Legal

Privacy Policy

Last updated: [DATE]

Before publishing A working draft, not legal advice, not reviewed by an attorney. Section 4 (campaign recipients) is the one that matters most for a cold email business and the one a regulator would read first — have it reviewed. Fill every [BRACKETED] field, and note that if you knowingly target EU or UK contacts you may need a named representative under GDPR Article 27.

1. Who we are

[LEGAL ENTITY NAME] trading as BuiltCold is the data controller for information collected through this website and for our own outreach. Contact: [EMAIL], [POSTAL ADDRESS].

When we run campaigns on behalf of a client, that client is the controller of their campaign data and we act as processor on their instructions.

2. Website visitors

What we collect

Why

To respond to your enquiry and, if you become a client, to deliver the service. Our lawful basis is your consent when you submit the form, and legitimate interest in operating and securing the site.

How long

Enquiries that don't become clients: 24 months. Client records: for the engagement plus 7 years, for tax and legal purposes. Server logs: 90 days.

Cookies

[This site sets no cookies and runs no analytics. If you add analytics, replace this with a description of what's set, and add a consent banner if you have EU or UK visitors.]

3. Client data

For clients we hold business contact details, billing information, campaign configuration, the contact lists we build or you supply, and campaign performance data. We use it to deliver the service and nothing else. We do not sell it, and we do not use one client's list for another client's campaign.

4. People who receive our campaign emails

If you received a cold email from BuiltCold or from a campaign we operate, this section is for you.

What we hold

Business contact information: name, business email address, job title, employer, and publicly available professional details such as company size, industry and location. We do not knowingly collect personal email addresses, home addresses, or any special category data.

Where it came from

Licensed B2B data providers, publicly available business sources, or lists supplied by the client whose campaign it is. We do not scrape personal social media profiles.

Why we're allowed to contact you

United States: CAN-SPAM permits unsolicited commercial email to business addresses provided the sender is accurately identified, a valid physical postal address appears in the message, and opt-out requests are honoured. Every message we send meets these requirements.

EU and UK: where we process data about people in these jurisdictions, we rely on legitimate interest under Article 6(1)(f) — specifically, business-to-business marketing to a professional contact whose role makes the message relevant. We assess this against your rights and interests before sending. You can object at any time and we will stop immediately.

Canada: CASL requires consent or a recognised exemption. Where we cannot establish one, we exclude Canadian contacts.

How to make it stop

Every message we send has a one-click opt-out. You can also email [OPT-OUT EMAIL] and we will remove you and add your address to a permanent suppression list so you aren't contacted again by any campaign we operate. We action opt-outs within 3 business days and typically far faster.

Your rights

Depending on where you live, you may have the right to access the data we hold about you, correct it, have it deleted, object to processing, or ask for it in a portable format. Email [EMAIL] and we'll respond within thirty days. There's no charge, and we won't ask you to justify the request.

If we're processing your data on a client's behalf, we'll forward your request to them and tell you who they are.

How long we keep it

Active campaign data: for the campaign plus 12 months. Opt-out records: retained indefinitely, because that's the only way to guarantee we never contact you again. A suppression record contains your email address and nothing else.

5. Who we share data with

We share data only with service providers necessary to run the service, each bound by contract:

We do not sell personal data. We will disclose data where legally required, and will tell you unless prohibited from doing so.

6. International transfers

We operate from the United States, so data about people outside the US is transferred there. Where required for EU or UK data, transfers rely on Standard Contractual Clauses or another approved mechanism.

7. Security

Access to client and campaign data is limited to those who need it. Data is held in reputable third-party platforms with encryption in transit and at rest. This site is served over HTTPS. No system is perfectly secure, and we will notify affected parties and any relevant regulator without undue delay if a breach occurs.

8. Children

This is a business-to-business service not directed at anyone under 18, and we do not knowingly collect data about children.

9. Changes

We'll update this policy as the business changes. The date at the top reflects the current version.

10. Complaints

Contact us first at [EMAIL] — most things are resolved quickly. You also have the right to complain to your data protection authority: the ICO in the UK, your national supervisory authority in the EU, or your state attorney general in the US.