Buyer due diligence pack
SiteLens, a trading name of Alcyone AI Ltd, company 17060294 (England and Wales). privacy@sitelens.co.uk
Version 1.0, 17 August 2026.
For a prospective customer's compliance, procurement or legal function. It answers the questions the ICO's data broker checklist asks, in the order it asks them, because that is the list your reviewer will be working from.
Every claim here is backed by a named file in the product or by one of two companion documents: the legitimate interests assessment (docs/legitimate-interests-assessment.md) and the DPIA (docs/dpia.md). The Article 30 record (docs/article-30-record.md) is generated from the same configuration the software reads at runtime, so it cannot describe processing the code does not do.
The short version
- We are a controller, not your processor. You do not need a data processing agreement from us, and we do not need one from you.
- We give an Article 14 notice to the people whose details we hold. Of sixteen competing products surveyed, none appears to.
- We are never the sender on any electronic channel. There is no dialler, template store, reply capture, contacted flag or audience builder, and there will not be. A path to send a printed LETTER to an applicant at the application site through Stannp is built but held in test mode, so no customer can send one today. Post is outside PECR entirely, the path carries no email address or telephone number, and the customer still chooses the recipient and writes the copy.
- You are the marketer. Per-channel screening is your obligation, and your terms say so, with an instruction to re-match before every campaign.
1. Where does the data come from?
Council planning registers (OGL v3.0), Companies House (OGL v3.0), HM Land Registry CCOD, Contracts Finder and Find a Tender OCDS releases (OGL v3.0), EPC registers, an open places dataset, and firms' own published websites.
Per-class source and licence are recorded in the source register kept with the Article 30 record. It is not on the public page; ask privacy@sitelens.co.uk if your review needs it. OGL attribution is per-provider and appears on the record card and in the CSV export footer.
2. What is the lawful basis?
Article 6(1)(f), legitimate interests, for the register-derived party data. Contract for our own customer records. Legal obligation for suppression, complaint and proof-of-notice records.
The full three-part assessment is in the LIA. It is worth noting what is NOT in it: no claim that we screen against the Mailing Preference Service. We never have, and an earlier internal draft that leaned on it has been corrected rather than quietly kept.
3. Are the people told? (Article 14)
Yes, and this is the answer most likely to differ from the other vendors you are comparing.
An Article 14 notice is sent at ingest, per person, on an isolated sending identity, carrying: our identity and contact details; the purpose; the categories of data; the source and whether it was public; the retention period; the categories of recipient; the Article 14(2)(da) right to complain to us and to the ICO; and, presented separately as Article 21(4) requires, the right to object.
The notice is deliberately neutral and registry-like. It contains no marketing, no offer, no benefit claim, no link to our homepage, and exactly one call to action: a removal link that never expires.
Why we do not rely on the disproportionate-effort exemption. Article 14(5)(b) is the exemption this sector generally leans on. *Information Commissioner v Experian* [2024] UKUT 105 (AAC) held that it did not excuse the notice for register-derived data used for direct marketing at a scale of 5.3 million people, and that cost alone is not disproportionate effort. We do not build on it.
4. Who else gets the data?
Twenty-three recipients, listed in the Article 30 record with their category, purpose, the classes they receive, their location, and whether they receive data about anyone other than our own customers. Nineteen are named there. The other four supply our data-gathering stack, which the published record describes rather than names; their names are held in our register and given on request.
Thirteen of them were declared on 2026-09-30 after two audits found them receiving data without being listed. The first found the web search services (Tavily, SerpApi, Serper, Brave Search and Wikidata) that our contact enricher sends a firm's or supplier's name to, as a search query, to find the firm's own website. No email address, telephone number or named individual is ever part of a query, but a sole trader's trading name can be their own name, so they are recipients of personal data. Four publish a United States location and one (Serper) publishes none; the record says so rather than guessing.
The second traced every outbound call that carries a name, an address or a typed query, and found eight more. Companies House and three professional and charity directories receive a firm's or applicant's name, to match it to a register entry. Hunter and Apollo, both in the United States, receive a company director's name and the firm's web domain to find a business email address, only when a subscriber asks for a firm's contacts. A web-fetching service in Ireland retrieves public council pages and firm websites where a site refuses direct requests, and sees them in full. The OpenStreetMap Foundation's geocoder receives places customers type into search.
The verification list is deliberately small. The email verification rotation ran on sixteen providers and was cut to three, because sixteen recipients cannot be honestly described to the person whose address is being verified, and a list that cannot be disclosed is a list that should not exist. An unapproved provider is rejected in code, so a configuration change cannot widen it.
Three of the three verification providers process in the United States under the UK Addendum to the EU SCCs. That is disclosed as a residual transfer risk in the DPIA rather than presented as solved.
5. Can people get out?
Yes, absolutely and permanently.
- A removal link in every notice that never expires and needs no account.
- A public objection form at
/contact-privacy. - A complaint form at the same place, recorded with its acknowledgement clock (DPA 2018 s.164A: acknowledged within 30 days, answered without undue delay).
Suppression is keyed on normalised identity rather than a display string, so a firm cannot reappear under a different spelling, and it is checked before re-enrichment rather than only at serving, so a later scrape cannot undo it. The suppression record is permanent by design: deleting it on erasure would silently re-admit the person.
6. What are our obligations if we buy this?
Stated plainly, because the honest answer is "several", and a vendor who tells you there are none is not one to trust with this.
- You are the controller of your own outreach. We surface contact details; you decide who to contact and how.
- You screen per channel. TPS and CTPS for calls, MPS for postal marketing. We do not do it for you and nothing we show you records a screening result.
- You re-match before every campaign. A registration can be added at any time and takes up to 28 days to take effect, so a screening result is only good for the campaign it was run for. If you export a file and use it again a month later, screen it again.
- You do not send unsolicited marketing email to individual subscribers, including sole traders, without consent (PECR reg 22).
- No resale, no appending, and deletion on termination, per the acceptable use terms.
- The indicators we show are evidence, not verdicts. "Companies House exact name match, company 12345678, active, checked 2026-08-14" is a fact. It is not advice that a given send is lawful, and it should not be relied on as one.
7. What is the enforcement risk, realistically?
We would rather give you the calibrated answer than a reassuring one.
Between 14 December 2022 and 7 August 2026 the ICO issued 48 PECR direct-marketing fines totalling £5,720,000, median £100,000, range £30,000 to £300,000. The channel split was 32 calls, 13 SMS, 3 email. Zero fines in those 44 months for B2B email prospecting, and zero for selling a B2B contact list. Every one landed on a sender, an instigator or a caller.
That is the reason our product boundary is where it is: we are none of those three and are not becoming one. The relevant vectors for a buyer are therefore your own sending practice, and, at one remove, whether a supplier's infrastructure can be traced through to unlawful sending. Argentum Data Solutions was fined £65,000 largely in connection with 2.3 million messages it did not itself send.
8. What are the gaps?
A due diligence pack that lists none is not credible. These are the open items at this version, and each is in the DPIA with its severity:
- Three historical row sweeps are outstanding: email open IP addresses and user agents, and outreach free text on two tables. These fields are prohibited going forward and are dropped before persistence; the rows already stored have not yet been cleared. Until they are, the claim is true of new data and not of the entire history.
- The notice programme requires a verified address. A person whose address we never verified is not notified. That protects the sending identity every other notice depends on, and it means "everyone is notified" is not literally true.
- The Article 21 objection form on the public page requires JavaScript. The emailed removal link and the new complaint form both work without it; that form does not yet.
- The applicant corporate test is a proxy, not proof. Since 2026-09-07 it is a Companies House match plus a business-shaped name and two vetoes; it could admit a sole trader trading under a company name, and no longer requires a corroborating mailbox or landline. The residual on that class was raised from medium-low to medium in the DPIA at the same time.
- Article 14 is not discharged for applicant electronic channels. That class is notice-owed and no notice path reads it.
- No DPO is appointed and no data subject consultation has been carried out. The Article 37 threshold is not met; the objection and complaint routes are the feedback channel used instead.
9. Documents
| Document | What it is |
|---|---|
docs/legitimate-interests-assessment.md | The Article 6(1)(f) three-part test |
docs/dpia.md | The Article 35 assessment, with residual risk per item |
docs/article-30-record.md | The Article 30 record, generated from the register |
docs/parser-drop-rule.md | How prohibited fields are prevented from being stored (on request) |
/contact-privacy | The public notice, objection form and complaint form |
/terms | Acceptable use, including your screening obligations |
This pack and the three documents above it are published at https://sitelens.co.uk/trust/. Anything marked on request, or a copy of any of them, is available from privacy@sitelens.co.uk.