ProspectX
How It Works Pricing Case Studies Contact Us

GDPR Compliance

How ProspectX ensures compliance with data protection regulations

Last Updated: April 14, 2025

Introduction to GDPR Compliance

At ProspectX, we take data protection and privacy seriously. As a B2B lead generation company operating in the United Kingdom and serving clients across Europe, we fully comply with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

This document outlines our approach to GDPR compliance, particularly in the context of B2B lead generation and outreach activities. We aim to provide transparency about how we collect, process, and protect personal data while ensuring that our business practices respect the rights of data subjects.

Our Role Under GDPR

In the context of our services, ProspectX can act as both a data controller and a data processor:

  • As a Data Controller: When we collect and process personal data for our own business purposes, such as marketing our services to potential clients or managing relationships with existing clients.
  • As a Data Processor: When we process personal data on behalf of our clients as part of our lead generation services.

In either role, we are committed to adhering to the principles of the GDPR and implementing appropriate technical and organizational measures to ensure the security and lawful processing of personal data.

GDPR Principles and How We Apply Them

The GDPR is built around six core principles. Here's how we apply each principle in our operations:

GDPR Principle How ProspectX Applies It
Lawfulness, Fairness, and Transparency We process personal data legally, fairly, and transparently. We clearly inform data subjects about our processing activities through our Privacy Policy and other communications.
Purpose Limitation We collect personal data for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes. Our lead generation activities are focused on business-related purposes.
Data Minimization We limit the personal data we collect to what is necessary for our stated purposes. For B2B lead generation, we focus on professional contact information and relevant business details.
Accuracy We take reasonable steps to ensure that personal data is accurate and up-to-date. We regularly verify and update our databases and promptly correct inaccurate data when identified.
Storage Limitation We retain personal data only for as long as necessary for the purposes for which it was collected. We have established retention periods and regularly review and delete data that is no longer needed.
Integrity and Confidentiality We implement appropriate technical and organizational measures to protect personal data from unauthorized access, accidental loss, and damage. This includes encryption, access controls, and staff training.

Legal Basis for Processing

Under GDPR, any processing of personal data must have a valid legal basis. For our B2B lead generation activities, we primarily rely on the following legal bases:

Legitimate Interest

For most of our B2B lead generation activities, we rely on legitimate interest as our legal basis for processing personal data. We have conducted legitimate interest assessments to ensure that:

  • We have a legitimate interest in conducting B2B marketing and outreach
  • The processing is necessary to achieve these interests
  • The legitimate interest is balanced against the rights and interests of the data subjects

For B2B communications, legitimate interest is often the most appropriate legal basis, as recognized by data protection authorities. However, we always ensure that our assessment considers the specific context and the reasonable expectations of the data subjects.

Contract

When processing data of our existing clients, we typically rely on the legal basis that the processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract.

Consent

In situations where legitimate interest or contractual necessity are not applicable, we may seek consent as the legal basis for processing. When we rely on consent, we ensure that it is:

  • Freely given, specific, informed, and unambiguous
  • Provided through a clear affirmative action
  • Easy to withdraw at any time

B2B Lead Generation and GDPR

Our B2B lead generation services involve collecting and processing personal data of business professionals. We ensure GDPR compliance in this area through the following practices:

Data Collection

We collect business contact information from legitimate sources, including:

  • Publicly available professional directories and databases
  • Company websites
  • Professional networking platforms like LinkedIn
  • Business events and conferences
  • Referrals and recommendations

We do not use data scraped from websites without proper consideration of legal requirements and the rights of data subjects.

Targeting Criteria

We work with our clients to establish targeting criteria that are appropriate and proportionate for B2B lead generation. These criteria focus on business characteristics (industry, company size, etc.) and professional roles rather than personal attributes.

Cold Outreach

For cold email outreach to business contacts, we ensure compliance with both GDPR and ePrivacy regulations:

  • We only contact individuals in their professional capacity
  • We clearly identify ourselves and our client as the sender of the communication
  • We provide transparent information about how we obtained their contact details
  • We offer an easy way to opt-out of future communications
  • We respect opt-out requests promptly and effectively

Personalization

While we personalize our outreach to make it more relevant and effective, we do so in a way that respects privacy and does not involve extensive profiling or invasive data collection. Our personalization is based on professional and business information that is directly relevant to the services being offered.

Data Subject Rights

We respect the rights of data subjects under GDPR and have implemented processes to respond to requests in a timely manner. These rights include:

Right How We Facilitate It
Right to Be Informed We provide clear information about our data processing activities in our Privacy Policy and in our communications.
Right of Access Data subjects can request a copy of their personal data that we process. We respond to such requests within 30 days.
Right to Rectification Data subjects can request that inaccurate or incomplete data be corrected. We promptly update our records when such requests are received.
Right to Erasure Data subjects can request the deletion of their personal data in specific circumstances. We have processes in place to erase data when such requests are valid.
Right to Restrict Processing Data subjects can request that we limit how we use their data. We have systems to flag and restrict processing when required.
Right to Data Portability Data subjects can request their data in a structured, commonly used, and machine-readable format. We can provide data in standard formats like CSV or JSON.
Right to Object Data subjects can object to processing based on legitimate interest, particularly for direct marketing. We immediately honor objections to marketing.
Rights Related to Automated Decision Making We do not engage in fully automated decision-making that has significant effects on data subjects.

To exercise these rights, data subjects can contact us at privacy@getprospectx.com. We verify the identity of the requester before processing any request to ensure data security.

Data Protection Measures

We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include:

Technical Measures

  • Encryption of personal data in transit and at rest
  • Secure access controls and authentication
  • Regular security updates and patches
  • Firewalls and intrusion detection systems
  • Regular backups and disaster recovery plans
  • Secure development practices

Organizational Measures

  • Staff training on data protection and security
  • Data protection policies and procedures
  • Clear access controls and permissions based on role
  • Regular data protection impact assessments
  • Due diligence on third-party processors
  • Data processing agreements with all processors

Data Processors and International Transfers

We work with carefully selected third-party service providers who process personal data on our behalf. These include:

  • Email service providers
  • CRM systems
  • Cloud storage providers
  • Analytics tools

We have data processing agreements in place with all our processors that require them to comply with GDPR requirements and provide appropriate safeguards for personal data.

International Transfers

As a UK-based company, we primarily store and process data within the United Kingdom and European Economic Area (EEA). However, some of our service providers may be located outside these regions.

When we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, such as:

  • Transfer to countries with an adequacy decision from the UK or EU Commission
  • Standard Contractual Clauses approved by the European Commission or UK authorities
  • Binding Corporate Rules for transfers within a corporate group

Data Breach Procedures

We have a documented data breach response plan that includes:

  • Procedures for identifying and containing breaches
  • Assessment of the severity and potential impact
  • Internal reporting and escalation protocols
  • Notification to supervisory authorities within 72 hours where required
  • Communication with affected data subjects
  • Documentation and review of the incident

Our team is trained to recognize and respond to potential data breaches promptly and effectively.

Accountability and Governance

We maintain records of our processing activities as required by GDPR. Our data protection governance framework includes:

  • Regular reviews of our data protection policies and procedures
  • Staff training and awareness programs
  • Data protection impact assessments for new processing activities
  • A designated point of contact for data protection matters

We regularly assess our compliance with GDPR and other applicable data protection regulations and make continuous improvements to our practices.

Contact Us About GDPR

If you have any questions, concerns, or requests regarding our GDPR compliance or the processing of your personal data, please contact us at:

ProspectX Ltd
Data Protection Team
128 City Road
London, EC1V 2NX
United Kingdom

Email: privacy@getprospectx.com

We are committed to addressing your concerns and providing transparent information about our data protection practices.

ProspectX
We deliver high-quality B2B leads and booked meetings directly to your inbox and calendar. No fluff. No long-term contracts. Just results.
PROSPECTX LTD
Company Number: 16307673
128 City Road, London,
United Kingdom, EC1V 2NX

Services

  • How It Works
  • Pricing
  • Case Studies
  • FAQ

Contact

  • hello@getprospectx.com
  • Book a Call

Legal

  • Privacy Policy
  • Terms of Service
  • GDPR Compliance
  • ICO Certificate
© 2025 ProspectX. All rights reserved.
LinkedIn Twitter