Legal

GDPR & compliance

How we stay on the right side of UK GDPR and PECR, and what we expect from you as a customer.

Last updated: 30 August 2026

AdaptLeads, operated by Reeve Solutions Ltd, is built for business-to-business outreach and nothing else. This page explains, in plain English, how we approach UK GDPR and PECR, and the responsibilities you take on as a customer when you use our data.

Compliance is shared. We hold and provide the data lawfully; you are responsible for running your outreach lawfully. This page is not legal advice — if in doubt, take your own.

1. Our compliance approach

We process business-context contact data for one purpose: enabling lawful business-to-business marketing and outreach. We rely on legitimate interests as our lawful basis, we keep the data to a professional context, and we make it easy for any individual to object and be removed. We do not provide data for consumer (B2C) marketing.

2. The legitimate-interest and balancing test, in plain English

UK GDPR lets us process personal data where we have a legitimate interest that is not outweighed by the individual's rights. We have weighed this up:

  • The interest — helping businesses find and contact other businesses that may want their products or services. This is a recognised legitimate interest for B2B marketing.
  • Is it necessary? — a searchable directory of business contacts is a proportionate way to achieve it, and we limit what we hold to business-context fields.
  • Is it fair to the individual? — the data relates to people in their working capacity, the privacy impact is low, we are transparent about what we do, and anyone can object and be removed quickly and free.

On balance we consider the processing fair and proportionate. If someone objects, we suppress their details.

3. PECR and your responsibilities as a customer

The Privacy and Electronic Communications Regulations (PECR) sit alongside UK GDPR and govern electronic marketing. When you use our data to run outreach, you are the sender, and in most cases the controller for that campaign. You must:

  • market only to businesses, about products or services relevant to them;
  • clearly identify yourself and, where required, who you are acting on behalf of;
  • provide a simple, working opt-out in every message;
  • honour opt-outs promptly, and keep your own suppression list;
  • check the rules that apply to your channel — for example screening telephone numbers against the TPS/CTPS before calling, and applying the correct rules for corporate subscribers.

4. Data minimisation and business context

We hold business-context data only: business names, trading names, business addresses, business phone numbers, business email addresses, websites, and company-director names from Companies House. We do not seek special-category data, and we ask customers not to upload it. We keep records only while they remain relevant and re-verify over time.

5. Individual rights and easy removal

Anyone we hold information about can exercise their UK GDPR rights, including the right to object to our processing and the right to erasure. The fastest route is our Remove my data page — no account is needed and it is free. We action requests promptly and within one month.

6. Suppression and opt-out handling

When someone asks to be removed, we suppress their details across the database and keep a minimal suppression record so that the same details are not re-added from future sources. Customers must also maintain their own suppression lists for their campaigns, because you are responsible for opt-outs that come to you directly.

7. Security practices

We take a practical, layered approach to security:

  • encryption in transit (HTTPS/TLS);
  • access controls and least-privilege permissions;
  • securely hashed account passwords;
  • UK/EU-based hosting and regular backups;
  • ongoing review as the service grows.

[Formal certifications such as ISO 27001 or SOC 2 — add if/when certified.] We describe our practices honestly and do not claim accreditations we do not hold.

8. Data Processing Agreement

Where you need a Data Processing Agreement (DPA) for your own compliance records, one is available to customers on request. Email hello@adaptleads.co.uk and we will provide it.

9. International transfers

We host and process data primarily in the UK and EU. Where a processor handles data outside the UK, we put appropriate safeguards in place, such as reliance on a UK adequacy decision or standard contractual clauses (including the UK International Data Transfer Agreement or Addendum) where required.

10. Contact for privacy matters

For any privacy or compliance question, email hello@adaptleads.co.uk. Our ICO registration reference is [ICO registration reference]. You can also read our full Privacy Policy, and you have the right to complain to the Information Commissioner's Office at ico.org.uk.