Compliance pack

Legitimate interests assessment

Controller: SiteLens, a trading name of Alcyone AI Ltd, company 17060294 (England and Wales). Contact: privacy@sitelens.co.uk.

Version 1.0, 17 August 2026. Published at https://sitelens.co.uk/trust/ and available on request.

This is the assessment required to rely on Article 6(1)(f) for the party data we hold. It follows the ICO's three-part test: purpose, necessity, balance. It is written to be read by a prospective customer's compliance function as well as by us, which is why it states what we do NOT do as precisely as what we do.

It contains no claim that we screen against the Mailing Preference Service. An earlier draft of our posture leaned on MPS screening three times as a safeguard. We have never operated it: a grep of the codebase finds it implemented zero times. Claiming a safeguard you do not run is worse than not claiming one, because the assessment then rests on it and every statement built on the assessment inherits the defect. MPS is voluntary, is enforced through CAP Code 10.10, and CAP Code 10.10 binds the marketer. Our customer is the marketer and we are not the sender on any electronic channel, so the obligation sits in their terms, together with an instruction to re-match before every campaign. It stays theirs on POST as well, where we do fulfil the send: they choose the recipient and write the copy, which is what CAP Code 10.10 binds.

1. Purpose

What we do

We index UK planning applications, building control records and public procurement notices, and identify which firms are named on them, so that construction suppliers and subcontractors can find live projects and the firms running them.

To do that we hold, for a party named on a public register:

  • their name and the role they played (applicant, agent, or a project-team role);
  • the correspondence or site address the register publishes;
  • a published business contact channel, where one exists and where the party is a business.

Whose interests

Ours, in operating a lawful business. Our customers', in finding work they are qualified to compete for. And a third interest that is easy to overlook and is genuinely part of the balance: the named firms' own, in being findable by suppliers. A planning agent who publishes an enquiry inbox on their own website is not indifferent to being contacted about live projects; that is what the inbox is for.

What we do not do

Stated here because a purpose is only meaningful alongside its boundary, and because these are the questions the ICO's data broker checklist asks.

  • We do not send on any electronic channel. There is no dialler, no template store, no reply capture, no contacted flag and no audience builder in the product, and there will not be. Our customers do their own email and telephone outreach with their own systems. On those channels we are never the sender, the instigator or the caller.

POST is the exception, built on 2026-08-23 but not yet offered: a printed letter to the applicant at the application site, fulfilled through Stannp, runs in test mode and dispatches nothing. Every one of the 48 PECR fines below landed on an ELECTRONIC sender, instigator or caller; reg 22 covers electronic mail only and post sits outside PECR entirely, which is why this is the one channel where fulfilling the send does not move the liability. This matters disproportionately: every one of the 48 PECR direct-marketing fines issued between 14 December 2022 and 7 August 2026 landed on a sender, an instigator or a caller.

  • We do not index people. There is no reverse lookup by person name. You cannot ask this product "what is this individual involved in". You ask it about land and schemes, and names appear as attributes of those.
  • We do not generate contact details. No guessed address, no pattern expansion (first.last@firm.co.uk), no provider-supplied channel for a named individual. We store a channel the party or their firm actually published. Where we hold an email PATTERN for a firm, it is recorded as a pattern and is never expanded into an address for a person.
  • We do not publish conclusions about lawfulness. We show the evidence ("Companies House exact name match, company 12345678, active, checked 2026-08-14"), never a verdict like "safe to email". A verdict invites the customer to rely on ours and then blame us, and it would become their reasonable-care defence under PECR reg 30(2), which makes it our problem in any instigation question.

2. Necessity

Could we achieve the purpose in a less intrusive way?

Consent is not available and pursuing it would be worse. The parties are named on a public register by a council, not by us, and there is no relationship in which consent could be sought before the data exists. Asking hundreds of thousands of firms to opt in would require contacting all of them first, which is more intrusive than the processing itself and, for the sole traders among them, would be unlawful under PECR reg 22 without prior consent. That circularity is why Article 6(1)(f) is the right basis here.

Could we hold less? We have reduced what we hold on this assessment several times, and the reductions are the substance of it:

  • The applicant's own electronic channel is served only where a corporate test passes: a Companies House match AND a published name that reads as a business, with vetoes for a consumer mailbox and an applicant sitting at the application site. Amended 2026-09-07 (controller decision, docs/applicant-gate-minimum-2026-09-07.md): this previously also required an independent second signal, a business mailbox verified within 730 days or a UK 01/02/03 landline. That conjunct was removed because it was unobtainable rather than protective: measured on production, 0 rows had ever gone stale and only 422 of 9,017 were ever verified at all, so it excluded rows for want of a corroboration we had never attempted. A namesake guard replaced it, because a Companies House match is a name match and 43 rows carried one whose name did not read as a business, 34 of them opening with a personal title. Served set 5,404 to 8,419. Where the answer is unknown we redact, because the ICO's instruction is that where you cannot tell you treat the details as belonging to an individual subscriber.
  • Email open IP addresses and user agents are prohibited outright. They told us nothing that the open timestamp did not, and Apple Mail Privacy Protection made them a fiction anyway.
  • Free-text notes about a prospect are prohibited outright and replaced with a status enum. Free text about a person is unbounded by construction and lands in a subject access response.
  • The email verification rotation was cut from sixteen providers to three, because sixteen recipients cannot be honestly described to the person whose address is being checked.

Could we hold it for less time? Business contact channels are held for two years from the last time we confirmed them, which is the point at which a register contact is more likely stale than current. Register names are held for as long as the application record, because removing a name would misstate who applied for what.

3. Balance

What the parties would expect

A firm named as the agent on a planning application, publishing an enquiry inbox on its own website, would not be surprised that suppliers can find it in connection with that application. That is the ordinary commerce of the construction industry and predates us by a century.

A private individual applying for an extension to their own home would be surprised to find their personal email address in a marketing list. So we do not put it there. Their name and the site address are on the public register and stay visible; their electronic channels are not served.

The Experian holding, which we take as directly on point

*Information Commissioner v Experian* [2024] UKUT 105 (AAC) is the case that matters most here, and the surviving holding is not comfortable reading for this sector: Article 14 notice IS owed to people whose data comes from public registers and is used for direct marketing, and Article 14(5)(b) disproportionate effort did not excuse it at a scale of 5.3 million people.

We therefore give the notice. Of sixteen competing products surveyed, none appears to. We do not rely on Article 14(5) at all, and we specifically do not build on the disproportionate-effort limb: the ICO's own summary describes that change as a research measure, its transparency guidance is under review, *Experian* held that cost alone is not disproportionate effort, and Article 14(7) requires public availability regardless.

Safeguards

Each of these exists in code, not only in this document.

SafeguardWhere it lives
One serving function decides whether any value may reach any recipient on any channelsrc/lib/serving-gate.ts, permissions(class, channel, recipient)
Business-versus-individual decided by positive evidence of a firm, not by a salutationsrc/lib/subscriber-type.ts, looksLikeCompany
Applicant electronic channels split by a Companies House match plus a business-shaped name, with two vetoes, unknown resolving to redactsrc/lib/contact-privacy.ts, applicantChannelDecision
Every personal-data column carries a recorded class, source, licence, basis and retention period, enforced at merge timesrc/lib/data-class-register.ts plus the CI intake gate
Prohibited classes dropped before persistence, not filtered on the way outsrc/lib/parser-drop.ts and docs/parser-drop-rule.md
Article 14 notice at ingest, per person, on an isolated sending identitysrc/functions/contact-notify.ts
A never-expiring objection link in every notice, honoured permanentlysrc/lib/signed-links.ts, src/lib/contact-suppress.ts
Objection records survive erasure and re-acquisition, so a suppression cannot be undone by a later scrapeclass H29, permanent by design
Entitlement resolved against the database, so a cancelled subscription stops serving contact data immediatelysrc/lib/effective-plan.ts
Per-class kill switch, so a legal surprise is a config change rather than an outageSERVING_DISABLED_CLASSES

Objection is absolute and we treat it that way

Article 21(2) and (3) make an objection to direct marketing absolute. There is no balancing test and we do not apply one. The objection link in the notice never expires, needs no account, and works from the email itself. A suppression is recorded permanently and is checked before any re-enrichment, so the firm cannot return through a later scrape.

4. Outcome

We consider Article 6(1)(f) available for the classes marked legitimate_interests in the register, subject to the safeguards above, and we consider it unavailable for anything else, which is why those classes are prohibited rather than restricted.

The places this assessment is most likely to be wrong, recorded so a reviewer can go straight to them:

  1. The corporate test is a proxy, and since 2026-09-07 it rests on fewer predicates. A Companies House match plus a business-shaped name is good evidence of a corporate subscriber and is not proof. The residual is therefore LARGER than when this assessment first recorded it: a sole trader trading under a company name now passes on the match and the name alone, where previously a mailbox or landline also had to corroborate. It is accepted because the removed conjunct was measurably not doing the work attributed to it (0 stale rows ever, 422 of 9,017 verified at all), and because both vetoes and the namesake guard still stand in front of the household case. 598 of 9,017 rows remain withheld: 427 with no Companies House match, 126 on the two vetoes, 43 on the namesake guard.
  2. We are never the sender. On every electronic channel the customer is the sender, so a misclassification is their reg 22 exposure rather than a send we make. Our exposure is the accuracy of the label we publish.
  3. Article 14 is not discharged for this class. H30 is notice-owed and no notice path reads applicant channels; the 2026-09-07 widening adds roughly 3,015 rows to that existing gap. Recorded rather than fixed in that change.
  4. Retention of two years is a judgement, not a derivation. It matches our refresh cycle rather than any external standard.

Review

Reviewed on any change to the class register, and otherwise annually. The Article 30 record is generated from the same register (docs/article-30-record.md), so it cannot drift from this assessment without CI failing.

Questions about this document, or anything else your review needs: email privacy@sitelens.co.uk.