Data and compliance
What we hold, and on what basis.
Business contact data, built from primary sources, held for a stated period, and removable on request. The documents below are linked here rather than buried in a footer.
Data and compliance
Six answers, each with the document behind it.
GDPR alignment
Business contact data, legitimate-interest basis, and a removal route that works on request.
CAN-SPAM / CASL
What we deliver, and the sending obligations that stay yours as the sender.
DPA on request
A signed data processing addendum for any engagement where we handle records you hold.
Source transparency
Every delivery ships a Method sheet naming the sources used and the exclusions applied.
90-day retention
Research working files are deleted 90 days after delivery unless you ask us to hold them.
Human verification
A person cross-checks each record against LinkedIn and the company website, and dates it.
The documents
Every policy, with the date it last changed.
| Document | What it covers | Last updated |
|---|---|---|
| Privacy policy | How Qualified Deals collects, uses, stores and deletes personal data, and the rights you have over it. | 14 Aug 2026 |
| Terms and conditions | The contractual terms governing every engagement between Gallivant Ventures LLP, trading as Qualified Deals, and its clients. | 14 Aug 2026 |
| Data processing addendum | The processing terms that apply when Qualified Deals handles personal data on your behalf. | 14 Aug 2026 |
| Anti-spam and acceptable use policy | How our data may and may not be used, and the sending obligations that stay with you. | 14 Aug 2026 |
| Refund policy | When refunds apply, when they do not, and how to request one. | 14 Aug 2026 |
| Cookie policy | What qualifieddeals.com stores in your browser, why, and how to change your choices. | 14 Aug 2026 |
FAQ
What procurement and legal teams ask.
Is buying B2B lead lists legal under GDPR?
Processing business contact data for B2B prospecting is lawful in the EU and UK under legitimate interest, GDPR Article 6(1)(f), provided the interest is balanced against the individual’s rights and the first contact is relevant to their professional role. It is not lawful to treat a purchased list as consent. What matters in practice is whether the seller can show where each record came from and honour a deletion request — both of which we can.
What is your lawful basis, and can you evidence it?
Legitimate interest under GDPR Article 6(1)(f), with equivalents under CCPA and the UAE PDPL. Records come from public business directories, company websites and licensed platforms used under their terms. The source of any delivered record is auditable on request.
Do you sign a DPA?
Yes. The data processing addendum is published at /legal/dpa/ and can be reviewed before you brief us rather than after. Procurement teams usually want it alongside the anti-spam policy.
What happens if someone asks to be removed?
Send us the request and the record is deleted from our systems and added to a suppression list so it is not re-sourced on a later project. Deletion requests are actioned regardless of which client the record was delivered to.
Do you deliver personal email addresses or mobile numbers?
No. Work email addresses and direct business lines where available. Personal Gmail addresses and personal mobiles are outside what we source, which is both a compliance position and the reason our deliverability holds.
Can we use the data for outreach into the EU and UK?
Yes, subject to your own sending practices: identify yourself, state why you are contacting them, and honour opt-outs on the first request. We deliver the data and the audit trail; the sending obligations under PECR and the ePrivacy rules sit with you as the sender.