/

Results appear as you type. Use the up and down arrow keys to move through them and Enter to open one.

GDPR: how FindAndClose handles business contact data

Which fields are personal data, who is controller for what, what we hold and why, and where our responsibility ends and yours begins.


This article describes how the product works. It is not legal advice — see the note at the end.

Business contact data is often still personal data

A company's switchboard number is not personal data. marie@clinic.no is, because it identifies a person. So can a business name containing someone's name, and so can a sole trader's address. Under GDPR the test is identifiability, not whether the context is commercial.

The practical consequence: treat an export as containing personal data and apply the same care you would to any other contact list.

Who is controller for what

ForControllerMeaning
Our indexFindAndCloseWe decide what to crawl, what to keep and for how long.
Your exported fileYouYou decide what it is used for, who sees it and when it is deleted.

We are independent controllers, not your processor, for the index itself. That distinction matters when a request arrives: suppressing a record in our index does not remove it from your CRM, and we have no access to your systems to do it for you.

Where the relationship warrants a DPA we sign one. Ask at privacy@findandclose.com.

What we hold, and where it came from

Public business listings on Google, Apple and Bing Maps, plus what businesses publish on their own websites and linked social profiles. Every row records the Google ID it is keyed on and a Link to the public listing it was read from, so any row can be traced back to its source in one click; every address found on a website carries its own list of source URLs inside All emails. Nothing enters the index without that provenance — see where the data comes from and the enrichment columns.

Article 14: you have to tell people where you got their details

Because you did not collect the data from the person, GDPR Article 14 requires you to tell them — generally within a month, or at first contact, whichever is sooner. In practice that is a line in your first email plus a linked privacy notice naming the public map listing as the source.

This is what the provenance columns are for

Keep the google_id and link groups in your exports, and all_emails where you are contacting a named individual. Between them they name the public listing each row was read from and the URLs each address was published on. Together they let you make an Article 14 statement truthfully rather than approximately, and they cost nothing to carry, because a credit buys a business and not a field. The 64 columns.

Data subject requests

  • About our index — send them to us, or forward the request. We suppress the record and add its identifiers to a suppression list so a later crawl cannot quietly reinstate it. How removal requests work.
  • About your copy — you handle it. We cannot reach your CRM.
  • About your own account data — access, correction and erasure of the personal data we hold about you as a customer: write to privacy@findandclose.com.

Retention

Index records are kept while the business is live on a public map and for a period after it is marked closed, because "did this business exist" is a question our customers legitimately ask. Suppressed records are kept only as identifiers on the suppression list — that is the minimum needed to honour the suppression, and it is why we do not delete the identifier itself.

Not legal advice

We describe how our product works and what the regimes generally require. We are not your lawyers, your circumstances differ, and the rules differ by country — notably for cold outreach. Take advice before a large campaign.

The pre-purchase version of these questions is on the FAQ.

Updated on:

Was this article helpful?

Related articles