Skip to content
HomeLegal

European privacy supplement

EEA and UK Privacy Information

Additional information for people in the European Economic Area and United Kingdom—and an important reminder for customers planning international outreach.

Effective and last updated September 15, 2026

1. Scope and data-protection roles

This page supplements our Privacy Policy where the EU GDPR, UK GDPR, or related law applies. It is information about our practices, not a certification that every use of AgentEmailer data is lawful in every country.

AgentEmailer generally acts as a controller for information used to operate customer accounts, sell and deliver our data products, maintain our professional directory, secure the Service, and respond to privacy requests. A customer that imports a purchased file into its own systems or uses it for outreach normally determines its own purposes and means of processing and is independently responsible for its controller obligations.

2. Information, sources, and purposes

The categories of customer, website, and professional information we handle; where they come from; why we use them; and the recipients to whom we disclose them are described in our Privacy Policy. Professional records can include names, business contact details, office and location information, licensing details, association information, and source or verification metadata.

Some professional information is obtained from public, licensed, or other permitted sources rather than directly from the individual. Where European law applies, we assess the transparency requirements for indirectly obtained information and any lawful exception on the facts—not merely because a record is public or used for business.

3. Lawful bases we may rely on

The lawful basis depends on the purpose and context. We may rely on:

  • Contract: to create an account, process an order, deliver a file, and provide support requested by a customer;
  • Legitimate interests: to operate and secure the Service, prevent fraud, improve products, maintain relevant professional business records, and pursue or defend legal claims, after considering necessity and individual impact;
  • Legal obligation: to meet tax, accounting, regulatory, court, and valid government requirements; and
  • Consent: when we specifically ask for consent and the processing is based on that choice. Consent can be withdrawn prospectively.

4. Customer responsibility for email, calls, texts, and faxes

The GDPR is only part of the analysis. Electronic marketing, telephone, fax, cookie, and national rules may require consent or impose additional restrictions. Rules can differ between corporate addresses and addresses belonging to individuals, sole traders, or certain partnerships.

A customer planning outreach should, at minimum:

  • document the lawful basis and, when relying on legitimate interests, complete a context-specific assessment before the campaign;
  • give required privacy information, including the source and categories of data when information was not collected from the person;
  • identify the sender, use the data only for a relevant and proportionate purpose, and avoid sensitive or unexpected profiling;
  • screen against applicable preference and suppression lists; and
  • provide an easy objection or unsubscribe method and honor direct-marketing objections without delay.

5. Transparency and the right to object

If personal information is obtained from someone else, European law may require the controller to provide privacy information within a specified period and, in some cases, by the first communication or first disclosure. The notice should identify the controller, purposes, lawful basis, categories and source of information, recipients, retention approach, transfers, and individual rights.

A person has an absolute right to object to processing for direct marketing under the GDPR. Once that objection applies, the controller must stop using the person’s information for that direct-marketing purpose. A minimal suppression record may be retained to ensure the objection continues to be honored.

6. Your EEA and UK rights

Subject to scope, verification, and legal exceptions, an individual may have the right to:

  • access personal information and receive information about its processing;
  • correct inaccurate or incomplete information;
  • request erasure or restriction;
  • object to processing based on legitimate interests and object to direct marketing;
  • receive certain information in a portable format;
  • withdraw consent without affecting earlier lawful processing; and
  • complain to the data-protection authority where they live, work, or believe an infringement occurred.

Submit a request through our contact form with the subject “European privacy request.” Include enough matching information for us to locate the relevant account or professional record, but never send your password or complete payment-card number.

7. International transfers, retention, and security

AgentEmailer and its providers may process information outside the EEA or UK, including in the United States. Where a restricted transfer occurs, we use a legally recognized mechanism and supplementary measures when required. Retention and security practices are described in our Privacy Policy. No security measure eliminates every risk, and customers must separately protect files they download.

8. Contact, complaints, and official guidance

Contact us through our privacy request channel. You may also contact your local supervisory authority. The official EU GDPR text and the UK Information Commissioner’s business-to-business marketing guidance provide additional information.