Privacy Notice
What personal information we collect through this website, why we are allowed to use it, who else sees it, how long we keep it, and the rights you have over it under UK data protection law.
Last updated 16 August 2026
Draft — needs a solicitor's review before launch
This page was drafted from how the website and database actually work. It is a working draft, not settled legal advice, and it has not been checked by a qualified adviser. Every [highlighted placeholder] below must be filled in, and the whole document reviewed by a solicitor, before this site is treated as compliant.
Section 1
Who we are and how to contact us
This website trades as The Business Directory. The data controller responsible for the personal data described in this notice is [PLACEHOLDER — registered company name], a company registered in England and Wales with company number [PLACEHOLDER — company registration number], whose registered office is at [PLACEHOLDER — registered office address].
We are registered with the Information Commissioner's Office (ICO) under registration number [PLACEHOLDER — ICO registration number].
For anything to do with your personal data — a question, a request to see your data, or a complaint — contact us at [PLACEHOLDER — contact email address] or call +44 1494 265219. We have not appointed a statutory Data Protection Officer; we are not a public authority and we do not carry out large-scale monitoring or process special category data at scale, so the Article 37 duty does not apply. If that changes, this notice will be updated.
Section 2
What this notice covers
This notice explains what we do with personal data when you use this website — whether you browse the marketing pages, send an enquiry, place an order, hold an account in the customer dashboard, or appear in our public business directory. It is written for the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
It does not cover the third-party websites we link to, or the directory and advertising platforms your business listing is published on. Those organisations decide for themselves what they do with data and publish their own privacy notices — section 8 lists who they are.
Section 3
The information we collect
We only collect what the site actually asks for. Each group below matches a specific place in the product, so you can see exactly which action causes which data to be stored.
Enquiry, quote and callback forms
The contact forms on the home page and on each service page (Directory Listing, Online Marketing, Website Design, Google Guaranteed, Hire a Manager, Grow Your Business) submit your business name, postcode, phone number, email address and, where the form offers it, your name and message. We also record which page the enquiry came from and the date and time, so the right person can call you back with the right context.
Postcode and coverage search
The coverage tool on the home page takes the postcode or address you type and sends it to OpenStreetMap's Nominatim service to place a pin on the map. That lookup happens in your browser and the postcode is not saved to our database unless you go on to submit an enquiry form.
Checkout and billing details
When you place an order we collect your full name, email address, company or trading name, address line, city, postcode and country, together with the plans you selected, any promotional code applied and the order total. This is the billing information we need to raise a valid invoice and to identify who the contract is with.
Account and profile data
If you create an account we store your email address, a securely hashed password, your name, your phone number, an optional profile photo, and the role your account holds (customer, manager, support, admin or owner). We never store your password in a readable form and nobody at our company can see it.
Business and listing data
To deliver a listing service we hold your business name, category, contact email and phone number, address, city and postcode, website address, business description, logo, and the plan you are on. If you use the Companies House lookup during onboarding we also store the company number, company status, SIC codes, incorporation date and registered office address returned by the public register, plus the date you verified it.
Messages, support and dashboard activity
Messages you send us through the dashboard, notes our team adds to your account, tasks raised for your project, approval decisions you make, and a record of significant account events (an order placed, a listing published, a setting changed) are stored against your business so we have a reliable history of the work.
Reviews
If a review is submitted for a business in our directory, we store the reviewer's name, rating and comments. Approved reviews are shown publicly on the business's directory page.
Technical data
Our servers keep ordinary web and application logs — IP address, date and time, the page or API endpoint requested, response status and browser user-agent. These are security and reliability records, not analytics. We do not run any analytics, advertising or session-recording product on this site.
Section 4
Where the information comes from
Most of the personal data we hold comes directly from you — typed into a form, entered at checkout, or added in your dashboard. We also obtain data from two other sources:
- Companies House. When you use the company lookup, we retrieve your company's entry from the free public register. That entry can include the names and appointment details of directors, which are already public information published by Companies House.
- Publicly available business information. Where we audit your existing online presence we look at information you or others have already published — your Google Business Profile, existing directory entries and your own website.
If someone gives us your details on your behalf (for example a colleague submitting an enquiry for your business), we rely on them having your authority to do so, and we will identify ourselves and the purpose the first time we contact you.
Section 5
Why we use your information, and our lawful basis
UK GDPR requires a lawful basis for every use of personal data. Ours are set out below. We do not sell personal data, and we do not carry out automated decision-making or profiling that produces legal effects for you.
| What we do | Data used | Lawful basis |
|---|---|---|
| Respond to an enquiry, quote request or callback | Name, business name, postcode, phone, email, message | Article 6(1)(b) — steps taken at your request before entering a contract. Where the enquiry is speculative, Article 6(1)(f) legitimate interests: replying to people who ask us to. |
| Take and fulfil an order; deliver the services you buy | Billing details, order and plan data, business and listing data | Article 6(1)(b) — performance of our contract with you. |
| Run your account and the customer dashboard | Account, profile, business and project data | Article 6(1)(b) — performance of our contract with you. |
| Verify your business against the public register | Company name or number, and the register data returned | Article 6(1)(f) legitimate interests: confirming a customer is a real, active trading business and preventing fraudulent orders. |
| Publish your listing to directories and platforms | Business name, address, postcode, phone, email, website, description, logo, category | Article 6(1)(b) — this is the service you have bought. |
| Raise invoices and keep accounting records | Billing details, order and payment records | Article 6(1)(c) — legal obligation under tax and company law. |
| Handle complaints, disputes and refunds | Whatever is relevant to the matter | Article 6(1)(f) legitimate interests: defending and resolving claims; and Article 6(1)(c) where a legal obligation applies. |
| Send service messages (order confirmations, invoices, listing updates, password resets) | Name and email address | Article 6(1)(b) — necessary to deliver the service. These are not marketing and cannot be unsubscribed from while you hold an account. |
| Send marketing about our services | Name, email address, phone number | Article 6(1)(f) legitimate interests, with PECR regulation 22 soft opt-in where you are an existing customer; otherwise your consent. Every message carries an unsubscribe link. |
| Publish approved reviews in the public directory | Reviewer name, rating, comments | Article 6(1)(f) legitimate interests: helping people choose a business, balanced against a reviewer's expectation that a review they wrote for publication will be published. |
| Keep the site secure and diagnose faults | IP address, timestamps, request and error logs | Article 6(1)(f) legitimate interests: protecting our systems and our customers' data. |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object to any of that processing — see section 10.
Section 6
Marketing and electronic messages
We will send you marketing by email or text only if you are an existing customer who bought or negotiated for a similar service (the PECR “soft opt-in”), or if you have told us you want to hear from us. You are given a clear way to refuse when we first collect your details and in every message afterwards.
We may call you on a business number about services you have enquired about. If your number is registered with the Telephone Preference Service or Corporate TPS, we will not make unsolicited marketing calls to it. Tell us at any time to stop calling and we will record that against your record permanently.
Section 7
How long we keep it
We keep personal data only for as long as we need it for the purpose we collected it, plus any period the law requires. Our standard periods are below.
| Record | Retention period | Why |
|---|---|---|
| Enquiries that do not become customers | 24 months from the last contact | Long enough to recognise a returning enquirer and to evidence how we handled the enquiry. |
| Customer account, business and listing data | For the life of the account, then 24 months after it closes | So a returning customer's listings can be restored, and so we can answer post-termination questions. |
| Orders, invoices, payments and refunds | 6 years from the end of the financial year they relate to | Companies Act 2006 and HMRC record-keeping requirements. |
| Contracts and correspondence about them | 6 years from the end of the contract | The limitation period for a contract claim in England and Wales. |
| Support messages, project notes and approvals | 3 years after the related work ends | Evidence of what was agreed and delivered. |
| Published reviews | Until removed by the reviewer, the business or us | A review only serves its purpose while it is visible. |
| Marketing suppression list (people who opted out) | Indefinitely | We must keep a record of who not to contact — deleting it would cause the very problem it prevents. |
| Technical and security logs | [PLACEHOLDER — confirm server log retention] (typically 30–90 days) | Security monitoring and fault diagnosis. |
At the end of a retention period the data is deleted or irreversibly anonymised. Where deletion is not immediately possible — for example in an encrypted backup — the data is put beyond use and deleted when that backup is rotated out.
Section 9
Information published in our directory
Active businesses appear in the public directory on this site. The published entry shows your business name, category, city, postcode, phone number, website address, description, logo, the date you joined and your average review score. Your account email address, your owner details, our internal notes and everything else in your record are never published — the directory reads through a restricted database function that can only return those safe fields.
Being listed is the point of the service, so we cannot deliver it and keep your details private at the same time. If you want your entry removed, tell us and we will unpublish it; note that copies already syndicated to third-party platforms have to be removed by those platforms, and we will tell you what we have requested on your behalf.
Section 10
Transfers outside the UK
Our own servers, database and file storage are located at [PLACEHOLDER — hosting location / data centre], and the personal data we hold stays there.
Some of the third-party content described in section 8 is served from outside the UK. When your browser fetches a map tile, an icon or a geocoding result, your IP address and the request reach that provider directly and we are not in a position to impose transfer terms on a request we do not make. Where we ourselves send data abroad — or where a provider we instruct does — we rely on the UK adequacy regulations for countries the UK has approved, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
Section 11
Your rights
Under the UK GDPR you have the following rights. They are free to exercise, and we will respond within one month — extendable by a further two months for genuinely complex requests, in which case we will tell you why within the first month.
- Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
- Rectification — correction of anything inaccurate, and completion of anything incomplete. Most of it you can correct yourself in your dashboard settings.
- Erasure — deletion, where we no longer need the data, where you withdraw consent we were relying on, or where you successfully object. It does not apply to records we must keep by law, such as invoices.
- Restriction — a freeze on our use of your data while a dispute about its accuracy or our lawful basis is resolved.
- Portability — the data you gave us, in a structured, commonly used, machine-readable format, for data we process by automated means on the basis of consent or contract.
- Objection — you can object to processing based on legitimate interests, and we must stop unless we can show compelling grounds that override your rights. You can object to direct marketing at any time and we must stop immediately, with no exceptions.
- Withdrawing consent — where we relied on consent, you can withdraw it at any time. That does not affect anything done before you withdrew it.
- Automated decisions — you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make decisions that way.
To make a request, email [PLACEHOLDER — contact email address] or write to us at the address in section 1. We may ask for enough information to be satisfied you are who you say you are — we will not hand your data to someone else on the strength of an email address alone.
Section 12
How we keep it safe
Access to data in our database is enforced at the database itself through row-level security policies, so a customer's session can only ever read the rows belonging to that customer, regardless of what the browser asks for. Sign-in is handled by a dedicated authentication service, passwords are stored only as salted hashes, and every write that matters goes through a controlled server-side function rather than a direct table write.
Traffic to and from this site is encrypted with TLS. Staff accounts are role-based, so support and management staff can only see what their role requires, and significant admin actions are recorded in an audit log.
No system is perfectly secure. If a personal data breach happens and it is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell you directly if the risk to you is high.
Section 13
Children
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their details, tell us and we will delete them.
Section 14
How to complain
Please raise any concern with us first — email [PLACEHOLDER — contact email address] or call +44 1494 265219 and we will investigate and reply.
You also have the right to complain to the UK's data protection regulator at any time, whether or not you have come to us first:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint
If you think we have broken the rules on marketing calls, emails or cookies, that is also the ICO, under PECR.
Section 15
Changes to this notice
We review this notice whenever the site changes in a way that affects personal data, and at least once a year. The “last updated” date at the top of the page always shows the current version. If we make a change that materially affects how we use your data, we will tell account holders by email before it takes effect.
Our Cookie Policy and Terms & Conditions form part of the same set of documents and should be read alongside this one.
Questions about this page?
Get in touch and we'll answer within one working day.
- [PLACEHOLDER — contact email address]
- +44 1494 265219
- [PLACEHOLDER — registered office address]
