Privacy Policy
Last updated: 18 August 2026
This policy explains how Ilie Andrei Irimie (“we”, “us”, “our”) uses personal data for Company Leads Hub (companyleadshub.co.uk), under the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
We are the data controller for account, billing, and agenda data, and for how we store and display public-register extracts.
Contact
Ilie Andrei Irimie, 35 Bridge Street, NE24 2AA
tasteofgreeknow@gmail.com
You can also complain to the Information Commissioner’s Office (ICO): ico.org.uk, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
If we are required to pay the ICO data protection fee, we will do so. That fee is an operator duty; it is not a government “licence” for the product.
1. Two kinds of personal data
A. Data about you (our customer)
We collect this because you use the Service.
| What | Examples | |---|---| | Account | Username, email, hashed password | | Billing | Plan, payment status, Stripe customer/subscription IDs (not full card numbers) | | Your pipeline | Lead status, favourites, free-text notes | | Your agenda | Contract type, dates, and notes you type | | Digest settings | On/off and filters, on Professional / Enterprise only | | Technical | IP address, browser, pages, time, security logs | | Sample form | Email if you unlock the homepage sample |
B. Data about other people (company officers)
The Service shows names, roles, appointment dates, nationality, country of residence, and registered office details that Companies House already publishes. That is still personal data under UK GDPR, even though it is public.
We do not collect that officer data from you. We copy it from the statutory register (API and official snapshot) under the Open Government Licence v3.0.
We do not buy extra consumer credit files, electoral-roll packs, or secret contact lists to attach to those officers.
C. Public business contacts (Workplace & Contact add-on)
If a subscriber pays for this add-on and asks us to look up a company, we may store a published trading address, business telephone number, website, VAT number if the company prints it, and role inbox (info@, sales@ and similar) taken from Google Places or from pages the company publishes on its own site.
That can include personal data if a phone or inbox identifies a person. We do not store personal webmail, director home emails, or addresses we guessed. We do not send marketing to those contacts ourselves.
2. Why we use the data (lawful bases)
| Purpose | Lawful basis (UK GDPR Art. 6) | |---|---| | Create your account, log you in, show the dashboard, map, exports | Contract | | Take payment, renew, fail or restore access | Contract / legal obligation (tax records) | | Password reset, security, abuse prevention | Legitimate interests and/or contract | | Daily digest you switched on | Contract (a feature of your plan) and your setting | | Agenda reminders you asked us to send | Contract (you stored the date) | | Homepage sample email | Consent / legitimate interests to deliver the sample | | Help messages you send us | Contract / legitimate interests (support) | | Store and show Companies House officer data to subscribers | Legitimate interests (operating a public-register research tool) and the fact the data is already published by law | | Look up and show published business contacts on the paid add-on | Legitimate interests (helping a subscriber research a company they opened) using information already published by the company or on Google | | Cookies strictly needed for login and security | Necessary for the service (PECR) | | Optional preference cookies | Consent (cookie banner) |
Legitimate interests (officer data). Companies House is required to make certain officer information public. We republish and filter that public set for business research. We do not use it to build a secret profile, sell a marketing list of home addresses, or contact those officers ourselves.
If you are an officer and you object, contact us. We will consider the request. We cannot delete data that the law still requires Companies House to publish; we can explain how to correct it at Companies House.
3. What we do not do
- We do not sell your account data.
- We do not sell a bulk “director home mailing list”.
- We do not sell CSV packs of personal emails or mobile numbers.
- We do not email companies from the register on your behalf as cold marketing.
- We do not invent contract end dates. Agenda dates are only what you typed.
- Another subscriber cannot see your notes, status, favourites, or agenda.
4. Who we share data with
Only what each provider needs:
| Provider | Role | Typical data | |---|---|---| | Stripe | Payments | Email, customer/subscription IDs, payment events | | Resend | Transactional email | Your email, message content (reset, digest, reminders) | | Google | Maps JavaScript API and, for the paid add-on, Places | IP and device data on the map; place name, address, phone and website when a paid lookup runs (Google’s terms also apply) | | Hosting (this server) | Storage and the website | The database and logs | | postcodes.io / similar | Turn a postcode into a map point | Postcode only | | Companies House | Source of register data | We pull public records; we do not send them your notes |
We may disclose data if the law requires it (police, court, ICO, HMRC).
Stripe, Resend, and Google may process some data outside the UK. Where that happens we rely on the UK adequacy decisions and/or standard contractual clauses those vendors publish.
5. How long we keep it
- Account and pipeline / agenda: while the account is open, then a short period so we can close it cleanly.
- Billing: usually up to 6 years (UK tax practice).
- Security logs: a limited period unless we are investigating abuse.
- Companies House extracts: refreshed and replaced as the register changes; we are not the master copy.
- Workplace & Contact cache: replaced on the next paid lookup or when it goes stale.
- Homepage sample emails: until you ask us to delete them, or they are no longer needed.
You can ask us to delete your account. We will delete or anonymise what we can. We may keep what the law says we must keep.
6. Your rights (UK GDPR)
You can ask to:
- access your data;
- correct it;
- delete it (with legal limits);
- restrict or object to some processing;
- receive a portable copy;
- withdraw consent where we relied on consent;
- complain to the ICO.
Email tasteofgreeknow@gmail.com. We may need to check it is you.
Officers on the public register: to change the official record, go to Companies House first. We display what the register publishes.
7. Emails and PECR
6.1-style service mail (security, billing, password reset) is sent because the account needs it.
Digest and agenda reminders go only to you, on an address you gave us, for a feature you use. They are not ads sent to strangers on the register.
If you do not want digest mail, switch it off under Email Alerts (only shown on plans that include it).
8. Security
We use HTTPS, hashed passwords, login-required areas, and per-account filters so one user does not load another user’s notes or contracts. No system is perfectly secure.
9. Children
The Service is not for anyone under 18. We do not knowingly keep children’s data.
10. Cookies
See the Cookie Policy. A banner lets you accept or decline non-essential cookies.
11. Changes
We will post updates here with a new “Last updated” date. Important changes may also be emailed or shown in the product.
12. Contact
Ilie Andrei Irimie
35 Bridge Street, NE24 2AA
tasteofgreeknow@gmail.com
Information Commissioner’s Office: ico.org.uk