it No data region commitment is configured for our account. The provider offers a data region setting for mailbox content only on certain editions, and ours does not include it, so its terms allow mailbox content to be processed in any country where it or its sub-processors maintain facilities. We state that rather than let the Irish contracting entity imply otherwise. EU Standard Contractual Clauses (Decision (EU) 2021/914) at the provider's published clause URLs, with the UK International Data Transfer Addendum (ICO template version B1.0) for UK transfers. The provider also relies on the EU-US Data Privacy Framework and, since 16 September 2024, its UK Extension.
6 Netlify, Inc. (United States), 512 2nd Street, Suite 200, San Francisco, CA 94107 Serves the website and the portal's static pages. It does not receive your file or any record derived from it; contact data travels directly between your browser and the hosting platform at entry 1. Connection data only (IP address, request metadata) United States, served through a global content delivery network EU-US Data Privacy Framework and its UK Extension, on which the provider states it is certified. Where that certification does not apply, EU Standard Contractual Clauses (Decision (EU) 2021/914), Module 2 or Module 3, and the UK International Data Transfer Addendum.
7 Language model provider (diagnostics only) Where a processing run fails, a short diagnostic summary is sent to draft an internal diagnosis and a suggested reply for our operator. The summary contains the batch identifier, the account identifier, the uploaded file name, the recorded error message, record counts, and recent processing log lines. It does not contain contact records. The provider's published terms state that it does not train models on content submitted through this interface, and that inputs and outputs are deleted within 30 days of receipt unless a longer period is agreed or required. Diagnostic metadata as described. Personal data only where it happens to appear in a file name or a log line. The provider does not commit to a processing region for this interface by default; its infrastructure sub-processors are listed as worldwide. EU Standard Contractual Clauses (Decision (EU) 2021/914), Module 2 or Module 3 as applicable, with the UK International Data Transfer Addendum (ICO template version B.1.0). The provider does not rely on the Data Privacy Framework here and we do not claim it does.
8 Plausible Insights OÜ (Estonia) Website and portal page analytics. Cookieless, no contact data, IP addresses hashed transiently and not retained. Aggregate visit data. No data from your file. European Union No transfer outside the UK and EU
9 Cloudflare, Inc. (United States), 101 Townsend Street, San Francisco, CA 94107, for its Turnstile product Bot protection on public forms. It does not receive your file or any record derived from it. It sees the visitor's IP address, browser identification and connection fingerprint. The provider states that it acts on our instructions for this purpose, but also uses the same signals as a controller in its own right to improve its bot detection. We record that split rather than describe it as a pure processor. Connection data only United States, served globally EU-US Data Privacy Framework, including its UK Extension, on which the provider states it is certified. Where that certification does not apply, EU Standard Contractual Clauses (Decision (EU) 2021/914), Module 2 or Module 3, and the UK International Data Transfer Addendum (ICO template version B1.0).

A recipient we disclose alongside them: the contact data enrichment provider. Where you instruct the identity layer, individual lookup identifiers (a professional profile URL, a name, a company domain) are disclosed to our contact data enrichment provider, which is established in the United States. It looks up whether the named individual is still in the role and organisation your record states, and returns professional and organisational data. It processes those identifiers under its own published terms, as a controller in its own right rather than on our instructions, so it is a recipient of personal data disclosed on your instruction and not our sub-processor. The equivalent-protection commitment in section 4.4 of the terms describes our sub-processors and does not describe this disclosure; we list it here separately rather than under a heading that would misdescribe it. The transfer is covered by the EU Standard Contractual Clauses (Decision (EU) 2021/914), Module 1 (controller to controller), with the UK International Data Transfer Addendum (ICO template version B1.0). It receives no other field from your file, and nothing is sent to it unless you instruct the identity layer. We will give you the same 30 days' written notice before replacing it as section 4.4 provides for a sub-processor, and you may object on the same grounds.

Names on request. Some providers above are listed by role rather than by name. The legal identity of each provider listed by role, together with details of its own sub-processors, is available on request to customers and to prospective customers before they accept these terms. Write to support@datuma.co.uk.

How the providers above appoint their own sub-processors. Each of them engages sub-processors of its own, and each publishes its list. Where a provider gives us notice of a change, that notice reaches you under section 4.4 of the terms in the same way as a change of our own.

Not sub-processors, and named here to avoid confusion.

  • Your own connected systems. Where you connect your own CRM or sending tool so that we can read records from it, that system is yours and its provider is your processor, not ours. We act on the records you make available to us through it. This applies to HubSpot and Salesforce connections and to any file you export from them yourself.
  • Our payments provider. Payment and any Direct Debit mandate are handled by GoCardless Ltd (registered in England and Wales, company number 07495895, registered office Sutton Yard, 65 Goswell Road, London EC1V 7EN), which is authorised by the Financial Conduct Authority under the Payment Services Regulations 2017. It is not our sub-processor and we do not list it as one. Its own merchant terms state that it and its merchants each act as controllers in their own right for the personal data processed in running the payment relationship, and it publishes no Article 28 processing agreement for that reason. It receives the billing contact and bank details of the organisation that pays us. It never receives your file or any record derived from it. Its processing for European payments is carried out on servers in the European Economic Area, and its own privacy notice is the right place to read what it does with that data.

Annex 2: Retention statement

Annex 2 to the Datuma Data Processing Terms, version 1.0. Effective 7 August 2026.

This annex sets out what we keep, where it is held, for how long, and what deletion means in practice. It applies to every engagement, including a free check.

1. Where your data is held

Your file, the records derived from it, and the result files we produce are held in the European Union, in Ireland, on our hosting platform's infrastructure. Annex 1 lists the providers involved and the limited cases where specific fields leave the UK and EU.

2. What is kept, and for how long

What Where it is held How long How it is removed
The file you send us Upload storage Deleted 30 days after upload Automatically, by a scheduled sweep that runs daily at 02:00 UTC across all accounts. It does not wait for a request from you.
Files sent to the deduplication tool Separate upload storage for that tool Deleted 7 days after upload Automatically, by a separate scheduled sweep that runs daily at 04:45 UTC.
The contact records derived from your file (the working records, including the results of the checks) Our database, in your account Kept while your account is open, so that a later pass can be compared with an earlier one. Deleted whenever you ask, and on account closure. There is no automatic deletion after a fixed period; at 365 days a record is flagged to us for review. On your instruction, or on account closure, by the account erasure process described in section 3.
Result files we produce for you (the files you download) Result storage, in your account Kept while your account is open. Deleted whenever you ask, and on account closure. There is no automatic deletion after a fixed period. On your instruction, or on account closure.
Cached lookup results (the outcome of a third-party lookup, held so that the same lookup is not paid for twice) Our database, not in your account A cached result is treated as out of date and re-checked after 90 days. Cached role and organisation lookups are deleted after 180 days, by a sweep that runs weekly on Sunday at 04:00 UTC. Cached email deliverability results and the identity match records used to recognise the same contact across passes have no fixed deletion date. The 180 day sweep runs automatically. All of them are removed for your records on account erasure, and on request.
Your message to us, and anything attached to it Our mailbox, with the mail host named in Annex 1 The copy of your file in our mailbox is deleted once the file is safely in our systems, which in practice is the same working day we pick it up. Your written instruction and your acceptance of these terms are kept for as long as we must be able to show what you asked us to do and on what terms, because they are the record of your instruction rather than a copy of your data. By hand, as a step in taking the file in. This one is a procedure we follow, not an automatic sweep, and we say so rather than imply a machine does it.
The email that returns your results to you Sent through the transactional email provider named in Annex 1, and thereafter in your own mailbox Once it is sent it is yours. The provider holds it only for as long as its own retention terms allow, which Annex 1 records. Where results were sent as a link rather than an attachment, the link expires on the period stated in the message. We cannot delete a message from your mailbox, and we do not claim to. If you want the copy in our systems removed, that is covered by the rows above.
Free check and demonstration data Our database, in the working account we create to run the check. You are not given access to that account: a free check is delivered as figures on a call, not as a file or a login. The whole account is erased 7 days after we create it. That takes the file, the records, the result files and the account itself, whether or not the check has finished and whether or not anyone asks. The clock runs from the moment the account is created, so nothing put into it can outlive that. Separately, any batch marked as demonstration data is purged 7 days after it is created. Automatically and irreversibly, by two scheduled sweeps: a daily account erasure sweep at 02:00 UTC, and a daily demonstration-data purge at 03:00 UTC.
Records of the fact that processing happened (dates, record counts, who accepted the terms and which version, billing entries, processing logs) Our database Kept after your data is deleted. We are required to be able to demonstrate compliance, and to keep accounting records. Retained. These records contain no contact records of yours.

Where you have asked for it and it is enabled for your account, a personal mobile number is re-verified or expired on a 90 day cycle and is removed with the rest of the contact record.

2a. Where we run the check for you, without an account: the usual case

This is how the work normally runs, and unless we have agreed otherwise it is how yours will run: you send us the file, we run the check on our own systems, we review and assemble the results by hand, and we hand the finished files back to you. You are not given an account and you are not asked to operate anything. The table above still applies, with these differences:

  • The file you send us is deleted once you confirm the results have arrived, and in any event within 30 days of upload, by the same automatic sweep.
  • The working records derived from your file are deleted once you confirm the results have arrived, and in any event within 30 days.
  • The finished files we hand back to you, and the delivery page they are presented on where we provide one, are kept while we are working together, so that we can send them again if you ask and compare your next pass with this one. They are deleted whenever you ask, and when our engagement ends.
  • Records of the fact that processing happened, and cached lookup results, are handled exactly as described above.
  • The copy of your file in our mailbox is deleted once the file is in our systems, as the table above says. That step is ours to perform and we perform it at ingest; it is not waiting on a scheduled sweep.
  • A free check is different in one way that is worth saying plainly. Where we run a free check we create a working account for it, and that account and everything in it is erased 7 days after we create it, automatically and irreversibly. That is a shorter period than any other in this statement, it applies to the whole account rather than to a file, and it is not a period you can extend by asking. If a free check leads to paid work, the paid work is set up separately and the 7-day period does not follow it.

3. What deletion means

When you ask us to delete. We delete the contact records we hold for you, the file you sent, the result files, and the cached lookup results held for your records. Where the request is to close the account, the user accounts are removed as well and the organisation record is retained only as an anonymised shell, so that billing and compliance history remains intact without holding anyone's personal data. We can carry out a preview of an erasure, showing exactly what would be removed, before it happens.

Timing. Erasure on request is carried out promptly and is not queued behind a scheduled sweep. The scheduled sweeps in section 2 are a backstop that runs whether or not anyone asks.

Result files. Links to result files are issued individually and are scoped to your account. A link sent to you by email expires 48 hours after it is sent; a link issued to you in the portal expires one hour after it is issued. A link that has expired cannot be used to retrieve a file.

Backups. Deleting live data does not immediately remove it from system backups. Backup copies are held in the same environment, are not used to serve requests, are not accessible to the service, and are overwritten on the backup cycle. Any copy of your data that remains in a backup after deletion is put beyond use, and is removed on the next backup expiry cycle, which is seven days: the platform takes a daily backup and retains each one for seven days, and point-in-time recovery is not enabled.

This is the position the Information Commissioner's Office describes: where appropriate safeguards are in place, such as the data being put immediately beyond use, it may be acceptable that data is not deleted from backups immediately on termination, provided the retention period is appropriate and the data is subsequently deleted as soon as possible, on the next deletion or destruction cycle.

So the honest summary is: erasure on request removes your data from everything the service can see, immediately. It does not reach into backups, and the two therefore have different timings. A backup copy is unreachable by the service, unused, and expires on the cycle above.

4. Deletion or return at the end of the engagement

At the end of the engagement you choose whether we delete your data or return it to you and then delete our copies. If you do not tell us, we delete. Your choice is recorded with your instruction.

Return means the result files and, if you ask for it, an export of the records we hold for you, in a format you can open. Return is followed by deletion on the same basis as section 3.

5. If you want a different retention period

The periods above are our defaults. If your own retention policy requires something shorter, tell us in your instruction and we will apply it. If it requires something longer, tell us, because the automatic sweeps in section 2 will otherwise delete your file on schedule.

Version history

VersionDateChange
1.07 August 2026First version.

The version string recorded on acceptance is 1.0.