PROSPEXTO™ PRIVACYUK DATA PROTECTIONUPDATED 11 AUGUST 2026
PRIVACY POLICY

Privacy Built Around Responsible Intelligence.

This Policy explains how personal information is handled across the Prospexto™ website, platform, member services and AI-supported workflows.

TRANSPARENTPROPORTIONATEHUMAN REVIEW
OUR OWN OPERATIONSData Controller

For website, account, billing, support, security and our own communications data.

CUSTOMER WORKSPACESData Processor

Where customers submit prospect personal data for platform processing under their instructions.

AI-SUPPORTED WORKFLOWHuman Judgement

AI supports analysis and organisation; people remain responsible for commercial decisions.

PLAIN-LANGUAGE SUMMARY

We collect only the information reasonably needed to provide, secure and improve Prospexto™, manage business relationships and meet legal obligations. We do not sell personal information for third parties’ own marketing.

01

About This Policy

This Privacy Policy applies to the Prospexto™ website, software platform, member area, licences, support and associated services unless a more specific notice is provided.

Prospexto™ is a B2B prospect-intelligence platform operated by The Digital Takeover®. For legal identification, The Digital Takeover® is a trading name of John Thompson. Privacy enquiries can be sent to team@thedigitaltakeover.com.

In this Policy, “personal information” means information relating to an identified or identifiable living person. Purely corporate information that does not identify a person is not personal information, although we still handle business information responsibly.

02

Our Data-Protection Roles

When we are the controller

We act as controller when we decide why and how personal information is used for our website, account administration, billing, customer support, security, service management, legal compliance and our own business communications.

When we are a processor

A customer may choose to capture, upload, research or organise personal information about its business prospects in Prospexto™. Where we process that information only to provide the contracted platform under the customer’s instructions, the customer is normally the controller and we act as its processor.

Processor activity is governed by the customer agreement and applicable Data Processing Addendum. The customer remains responsible for its lawful basis, transparency, outreach decisions and handling of individual rights, while we assist as required by the applicable agreement.

03

Information We Collect

Account and contact

Name, work email, telephone number, organisation, role, account credentials, preferences and communications.

Commercial and billing

Order, licence, transaction, invoice and payment-status information. Full card details are normally handled by the payment provider.

Platform and workspace

Campaign settings, business records, qualification activity, notes, workflow actions, outreach information and generated outputs.

Technical and security

IP address, device, browser, login events, diagnostics, audit trails, cookie identifiers, usage and security logs.

Support and feedback

Messages, support requests, survey responses, product feedback and information supplied while resolving an issue.

Prospect information

Business contact details and professional information selected or submitted by a customer for its own prospecting workflow.

04

Where Information Comes From

We may receive personal information:

  • directly from you when you contact us, create an account, purchase, request support or use the platform;
  • from your employer, organisation, account owner or an authorised team member;
  • from customers that submit prospect information to their workspace;
  • from public business websites, public registers, professional profiles, mapping or search services and reputable business-data providers;
  • automatically through platform use, cookies, logs and security technologies; and
  • from payment, hosting, authentication, integration and support providers involved in delivering the service.

Where we obtain personal information indirectly as controller, we provide privacy information as required by law unless a lawful exception applies. Where we act as processor, the customer controller is responsible for its transparency obligations.

05

Purposes and Lawful Bases

PurposeTypical lawful basis
Set up accounts, provide paid access and administer licencesContract; legitimate interests
Process orders, maintain financial records and prevent fraudContract; legal obligation; legitimate interests
Answer enquiries, provide support and manage relationshipsContract or steps requested before contract; legitimate interests
Secure, diagnose, maintain and improve the platformLegitimate interests; legal obligation where applicable
Send relevant B2B service and business communicationsLegitimate interests or consent where required
Operate optional analytics or non-essential cookiesConsent where required
Establish, exercise or defend legal rightsLegitimate interests; legal obligation

Where we rely on legitimate interests, we consider necessity and balance our interests against the rights and reasonable expectations of affected people. You can object to processing based on legitimate interests.

06

Customer Prospect Data

Prospexto™ gives business customers tools to capture, research, qualify, organise and progress potential business opportunities. Customers decide which businesses and contacts to place into their workspace, why they are processed, how the outputs are reviewed and whether any outreach takes place.

Customers must use Prospexto™ lawfully, provide appropriate privacy information, respect objections and suppression records, and comply with the UK GDPR, Data Protection Act 2018, PECR and other rules applicable to their campaigns.

If your information appears in a customer’s Prospexto™ workspace, that customer will normally be the organisation responsible for responding to your request. You may also contact us and we will take reasonable steps to identify and assist the relevant controller where appropriate.

07

AI-Supported Processing and Human Review

Prospexto™ may use AI-supported tools to organise research, summarise available information, suggest qualification factors, identify possible commercial signals and prepare workflow recommendations.

Outputs may be based on information supplied by the customer, available business information and configured campaign criteria. AI outputs can be incomplete or inaccurate and must be reviewed by an authorised person before commercial action is taken.

Prospexto™ is not intended to make solely automated decisions about individuals that produce legal or similarly significant effects. Customers must not use the platform for such decisions without establishing their own lawful basis, safeguards, transparency and meaningful human review.

08

Cookies and Analytics

Essential cookies and similar technologies may be used to maintain sessions, authenticate users, protect security, remember necessary settings and deliver core functionality.

Analytics, preference or other non-essential technologies are used only where permitted and, where required, after consent through the site’s cookie controls. You can change available preferences through the cookie tool or browser settings, although disabling essential technologies may prevent parts of the service from working.

09

Who Receives Information

We do not sell or rent personal information for another organisation’s own marketing. Information may be shared only where reasonably necessary with:

  • hosting, cloud infrastructure, security and technical-support providers;
  • payment, invoicing, accounting and fraud-prevention providers;
  • AI, search, mapping, business-data and integration providers used to supply configured features;
  • email, authentication, analytics and customer-support providers;
  • professional advisers, insurers, auditors and prospective business transaction parties under suitable confidentiality protections; and
  • courts, regulators, law-enforcement bodies or other parties where disclosure is legally required or necessary to protect rights and security.

Providers acting as processors are limited by contract and may use information only as authorised to provide their services.

10

International Transfers

Some technology providers or support operations may store or make personal information accessible outside the United Kingdom. Where this creates a restricted transfer, we use a lawful transfer mechanism and appropriate safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another mechanism permitted by law.

Additional technical, contractual and organisational measures are applied where appropriate. You may contact us for further information about safeguards relevant to your personal information.

11

How Long We Keep Information

We keep personal information only for as long as reasonably necessary for the purpose collected. Retention is determined by the service relationship, account status, customer instructions, legal and tax requirements, limitation periods, security needs and the time needed to resolve disputes.

  • Account and contract records are generally retained for the relationship and an appropriate period afterwards for legal, financial and support purposes.
  • Financial records are retained for the periods required by tax and accounting law.
  • Support, enquiry and communications records are reviewed and deleted or anonymised when no longer reasonably needed.
  • Security and diagnostic logs are kept for a proportionate period unless required for an investigation or legal claim.
  • Customer workspace information is retained according to the customer agreement, customer instructions, account status and documented backup cycles.
  • Marketing records are retained until objection, withdrawal or periodic review indicates they are no longer needed. Minimum suppression information may be retained to honour an opt-out.

Information may be anonymised so that it no longer identifies a person, after which anonymised information may be retained for analytics and service improvement.

12

Security and Accountability

We use proportionate technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, alteration, disclosure and misuse. Measures may include access controls, account authentication, encryption in transit, logging, backups, provider assessment, restricted administrative access and incident procedures.

No internet service is completely risk-free. Customers must protect login details, use individual accounts where required, apply suitable device security and notify us promptly if they suspect unauthorised access.

13

Your Data-Protection Rights

Depending on the circumstances, you may have the right to:

  • be informed about processing and request access to your personal information;
  • request correction of inaccurate or incomplete information;
  • request erasure or restriction where the legal conditions apply;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive qualifying information in a portable format;
  • withdraw consent without affecting earlier lawful processing; and
  • raise concerns about qualifying solely automated decisions.

To exercise a right, email team@thedigitaltakeover.com. We may request proportionate information to confirm identity. Rights are not absolute and a lawful exemption may apply.

You can complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint/. We would appreciate the opportunity to address your concern first.

14

Children and Sensitive Information

Prospexto™ is a business platform intended for users aged 18 or over and is not directed at children.

The platform is not designed for special-category personal information, criminal-offence information or highly sensitive personal records. Customers must not submit such information unless its use has been expressly agreed, is necessary and lawful, and appropriate contractual and security measures are in place.

15

Contact, Questions and Policy Changes

Questions about this Policy or our handling of personal information can be sent to:

The Digital Takeover® / Prospexto™Melton Mowbray, Leicestershire, United Kingdomteam@thedigitaltakeover.com

We may update this Policy when services, providers, processing or legal requirements change. Material updates will be communicated through an appropriate channel where required. The current version and effective date will remain available on this page.

LAST UPDATED11 August 2026
POLICY SCOPEProspexto™ Website + Platform