Who controls the data?
Data Forest Ltd is the controller for the processing described in this notice, unless stated otherwise.
This notice explains how Data Forest Ltd collects, uses, licenses, shares, stores and protects personal information, including customer, website and business-contact data.
A quick summary is provided below. Please read the full notice for complete details.
Data Forest Ltd is the controller for the processing described in this notice, unless stated otherwise.
Customer, website, transaction, professional and business-contact information relevant to our services.
To operate our services, respond to enquiries, maintain B2B datasets, fulfil contracts and conduct lawful marketing.
From you, public business sources, customers, authorised suppliers and service providers.
Approved customers, contracted processors, advisers, payment providers and authorities where legally required.
You may have rights to access, correct, erase, restrict, port or object to the use of your information.
This notice explains how Data Forest Ltd handles personal information under applicable UK data-protection and electronic-marketing laws.
It covers information collected directly from people and information obtained from other sources, including public business sources and authorised data suppliers. It applies when Data Forest Ltd acts as a controller and determines why and how personal information is used.
“Personal information” means information relating to an identified or identifiable living person. A named business email address, business telephone number or professional profile may be personal information even when used in a business context.
Data Forest Ltd provides business data, B2B contact-list, market-research, lead-generation and digital-marketing support services.
Office 14341, 182-184 High Street North
East Ham, London, United Kingdom, E6 2JA
Data Forest Ltd is an active private limited company incorporated in England and Wales on 3 September 2025.
This notice may apply to:
People who browse dataforest.uk, submit a form or interact with website features.
People who request a sample, quote, proposal, invoice or service.
Named contacts whose professional details may appear in a B2B dataset.
Representatives of organisations that provide products, data or services to us.
People who receive or interact with a business-marketing communication.
People who submit a privacy request, objection or data-protection complaint.
Our services are intended for organisations and business professionals. We do not knowingly design B2B datasets for children and do not intentionally collect children’s information for business marketing.
Depending on the relationship and service, we may use the following categories:
We may receive personal information from:
Where reasonably possible, we record or retain information about the source or source category. If you ask where we obtained your information, we will provide the available source information, subject to applicable legal limitations and the rights of others.
We identify a lawful basis for each purpose. The basis depends on the information, relationship, communication channel and recipient.
| Purpose | Typical information | Typical lawful basis |
|---|---|---|
| Respond to enquiries, prepare samples or quotations, and discuss requirements | Identity, business contact, enquiry and organisation data | Steps before a contract and/or legitimate interests in responding to business enquiries |
| Deliver services, manage orders and provide customer support | Customer, contact, order, contract and service data | Contract; legitimate interests where the customer is an organisation rather than the individual |
| Invoice, collect payment, keep accounting records and meet legal duties | Identity, transaction, contract and billing data | Contract and legal obligation |
| Research, compile, standardise, verify and maintain B2B contact information | Professional identity, role, organisation and business contact data | Legitimate interests, supported by necessity and balancing assessments where required |
| License or supply relevant B2B contact data to business customers | Professional identity, organisation, business contact and segmentation data | Legitimate interests, subject to fairness, transparency, necessity and balancing considerations |
| Send our own business-marketing communications | Business contact data, communication history and preferences | Consent where required; otherwise legitimate interests, together with applicable PECR rules |
| Protect systems, investigate misuse, prevent fraud and establish legal claims | Technical, transaction, communications and security data | Legitimate interests and/or legal obligation |
| Operate analytics, preferences and non-essential website technologies | Device, usage, preference and cookie identifiers | Consent where required; a statutory exemption may apply to limited technologies that meet legal conditions |
| Handle rights requests and data-protection complaints | Request, identity-verification, correspondence and outcome data | Legal obligation and legitimate interests in managing and evidencing compliance |
Where we rely on legitimate interests, the relevant interests may include operating a B2B information service, helping organisations identify relevant professional audiences, maintaining accurate records, developing customer relationships, protecting our services and preventing misuse. We assess necessity, reasonable expectations and potential impact before relying on this basis.
UK rules distinguish between corporate subscribers and individual subscribers. The applicable rule depends on the recipient and the communication method.
For email marketing to corporate subscribers, such as limited companies and limited liability partnerships, PECR does not generally require prior consent. The sender must identify itself and provide a valid way to opt out. Where a message uses a named employee’s details, UK data-protection law still applies and a lawful basis is required.
Sole traders and some partnerships are treated similarly to individual subscribers under PECR. Email or text marketing generally requires valid consent unless the limited “soft opt-in” conditions apply.
Telephone campaigns must follow applicable PECR rules, including relevant Telephone Preference Service, Corporate Telephone Preference Service, caller-identification and prior-objection requirements.
You may object at any time to the use of your personal information for direct marketing, including related profiling. Once we receive a valid objection, we will stop using your information for that purpose. We may retain only the minimum information needed on a suppression list so that your preference is respected in the future.
Email info@dataforest.uk with the subject “Direct marketing objection”.
Because Data Forest Ltd provides B2B data services, we may license or supply relevant business-contact data to customers for defined business purposes. We do not describe this activity as merely “sharing with processors”; it is part of the service we provide.
Before supplying data, we may take steps such as:
A customer receiving business-contact data will generally act as an independent controller for its own subsequent use. The customer must identify its own lawful basis, comply with PECR and other applicable marketing rules, provide required privacy information, honour objections and maintain appropriate security.
We may disclose information to appropriate categories of recipients, including:
Processors acting on our behalf are required to follow contractual data- protection, confidentiality and security obligations. We do not authorise them to use personal information for unrelated independent purposes.
Some customers or service providers may be located outside the United Kingdom, or may process information using infrastructure located outside the UK. A transfer outside the UK is made only where a lawful transfer mechanism is available.
Depending on the destination and arrangement, safeguards may include:
You may contact us for further information about the transfer mechanism relevant to your personal information. Commercially confidential details and information affecting the rights of others may be redacted.
We keep personal information only for as long as it is reasonably needed for the relevant purpose, legal obligations, disputes, security and the exercise or defence of legal claims. Retention is reviewed using the criteria below.
| Information type | Retention approach |
|---|---|
| Enquiries, proposals and pre-contract correspondence | Kept while the opportunity remains active and then for a proportionate follow-up and dispute period, taking account of the nature of the enquiry and any objection. |
| Customer contracts, invoices and accounting records | Normally retained for at least six years from the end of the relevant company financial year where required for UK tax and accounting purposes, and longer if a legal exception applies. |
| B2B contact records | Reviewed according to source age, verification status, role relevance, accuracy, customer need, reasonable expectations, objections and legal risk. Records are corrected, suppressed, anonymised or deleted when no longer necessary. |
| Marketing preferences and suppression records | Active marketing records are retained while relevant. Minimal suppression information may be retained for as long as needed to prevent future unwanted contact and comply with objections. |
| Website and cookie information | Kept according to the duration shown in the cookie preference tool or relevant cookie table, subject to security and legal requirements. |
| Rights requests and complaints | Kept long enough to investigate, respond, demonstrate compliance and manage any related regulatory or legal proceedings. |
| Security and fraud records | Kept for a period proportionate to the incident, threat, investigation and applicable limitation periods. |
When information is no longer required, we delete it, securely dispose of it, anonymise it, or restrict it where retention is still legally necessary.
We use proportionate technical and organisational measures designed to protect information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.
Measures may include:
No internet or storage system is completely secure. We therefore cannot guarantee absolute security, but we review measures in light of risk, available technology, implementation cost and the nature of the information.
Cookies and similar technologies may store or access information on your device. They can support essential website functions, preferences, security, analytics and advertising.
Required for security, page delivery, consent storage or a service you request. These cannot normally be disabled through our tool.
Remember choices or improve features. Consent is requested where the law requires it.
Help us understand website use. We seek consent unless a valid statutory exemption applies and all conditions are met.
Support campaign measurement, audience selection or retargeting. These are not activated without consent where consent is required.
The preference control on this page stores your selection locally. It does not itself activate third-party analytics or advertising scripts. Website administrators must configure those scripts so they load only after the appropriate consent signal.
Your rights depend on the circumstances and lawful basis. They are not all absolute, and legal exemptions may apply.
Receive clear information about how your personal information is used.
Ask whether we process your information and request a copy and related details.
Ask us to correct inaccurate information or complete information that is incomplete.
Ask for deletion in circumstances where the legal conditions for erasure apply.
Ask us to limit use while an issue about accuracy, lawfulness or objection is considered.
Object to processing based on legitimate interests. Objection to direct marketing is absolute.
Receive certain information you provided in a reusable format where the legal conditions apply.
Withdraw consent at any time where consent is the basis, without affecting earlier lawful use.
Email info@dataforest.uk and describe the right you wish to exercise. You may also telephone or write to us using the details in this notice.
We may ask for information reasonably necessary to confirm identity or locate the relevant records. We will not request excessive identification where we already have enough information.
We normally respond without undue delay and within one month of receiving a valid request. The period may be extended where the request is complex or multiple requests are made, where the law permits; if so, we will explain the extension.
You may complain if you believe we have handled your personal information unfairly, inaccurately, unlawfully or without appropriate security, or if you are dissatisfied with our response to a rights request.
Email info@dataforest.uk with the subject “Data protection complaint”. Please explain what happened, the information involved, the outcome you seek and any relevant dates or evidence.
In line with current UK requirements, we will:
You may also raise a concern with the Information Commissioner’s Office, the UK supervisory authority. We encourage you to contact us first so we have an opportunity to investigate and resolve the matter.
ICO information and complaint services are available at ico.org.uk/make-a-complaint.
Questions, rights requests, objections and complaints may be sent to:
Office 14341, 182-184 High Street North
East Ham, London, United Kingdom, E6 2JA
We may update this notice when our services, processing activities, suppliers or legal obligations change. Material changes will be highlighted where appropriate. The current version will be published on this page with an updated review date.
Earlier versions may be requested by emailing us. Continued website use does not replace any consent that is legally required for a specific processing activity.
Send the email address, phone number or professional identity you want us to locate, and state the action you are requesting. Please do not send unnecessary sensitive documents.
We use essential storage for security and to remember your choices. Optional analytics, functional and advertising technologies are used only according to your selected preference and applicable law.
Choose which optional categories may be used on this website.
Required for core website functions and saving your privacy choice.
Remember preferences and support enhanced website features.
Measure website use and help improve content and performance.
Support campaign measurement, audience selection and retargeting.