Contact usTry for free

TargetWise legal

Privacy notice

How TargetWise uses account, website and professional contact data, and how to request access, correction, deletion or an opt-out.

Updated 10 September 2026Version 2.1

At a glance

You can object to direct marketing and ask us to correct or suppress your professional record. You do not need a TargetWise account to make a privacy request.

1. Who is responsible for your information

TargetWise is a service operated by GDB HOLDINGS LIMITED, a company registered in England and Wales with company number 16949965. Registered office: Artisans' House, 7 Queensbridge, Northampton, Northamptonshire, United Kingdom, NN4 7BF. Contact: office@targetwise.ai.

This notice covers website visitors, account users, customer and partner contacts, and people whose professional information appears in a lookup or enrichment result. TargetWise is controller for account administration, billing, security, enquiries and its independently determined professional-data activities. Where we process customer-supplied personal data solely on a customer’s instructions, we are a processor and our DPA applies.

A business receiving a professional result is responsible for its own subsequent use, privacy notices and communications. WorkOS, Stripe and other providers may also act as independent controllers for particular activities described in their own notices, such as fraud prevention or legal compliance.

2. Information and sources

We receive information directly from users and customers, through authentication and payment providers, from use of the service, and from public or licensed professional and company-data sources. A person may appear in a business-data result without having created an account with us.

Professional sources can include company websites, public professional profiles, official business records and licensed business-information services. Availability varies by field and market. Contact us with the relevant identifier to request the source information available for your record, including whether it came from a public source. We may derive a proposed match from identifiers such as a name, employer, domain, work email or profile URL.

CategoryExamplesWhere it comes from
Account and identityName, work email, organisation, user and authentication IDsYou, your organisation and WorkOS or your chosen identity provider
BillingPlan, billing contact, invoices, payment and subscription statusYou and Stripe; full card credentials are entered on Stripe’s payment pages
Professional dataName, role, employer, professional profile, work email, business phone and company contextCustomer queries and public or licensed business-data sources
Service recordsRequest IDs, requested operation, usage, errors and saved resultsUse of the dashboard, API or MCP
Support and enquiriesContact details, correspondence, requested workflow and support contextForms, email and account support
Technical informationIP address, device or browser information and security eventsRequests to the service and hosting infrastructure
Optional analyticsRandom browser ID, landing path, referring domain, campaign labels and conversion eventsYour browser after you allow analytics
  • Account and billing information marked as required is needed to provide the requested service; without it we may be unable to create an account, fulfil an order or respond.
  • We do not ask for sensitive personal information in enrichment requests. Do not send health information, identity documents, passwords or financial-account credentials.

3. Purposes and lawful bases

Where UK or EU data-protection law applies, the basis depends on the activity and our role. Contract applies where the individual is a party to the service agreement or requests steps before entering it. For employees and representatives of a business customer, administration generally relies on our legitimate interest in providing and managing that business relationship.

For professional-data matching, the interests are helping businesses identify relevant professional contacts, maintain accurate business records and perform proportionate B2B research. Legitimate interests are not a blanket permission: the processing must be necessary and balanced against the individual’s rights and reasonable expectations.

PurposeBasis where we are controller
Account setup, service delivery and supportContract with an individual customer; legitimate interests in administering a corporate customer relationship
Invoices, payment reconciliation and required recordsContract or legitimate interests; legal obligation for required accounting and tax records
Professional-data matching and supplyLegitimate interests in accurate, relevant B2B information, subject to balancing and applicable local restrictions
Fraud prevention, access controls and diagnosticsLegitimate interests in a secure, reliable service; legal obligation where required
Responding to an enquiry or partner applicationSteps at your request before a contract or legitimate interests in handling business enquiries
Our business communicationsLegitimate interests where permitted; consent where required by communications law
Optional browser analytics and acquisition reportingConsent, withdrawable through Privacy settings
Rights requests, legal claims and regulatory dutiesLegal obligation and, where appropriate, legitimate interests in defending legal rights

4. Recipients and professional-data licensing

We disclose professional data to customers requesting relevant enrichment or search results. We share the inputs needed to resolve a request with the data sources used for that operation. We also use hosting, authentication, payment and customer-management providers, and limit access by personnel and advisers to their work responsibilities.

Paid licensing or disclosure of professional contact data can constitute a ‘sale’ under some US state privacy laws. We do not describe all business-data licensing as exempt from those laws. The rights section below explains how to request an opt-out or suppression. Account credentials and full payment-card details are not licensed as contact data.

We may disclose information when legally required, to protect rights and investigate misuse, or as part of a proposed business transfer subject to appropriate confidentiality and data-protection safeguards. The provider register explains the core services used to run TargetWise and the distinction between processors and independent data suppliers.

5. International processing

Our hosting and service providers operate internationally, including in the United Kingdom, EEA and United States. A provider’s headquarters does not establish where every copy of data is processed. TargetWise does not offer a UK-only or EU-only hosting commitment under the standard terms.

Where a transfer is restricted under applicable data-protection law, an appropriate mechanism is required, such as an applicable adequacy decision or executed EU Standard Contractual Clauses with the UK Addendum or a UK International Data Transfer Agreement where relevant. The destination, recipient role and necessary additional protections determine the mechanism. Ask office@targetwise.ai for the applicable transfer information and a copy of relevant safeguards, with commercial or security information redacted where necessary.

6. Retention and security

We determine retention by the purpose of the record, account activity, contractual requirements, the need to resolve disputes or investigate misuse, and applicable recordkeeping law. A retained accounting record does not justify retaining all underlying enrichment results.

Saved dashboard result retrieval expires after 30 days. Encrypted result payloads are removed through expiry cleanup; expiry of access is distinct from immediate deletion of every backup copy. Usage, billing and security metadata may remain for the purposes below.

Controls implemented in the service include encrypted connections, protected server-side credentials, workspace access checks and encrypted saved results. No online service can guarantee absolute security. Report a suspected issue to office@targetwise.ai without including secrets or unnecessary personal data.

RecordRetention period or criteria
Account and customer recordsWhile the account or relationship is active, then only while needed for closure, contractual duties, legal claims or required records
Invoices and contractual recordsGenerally up to seven years where needed for accounting, tax or legal claims; longer only where a specific legal hold or obligation requires it
Saved enrichment results30-day retrieval window, followed by expiry cleanup; not indefinite result storage
Usage and security metadataFor billing reconciliation, abuse investigation, support and applicable claims periods, based on the record’s purpose and risk
Enquiries and correspondenceWhile needed to answer, maintain the relevant business relationship or address a dispute
Optional acquisition recordsUp to 90 days; removal and CRM clearing follow the analytics process below
Professional source dataAccording to ongoing relevance, source refreshes, contractual availability and applicable correction, deletion or objection requests
Suppression recordsThe minimum identifier needed to continue honouring an objection or opt-out

7. Cookies and optional analytics

Essential authentication and security storage supports sign-in and protects the service. Optional analytics is off until you choose Allow analytics. Decline lets you use the site without this optional browser tracking. You can revisit your choice using Privacy settings in the footer.

With permission, a random first-party browser identifier connects landing path, referring domain and campaign source, medium and name with website clicks, signup, enquiries, checkout and product milestones. Acquisition labels may be linked to your account or enquiry in HubSpot for acquisition reporting. The preference and browser identifier expire after 90 days.

Declining removes the current browser identifier and its stored click and acquisition records. Associated CRM acquisition fields are cleared on the next successful sync. Repeat the choice for other browsers you use. Withdrawing optional analytics does not erase records independently needed for your account, payments or service use.

The optional tracker does not record enrichment inputs, returned contact records, card details or raw URL query strings. Account creation, usage and payment records also support aggregate service reporting. These administrative records do not depend on optional browser consent.

8. Your rights, objections and opt-outs

You can object at any time to processing of your personal data for direct marketing, including related profiling. If you object, we must stop using it for that purpose. You can also object to processing based on legitimate interests; for other purposes we will assess whether the law allows continued processing.

Depending on the applicable law, you may request access, correction, deletion, restriction or portability, withdraw consent, and obtain information about sources and recipients. Where applicable US state privacy law provides them, you may also request an opt-out of sale or sharing, restriction of qualifying sensitive-data use, and an appeal of a refused request. We will not discriminate against you for exercising a privacy right.

Email office@targetwise.ai with the subject ‘Privacy request’ and the email address, professional profile URL or other identifier needed to locate the record. State whether you want access, correction, deletion, suppression, an opt-out or another action. You do not need to register, pay or provide marketing consent. An authorised agent may contact us; we may need reasonable evidence of authority or identity.

We respond within the applicable legal period—normally one month for UK/EU rights requests or 45 days for relevant US state requests—and explain any permitted extension or refusal. Some rights have exceptions, for example required accounting records or a minimal suppression record. If we act as processor for a customer, we will direct or pass the request to that customer and assist it as required.

An analytics choice controls browser tracking, not every professional record held under your name. To identify and suppress a professional record, use the request route with the relevant identifier. We cannot delete records held independently by another controller, but will explain relevant recipient information and communicate corrections or restrictions where the law requires.

9. Automated matching and children

We use automated matching to connect query identifiers with likely professional or company records and return available fields. Matching can be incomplete or wrong; you may challenge an inaccurate record. TargetWise’s enrichment service is not designed to make decisions with legal or similarly significant effects about a person, such as whether they qualify for credit, housing or employment.

TargetWise is a business service for adults. We do not intend to collect or provide children’s contact information. Contact us if you believe a child’s information is present so that we can investigate and remove it where appropriate.

10. Complaints and changes

Contact office@targetwise.ai if you have concerns about this notice or our processing. You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or to the competent authority where you live, work or believe an infringement occurred. You do not have to contact us before approaching an authority.

We update this notice when relevant practices change and show the version and date above. Material changes will be brought to affected users’ attention through an appropriate channel. Publishing a notice does not replace any individual notification or new consent required by law.

Questions about this document?

Email office@targetwise.ai. For privacy requests, include only the details needed to identify the relevant record.