How we run B2B demand generation in line with the EU GDPR and UK GDPR — from the lawful basis for outreach to how we answer a data subject request.
The EU General Data Protection Regulation and the UK GDPR apply whenever we process personal data about people in the European Economic Area or the United Kingdom — including the business contact data behind a B2B campaign. We treat them as the baseline for every campaign that touches those regions, not as an add-on for clients who ask.
For our own website, prospects and clients we act as a controller. When we run a campaign on a client's behalf we generally act as a processor under their documented instructions, and we sign a data processing agreement before any personal data changes hands.
Every processing activity is mapped to a lawful basis before a campaign launches:
Where e-privacy law in a given EU member state is stricter than the GDPR baseline for email or phone outreach, the stricter rule governs that country's portion of the campaign.
Anyone whose data we hold can ask to access, correct, delete, restrict or port it, object to processing — including an absolute right to object to direct marketing — and withdraw consent at any time.
Lidespy operates from India. Where personal data leaves the EEA or UK, transfers rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, backed by a transfer risk assessment and supplementary measures such as encryption in transit and at rest and least-privilege access.
We collect only the fields a campaign needs to qualify a lead, and retention periods are set per data category as described in our Privacy Policy. Suppression records are the exception — they are kept so that an opt-out keeps working.
Write to us and a member of the team will respond. For data requests, please include the email address the request relates to.