1. Introduction

WebRefer Data Ltd ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard personal information when you use our website and services.

2. Information We Collect

Contact Information: When you contact us or request services, we collect name, email address, company name, and other information you provide.

Website Usage: We collect standard web analytics data including pages visited, time on site, and referring sources.

Service Data: For client engagements, we may receive data necessary to fulfill service requirements.

3. Personal Data in Our Research Data

Our research services involve collecting information from the public web, including domain registration records obtained through WHOIS and RDAP. Those records regularly contain the name, email address, postal address or telephone number of the person who registered a domain. Where the registrant is a living individual, that is personal data, and we are a controller in respect of it even though that person has never contacted us.

This data is used to produce the research deliverables and datasets described under our domain intelligence services, and may be disclosed to the client who commissioned a given piece of research, under contract terms restricting how it may be used.

If your personal data may be in this material, you have rights over it — access, rectification, erasure, restriction and objection — and a route to exercise them: see Data & Removal Requests or email [email protected]. Website operators can use the same route to ask to be excluded from our crawling.

4. How We Use Information

We use personal information to respond to inquiries and service requests, deliver contracted services, improve our website and services, and send relevant communications about our services.

5. Legal Basis for Processing

We process personal data based on performance of contracts for service delivery, legitimate interests for business operations and service improvement, and consent for marketing communications.

6. Data Sharing

We do not sell the personal data of our website visitors or of the people who contact us, and we do not compile datasets for the purpose of marketing to individuals. Separately, research deliverables licensed to clients can contain personal data drawn from public registration records, as described in section 3, and those licences restrict how the data may be used. We may also share data with service providers who support our operations under data protection agreements, and where the law requires it.

7. Data Retention

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and resolve disputes.

8. Your Rights

Under UK GDPR you have the right to access your personal data, have inaccurate data rectified, have your data erased, restrict our processing of it, receive it in a portable form, and object to processing. Email [email protected] to exercise any of them; we will respond within one month, as Article 12(3) requires. See Data & Removal Requests for what to include. If you are not satisfied with our response you can complain to the Information Commissioner's Office at ico.org.uk.

9. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction.

10. International Transfers

Data may be transferred to and processed in countries outside the UK/EEA. We ensure appropriate safeguards are in place for such transfers.

11. Contact

For privacy inquiries, contact [email protected] or write to WebRefer Data Ltd, 61 The Cut, London SE1 8LL, United Kingdom.