Legal · Last updated 24 September 2026
Prospect Privacy Notice
Contents
This notice is for people who are not Warmerly customers, but whose business contact details appear in the database that powers our lead finder and email finder. Data protection law requires us to tell you this even though you never gave us your details directly (Article 14, UK and EU GDPR). If you are a customer, our Privacy Policy is the one that applies to you. If you are a resident of California or another US state with a comprehensive privacy law, see also our US State Privacy Notice.
Controller: Warmerly, a UK-based sole trader. Contact: privacy@warmerly.com. We are the controller of the database described below. Where a customer takes a copy of your details out of it, that customer is a separate controller of their copy — see section 4.
1. What we hold
Our database is organised around businesses, not individuals. For a given company domain we may hold:
- the company name and legal name, website, description, industry or business type, approximate size, country, and the year it was founded;
- contact details the business publishes: email addresses, a phone number, a business address, a contact-form link, opening hours, and links to its LinkedIn and other social profiles;
- registration details the business publishes, such as a company number or VAT number, and signals such as whether it links to a careers page;
- which provider handles the domain's email (for example Google Workspace or Microsoft 365);
- technical facts about the domain's email setup — whether it has mail records, its SPF and DMARC configuration — which our deliverability tooling uses internally and which customers cannot see.
Most published addresses are role-based, such as info@, hello@, or contact@. But where a business publishes an individual's work address, or runs its business from a personal or free-mail address, that is what we hold. If you run a business on your own, some of these business details (including a business address or phone number) may also be personal data about you.
Separately, our email finder can be asked by a customer to work out the likely email address of a named individual at a given company. Where that happens we hold that person's first and last name, the company domain, the address or addresses produced, where each was found or how it was derived, and a confidence score. If the customer supplied a link to a LinkedIn profile, we also hold that link and the name and current employer we obtained from it.
We also hold the results of deliverability checks on addresses (for example, whether an address appears to accept mail and when that was checked), and, if you have asked not to be contacted, a suppression record containing your email address or domain.
We do not intentionally collect special category data (such as health, ethnicity or religion) or criminal offence data, and we do not collect home addresses or personal phone numbers except where a business publishes them as its own contact details.
2. Where it came from
- Public lists of websites. We find company domains in publicly available datasets of website addresses, such as the Chrome UX Report and Common Crawl.
- Public company websites. Our crawler reads a company's publicly accessible homepage and, at most, one contact page. It identifies itself in its user agent and obeys
robots.txt; if a site disallows us, we do not crawl it. It reads structured data the site publishes for search engines as well as the visible page. - Public DNS records, for the mail-configuration facts.
- Public web search. The email finder searches the public web for the company's website and published addresses, and can read public search-result snippets of professional profiles to work out a person's current employer.
- Our customers. A customer using the email finder gives us the name, company or domain, and sometimes a LinkedIn profile link, of the person they are looking for. Where they supply a profile link and have connected their own LinkedIn account, we use that account to read the name and current employer shown on the profile.
- Inference and checks. Some addresses are not published anywhere — they are generated from a person's name and their employer's known address format, then tested for deliverability using technical checks against the receiving mail system that do not deliver a message to you. An address produced this way is a well-informed guess, and we label it as such internally with a confidence score.
3. Why we hold it, and our lawful basis
We use this data to:
- operate our lead finder and email finder, which our customers use to identify businesses, and people in their business roles, who might want to hear from them;
- check whether addresses are likely to be deliverable, so that customers do not send mail that bounces;
- keep suppression records so that people who have asked not to be contacted are not contacted through Warmerly;
- maintain, secure and improve the database and our service, including producing aggregated statistics that do not identify anyone; and
- establish, exercise or defend legal claims, and comply with our legal obligations.
Our lawful basis is legitimate interests (Article 6(1)(f)): operating a business-to-business prospecting tool, and our customers' interest in finding businesses to offer their products and services to. For suppression records, we also rely on the need to comply with the law. We have carried out a balancing test. In short: the data is limited to the business sphere, most of it is company-level rather than personal, it comes from sources the business itself made public, we do not build behavioural profiles of individuals, customers cannot see the technical mail-configuration data, customers are bound by our Lead Database Use Terms to use it only for business prospecting, and we give you an unconditional right to have your details removed — see section 6. People in a business role can reasonably expect their published business contact details to be used to contact them about their business.
You have the right to object to processing based on legitimate interests. If you object, we will stop, and there is no test you have to pass first.
You are not required to provide any of this data to us, and we did not ask you for it.
4. Who we share it with
Warmerly customers can search the database, use the email finder, and export records for their own outreach, under our Lead Database Use Terms. Results the email finder produces for one customer may be reused, for a limited period, to answer another customer's lookup of the same company. Once a customer has exported your details, they become the controller of that copy — and they, not us, are responsible for how they contact you. If you have received an email you did not want, the fastest route is to use the unsubscribe link in that email, which suppresses you for that sender immediately. Emailing us also works, and covers our database itself.
We also share it with:
- the sub-processors listed on our Sub-processors page, which host, store, secure and process data for us — including our hosting, cloud and storage providers, and web-search and AI providers where a customer's lookup or AI feature uses a record;
- professional advisers, insurers, and law enforcement bodies, regulators, courts or other authorities where the law requires it or where it is needed to establish, exercise or defend legal claims; and
- a buyer or successor if all or part of our business is sold or transferred, who would be bound by this notice.
We do not sell or license the database as a dataset to data brokers or list sellers. Customers can use it only within Warmerly, subject to our Lead Database Use Terms.
5. How long we keep it
Company records are retained while the business appears to be trading and the record remains useful for business prospecting. Records for domains that no longer resolve or no longer accept mail are retired. Individual-level records produced by the email finder are retained for 24 months from the date they were generated, and then deleted. Deliverability check results are kept for as long as they help keep our deliverability checks accurate. Suppression records — the fact that you asked not to be contacted — are kept indefinitely, because deleting them would allow you to be added back.
6. Your rights, including removal
You have the right to:
- Object to our processing, and have your details removed from the database. We will action this and add you to a permanent suppression list so the same details are not re-added by a future crawl.
- Access the data we hold about you, and receive a copy.
- Correct anything inaccurate — this matters most for inferred email addresses, which can be wrong.
- Erase your data.
- Restrict processing while a dispute is resolved.
- Complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority. We would appreciate the chance to deal with your concern first, but you do not have to contact us before complaining.
To remove yourself or your company, use our privacy request form or email privacy@warmerly.com with the domain or email address concerned. No account needed, no justification needed. We act within one month, and usually much sooner. We may ask you to confirm that you control the address or domain concerned before we act, so that nobody can remove, or see, someone else's details.
What removal does in practice. When we action a removal:
- your email address is added to our platform-wide suppression list, which stops every Warmerly customer sending campaign or transactional email to it through Warmerly, including customers who add it later;
- the company record or address concerned is marked as removed, so it no longer appears in search results or exports, and the mark stays in place if the website is crawled again; and
- we keep only the suppression record needed to make this last.
Removal cannot reach copies a customer exported before your request, or mail a customer sends from their own systems outside Warmerly. For those, contact the sender directly or use the unsubscribe link in their message; where we can identify a customer who obtained your details from us, we may pass your objection on to them.
7. Automated processing
We use automated processing to extract business details from web pages, to classify businesses by industry and size, and to estimate how likely an address is to be correct and deliverable. We do not make decisions about you based solely on automated processing that produce legal effects on you or similarly significantly affect you.
8. International transfers
The database is stored on our primary infrastructure in the European Economic Area, and parts of it are processed by our cloud providers in the UK and the EEA. Some of our sub-processors are located outside the UK and EEA, in particular in the United States. Where personal data is transferred outside the UK or EEA, we rely on adequacy regulations or decisions, or on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, as described in our Privacy Policy. You can ask us for more information about these safeguards at privacy@warmerly.com.
9. Changes
We will post updates to this notice on this page and update the date above. If we start using this data for a new purpose, we will update this notice before we do.
10. Contact
Warmerly. Privacy questions and requests: privacy@warmerly.com.



