GDPR & Compliance

Last updated 23 August 2026 · Applies to organictraffic.io

Read this before you send. B2B contact data is lawful to buy and use in most of the world, but the rules differ by country and by channel. This page sets out our position and what you are responsible for. It is not legal advice — if you are running large cross-border campaigns, get some.

1. What kind of data this is

We supply business contact information: the trading name of a business, the inbox and phone number it publishes for enquiries, its trading address, its website and its public review profile. This is information a business has chosen to publish so that customers and suppliers can reach it.

We do not supply consumer data, home addresses, personal mobile numbers, or any information about a person acting in a private capacity.

Note that in the EU and UK, an address like firstname@business.com at a sole trader or partnership can still constitute personal data even though it is a business address. We treat such records as personal data and handle them accordingly.

2. Where it comes from

  • Public business directories and listing platforms.
  • Official company and trade registers.
  • The businesses' own websites — contact and about pages.
  • Publicly accessible review platforms, for ratings and review counts.

Every delivered record carries the source category and the date of collection, so you can evidence provenance if you are ever asked to.

3. Lawful basis (EU / UK)

For B2B marketing to corporate subscribers we rely on legitimate interest under Article 6(1)(f) GDPR, both for our compilation and for your outreach. We maintain a Legitimate Interests Assessment covering the collection and supply of this data; a copy is available on request.

Under Article 14 GDPR, where personal data is not collected from the data subject directly, notice obligations apply. In practice, your first communication should identify who you are, how you obtained their details, and how to opt out. That satisfies the requirement and is good outreach practice regardless.

PECR (UK) permits unsolicited B2B email to corporate subscribers — limited companies, LLPs, public bodies — without prior consent, provided an opt-out is offered. Sole traders and unincorporated partnerships are treated as individual subscribers and require consent or a soft opt-in. Filter accordingly; review count and business type in the file will usually tell you which is which.

4. Controller and processor roles

We are an independent controller for the compilation and supply of the data. On delivery, you become an independent controller for your use of it. We are not your processor and you are not ours.

A Data Processing Agreement covering the transfer, including Standard Contractual Clauses where relevant, is available at hello@organictraffic.io. We will sign yours if you prefer.

5. Regime-by-regime summary

RegimeB2B cold emailWhat you must do
CAN-SPAM (US)PermittedAccurate headers and subject line, a physical postal address, a working opt-out honoured within 10 business days.
CASL (Canada)Permitted with careImplied consent applies where the address is conspicuously published without a “no unsolicited email” notice and your message is relevant to their role. Identify yourself and include an unsubscribe.
UK GDPR + PECRPermitted to corporate subscribersLegitimate interest, Article 14 notice, opt-out in every message. Sole traders need consent or soft opt-in.
EU GDPR + ePrivacyVaries by member stateLegitimate interest is workable in most states. Germany, Italy and Austria are materially stricter — take local advice before volume sending.
Spam Act (Australia)Permitted with inferred consentAddress must be published in a business capacity without a disclaimer, and the message must be relevant to that role. Include sender details and an unsubscribe.

6. Suppression and data subject requests

Any business or individual can ask to be removed from our data by emailing hello@organictraffic.io. We suppress within 5 working days and the suppression is permanent across all future builds.

If you receive an objection or erasure request relating to a record you bought from us, honour it in your own systems immediately and forward it to us so we can suppress it at source.

7. A practical checklist before you send

  1. Identify your business clearly in every message.
  2. Say where you got their details — one honest sentence is enough.
  3. Make the message relevant to the recipient's business role.
  4. Include a working, one-click opt-out in every send.
  5. Honour opt-outs immediately and keep a suppression list forever.
  6. Authenticate your sending domain: SPF, DKIM and DMARC.
  7. Keep a record of your lawful basis and where the data came from.

8. Compliance contact

Data protection queries, DPA requests and Legitimate Interests Assessments: hello@organictraffic.io.