Privacy Notice for Prospects
Why you received a business message, what data is held about you, where it came from, and how to opt out, under Article 14 of the GDPR.
On this page
Who is contacting you: the Sequenz customer who contacted you (the "Company", "we", "us")
Contact for privacy questions: the address that sent you the message (you can reply to it directly)
Postal address: the postal address shown in that message
Effective date: 28 September 2026 Version: 1.0
You are reading this because we recently contacted you — or are about to — with a business message (by email, LinkedIn, or WhatsApp) that isn't a reply to something you sent us. We didn't collect your details directly from you, so the law requires us to tell you what data we hold, where we got it, why we're using it, and what you can do about it.
This notice is issued under Article 14 of the EU General Data Protection Regulation (GDPR) (and the equivalent UK GDPR), which applies when a business processes personal data it obtained from a source other than the individual.
1.Who is responsible for your data
the Sequenz customer who contacted you is the controller of your personal data — we decide what data to hold about you and why.
To run our outreach, we use Sequenz (sequenz.ai), a sales-outreach platform, as our processor. Sequenz stores and sends these messages on our behalf and acts only on our documented instructions. It does not use your data for its own purposes, does not sell it, and does not operate a contact database that your details came from. Sequenz's own role and safeguards are described in its Privacy Policy and Data Processing Agreement.
If you have any question about how your data is used, contact us at the address that sent you the message (you can reply to it directly) — not Sequenz — because we, as the controller, are responsible for it.
Back to top2.What personal data we hold about you
We only hold business contact information relevant to professional outreach. We do not knowingly collect special-category data (such as health, political, religious, or similar sensitive information).
| Category | Data elements |
|---|---|
| Contact identity | your name, business email address, job title / seniority, business phone number, LinkedIn profile URL |
| Company | company name, company website / domain, industry, company size |
| Location | business location, time zone (used to send at a reasonable local hour) |
| Outreach metadata | whether a message was sent, delivered, replied to, or bounced, and which sequence step you are at; whether it was opened or a link clicked only if the sender turned tracking on (the email then says so) |
| Message content | the outbound messages we send you and any replies you send back |
| Consent & suppression | opt-out / unsubscribe records, and (for WhatsApp) any opt-in we captured, so we can honour your choices |
3.Where we got your data (the source)
Under Article 14(2)(f), we must tell you where your data came from. Your details reached us from one or more of these sources:
- our own customer relationship management (CRM) records or prior business records;
- publicly available professional sources — for example your company's website, a professional networking profile such as LinkedIn, or a business directory; and/or
- a contact list that we compiled ourselves or that was lawfully provided to us for business outreach.
We did not buy your data from a data broker operated by Sequenz, and Sequenz does not enrich it from any database of its own.
Back to top4.Why we're contacting you, and our legal basis
We are contacting you for business-to-business outreach — to introduce a product or service that we believe is relevant to your professional role, and, where an AI assistant helps us, to draft and personalise that message (a person at our company reviews it before it is sent).
Our legal basis is legitimate interests under Article 6(1)(f) GDPR: our legitimate interest in promoting our business to relevant professional contacts. Before relying on this, we weighed that interest against your rights and freedoms (a "legitimate interests assessment"), and we limit ourselves to business contact data, relevant recipients, and an easy way to opt out. You can ask us for more detail about that balancing test using the contact details above.
We do not use automated processing to make decisions that produce legal or similarly significant effects on you within the meaning of Article 22.
Back to top5.Why you are hearing this now, and not sooner
Where a business obtains contact details indirectly, GDPR allows it to inform people through a public notice like this one when contacting every individual separately would involve disproportionate effort (Article 14(5)(b)). Because we reach professional contacts at scale, we have documented that assessment and publish this notice — linked from every email we send you — as the way we tell you about our processing. If you would like the specific information about your record, contact us and we will provide it.
Back to top6.How long we keep your data
| Data | Retention |
|---|---|
| Your contact identity & company details | kept while you remain an active prospect; deleted or anonymised within 30 days if we close the account holding it |
| Outreach metadata (opens, clicks, etc.) | deleted on our configured retention horizon |
| Message content | kept for the life of the conversation, then deleted or anonymised on the same horizon |
| Opt-out / suppression records | kept for as long as needed to make sure we do not contact you again after you object |
If you object or unsubscribe (see Section 8), we stop contacting you on every channel and keep the minimum needed to remember not to contact you again. If you also want your data deleted, ask us (Article 17, Section 8).
Back to top7.Who else may receive your data
To deliver this outreach we share your data with Sequenz (our processor) and, through Sequenz, with its sub-processors that provide hosting, email/messaging delivery, and AI drafting. The current, named list of those sub-processors — with their role, legal entity, and region — is published on Sequenz's Compliance page and in its DPA.
Our primary systems are hosted in the EU. Where a provider is outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses or an applicable adequacy decision (such as the EU–US Data Privacy Framework). We do not sell your personal data.
Back to top8.Your rights
You have the following rights over your personal data. Most can be exercised simply by replying to us or writing to the address that sent you the message (you can reply to it directly):
- Object to direct marketing (Article 21). This is an absolute right: if you tell us to stop contacting you for marketing, we must stop — there is no balancing, and no reason is required. The fastest way is the unsubscribe / opt-out link in the message that brought you here (one click; your address is suppressed before the next send). You can also simply reply asking us to stop.
- Access (Article 15) — ask what data we hold about you and get a copy.
- Rectification (Article 16) — ask us to correct anything inaccurate or incomplete.
- Erasure (Article 17) — ask us to delete your data ("right to be forgotten").
- Restriction (Article 18) — ask us to pause our use of your data while a query is resolved.
- Portability (Article 20) — ask for the data you gave us in a machine-readable format.
You never have to pay to exercise these rights, and we will respond within one month (extendable by two further months for complex requests, in which case we will tell you).
Back to top9.How to opt out or contact us
- To stop hearing from us immediately: use the unsubscribe / opt-out link in our message, or reply and ask us to stop.
- For any other request or question: email the address that sent you the message (you can reply to it directly), or write to the postal address shown in that message.
Please mention "privacy request" so we can route it quickly.
Back to top10.Complaints to a supervisory authority
If you are unhappy with how we handle your data, you have the right to complain to a data protection supervisory authority. In the EU/EEA this is the authority in the country where you live, work, or where you believe the issue arose; in the UK it is the Information Commissioner's Office (ICO). We would, however, appreciate the chance to address your concern first — please contact us at the address that sent you the message (you can reply to it directly).
Back to top11.Changes to this notice
We may update this notice; the version and effective date at the top show the current one. Material changes will be reflected here.
Back to top