Solutions

Content Syndication

Your content in front of key decision makers


Social Advertising

Precision LinkedIn engagement.


Display Advertising

Programmatic display built to reach and influence buying groups.


Content Creation

Build authority-driving content across formats and funnels.


Audio Advertising

Deliver brand messages in high-attention, screen-free environments.


Email Marketing

Email outreach built for modern B2B buying teams


ConnectedTV

Premium video for senior decision-makers.

ABM Acceleration

A comprehensive multi-channel ABM strategy that ensures your messaging is seen and engaged with by all of your ABM accounts.

Latest Resource
ProspectBase downloadable guide
2025: The state of AI within B2B marketing
Download the report
CommitSignal™AI ProspectHubResources
Resources

Blog categories

B2B Data
ABM
Insights
Latest News
View all news
60% of B2B Research Never Touches Your Website. Here's What to Do Next.

60% of your buyer research happens before they reach your website. Here's how your brand can now influence discovery before the website visit happens.

Read more
The AI Execution Gap: Why B2B Teams Are Stuck Between Strategy and Action

AI adoption in B2B is accelerating. Execution isn't. Insights from our recent panel discussions reveal why GTM teams are stuck - and what closes the gap.

Read more
3 ways to adapt your marketing outreach

3 ways to adapt your marketing outreach

Read more
Latest Events
View all events
AI - Beyond The Hype

art'otel, Shoreditch, London

May 13, 2026

Read more
AI & Modern GTM Execution

Treehouse Silicon Valley

February 25, 2026

Read more
Company
Start Generating Leads

Standard Terms and Conditions

Background

These Terms and Conditions shall apply to the provision of the services performed by ProspectBase Ireland Ltd with registered number: 762727 whose registered office is: 18 Church Street, Portlaoise, Co. Laois, R32 TP89 (“Provider” or “Service Provider”) to you (“Client”).  No other terms and conditions shall apply to the provision of Services unless agreed upon in writing between Provider and the Client.

1. Definitions and Interpretation

1.1 In these Terms and Conditions, unless the context otherwise requires, the following expressions have the following meanings:

“Applicable Laws” means all laws, statutes, regulations, and similar instruments from time to time in force applicable to the Parties, the Services, and to the Contract;

“Business Day” means, any day (other than Saturday or Sunday) on which ordinary banks are open for their full range of normal business in the United Kingdom and/or in Ireland;

“Client” means the party procuring the Services from the Service Provider under the Contract;

“Client Materials” means any and all information, documents, and other materials provided by the Client to the Service Provider in relation to the provision of the Services;

“Commencement Date” means the date on which the Contract shall enter into effect, as set out in Clause 2 (Basis of Contract);

“Confidential Information” means, in relation to either Party, information which is disclosed to that Party by the other Party pursuant to or in connection with the Contract (whether orally or in writing or any other medium, and whether or not the information is expressly stated to be confidential or marked as such);

“Contract” means the contract entered into by the Service Provider and the Client for the provision of Services in accordance with and on the basis of these Terms and Conditions, any Schedules, relevant documents such as the Data Processing Agreement (“DPA”) mentioned in clause 10.4, and any appropriate Order or Statement of Work (“SOW”) connected with, and/or appended or attached to these Terms and Conditions;

“Data Protection Legislation” means all applicable legislation in force from time to time in the Republic of Ireland or the United Kingdom (or other region as appropriate) applicable to data protection and privacy including, but not limited to, the GDPR (EU) 2016/679, the UK GDPR (as defined in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018; the Irish Data Protection Act 2018; ePrivacy Regulations SI 336/2011; the Data Protection Act 2018 (and regulations made thereunder); CCPA (& CPRA revisions), CASL, CAN-SPAM and the Privacy and Electronic Communications Regulations 2003 (“PECR”) as amended;

“Fees” means any and all sums due under the Contract from the Client to the Service Provider in consideration of the Services, as set out in Clause 5 (Fees, Payment, and Records);

“Intellectual Property Rights” means patents, rights to inventions, copyright and related rights, trade marks, business names, domain names, design rights, database rights, rights subsisting in software, rights to use confidential information and the right to protect the same, and any and all other intellectual property rights, whether registered or unregistered, including applications and the right to apply for (and be granted) renewals or extensions of, and rights to claim priority from, any such rights and any and all equivalent rights or other forms of protection subsisting now or in the future anywhere in the world;

“Order” means the Client’s order for the Services as set out on Provider’s order form attached with these T&Cs, or as provided by the Client on a purchase order, insertion order (“IO”) or relevant Statement of Work (“SoW”) in conjunction with these terms and conditions or other terms and conditions as agreed between the Client and Service Provider where applicable;

“Services” means the services to be provided by the Provider to the Client in accordance with the Contract, as fully defined in the Specification;

“Specification” means the full description and specification of the Services as agreed in writing by the Client and the Service Provider.  

2. Interpretation in these Terms and Conditions

Headings are for convenience only and shall not affect their interpretation. Words imparting the singular number shall include the plural and vice-versa.

3. Services

3.1 With effect from the commencement date stated in these Terms and Conditions (“T&Cs”) and in consideration of the Fees being paid in accordance with these T&Cs, the Provider shall provide the Services to the Client.

3.2 The Provider shall use reasonable care and skill in its performance of the Services and shall ensure compliance with applicable laws and relevant codes of practice.

3.3 The Provider shall use its best and reasonable endeavours to perform the Services; however, time will not be of the essence in the performance of these obligations.

3.4 The Service Provider shall act in accordance with all reasonable instructions issued by the Client. With regards to such instructions requiring the Provider to process Personal Data (as defined by the GDPR/UK GDPR), Client acknowledges and accepts that it is the Data Controller and Provider is a Data Processor.

3.5 Dual Data Controller and Processor Roles:

(a) Provider as Independent Data Controller: Provider operates and maintains its proprietary database of business contact information ("Provider Database"). Provider is the sole data controller for the Provider Database, including decisions regarding:

  1. Collection, storage, and maintenance of business contact data;
  1. Data quality, verification, and enhancement procedures;
  1. Selection of tools, systems, and sub-processors for database management.

(b) Provider as Data Processor for Services: When performing Services under this Contract, Provider acts as a data processor on behalf of Client (the data controller) with respect to:

  1. Contacts selected from the Provider Database based on Client's targeting criteria and instructions;
  1. Execution of marketing campaigns to selected contacts using Client Materials (which includes messaging and content);
  1. Processing of any personal data provided by Client or collected during campaign execution.

(c) Clarification of "Means" vs "Purposes": Client solely determines the purposes and essential means of processing (target audience criteria, campaign objectives, permitted communication channels, messaging content). Provider determines only the technical and organisational means of executing Client's instructions (selection of email platform, telemarketing provider, delivery optimisation).

(d) No Joint Control: The Parties acknowledge they do not act as joint controllers. Provider's role as processor does not diminish its independent controller obligations for the Provider Database outside the scope of Client instructions.

(e) Provider Warranties: Provider warrants that all contacts in the Provider Database were lawfully obtained and that Provider maintains appropriate legal bases for their processing.

3.6 Marketing Compliance

(a) Provider shall ensure all marketing communications comply with:

  1. CAN-SPAM Act (United States);
  1. Canada's Anti-Spam Legislation (CASL);
  1. Privacy Regulations SI 336/2011 (Ireland) and Privacy and Electronic Communications Regulations 2003 (PECR) as amended (United Kingdom);
  1. Applicable regional and international marketing laws.

(b) Provider shall:

  1. Maintain valid legal basis and consent records for all contacts;
  1. Include functional unsubscribe mechanisms in all email communications;
  1. Honour opt-out requests within legally required timeframes (10 business days for CAN-SPAM, without delay for CASL);
  1. Respect suppression lists provided by Client;
  1. Not contact individuals who have opted out of communications.

(c) Client warrants it has lawful basis to engage Provider for marketing to its target audience and that any materials, content, or instructions provided to Provider comply with applicable marketing laws.

(d) Each Party shall indemnify the other for violations of marketing laws caused solely by its own non-compliance, breach of warranty, or provision of non-compliant instructions/materials.

4. Client Obligations

4.1 The Client shall use its best and reasonable endeavours to provide the Provider with access to any, and all relevant information, materials, properties, and other matters which are required to enable the Provider to provide the Services.

4.2 The Client shall use its best and reasonable endeavours to acquire any permissions, consents, licences, or other matters which are required to enable the Provider to provide the Services.

4.3 The Provider shall not be liable for any delay or failure to provide the Services where such delay or failure is due to the Client’s failure to comply with this Clause 4.

4.4 The Client will at all times comply with Applicable Laws, and immediately inform the Provider if it believes, for any reason, it can no longer comply, or has not complied with Applicable Laws

5. Fees

5.1 The fees (“Fees”) for the Services are set out on the Order.

5.2 In addition to the Fees, the Provider shall be entitled to charge the Client interest for late payment of fees at an annual rate of 8%+ base rate.

5.3 The Fees are exclusive of any applicable value added tax, goods and services tax, sales tax, digital services tax, withholding tax, or any other tax, levy, or duty imposed or charged by any competent authority in any jurisdiction (collectively, "Taxes"). Unless otherwise specified on the Order, all such Taxes shall be payable by the Client in addition to the Fees. Where any applicable law requires the Client to withhold or deduct tax from payments due to the Provider, the Client shall gross up the payment so that the Provider receives the full invoiced amount and shall promptly provide the Provider with the relevant withholding certificate.

6. Variation

6.1 If the Client wishes to vary any details of the Services it must notify the Provider in writing as soon as possible.  The Provider shall endeavour to make any required changes the Client agrees to pay any additional fees related to its request. Provider may accept variation requests at its sole discretion.

6.2 If, due to circumstances beyond its control, the Provider has to make any change in the Services or the arrangements relating to the provision thereof, it shall notify the Client immediately.  The Provider shall endeavour to keep any such changes to a minimum and shall seek to offer the Client arrangements as close to the original as is reasonably possible in the circumstances.

7. Payment

7.1 The Provider shall invoice the Client for the Fees each month in arrears for the provision of the Services rendered;

7.2 The Client shall pay the Fees due within 30 days of the date of the Provider’s invoice.

7.3 Time for payment shall be of the essence of the Contract between the Provider and the Client.

7.4 If the Client fails to make payment within the period in sub-Clause 7.2, the Provider shall have the right to suspend any further provision of the Services until the balance due has been paid in full. The Provider may also cancel any future services which may have been ordered by, or otherwise arranged with, the Client if (a) the client has not paid all outstanding fees in full within 60 days of the date of the oldest invoice, or (b) the Client fails to make future payments on time and in full.

7.5 All Fees and invoices under this Contract shall be denominated and payable in United States Dollars (USD) unless otherwise specified on the Order or agreed in writing between the Parties. The Provider must receive the full invoiced USD amount net of any bank transfer charges, currency conversion costs, or payment processing fees, which shall be borne solely by the Client.

8. Confidentiality

8.1 Each Party undertakes that, except as provided by sub-Clause 8.2 or as authorised in writing by the other Party (such authorisation not to be unreasonably withheld), it shall, at all times during the term of the Contract and for a minimum of three (3) years after its termination or expiry:

  1. keep confidential all Confidential Information;
  1. not disclose any Confidential Information to any other party;
  1. not use any Confidential Information for any purpose other than as contemplated by the Contract; and
  1. ensure that (as applicable) none of its employees, directors, officers, agents, or sub-contractors does any act which, if done by that Party, would be a breach of the provisions of this Clause 8.

8.2 Subject to sub-Clause 8.3, either Party may disclose any Confidential Information to:

  1. any sub-contractors, substitutes, or suppliers;
  1. any governmental or other authority or regulatory body; or
  1. any employee or officer of that Party or of any of the aforementioned persons, parties, or bodies.

8.3 Disclosure under sub-Clause 8.2 may be made only to the extent that it is necessary for the purposes contemplated by the Contract, or as required by law. In each case, the disclosing Party must first inform the recipient that the Confidential Information is confidential. Unless the recipient is a body described in sub-Clause 8.2(b) or is an authorised employee or officer of such a body, the Party disclosing the Confidential Information under sub-Clause 8.2 must obtain and submit to the other Party a written undertaking from the recipient to keep the Confidential Information confidential and to use it only for the purposes for which the disclosure is made.

8.4 Either Party may use any Confidential for any purpose, or disclose it to any other party, where that Confidential Information is or becomes public knowledge through no fault of that Party.

8.5 When using or disclosing Confidential Information under sub-Clause 8.4, the Party using or disclosing that Confidential Information must ensure that it does not use or disclose any part of that Confidential Information which is not public knowledge.

8.6 The provisions of this Clause 8 shall continue in force in accordance with their terms, notwithstanding the termination or expiry of the Contract for any reason.

9. Termination

9.1 Provider party may terminate this Contract for convenience by providing Client with at least thirty (30) days' written notice.

9.2 Either Party may terminate the provision of the Services immediately if:

  1. a material breach is committed by either party of its obligations under these T&Cs; or
  1. a party becomes the subject of a bankruptcy order or takes advantage of any other statutory provision for the relief of insolvent debtors.
  1. a party enters into a voluntary arrangement under Companies Act 2014 (Parts 10–12) and the Companies (Accounting) Act 2017 (Ireland), or Part 1 of the Insolvency Act 1986 (UK), or any other scheme or arrangement is made with its creditors; or
  1. a party convenes any meeting of its creditors, enters into voluntary or compulsory liquidation, has a receiver, examiner, administrator, or administrative receiver appointed in respect of its assets or undertakings or any part thereof, enters into any scheme of arrangement or compromise with its creditors, any documents are filed with the court for the appointment of an administrator or examiner, a resolution is passed or petition presented to any court for the winding up of either party, or any proceedings are commenced relating to the insolvency or possible insolvency of either party, whether under the Insolvency Act 1986 and Schedule B1 thereof (England and Wales), the Companies Act 2014 Parts 10–12 (Ireland), or any equivalent legislation in any applicable jurisdiction.
10. Data Protection and Intellectual Property

10.1 In this Clause 10, the terms “personal data”, “processing”, “data subject”, “controller”, “processor”, and “personal data breach” shall have the meanings defined in Article 4 of the EU GDPR, and the terms “Data Processor” and “Data Controller” shall have the same meanings as “processor” and “controller” respectively. The term “domestic law” means the law of Ireland or, where applicable, European Union law binding in Ireland, including EU GDPR and the Irish Data Protection Act 2018.

10.2 The Parties shall both comply with all applicable data protection requirements set out in the Data Protection Legislation. This Clause 10 shall not relieve either Party of any obligations set out in the Data Protection Legislation and does not remove or replace any of those obligations.

10.3 Data Controller and Processor Relationship. For the purposes of Data Protection Legislation and this Clause 10:

  1. Regarding the Provider Database: Provider is the data controller;
  1. Regarding Services performed under Client instructions:

2.1 Client is the data controller for campaign execution and results;

2.2 Provider is the data processor executing Client's instructions.

  1. Regarding transfer of leads to Client: Provider acts as a data controller transferring personal data to Client (also a data controller) under legitimate interests (Article 6(1)(f) UK GDPR).
  1. Each Party shall comply with its respective obligations under Data Protection Legislation corresponding to its role(s).
  1. Where Provider processes personal data as a processor, the provisions of Clauses 10.5 through 10.10 shall apply.
  1. Client acknowledges that Provider's status as data controller for its Provider Database does not create joint controller obligations for campaign execution activities.

10.4 The scope, nature, and purpose of the processing; the duration of the processing; the type(s) of personal data; and the category or categories of data subject shall be set out in Schedule 2.

10.5 Both Data Controller and Data Processor shall (without prejudice to the generality of sub-Clause 10.2) ensure all necessary consents and notices required are in place to enable the lawful transfer and receipt of personal data to and from one another, and for the lawful processing of personal data by the Data Processor for the purposes described in Schedule 1 and for its provision of Services under this Contract.

10.6 The Data Processor shall (without prejudice to the generality of sub-Clause 10.2), with respect to any personal data processed by it in relation to its performance of any of its obligations under the Contract:

(a) process the personal data only on the written documented instructions of the Data Controller unless the Data Processor is otherwise required to process such personal data by domestic law. The Data Processor shall promptly notify the Data Controller before carrying out such processing unless it is prohibited from doing so by that law;

(b) ensure that it has in place appropriate technical and organisational measures to protect the personal data from unauthorised or unlawful processing, accidental loss, damage, or destruction. Such measures shall be appropriate and proportionate to the potential harm resulting from such events and to the nature, scope, and context of the personal data and processing involved, considering the current state of the art in technology and the cost of implementing those measures.

(c) ensure that any and all persons with access to the personal data (whether for processing purposes or otherwise) are contractually obliged to keep that personal data confidential;

(d) not transfer any personal data outside of the EEA or Ireland without the prior written consent of the Data Controller (such consent to be freely provided upon entering into a Contract with Provider) and only if the following conditions are satisfied:

  1. the Data Controller and/or the Data Processor has/have provided appropriate safeguards for the transfer of personal data;
  1. affected data subjects have enforceable rights and effective legal remedies;
  1. the Data Processor complies with its obligations under the Data Protection Legislation, providing an adequate level of protection to any and all personal data so transferred; and
  1. the Data Processor complies with all reasonable instructions given in advance by the Data Controller with respect to the processing of the personal data;

(e) assist the Data Controller, at the Data Controller’s cost, in responding to any and all requests from data subjects and in ensuring its compliance with the Data Protection Legislation with respect to impact assessments, security, breach notifications, and consultations with supervisory authorities or other applicable regulatory authorities (including, but not limited to, the Data Protection Commission of Ireland ("DPC"))

(f) notify the Data Controller without undue delay of any personal data breach of which it becomes aware;

(g) on the Data Controller’s written instruction, delete (or otherwise dispose of) or return all personal data and any and all copies thereof to the Data Controller on termination or expiry of the Contract unless it is required to retain any of the personal data by domestic law;

(h) maintain complete and accurate records of all processing activities and technical and organisational measures implemented necessary to demonstrate compliance with this Clause 10 and to allow for audits, including inspections, by the Data Controller and/or any reasonable party designated by the Data Controller. The Data Processor shall inform the Data Controller immediately if, in its opinion, any instruction infringes the Data Protection Legislation.

10.7 The Data Processor shall not sub-contract any of its obligations with respect to the processing of personal data under this Clause 10 to another processor without the prior written consent of the Data Controller (such consent not to be unreasonably withheld. In the event that the Data Processor appoints another processor, the Data Processor shall:

  1. enter into a written contract with the other processor, which shall impose upon that other processor substantially the same obligations as are imposed upon the Data Processor by this Clause 10, which the Data Processor shall ensure shall reflect the requirements of the Data Protection Legislation at all times;
  1. ensure that the other processor complies fully with its obligations under that agreement and the Data Protection Legislation; and
  1. remain fully liable to the Data Controller for the performance of that other processor’s obligations and the acts or omissions thereof.

10.8 Sub-Processors.

  1. Any approved sub-processors used in the provision of Services shall be confirmed with the Client upon request and Provider shall notify Client at least 30 days before engaging new sub-processors or materially changing existing sub-processor arrangements. Client may object to new sub-processors on reasonable data protection grounds within 14 days of notification. If Client objects and Provider cannot provide alternative arrangements, Client may terminate the affected Services without penalty.
  1. Provider shall ensure all sub-processors are bound by written agreements imposing substantially the same data protection obligations as set out in this Clause 10.
  1. Provider remains fully liable for the acts and omissions of all sub-processors as if they were Provider's own acts and omissions.

10.9 Data Breach Notification.

(a) Provider shall notify Client within 24 hours of becoming aware of a personal data breach affecting personal data processed under this Contract.

(b) The notification shall include:

  1. Nature of the breach and categories and approximate volumes of data subjects and personal data records affected;
  1. Contact details of Provider's responsible contact;
  1. Likely consequences of the breach;
  1. Measures taken or proposed to address the breach and mitigate potential adverse effects.

(c) Provider shall provide reasonable cooperation and assistance to Client in investigating, mitigating, and remediating the breach, and in complying with any breach notification obligations to supervisory authorities or data subjects.

(d) Provider shall document all personal data breaches and make such documentation available to Client and supervisory authorities upon reasonable request.

10.10 Audits and Compliance.

(a) Client or its authorised auditors may audit Provider's compliance with this Clause 10 upon 30 days' prior written notice, no more than once annually.

(b) Audits shall be conducted during Business Hours and in a manner that minimises disruption to Provider's operations.

(c) Provider may demonstrate compliance through:

  1. Providing copies of relevant certifications (ISO 27001, SOC 2 Type II, etc.);
  1. Third-party audit reports;
  1. Completed compliance questionnaires;
  1. Client shall bear the costs of audits.
  1. Both Parties shall maintain confidentiality of audit findings and use them solely for compliance verification purposes.

10.11 GDPR and California Privacy Rights.  

(a) To the extent Provider processes personal data of individuals located in the European Union, European Economic Area, or United Kingdom on Client's behalf, Provider shall comply with the requirements of the EU GDPR (Regulation 2016/679) and, where processing relates to UK data subjects, the UK GDPR as a concurrent obligation. Provider shall:

  1. Process personal data only in accordance with documented instructions from Client, unless required by law to process otherwise (in which case Provider shall inform Client before processing, unless prohibited by law);
  1. Ensure all persons authorised to process personal data are subject to appropriate confidentiality obligations;
  1. Implement appropriate technical and organisational measures as set out in Schedule 1 to ensure a level of security appropriate to the risk;
  1. Not engage sub-processors without prior authorisation from Client as set out in Clause 10.8;
  1. Assist Client in responding to data subject rights requests (access, rectification, erasure, restriction, portability, objection) within 5 business days of receiving Client's request for assistance;
  1. Assist Client in ensuring compliance with data protection impact assessments, prior consultation with supervisory authorities, and security breach obligations;
  1. Notify Client within 24 hours of becoming aware of any personal data breach as set out in Clause 10.9;
  1. Delete or return all personal data to Client after the end of provision of Services, unless retention is required by law;
  1. Make available to Client all information necessary to demonstrate compliance with Article 28 EU GDPR and allow for audits as set out in Clause 10.10;
  1. Immediately inform Client if, in Provider's opinion, any instruction from Client infringes EU GDPR, UK GDPR, or other Data Protection Legislation.

(b) CCPA/CPRA Compliance for California Residents: To the extent Provider processes personal information (as defined by the California Consumer Privacy Act as amended by the California Privacy Rights Act, collectively "CCPA") of California residents on Client's behalf, Provider shall:

  1. Not sell or share such personal information;
  1. Not retain, use, or disclose such personal information for any purpose other than performing the Services specified in this Contract;
  1. Not retain, use, or disclose such personal information outside of the direct business relationship between Provider and Client;
  1. Not combine such personal information with personal information received from or on behalf of another person, except as permitted by CCPA;
  1. Comply with applicable provisions of the CCPA, including but not limited to Sections 1798.100 through 1798.199;
  1. Assist Client in responding to verified consumer rights requests (access, deletion, correction, opt-out of sale/sharing, limit use of sensitive personal information) within 10 business days of receiving Client's request for assistance;
  1. Implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information to protect it from unauthorised or illegal access, destruction, use, modification, or disclosure;
  1. Notify Client within 24 hours of determining that it can no longer meet its obligations under CCPA;
  1. Certify annually upon Client's request that Provider understands and will comply with the applicable restrictions and obligations under CCPA;
  1. Upon Client's reasonable request, provide information necessary for Client to demonstrate Provider's compliance with CCPA service provider obligations.

(c) Cross-Jurisdictional Application: Where personal data/information relates to individuals who may be subject to both GDPR and CCPA protections, Provider shall comply with the requirements of both subsections (a) and (b), applying the most protective standard where requirements conflict.

(d) Grant of Rights to Client: Provider grants Client the right, upon reasonable notice and at reasonable times, to take reasonable and appropriate steps to ensure that Provider uses personal data/information in a manner consistent with Client's obligations under GDPR and CCPA, including through audits as provided in Clause 10.10.

1. Survival: These obligations shall survive termination for so long as Provider retains any personal data or personal information processed on Client's behalf under this Contract.

2. Sub-Processor Requirements: Provider shall ensure that any sub-processors engaged under Clause 10.8 are subject to the same data protection obligations set out in this Clause 10.11, whether through contractual arrangements or binding corporate rules.

10.12 Intellectual Property Rights.

  1. Background Intellectual Property: Each Party retains ownership of all intellectual property rights that existed prior to the Commencement Date or that are developed independently of this Contract ("Background IP").
  1. Provider Tools and Methodologies: Provider retains ownership of all proprietary methodologies, processes, software, tools, templates, databases (including the Provider Database), and know-how used to provide the Services ("Provider IP").
  1. Client Materials: Client retains ownership of all Client Materials, including content, branding, messaging, creative assets, and confidential information provided to Provider.
  1. Deliverables and Work Product:
    (a) Upon full payment of all Fees due, Client shall own all deliverables created specifically and exclusively for Client under this Contract, including:
  1. Campaign strategies and marketing plans developed specifically for Client;
  2. Custom reports, analyses, and insights specific to Client’s campaigns;  
  3. Lists of qualified leads generated through the Services.

(b) Provider retains ownership of any deliverables that incorporate Provider IP, but grants Client a perpetual, non-exclusive, worldwide, royalty-free license to use such deliverables for Client's internal business purposes.

  1. License Grants:
  1. Client grants Provider a non-exclusive license to use Client Materials solely to perform the Services during the Contract term.
  1. Provider grants Client a non-exclusive license to use any Provider IP embedded in deliverables for Client's internal business purposes, subject to full payment of Fees.
  1. Aggregated and Anonymised Data:

(a) Provider may collect, use, and retain aggregated, anonymised, and de-identified data derived from provision of Services for:

  1. Benchmarking and industry research;
  2. Service improvement and development;
  3. Internal analytics and reporting;

provided that such data does not identify Client, Client's customers, or any individuals, and cannot be reverse engineered to identify them.

(b) Infringement Indemnity: Provider shall indemnify and hold harmless Client from any claims that Provider IP infringes third-party intellectual property rights, provided Client:

  1. Promptly notifies Provider of any such claim;
  1. Gives Provider sole control of the defence and settlement;
  1. Provides reasonable cooperation in the defence.

(c) Enforcement: Provider reserves the right to take such action as may be appropriate to restrain or prevent infringement of Provider IP by third parties.

11. Liability and Indemnity

11.1 Limitation of Indirect Damages. Neither Party shall be liable to the other by reason of any representation, implied warranty, condition or other term, or any duty at common law or under this Contract, for any loss of profit, loss of revenue, loss of business opportunity, or any indirect, special, punitive, or consequential loss, damage, costs, expenses or other claims (whether caused by that Party's employees, agents or otherwise) in connection with the provision or use of the Services or the performance of obligations under this Contract.

11.2 Nothing in the Contract shall limit or exclude either Party’s liability under or in relation to the Contract for any form of liability which cannot be limited or excluded by law (without prejudice to the generality of sub-Clause 11.1) including, but not limited to:

  1. death or personal injury caused by negligence;
  1. fraud or fraudulent misrepresentation;
  1. for the wilful misconduct of either that Party or that of its employees or agents

11.3 Mutual Liability Cap.

(a) Subject to Clause 11.2 (liabilities which cannot be limited or excluded by law), the total aggregate liability of either Party to the other under or in relation to the Contract for any and all related or unrelated acts or omissions, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall be limited to three (3) times the total Fees paid or payable under the Contract in the 12 months preceding the event giving rise to liability.

(b) The limitations in this Clause 11.3 shall not apply to:

  1. Personal data breaches resulting from Provider's failure to implement security measures required under Schedule 1;
  1. Either Party's violation of Data Protection Legislation due to its own acts or omissions;
  1. Either Party's breach of Clause 8 (Confidentiality) or Clause 10.12 (Intellectual Property Rights);
  1. Provider's breach of Clause 3.6 causing regulatory fines or penalties to Client;
  1. Client's failure to pay Fees due under Clause 7;
  1. Fraud, wilful misconduct, or gross negligence by either Party.

(c) For clarity, the cap in subsection (a) applies per Party - each Party has its own separate liability cap.

11.4 Insurance.

(a) Provider shall maintain throughout the Contract term and for 12 months thereafter:

  1. Public and Product Liability Insurance with coverage of £2,000,000;
  1. Cyber Liability Insurance with coverage of £250,000;
  1. Employer's Liability with coverage of £10,000,000.

(b) All insurance policies shall be with reputable insurers authorised to conduct business in the United Kingdom.

1. Provider shall provide Client with certificates of insurance upon request (no more than annually) and shall notify Client within 20 Business Days of any material changes, cancellations, or non-renewal of required insurance coverage.

2. Maintenance of insurance does not limit Provider's liability under this Contract.

12. Force Majeure

12.1 Neither party shall be liable for any failure or delay in performing their obligations where such failure or delay results from any cause that is beyond the reasonable control of that party.  Such causes include, but are not limited to: power failure, Internet Service Provider failure, industrial action, civil unrest, fire, flood, storms, earthquakes, acts of terrorism, acts of war, governmental action, pandemics, epidemics, government-mandated lockdowns, public health emergencies, and cyber-attacks on critical infrastructure or public utilities not caused by either Party's security failures or breach of this Contract or any other event that is beyond the control of the Party in question.

12.2 The affected Party shall: (a) Notify the other Party in writing within 48 hours of the Force Majeure event occurring; (b) Use commercially reasonable efforts to mitigate the impact and resume performance as soon as reasonably practicable; (c) Provide regular updates (at least weekly) on the status and expected duration of the Force Majeure event.

12.3 If a Force Majeure event continues for more than 60 consecutive days, either Party may terminate this Contract without penalty upon 14 days' written notice to the other Party. Upon such termination, Client shall pay Provider for all Services satisfactorily performed up to the termination date.

13. Communications

13.1 All notices under these T&Cs shall be in writing and signed by, or on behalf of, the party giving notice (or a duly authorised officer of that party).

13.2 Notices shall be deemed to have been duly given:

  1. when delivered by courier, other messenger, or registered mail during the normal business hours of the recipient;
  1. when sent, if transmitted by fax or email and a successful transmission report or return receipt is generated;
  1. on the fifth business day following mailing, if mailed by national ordinary mail; or
  1. on the tenth business day following mailing, if mailed by airmail.

13.3 All notices under these T&Cs shall be addressed to the most recent address, email address or fax number notified to the other party.

14. No Waiver

14.1 No waiver by the Provider of any breach of these T&Cs by the Client shall be considered as a waiver of any subsequent breach of the same or any other provision.

14.2 No failure or delay on the part of either the Provider or the Client to exercise any right, power or privilege under these T&Cs shall operate as a waiver of, nor shall any single or partial exercise of any such right, power or privilege preclude any other or further exercise of any other right, power, or privilege.

15. Severance

In the event that one or more of these T&Cs is found to be unlawful, invalid, or otherwise unenforceable, that / those provisions shall be deemed severed from the remainder of these standard terms and conditions (which shall remain valid and enforceable).

16. Law and Jurisdiction

16.1 These T&Cs (including any non-contractual matters and obligations arising therefrom or associated therewith) shall be governed by, and construed in accordance with, the laws of England and Wales.

16.2 Any dispute, controversy, proceedings or claim between the Provider and the Client relating to these T&Cs (including any non-contractual matters and obligations arising therefrom or associated therewith) shall fall within the jurisdiction of the courts of England and Wales without prejudice to the right of either Party to bring proceedings in any other court of competent jurisdiction for enforcement purposes.

17. Anti-Bribery and Modern Slavery

17.1 Each Party shall:

  • Comply with all applicable anti-bribery and anti-corruption laws, including the Bribery Act 2010 (United Kingdom), Foreign Corrupt Practices Act (United States), and equivalent laws in all jurisdictions where Services are performed;
  • Comply with the Modern Slavery Act 2015 and maintain policies and procedures designed to prevent modern slavery and human trafficking in its operations and supply chain;
  • Not engage in any activity, practice, or conduct that would constitute an offense under the above laws if carried out in the United Kingdom;
  • Maintain adequate procedures to prevent bribery and modern slavery and provide evidence of such procedures upon reasonable request;
  • Promptly report to the other Party any request or demand for any undue financial or other advantage of any kind received in connection with the performance of this Contract.

17.2 Each Party shall notify the other immediately upon becoming aware of any breach or suspected breach of this Clause 17.

17.3 Breach of this Clause 17 shall constitute a material breach permitting the non-breaching Party to terminate this Contract immediately without penalty upon written notice.

17.4 Each Party shall indemnify the other against any losses, liabilities, damages, costs, or expenses incurred by the other Party arising from any breach of this Clause 17.

18. Non-Solicitation

18.1 During the term of this Contract and for 12 months following its termination or expiry, neither Party shall, without the prior written consent of the other Party:

  • Directly or indirectly solicit, entice, or induce any employee, contractor, or consultant of the other Party who has been materially involved in the provision or receipt of Services under this Contract to leave their employment or engagement; or
  • Directly or indirectly employ or engage any such person, whether as an employee, consultant, contractor, or otherwise.

18.2 This Clause 18 shall not prevent:

  • General advertising or recruitment campaigns not specifically targeted at the other Party's personnel;
  • Unsolicited approaches by individuals responding to general advertisements;
  • Hiring individuals whose employment or engagement with the other Party ended more than 6 months prior to commencement of discussions regarding employment;
  • Engaging individuals made redundant or whose roles were eliminated by the other Party.

18.3 As a genuine pre-estimate of liquidated damages (and not a penalty), if either Party breaches Clause 18.1, the breaching Party shall pay the other Party an amount equal to 6 months' salary (or equivalent fees for contractors/consultants) of the affected individual, calculated at the rate in effect immediately prior to their departure.

18.4 The remedy in Clause 18.3 shall be without prejudice to any other rights or remedies available to the non-breaching Party, including injunctive relief

‍

SCHEDULE 1
Technical and Organisational Measures

This Schedule 1 sets out the technical and organisational measures implemented by ProspectBase Ireland Ltd in accordance with the Applicable Laws. ProspectBase Ireland Ltd takes information security and data protection seriously, and these measures are designed to safeguard Personal Data during its processing. These measures ensure the security, confidentiality, integrity, availability, and resilience of systems and services involved in the processing of Personal Data.

1. Data Retention

(a) Personal Data shall be retained only for the duration necessary to provide Services to Clients or as required by applicable law.

(b) Retention periods:

  1. Active client campaign data: Duration of the Contract plus 30 days for final reporting.
  2. Provider Database contacts: Retained while a lawful basis exists and reviewed at least annually.
  3. Contractual and financial records: Six (6) years from the end of the Contract (seven (7) years where required for UK legal compliance).
  4. Marketing consent records: Duration of consent plus three (3) years.
  5. Data subject rights request records: Three (3) years from resolution.

(c) Upon termination of the Contract or upon the Client's written request, Personal Data processed on behalf of the Client shall be securely deleted or returned within 30 days, unless retention is required by law.

(d) Deletion methods shall comply with NIST SP 800-88 Guidelines for Media Sanitization or equivalent standards, including secure overwriting, cryptographic erasure, or physical destruction.

(e) The Provider shall provide written certification of deletion upon the Client's request.

(f) All storage media containing Personal Data shall be securely sanitized before reuse or physically destroyed when retired from service.

2. Data Security Measures

(a) Encryption and Pseudonymisation

  1. Data at rest shall be encrypted using AES-256 or an equivalent standard.
  2. Data in transit shall be protected using TLS 1.3 or higher.
  3. Pseudonymisation techniques shall be applied where technically feasible and appropriate.
  4. Encryption keys shall be stored separately from encrypted data with restricted access.

(b) Access Controls

  1. Multi-factor authentication (MFA) is required for all systems containing Personal Data.
  2. Role-based access control (RBAC) shall limit access based on job function and the need-to-know principle.
  3. All personnel shall have unique user credentials; shared accounts are prohibited.
  4. Access permissions shall be reviewed at least quarterly.
  5. User accounts shall be automatically locked after five (5) failed login attempts.
  6. Access shall be revoked immediately upon termination of employment or engagement.

(c) System Security

  1. Security patches and updates shall be applied within seven (7) days of release, with critical patches applied within three (3) days.
  2. Endpoint protection, including anti-malware and Endpoint Detection and Response (EDR), shall be deployed on all devices accessing Personal Data.
  3. Automated alerting shall be implemented for suspicious activities and security events.
3. Data Subject Rights

(a) Appropriate mechanisms shall be provided to enable data subjects to exercise their rights, including the rights of access, rectification, erasure, and restriction of processing.

(b) An individual or team shall be designated to oversee compliance with data subject rights and GDPR requirements.

4. Contractual Obligations

Contracts with Clients and third-party vendors shall include GDPR-compliant provisions relating to data processing, information security, confidentiality, and data protection.

5. Data Transfer Safeguards

Appropriate safeguards shall be implemented for international transfers of Personal Data, including the use of Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), where Personal Data is transferred outside the UK or the EEA.

6. Staff Training

(a) All employees, contractors, and other personnel with access to Personal Data shall complete mandatory data protection and information security training:

  1. Within the first 30 days of employment or engagement.
  2. Annually thereafter as refresher training.
  3. Whenever there are significant changes to data protection legislation or Company policies.

(b) Training shall include:

  1. Data protection principles and UK GDPR/CCPA requirements.
  2. Company data protection policies and procedures.
  3. Information security best practices.
  4. Acceptable IT usage policies.
  5. Recognition and reporting of security incidents and data breaches.
  6. Handling data subject rights requests.
  7. Social engineering and phishing awareness.

(c) Training completion records shall be retained for audit purposes for a minimum of three (3) years.

(d) Personnel in data protection, security, or other high-risk roles shall receive additional role-specific training where appropriate.

7. Third-Party Vendor Management

(a) All sub-processors, service providers, and vendors with access to Personal Data shall maintain security standards equivalent to those set out in this Schedule 1.

(b) Vendor due diligence shall be completed before engagement and shall include:

  1. A security questionnaire or assessment.
  2. Review of relevant certifications (e.g., ISO 27001, SOC 2).
  3. Assessment of contractual data protection obligations.

(c) All vendors with access to Personal Data shall be bound by written agreements requiring:

  1. Compliance with applicable Data Protection Legislation.
  2. Implementation of appropriate technical and organisational measures.
  3. Assistance with data subject rights requests.
  4. Prompt notification of data breaches.
  5. Deletion or return of Personal Data upon termination of the agreement.

(d) Vendor security performance shall be reviewed at least annually and following any material security incident.

SCHEDULE 2
Scope and Nature of Processing

This Schedule 2 describes the scope and nature of Personal Data processing carried out by the Service Provider in connection with its Services under the Contract. It also identifies the applicable Standard Contractual Clauses (SCCs), specifically Modules ONE and FOUR, depending on the type of transfer.

The Service Provider acts as a Data Controller for its proprietary Provider Database (as defined in Clause 3) and as a Data Processor when processing Personal Data strictly in accordance with Client instructions. For clarity, the Provider determines the technical and organisational means for service delivery, while the Client defines the purposes and essential parameters of processing.

1. Scope and Data Sources

(a) Only necessary Personal Data (Business Contact Data) shall be processed for providing the Services to the Client.

(b) Data may be obtained from the following sources:

  1. Public business registries (e.g., Companies House, EDGAR, and similar governmental registries).
  2. Company websites and publicly accessible business information pages.
  3. Professional networking platforms where users have made their profiles publicly available (e.g., LinkedIn public profiles).
  4. Business directories, trade publications, and industry databases.
  5. Publicly available business contact information published by companies or individuals.
  6. Reputable third-party data providers that operate lawfully under Data Protection Legislation and warrant appropriate legal bases for the collection and sale of business contact information.
  7. Client-provided data, where the Client has obtained the appropriate legal basis and warrants lawful transfer to the Provider.

(c) The Provider warrants that:

  1. All data sources comply with applicable Data Protection Legislation.
  2. An appropriate legal basis exists for the collection, storage, and processing of all data within the Provider Database.
  3. Data is regularly verified for accuracy and updated where necessary.
  4. Individuals whose data is processed have not opted out of the Provider Database or requested deletion, subject to ongoing monitoring.
2. Nature of Processing

"Processing" means collecting, recording, organising, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, dissemination, alignment or combination, restriction, erasure, or destruction of Personal Data.

The technical and organisational measures described in Schedule 1 ensure that such processing is carried out in compliance with applicable Data Protection Legislation.

3. Purpose of Processing

(a) Provider as Data Controller (Provider Database)

To maintain a database of business contact information for the purpose of providing B2B demand generation and marketing services to Clients.

Legal Basis: Legitimate Interests (Article 6(1)(f) UK GDPR).

(b) Provider as Data Processor (Service Delivery)

To provide Services under the Contract, including but not limited to:

  1. Content Syndication.
  2. ABM (Account-Based Marketing) Display.
  3. Email Marketing.
  4. Tele-Marketing.
  5. Cost-per-click (CPC) and Cost-per-impression (CPM) campaigns.
  6. Data Concierge Services (building, hygiene, enhancement, rectification, verification, etc.).
  7. Brand Promotion.
  8. Intent Solutions.
  9. Other B2B demand generation and lead generation services as agreed.

Legal Basis: Performance of Contract (Article 6(1)(b) UK GDPR) and processing under the Client's lawful instructions.

(c) Provider as Data Controller (Lead Transfer to Client)

To transfer qualified leads who have opted in to receive the Client's marketing materials and communications.

Legal Basis: Legitimate Interests (Article 6(1)(f) UK GDPR).

The Provider conducts Legitimate Interests Assessments (LIAs) to ensure:

  1. Data subjects are business contacts acting in a professional capacity.
  2. Processing is reasonably expected within the B2B marketing context.
  3. Opt-in consent is obtained before transferring leads to the Client.
  4. Data subjects' rights, including opt-out, access, and deletion, are respected.
4. Duration

Processing shall continue for as long as the Services are provided under the Contract and, where legally required, after termination of the Contract to comply with applicable laws.

5. Types and Categories of Personal Data

(a) Types of Personal Data Processed

  1. First Name and Surname.
  2. Job Title, Job Function, Job Role, and Department.
  3. Business Email Address.
  4. Company or Employer Name.
  5. Company Phone Number, Direct Dial Number, and Mobile Number.
  6. Business Address.
  7. IP Address (for campaign engagement tracking).
  8. Social Media Handles (e.g., public LinkedIn profile URLs).
  9. Cookie identifiers and similar tracking technologies where applicable.

(b) Firmographic and Technographic Information

Industry, Company Size, Revenue, Region, Country, Headquarters Location, Technology Stack, and similar business information.

(c) Categories of Personal Data

Non-sensitive Personal Data and Personally Identifiable Information (PII), collectively forming Business Contact Data relating to employees and directors of businesses.

(d) Cookies and Tracking Technologies

Where Services involve cookies, pixels, or similar tracking technologies:

  1. Cookie consent mechanisms shall comply with PECR (UK), the ePrivacy Directive, and applicable privacy laws.
  2. Strictly necessary cookies may be placed without consent.
  3. Non-essential cookies shall only be placed following valid opt-in consent.
  4. Consent records shall be maintained for audit purposes.
  5. The Provider's Cookie Policy shall be maintained and made available to data subjects.
  6. Data subjects may withdraw consent and request deletion of cookies at any time.

6. Legal Basis for Processing

(a) Controller-to-Controller Transfers

Legitimate Interests (Article 6(1)(f) UK GDPR).

(b) Controller-to-Processor Transfers

Performance of Contract (Article 6(1)(b) UK GDPR).

(c) Provider Database Processing

Legitimate Interests (Article 6(1)(f) UK GDPR).

(d) Legitimate Interests Assessments (LIAs)

The Provider shall maintain documented LIAs covering:

  1. Purpose and nature of processing.
  2. Legitimate interests pursued.
  3. Necessity and proportionality.
  4. Balancing of rights and freedoms.
  5. Safeguards implemented.
  6. Overall assessment.

(e) Additional Legal Bases

  1. Consent (Article 6(1)(a) UK GDPR), where applicable.
  2. Legal Obligation (Article 6(1)(c) UK GDPR), where required by law.
7. Data Subject Rights Procedures

(a) The Provider shall facilitate the exercise of data subject rights, including:

  1. Right of access.
  2. Right to rectification.
  3. Right to erasure.
  4. Right to restriction of processing.
  5. Right to data portability.
  6. Right to object.
  7. Rights relating to automated decision-making.
  8. CCPA/CPRA rights, where applicable.

(b) Data subjects may exercise these rights by email, post, online forms, or unsubscribe mechanisms.

(c) Requests shall be responded to within the timeframes required by applicable Data Protection Legislation.

(d) The Provider may request reasonable identity verification before processing a request.

(e) Requests relating to Client campaigns shall be forwarded to the Client within two (2) Business Days, and the Provider shall assist the Client where required.

(f) Requests relating to the Provider Database shall be handled directly by the Provider.

(g) Fees shall only be charged where permitted by law for manifestly unfounded, excessive, or repetitive requests.

(h) Records of all requests and responses shall be retained for a minimum of three (3) years.

8. Distinction Between Provider Controller and Processor Activities

(a) Provider Controller Activities (Provider Database)

The Provider is responsible for:

  1. Sourcing, verifying, enriching, and maintaining business contact data.
  2. Storing and securing the Provider Database.
  3. Determining retention periods.
  4. Responding to data subject rights requests.
  5. Determining the purposes for which the Provider Database is used.
  6. Selecting sub-processors and vendors.

Legal Basis: Legitimate Interests (Article 6(1)(f) UK GDPR).

(b) Provider Processor Activities (Service Delivery)

The Provider processes Personal Data on behalf of the Client by:

  1. Querying the Provider Database using Client criteria.
  2. Executing marketing campaigns.
  3. Tracking campaign engagement.
  4. Processing opt-outs and unsubscribe requests.
  5. Collecting opt-ins.
  6. Reporting campaign results.
  7. Following the Client's documented instructions.

Legal Basis: Performance of Contract (Article 6(1)(b) UK GDPR).

(c) Provider Controller Activities (Lead Transfer)

The Provider:

  1. Obtains opt-in consent.
  2. Transfers qualified leads to the Client.
  3. Provides transparency regarding data sharing.

Legal Basis: Legitimate Interests (Article 6(1)(f)) and Consent (Article 6(1)(a)).

9. Allocation of Responsibility
  1. Requests relating to inclusion in the Provider Database shall be handled by the Provider.
  2. Requests relating to specific Client campaigns shall be handled by the Client, with assistance from the Provider where required.
  3. Requests relating to lead data transferred to the Client shall be handled by the Client, with assistance from the Provider where appropriate.

A.   LIST OF PARTIES

MODULE ONE: Transfer controller to controller

MODULE TWO: Transfer controller to processor

MODULE THREE: Transfer processor to processor

MODULE FOUR: Transfer processor to controller

Data exporter: The Service Provider

Primary Data Privacy Contact: Gareth Morris. Email Address: privacy@prospectbase.com

Data importer: The Client

Primary Data Privacy Contact: the Client signatory on the Order Form or other Client representative as provided to the Service Provider as the main point of contact for Data Privacy and Data Protection matters.

B.   DESCRIPTION OF TRANSFER

MODULE ONE: Transfer controller to controller [Applicable when Provider transfers qualified leads to Client]

MODULE TWO: Transfer controller to processor [Applicable when Client provides data to Provider for processing]

MODULE FOUR: Transfer processor to controller [Applicable when Provider transfers campaign results/leads to Client]

Categories of data subjects whose personal data is transferred: Employees, directors, officers, and other business representatives of B2B companies acting in their professional capacity, primarily in industries such as technology, professional services, finance, healthcare, manufacturing, and other sectors as specified by Client. Categories/Types of personal data transferred: As detailed in Schedule 2, Clause 5(a): Name, job title, business email, business phone numbers, employer, business address, LinkedIn profile, IP address, cookie identifiers (where applicable). Sensitive data (if applicable): No special category data (sensitive personal data as defined in Article 9 UK GDPR) is intentionally collected or transferred. If any sensitive data is inadvertently discovered, it shall be immediately deleted and not processed. Frequency of the transfer: Continuous basis throughout the term of the Contract and as campaigns are executed. Nature of the processing: As covered in Schedule 2, Clause 2: Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, restriction, erasure, and destruction of personal data in connection with provision of B2B demand generation services.

Purpose(s) of the data transfer and further processing: As covered in Schedule 2, Clause 3:

  • Provider processes data to execute marketing campaigns per Client instructions;
  • Provider transfers qualified leads to Client for Client's sales and marketing follow-up;
  • Client processes leads for business development, sales, and ongoing customer relationship management.

Period for which the personal data will be retained: As covered in Schedule 2, Clause 4 and Schedule 1, Clause 3:

  • Lead data transferred to Client: Retained by Client per Client's retention policies;
  • Provider Database: Ongoing while lawful basis exists, subject to data subject rights;
  • Legal/compliance records: As required by applicable law (minimum 6 years for financial records).

For transfers to (sub-)processors (if applicable): The subject matter, nature, and duration of processing by sub-processors shall be the same as for transfers from the Data Processor (Provider) to the Data Controller (Client), limited to activities necessary to support Provider's delivery of Services (e.g., email platform providers, telemarketing service providers, data hosting providers).

C.   COMPETENT SUPERVISORY AUTHORITY

MODULE ONE: Transfer controller to controller

MODULE TWO: Transfer controller to processor

MODULE FOUR: Transfer processor to controller

The Data Protection Commission of Ireland ("DPC") shall be the lead supervisory authority for processing activities carried out by the Provider as an entity established in Ireland, pursuant to Article 56 EU GDPR.

Where processing relates to data subjects located in the United Kingdom, the Information Commissioner's Office ("ICO") shall act as the competent supervisory authority for those processing activities, pursuant to UK GDPR.

Nothing in this clause prevents a data subject from lodging a complaint with the supervisory authority of their Member State of habitual residence pursuant to Article 77 EU GDPR.

‍

Solutions
Content SyndicationDisplay AdvertisingAudio AdvertisingConnectedTVSocial AdvertisingContent CreationEmail Marketing
Company
CareersResourcesEventsRegistrationsContactPrivacy Preferences
© 2026 ProspectBase. 
Standard Terms and Conditions
Privacy Policy UK
Privacy Policy Ireland
Cookies Settings
Do Not Sell My Information