Privacy Notice | Data Forest Ltd
Legal & privacy

Privacy Notice

This notice explains how Data Forest Ltd collects, uses, licenses, shares, stores and protects personal information, including customer, website and business-contact data.

Last reviewed: 26 July 2026 Company no. 16690673 United Kingdom
Submit a data request

Privacy at a glance

A quick summary is provided below. Please read the full notice for complete details.

Who controls the data?

Data Forest Ltd is the controller for the processing described in this notice, unless stated otherwise.

What do we use?

Customer, website, transaction, professional and business-contact information relevant to our services.

Why do we use it?

To operate our services, respond to enquiries, maintain B2B datasets, fulfil contracts and conduct lawful marketing.

Where does it come from?

From you, public business sources, customers, authorised suppliers and service providers.

Who may receive it?

Approved customers, contracted processors, advisers, payment providers and authorities where legally required.

What control do you have?

You may have rights to access, correct, erase, restrict, port or object to the use of your information.

01

About this notice

This notice explains how Data Forest Ltd handles personal information under applicable UK data-protection and electronic-marketing laws.

It covers information collected directly from people and information obtained from other sources, including public business sources and authorised data suppliers. It applies when Data Forest Ltd acts as a controller and determines why and how personal information is used.

“Personal information” means information relating to an identified or identifiable living person. A named business email address, business telephone number or professional profile may be personal information even when used in a business context.

Applicable framework: this notice is designed around the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 (PECR), and relevant changes introduced by the Data (Use and Access) Act 2025.
02

Who we are

Data Forest Ltd provides business data, B2B contact-list, market-research, lead-generation and digital-marketing support services.

Data Forest Ltd

Office 14341, 182-184 High Street North

East Ham, London, United Kingdom, E6 2JA

info@dataforest.uk

+44 7456 321460

Company no. 16690673

Data Forest Ltd is an active private limited company incorporated in England and Wales on 3 September 2025.

03

Who this notice applies to

This notice may apply to:

Website visitors

People who browse dataforest.uk, submit a form or interact with website features.

Customers and prospects

People who request a sample, quote, proposal, invoice or service.

Business professionals

Named contacts whose professional details may appear in a B2B dataset.

Suppliers and partners

Representatives of organisations that provide products, data or services to us.

Marketing recipients

People who receive or interact with a business-marketing communication.

Rights requesters

People who submit a privacy request, objection or data-protection complaint.

Our services are intended for organisations and business professionals. We do not knowingly design B2B datasets for children and do not intentionally collect children’s information for business marketing.

04

Information we use

Depending on the relationship and service, we may use the following categories:

  • Identity data: name, professional title and business role.
  • Business contact data: work email, business phone number, business address and professional profile link.
  • Organisation data: company name, website, sector, size, location and other business characteristics.
  • Event and professional-interest data: business event, conference, trade-show, industry or role associations where lawfully obtained.
  • Customer and enquiry data: requirements, correspondence, quotations, sample requests, contracts and service history.
  • Transaction data: invoices, payment status and transaction references. Full card information is normally handled by the payment provider rather than stored by us.
  • Technical data: IP address, browser, device, security logs and website interactions.
  • Marketing data: communication history, preferences, objections, unsubscribe status and campaign interaction information.
  • Rights and complaint data: request details, identity-verification information and our response record.
Sensitive information: we do not intentionally build B2B marketing datasets using special-category information such as health, ethnicity, religion, political opinion, trade-union membership, biometric data or sexual orientation. Please do not send such information unless it is genuinely necessary for a specific legal request.
05

Where information comes from

We may receive personal information from:

  • You directly, including through forms, emails, calls, orders and privacy requests.
  • Public business sources, such as corporate websites, public registers, professional directories, exhibitor or sponsor directories, published event materials and other publicly accessible business information.
  • Authorised data suppliers and research partners that contractually confirm they are permitted to provide the information.
  • Customers, when they provide targeting requirements, suppression information or data for a contracted service.
  • Service providers, such as website, analytics, security, CRM, communications and payment providers.
  • Derived information, such as standardised job functions, industry categories, duplicate indicators and verification status produced from existing business information.

Where reasonably possible, we record or retain information about the source or source category. If you ask where we obtained your information, we will provide the available source information, subject to applicable legal limitations and the rights of others.

Where personal information is obtained from another source, privacy information is provided within the legally required timeframe unless a valid exception or exemption applies. This may occur through a first communication, a source notice, a direct notice or this prominently published notice, depending on the circumstances.
06

How and why we use information

We identify a lawful basis for each purpose. The basis depends on the information, relationship, communication channel and recipient.

Purpose Typical information Typical lawful basis
Respond to enquiries, prepare samples or quotations, and discuss requirements Identity, business contact, enquiry and organisation data Steps before a contract and/or legitimate interests in responding to business enquiries
Deliver services, manage orders and provide customer support Customer, contact, order, contract and service data Contract; legitimate interests where the customer is an organisation rather than the individual
Invoice, collect payment, keep accounting records and meet legal duties Identity, transaction, contract and billing data Contract and legal obligation
Research, compile, standardise, verify and maintain B2B contact information Professional identity, role, organisation and business contact data Legitimate interests, supported by necessity and balancing assessments where required
License or supply relevant B2B contact data to business customers Professional identity, organisation, business contact and segmentation data Legitimate interests, subject to fairness, transparency, necessity and balancing considerations
Send our own business-marketing communications Business contact data, communication history and preferences Consent where required; otherwise legitimate interests, together with applicable PECR rules
Protect systems, investigate misuse, prevent fraud and establish legal claims Technical, transaction, communications and security data Legitimate interests and/or legal obligation
Operate analytics, preferences and non-essential website technologies Device, usage, preference and cookie identifiers Consent where required; a statutory exemption may apply to limited technologies that meet legal conditions
Handle rights requests and data-protection complaints Request, identity-verification, correspondence and outcome data Legal obligation and legitimate interests in managing and evidencing compliance

Where we rely on legitimate interests, the relevant interests may include operating a B2B information service, helping organisations identify relevant professional audiences, maintaining accurate records, developing customer relationships, protecting our services and preventing misuse. We assess necessity, reasonable expectations and potential impact before relying on this basis.

07

B2B data and direct marketing

UK rules distinguish between corporate subscribers and individual subscribers. The applicable rule depends on the recipient and the communication method.

Corporate subscribers

For email marketing to corporate subscribers, such as limited companies and limited liability partnerships, PECR does not generally require prior consent. The sender must identify itself and provide a valid way to opt out. Where a message uses a named employee’s details, UK data-protection law still applies and a lawful basis is required.

Sole traders and certain partnerships

Sole traders and some partnerships are treated similarly to individual subscribers under PECR. Email or text marketing generally requires valid consent unless the limited “soft opt-in” conditions apply.

Telephone marketing

Telephone campaigns must follow applicable PECR rules, including relevant Telephone Preference Service, Corporate Telephone Preference Service, caller-identification and prior-objection requirements.

Your absolute right to object to direct marketing

You may object at any time to the use of your personal information for direct marketing, including related profiling. Once we receive a valid objection, we will stop using your information for that purpose. We may retain only the minimum information needed on a suppression list so that your preference is respected in the future.

Email info@dataforest.uk with the subject “Direct marketing objection”.

08

How business-contact data is disclosed or licensed

Because Data Forest Ltd provides B2B data services, we may license or supply relevant business-contact data to customers for defined business purposes. We do not describe this activity as merely “sharing with processors”; it is part of the service we provide.

Before supplying data, we may take steps such as:

  • reviewing the customer’s organisation, intended audience and stated purpose;
  • limiting data fields to those reasonably relevant to the project;
  • applying suppression, objection and quality controls;
  • requiring contractual restrictions on use, security, onward disclosure and compliance;
  • prohibiting spam, unlawful discrimination, harassment and use for purely personal or household purposes; and
  • suspending or ending access where misuse is identified.

A customer receiving business-contact data will generally act as an independent controller for its own subsequent use. The customer must identify its own lawful basis, comply with PECR and other applicable marketing rules, provide required privacy information, honour objections and maintain appropriate security.

Purchasing or receiving a business-contact list does not by itself make every proposed campaign lawful. Customers must assess their own purpose, audience, channel, jurisdiction and legal obligations before using the data.
09

Service providers and other recipients

We may disclose information to appropriate categories of recipients, including:

  • hosting, cloud-storage, backup and website-technology providers;
  • CRM, email, telephone, communications and customer-support providers;
  • data-validation, hygiene, research and quality-control providers;
  • analytics, security, anti-fraud and incident-response providers;
  • payment processors, banks, accountants, auditors and professional advisers;
  • B2B customers receiving licensed data as described above;
  • potential buyers, investors or advisers involved in a genuine corporate transaction; and
  • courts, regulators, law-enforcement bodies and public authorities where disclosure is required or permitted by law.

Processors acting on our behalf are required to follow contractual data- protection, confidentiality and security obligations. We do not authorise them to use personal information for unrelated independent purposes.

10

International transfers

Some customers or service providers may be located outside the United Kingdom, or may process information using infrastructure located outside the UK. A transfer outside the UK is made only where a lawful transfer mechanism is available.

Depending on the destination and arrangement, safeguards may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved EU Standard Contractual Clauses;
  • another legally approved safeguard, together with any required transfer-risk assessment; or
  • a limited statutory exception where legally available and appropriate.

You may contact us for further information about the transfer mechanism relevant to your personal information. Commercially confidential details and information affecting the rights of others may be redacted.

11

How long we keep information

We keep personal information only for as long as it is reasonably needed for the relevant purpose, legal obligations, disputes, security and the exercise or defence of legal claims. Retention is reviewed using the criteria below.

Information type Retention approach
Enquiries, proposals and pre-contract correspondence Kept while the opportunity remains active and then for a proportionate follow-up and dispute period, taking account of the nature of the enquiry and any objection.
Customer contracts, invoices and accounting records Normally retained for at least six years from the end of the relevant company financial year where required for UK tax and accounting purposes, and longer if a legal exception applies.
B2B contact records Reviewed according to source age, verification status, role relevance, accuracy, customer need, reasonable expectations, objections and legal risk. Records are corrected, suppressed, anonymised or deleted when no longer necessary.
Marketing preferences and suppression records Active marketing records are retained while relevant. Minimal suppression information may be retained for as long as needed to prevent future unwanted contact and comply with objections.
Website and cookie information Kept according to the duration shown in the cookie preference tool or relevant cookie table, subject to security and legal requirements.
Rights requests and complaints Kept long enough to investigate, respond, demonstrate compliance and manage any related regulatory or legal proceedings.
Security and fraud records Kept for a period proportionate to the incident, threat, investigation and applicable limitation periods.

When information is no longer required, we delete it, securely dispose of it, anonymise it, or restrict it where retention is still legally necessary.

12

How we protect information

We use proportionate technical and organisational measures designed to protect information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.

Measures may include:

  • role-based access controls and least-privilege access;
  • password, authentication and account-management controls;
  • encryption in transit and, where appropriate, at rest;
  • secure backups, malware protection and system monitoring;
  • supplier due diligence and contractual safeguards;
  • data minimisation, masking, validation and suppression controls;
  • staff confidentiality and privacy-awareness measures; and
  • incident assessment, response and notification procedures.

No internet or storage system is completely secure. We therefore cannot guarantee absolute security, but we review measures in light of risk, available technology, implementation cost and the nature of the information.

13

Cookies and similar technologies

Cookies and similar technologies may store or access information on your device. They can support essential website functions, preferences, security, analytics and advertising.

Strictly necessary

Required for security, page delivery, consent storage or a service you request. These cannot normally be disabled through our tool.

Functional

Remember choices or improve features. Consent is requested where the law requires it.

Analytics

Help us understand website use. We seek consent unless a valid statutory exemption applies and all conditions are met.

Advertising

Support campaign measurement, audience selection or retargeting. These are not activated without consent where consent is required.

The preference control on this page stores your selection locally. It does not itself activate third-party analytics or advertising scripts. Website administrators must configure those scripts so they load only after the appropriate consent signal.

14

Your data-protection rights

Your rights depend on the circumstances and lawful basis. They are not all absolute, and legal exemptions may apply.

Be informed

Receive clear information about how your personal information is used.

Access

Ask whether we process your information and request a copy and related details.

Rectification

Ask us to correct inaccurate information or complete information that is incomplete.

Erasure

Ask for deletion in circumstances where the legal conditions for erasure apply.

Restriction

Ask us to limit use while an issue about accuracy, lawfulness or objection is considered.

Object

Object to processing based on legitimate interests. Objection to direct marketing is absolute.

Data portability

Receive certain information you provided in a reusable format where the legal conditions apply.

Withdraw consent

Withdraw consent at any time where consent is the basis, without affecting earlier lawful use.

How to exercise a right

Email info@dataforest.uk and describe the right you wish to exercise. You may also telephone or write to us using the details in this notice.

We may ask for information reasonably necessary to confirm identity or locate the relevant records. We will not request excessive identification where we already have enough information.

We normally respond without undue delay and within one month of receiving a valid request. The period may be extended where the request is complex or multiple requests are made, where the law permits; if so, we will explain the extension.

15

Data-protection complaints

You may complain if you believe we have handled your personal information unfairly, inaccurately, unlawfully or without appropriate security, or if you are dissatisfied with our response to a rights request.

How to complain to Data Forest Ltd

Email info@dataforest.uk with the subject “Data protection complaint”. Please explain what happened, the information involved, the outcome you seek and any relevant dates or evidence.

In line with current UK requirements, we will:

  • provide a clear way to make a data-protection complaint;
  • acknowledge receipt within 30 days;
  • take appropriate steps to investigate without undue delay;
  • keep you appropriately informed; and
  • communicate the outcome without unjustifiable or excessive delay.

Complaining to the ICO

You may also raise a concern with the Information Commissioner’s Office, the UK supervisory authority. We encourage you to contact us first so we have an opportunity to investigate and resolve the matter.

ICO information and complaint services are available at ico.org.uk/make-a-complaint.

16

Contact details and changes to this notice

Questions, rights requests, objections and complaints may be sent to:

Privacy contact — Data Forest Ltd

info@dataforest.uk

+44 7456 321460

Office 14341, 182-184 High Street North

East Ham, London, United Kingdom, E6 2JA

Last reviewed 26 July 2026

We may update this notice when our services, processing activities, suppliers or legal obligations change. Material changes will be highlighted where appropriate. The current version will be published on this page with an updated review date.

Earlier versions may be requested by emailing us. Continued website use does not replace any consent that is legally required for a specific processing activity.

Need to access, correct, remove or suppress your business-contact information?

Send the email address, phone number or professional identity you want us to locate, and state the action you are requesting. Please do not send unnecessary sensitive documents.