Privacy

Privacy Notice

What personal information we collect through this website, why we are allowed to use it, who else sees it, how long we keep it, and the rights you have over it under UK data protection law.

Last updated 16 August 2026

Draft — needs a solicitor's review before launch

This page was drafted from how the website and database actually work. It is a working draft, not settled legal advice, and it has not been checked by a qualified adviser. Every [highlighted placeholder] below must be filled in, and the whole document reviewed by a solicitor, before this site is treated as compliant.

Section 1

Who we are and how to contact us

This website trades as The Business Directory. The data controller responsible for the personal data described in this notice is [PLACEHOLDER — registered company name], a company registered in England and Wales with company number [PLACEHOLDER — company registration number], whose registered office is at [PLACEHOLDER — registered office address].

We are registered with the Information Commissioner's Office (ICO) under registration number [PLACEHOLDER — ICO registration number].

For anything to do with your personal data — a question, a request to see your data, or a complaint — contact us at [PLACEHOLDER — contact email address] or call +44 1494 265219. We have not appointed a statutory Data Protection Officer; we are not a public authority and we do not carry out large-scale monitoring or process special category data at scale, so the Article 37 duty does not apply. If that changes, this notice will be updated.

Owner action: if the business is a sole trader or partnership rather than a limited company, the company-number line must be removed and replaced with the trading name and a service address. Whichever form the business takes, an ICO registration and fee are almost certainly required because personal data is processed electronically for commercial purposes.

Section 2

What this notice covers

This notice explains what we do with personal data when you use this website — whether you browse the marketing pages, send an enquiry, place an order, hold an account in the customer dashboard, or appear in our public business directory. It is written for the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

It does not cover the third-party websites we link to, or the directory and advertising platforms your business listing is published on. Those organisations decide for themselves what they do with data and publish their own privacy notices — section 8 lists who they are.

Section 3

The information we collect

We only collect what the site actually asks for. Each group below matches a specific place in the product, so you can see exactly which action causes which data to be stored.

Enquiry, quote and callback forms

The contact forms on the home page and on each service page (Directory Listing, Online Marketing, Website Design, Google Guaranteed, Hire a Manager, Grow Your Business) submit your business name, postcode, phone number, email address and, where the form offers it, your name and message. We also record which page the enquiry came from and the date and time, so the right person can call you back with the right context.

Postcode and coverage search

The coverage tool on the home page takes the postcode or address you type and sends it to OpenStreetMap's Nominatim service to place a pin on the map. That lookup happens in your browser and the postcode is not saved to our database unless you go on to submit an enquiry form.

Checkout and billing details

When you place an order we collect your full name, email address, company or trading name, address line, city, postcode and country, together with the plans you selected, any promotional code applied and the order total. This is the billing information we need to raise a valid invoice and to identify who the contract is with.

We do not take card details on this website. Placing an order creates a pending order for our team to confirm; payment is arranged afterwards by card, Direct Debit, bank transfer or invoice. No card number, expiry date or security code is ever entered into, transmitted by, or stored on this site.

Account and profile data

If you create an account we store your email address, a securely hashed password, your name, your phone number, an optional profile photo, and the role your account holds (customer, manager, support, admin or owner). We never store your password in a readable form and nobody at our company can see it.

Business and listing data

To deliver a listing service we hold your business name, category, contact email and phone number, address, city and postcode, website address, business description, logo, and the plan you are on. If you use the Companies House lookup during onboarding we also store the company number, company status, SIC codes, incorporation date and registered office address returned by the public register, plus the date you verified it.

Messages, support and dashboard activity

Messages you send us through the dashboard, notes our team adds to your account, tasks raised for your project, approval decisions you make, and a record of significant account events (an order placed, a listing published, a setting changed) are stored against your business so we have a reliable history of the work.

Reviews

If a review is submitted for a business in our directory, we store the reviewer's name, rating and comments. Approved reviews are shown publicly on the business's directory page.

Technical data

Our servers keep ordinary web and application logs — IP address, date and time, the page or API endpoint requested, response status and browser user-agent. These are security and reliability records, not analytics. We do not run any analytics, advertising or session-recording product on this site.

Owner action: confirm the retention period your server and reverse proxy actually apply to access logs, and align it with the “technical logs” row in section 7.

Section 4

Where the information comes from

Most of the personal data we hold comes directly from you — typed into a form, entered at checkout, or added in your dashboard. We also obtain data from two other sources:

  • Companies House. When you use the company lookup, we retrieve your company's entry from the free public register. That entry can include the names and appointment details of directors, which are already public information published by Companies House.
  • Publicly available business information. Where we audit your existing online presence we look at information you or others have already published — your Google Business Profile, existing directory entries and your own website.

If someone gives us your details on your behalf (for example a colleague submitting an enquiry for your business), we rely on them having your authority to do so, and we will identify ourselves and the purpose the first time we contact you.

Section 5

Why we use your information, and our lawful basis

UK GDPR requires a lawful basis for every use of personal data. Ours are set out below. We do not sell personal data, and we do not carry out automated decision-making or profiling that produces legal effects for you.

What we doData usedLawful basis
Respond to an enquiry, quote request or callbackName, business name, postcode, phone, email, messageArticle 6(1)(b) — steps taken at your request before entering a contract. Where the enquiry is speculative, Article 6(1)(f) legitimate interests: replying to people who ask us to.
Take and fulfil an order; deliver the services you buyBilling details, order and plan data, business and listing dataArticle 6(1)(b) — performance of our contract with you.
Run your account and the customer dashboardAccount, profile, business and project dataArticle 6(1)(b) — performance of our contract with you.
Verify your business against the public registerCompany name or number, and the register data returnedArticle 6(1)(f) legitimate interests: confirming a customer is a real, active trading business and preventing fraudulent orders.
Publish your listing to directories and platformsBusiness name, address, postcode, phone, email, website, description, logo, categoryArticle 6(1)(b) — this is the service you have bought.
Raise invoices and keep accounting recordsBilling details, order and payment recordsArticle 6(1)(c) — legal obligation under tax and company law.
Handle complaints, disputes and refundsWhatever is relevant to the matterArticle 6(1)(f) legitimate interests: defending and resolving claims; and Article 6(1)(c) where a legal obligation applies.
Send service messages (order confirmations, invoices, listing updates, password resets)Name and email addressArticle 6(1)(b) — necessary to deliver the service. These are not marketing and cannot be unsubscribed from while you hold an account.
Send marketing about our servicesName, email address, phone numberArticle 6(1)(f) legitimate interests, with PECR regulation 22 soft opt-in where you are an existing customer; otherwise your consent. Every message carries an unsubscribe link.
Publish approved reviews in the public directoryReviewer name, rating, commentsArticle 6(1)(f) legitimate interests: helping people choose a business, balanced against a reviewer's expectation that a review they wrote for publication will be published.
Keep the site secure and diagnose faultsIP address, timestamps, request and error logsArticle 6(1)(f) legitimate interests: protecting our systems and our customers' data.

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object to any of that processing — see section 10.

Section 6

Marketing and electronic messages

We will send you marketing by email or text only if you are an existing customer who bought or negotiated for a similar service (the PECR “soft opt-in”), or if you have told us you want to hear from us. You are given a clear way to refuse when we first collect your details and in every message afterwards.

We may call you on a business number about services you have enquired about. If your number is registered with the Telephone Preference Service or Corporate TPS, we will not make unsolicited marketing calls to it. Tell us at any time to stop calling and we will record that against your record permanently.

Opting out of marketing does not stop service messages — order confirmations, invoices, listing reports and security emails are part of the service you have bought.

Section 7

How long we keep it

We keep personal data only for as long as we need it for the purpose we collected it, plus any period the law requires. Our standard periods are below.

RecordRetention periodWhy
Enquiries that do not become customers24 months from the last contactLong enough to recognise a returning enquirer and to evidence how we handled the enquiry.
Customer account, business and listing dataFor the life of the account, then 24 months after it closesSo a returning customer's listings can be restored, and so we can answer post-termination questions.
Orders, invoices, payments and refunds6 years from the end of the financial year they relate toCompanies Act 2006 and HMRC record-keeping requirements.
Contracts and correspondence about them6 years from the end of the contractThe limitation period for a contract claim in England and Wales.
Support messages, project notes and approvals3 years after the related work endsEvidence of what was agreed and delivered.
Published reviewsUntil removed by the reviewer, the business or usA review only serves its purpose while it is visible.
Marketing suppression list (people who opted out)IndefinitelyWe must keep a record of who not to contact — deleting it would cause the very problem it prevents.
Technical and security logs[PLACEHOLDER — confirm server log retention] (typically 30–90 days)Security monitoring and fault diagnosis.

At the end of a retention period the data is deleted or irreversibly anonymised. Where deletion is not immediately possible — for example in an encrypted backup — the data is put beyond use and deleted when that backup is rotated out.

Section 8

Who we share your information with

This site runs on our own infrastructure. The website, the database, sign-in, file storage and the API are all hosted on servers we operate ourselves at [PLACEHOLDER — hosting location / data centre]. We do not use a third-party analytics platform, advertising network, customer-data platform or marketing automation suite, and no tracking pixels are embedded in these pages.

The organisations that do receive data, and why, are these — and no others:

Services this website calls directly

  • Companies House (api.company-information.service.gov.uk) — when you use the company lookup, the search term or company number you typed is sent from our server to the public register. Your own contact details are not sent.
  • OpenStreetMap Foundation (Nominatim) — the postcode or address you type into the coverage search is sent from your browser to nominatim.openstreetmap.org to convert it into map coordinates. That request carries your IP address.
  • CARTO — the coverage map draws its background tiles from basemaps.cartocdn.com, using map data from OpenStreetMap. Your browser requests those tiles directly, so CARTO sees your IP address, your browser user-agent and roughly which area of the map you are looking at.
  • Simple Icons (cdn.simpleicons.org) — brand logos shown next to the platforms we list to are fetched from this content delivery network by your browser, which reveals your IP address to it.
  • Google — small site icons for partner platforms are loaded from google.com/s2/favicons and gstatic.com. Your browser requests these directly, so Google receives your IP address and the address of the icon requested. We do not use Google Analytics, Google Ads tags or Google Fonts on this site.
  • Fena — if we send you an invoice that includes an instant bank-payment link, following that link takes you to Fena's own payment page. From that point Fena is responsible for the payment details you give them, under their own privacy notice.

Directory and advertising platforms

Delivering a listing or marketing service means submitting your business details to the platforms you are being listed on. Depending on the plan you buy, that can include Google Business Profile, Bing Places, Apple Business Connect, Yell, Thomson Local, Scoot, Cylex, FreeIndex, Hotfrog, 192.com, Yelp, Foursquare, Nextdoor, TripAdvisor, Checkatrade, TrustATrader, Rated People, MyBuilder, Bark, Houzz, Which? Trusted Traders, Trustpilot, Feefo, Reviews.io, LinkedIn, Meta and TikTok. Each of those platforms is a separate controller and applies its own privacy notice to what it publishes. Where the details you give us are those of a sole trader, they are personal data as well as business data — publishing them is the service you have asked us to perform.

Others

  • Professional advisers — our accountants, auditors, insurers and solicitors, where they need the information to advise us.
  • Law enforcement and regulators — where we are legally required to disclose, or need to establish or defend a legal claim.
  • A buyer of the business — if the business is sold or restructured, customer records would transfer with it. You would be told before that happened.
Owner action: if you later add an email provider, an accounting platform, a live-chat widget, a CRM or an analytics tool, each one becomes a processor or recipient and must be added to this list — and a written processor contract under Article 28 must be in place before any personal data reaches it.

Section 9

Information published in our directory

Active businesses appear in the public directory on this site. The published entry shows your business name, category, city, postcode, phone number, website address, description, logo, the date you joined and your average review score. Your account email address, your owner details, our internal notes and everything else in your record are never published — the directory reads through a restricted database function that can only return those safe fields.

Being listed is the point of the service, so we cannot deliver it and keep your details private at the same time. If you want your entry removed, tell us and we will unpublish it; note that copies already syndicated to third-party platforms have to be removed by those platforms, and we will tell you what we have requested on your behalf.

Section 10

Transfers outside the UK

Our own servers, database and file storage are located at [PLACEHOLDER — hosting location / data centre], and the personal data we hold stays there.

Some of the third-party content described in section 8 is served from outside the UK. When your browser fetches a map tile, an icon or a geocoding result, your IP address and the request reach that provider directly and we are not in a position to impose transfer terms on a request we do not make. Where we ourselves send data abroad — or where a provider we instruct does — we rely on the UK adequacy regulations for countries the UK has approved, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

Owner action: confirm, for each provider in section 8, which safeguard applies and keep a copy on file. If you would rather avoid the question entirely, the map tiles, brand icons and favicons can be self-hosted from this server, which removes those transfers altogether.

Section 11

Your rights

Under the UK GDPR you have the following rights. They are free to exercise, and we will respond within one month — extendable by a further two months for genuinely complex requests, in which case we will tell you why within the first month.

  • Access — a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Rectification — correction of anything inaccurate, and completion of anything incomplete. Most of it you can correct yourself in your dashboard settings.
  • Erasure — deletion, where we no longer need the data, where you withdraw consent we were relying on, or where you successfully object. It does not apply to records we must keep by law, such as invoices.
  • Restriction — a freeze on our use of your data while a dispute about its accuracy or our lawful basis is resolved.
  • Portability — the data you gave us, in a structured, commonly used, machine-readable format, for data we process by automated means on the basis of consent or contract.
  • Objection — you can object to processing based on legitimate interests, and we must stop unless we can show compelling grounds that override your rights. You can object to direct marketing at any time and we must stop immediately, with no exceptions.
  • Withdrawing consent — where we relied on consent, you can withdraw it at any time. That does not affect anything done before you withdrew it.
  • Automated decisions — you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make decisions that way.

To make a request, email [PLACEHOLDER — contact email address] or write to us at the address in section 1. We may ask for enough information to be satisfied you are who you say you are — we will not hand your data to someone else on the strength of an email address alone.

Section 12

How we keep it safe

Access to data in our database is enforced at the database itself through row-level security policies, so a customer's session can only ever read the rows belonging to that customer, regardless of what the browser asks for. Sign-in is handled by a dedicated authentication service, passwords are stored only as salted hashes, and every write that matters goes through a controlled server-side function rather than a direct table write.

Traffic to and from this site is encrypted with TLS. Staff accounts are role-based, so support and management staff can only see what their role requires, and significant admin actions are recorded in an audit log.

No system is perfectly secure. If a personal data breach happens and it is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell you directly if the risk to you is high.

Section 13

Children

Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their details, tell us and we will delete them.

Section 14

How to complain

Please raise any concern with us first — email [PLACEHOLDER — contact email address] or call +44 1494 265219 and we will investigate and reply.

You also have the right to complain to the UK's data protection regulator at any time, whether or not you have come to us first:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Helpline: 0303 123 1113 · ico.org.uk/make-a-complaint

If you think we have broken the rules on marketing calls, emails or cookies, that is also the ICO, under PECR.

Section 15

Changes to this notice

We review this notice whenever the site changes in a way that affects personal data, and at least once a year. The “last updated” date at the top of the page always shows the current version. If we make a change that materially affects how we use your data, we will tell account holders by email before it takes effect.

Our Cookie Policy and Terms & Conditions form part of the same set of documents and should be read alongside this one.

Questions about this page?

Get in touch and we'll answer within one working day.

  • [PLACEHOLDER — contact email address]
  • +44 1494 265219
  • [PLACEHOLDER — registered office address]