Purpose
Lead Conneqt Limited provides a managed outsourced SDR and outbound function. Personal data, principally business contact data about people at prospective client organisations, is central to that work. Handling it lawfully and carefully is a condition of operating, not an optional extra.
The purpose of this policy is to state how the business governs personal data: the principles we apply, the controls we require, who is accountable, and what must happen when something goes wrong. It gives clients, prospective clients and suppliers a clear view of the standard we hold ourselves to.
This policy is not a privacy notice and does not replace one. The authoritative public transparency document for individuals, covering what personal data we process, why, on what lawful basis and for how long, is our privacy notice at /privacy. Where this policy and the privacy notice describe the same processing, the privacy notice prevails for data subjects.
Scope
This policy applies to all personal data processed by Lead Conneqt Limited, in any format and on any system, and to everyone who processes personal data for or on behalf of the business, including directors, anyone employed or engaged directly by Lead Conneqt Limited, contractors, freelancers and suppliers acting as our processors.
- Prospect data: business contact details for individuals at target organisations, used to research, contact and qualify potential buyers on behalf of our clients.
- Client and prospective client data: contact details and correspondence for the people we deal with at client organisations.
- Enquiry and website data: information submitted through our website, email or booking links.
- Supplier and contractor data: contact and engagement details for the people and businesses we work with.
- Data we process on client instructions, where the client is the controller and we act as a processor under written terms.
The applicable law is the UK General Data Protection Regulation and the Data Protection Act 2018, together with the Privacy and Electronic Communications Regulations for electronic and telephone marketing. Where we act as a processor for a client, this policy applies alongside the written terms agreed with that client, and those terms take precedence in the event of conflict, save that we will not follow an instruction we consider unlawful.
The data protection principles in practice
The following principles govern every campaign we run. Each is stated with what it means in practice for outbound prospecting.
Lawfulness, fairness and transparency. We identify a lawful basis before processing begins and we do not disguise who we are or why we are making contact. Every outreach message identifies the business and, where we contact people on behalf of a client, the client we are acting for. We do not use misleading sender names, false pretexts or invented mutual connections.
Purpose limitation. Business contact data collected for a specific outreach campaign is used for that campaign and related follow up only. We do not repurpose a client campaign list for another client, and we do not sell or rent prospect data.
Data minimisation. We hold the fields we actually need to research, contact and qualify a business contact, such as name, job title, employer, business email address, business telephone number and professional profile information. We do not collect special category data or personal life details for prospecting purposes.
Accuracy. Prospect records are checked before use, corrected when we learn they are wrong, and updated when a contact tells us they have moved role or that our information is incorrect. Bounces, invalid numbers and stale records are removed or suppressed rather than repeatedly contacted.
Storage limitation. We keep personal data only for as long as there is a purpose for holding it, and we review holdings periodically. Suppression records are the deliberate exception: we keep the minimum information needed to make sure a person who has objected or opted out is not contacted again.
Integrity and confidentiality.Access to personal data is limited to those who need it for their work, accounts are individual rather than shared, and data is not moved onto personal devices or storage without authorisation. Client data is kept separate from other clients' data.
Accountability. We take responsibility for demonstrating compliance, not merely asserting it. We commit to keeping a written record of our processing activities that is proportionate to the size and nature of the business, to documenting the lawful basis for each campaign, and to being able to evidence how objections and opt-outs were actioned.
Our commitments
Prospect data. Prospect data is business contact data, gathered or prepared for business to business outreach and used for that purpose only. We do not target consumers, and we do not build profiles of individuals beyond what is needed to judge whether an organisation and a role are relevant to a client offer.
Lawful basis for outreach. The usual lawful basis for our business to business outreach is legitimate interests: the interest of our client in reaching relevant buyers and the interest of the recipient in learning about a service relevant to their role. We consider that basis campaign by campaign and weigh it against the reasonable expectations and rights of the people being contacted, narrowing targeting or declining to proceed where the balance does not hold. The right to object is unconditional: if a person objects to direct marketing, we stop, without argument and without asking for a reason.
Client data.Personal data belonging to client personnel is used to deliver and administer the service and to maintain the commercial relationship. Where we process personal data under a client's instructions, we act only on those documented instructions and return or delete the data at the end of the engagement in line with the agreed terms.
Access control. Access to personal data is granted on a need-to-know basis and is limited to what a person requires for their role. We require individual accounts, strong and unique credentials, and multi-factor authentication where the platform supports it. Access is reviewed when a role changes and removed promptly when someone stops working with us.
Third-party processors. We use third-party services to run outreach and to store and process data. We require written terms with every processor that handles personal data on our behalf, covering confidentiality, security, sub-processing, assistance with data subject rights and deletion or return of data. Where a processor stores or accesses personal data outside the United Kingdom, we require an appropriate transfer safeguard recognised under UK data protection law. We will not knowingly engage a processor that cannot meet these requirements.
Data incidents and personal data breaches.Any suspected loss, unauthorised disclosure, unauthorised access, alteration or destruction of personal data must be reported internally as soon as it is noticed, and never concealed or delayed. We will assess the risk to the individuals affected without undue delay, contain the incident, and record what happened and what was done. Where a personal data breach is notifiable under UK GDPR, we will report it to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to the rights and freedoms of the individuals affected, we will inform them without undue delay. Where the affected data belongs to a client for which we act as processor, we will notify that client without undue delay so they can meet their own obligations.
Data subject rights. We recognise the rights of individuals to be informed and to request access, rectification, erasure, restriction of processing, portability where it applies, and to object to processing, including the absolute right to object to direct marketing. Requests should be sent to info@leadconneqt.com, the address given in our privacy notice, and will be acknowledged and answered within the statutory period. We do not charge for responding to a routine request. Objections and opt-outs are actioned promptly and are not made conditional on anything.
Retention and deletion. Personal data is kept only for as long as it is needed for the purpose it was obtained for, or for as long as we are required to keep it to meet a legal or contractual obligation. Holdings are reviewed periodically and data that is no longer needed is deleted or anonymised. Prospect records that have gone cold, bounced or become inaccurate are removed from active use.
Direct marketing compliance
Outbound contact is regulated by more than data protection law, and we treat the marketing rules as binding operational limits rather than guidance.
- Electronic marketing, including email and messaging, is carried out in line with the Privacy and Electronic Communications Regulations as they apply to business to business contact.
- Every marketing email identifies the sender, states on whose behalf the contact is being made, and gives a clear and working way to opt out.
- Telephone numbers are screened against the Telephone Preference Service and the Corporate Telephone Preference Service before calling, and screening is repeated as data ages.
- We maintain an internal Do Not Contact list. Anyone who asks not to be contacted is added to it and is suppressed across future campaigns.
- Opt-outs and objections are honoured immediately and are not made subject to a further email, a form or a justification.
- Callers identify themselves and the client they are calling for, give a contact point on request, and end the call politely when asked to.
- We do not use withheld or misleading calling line identification, and we do not contact people who have told us to stop.
Responsibilities
The Managing Director owns this policy, is accountable for data protection across the business, decides on notifiable breaches, and approves the engagement of new processors.
- Everyone working for or with Lead Conneqt Limited must follow this policy, complete only the processing their role requires, and keep personal data confidential.
- Anyone running a campaign must confirm the lawful basis, the targeting rationale and the screening steps before outreach begins.
- Anyone who receives an objection, opt-out or rights request must action it or pass it on the same working day.
- Anyone who becomes aware of a suspected data incident must report it immediately, even if they are unsure whether it is serious.
- Contractors and suppliers who process personal data for us must meet the same standards under written terms, and are responsible for the conduct of anyone they use in turn.
- Clients remain responsible for the accuracy and lawfulness of any data they provide to us, and their instructions cannot require us to act unlawfully.
Reporting and escalation
Concerns about how personal data is being handled, and suspected data incidents, should be raised with the Managing Director at dane@leadconneqt.com. Requests to exercise data protection rights should be sent to the address published in our privacy notice, as set out above. Data incidents should be reported immediately rather than held until business hours or until the facts are complete.
Concerns are taken seriously, are looked into properly, and are handled confidentially so far as is reasonably possible. Where identifying the person who raised the concern is unavoidable in order to investigate, we will discuss that with them first wherever we can.
Nobody who raises a concern in good faith will suffer detriment or retaliation of any kind, including where the concern turns out to be mistaken. That protection applies to anyone working for or on behalf of Lead Conneqt Limited, to people working for our suppliers and contractors, and to anyone else who comes forward.
Individuals also have the right to complain to the Information Commissioner's Office, the United Kingdom supervisory authority for data protection, and are free to do so at any time. We would prefer the opportunity to put things right first, but raising a concern with us is not a precondition.
Breaches and non-compliance
This section concerns breaches of this policy. Personal data breaches are handled as set out under Our commitments above.
Failure to follow this policy is treated seriously. Depending on the circumstances and the seriousness of the failure, we may suspend the processing or campaign concerned, withdraw system access, take disciplinary action, or end an employment, contract or engagement. Where a supplier or processor fails to meet the standards required by this policy, we may suspend the flow of data to them and end the relationship.
Deliberately concealing a data incident, ignoring an opt-out or objection, or continuing to contact a person who has asked us to stop, are regarded as serious failures. Where a failure gives rise to a legal obligation to notify a regulator, a client or an affected individual, we will meet that obligation, and no internal consideration will be allowed to delay it.
Review
This policy is reviewed at least annually, or sooner where there is a material change to the business, its services, its supply chain or the law. The owner of this policy is the Managing Director, who is responsible for the review and for approving any revision.