Privacy Notice
Last updated / Effective date: [DATE]
DRAFT — NOT LEGAL ADVICE. This document is a working draft prepared for review and approval by qualified UK counsel. All items in [SQUARE BRACKETS] must be completed and verified before publication. Statements about data locations, processors and retention must be checked against the actual system configuration — an inaccurate statement in a privacy notice is itself a compliance failure.
1. About this notice
This notice explains how [LEGAL ENTITY NAME] (“HotelVisible”, “we”, “us”) handles personal data when we contact hotel businesses in the United Kingdom about our services.
It is addressed to individuals whose business contact details we hold — typically owners, managers or commercial staff at hotels and hospitality businesses — where we obtained those details from publicly available sources rather than from the individual directly. It is provided under Article 14 of the UK GDPR.
If you received an email from us and want to know why, sections 3, 4 and 5 answer that. If you want us to stop, section 10 tells you how.
2. Who we are (Data controller)
Controller: [FULL LEGAL COMPANY NAME]
Trading as: HotelVisible
Company registration number: [NUMBER / N/A]
Registered address: [ADDRESS]
Contact for privacy matters: [PRIVACY EMAIL]
[IF THE CONTROLLER IS ESTABLISHED OUTSIDE THE UK — INCLUDE:]
UK representative (UK GDPR Article 27): [NAME], [UK ADDRESS], [EMAIL]
We have appointed the above as our representative in the United Kingdom. You may contact either us or our representative on any matter relating to this notice.
[IF A DPO HAS BEEN APPOINTED:]
Data Protection Officer: [NAME / EMAIL]
3. What personal data we process
We process a limited set of business contact information:
- Business name and trading name
- Business email address (which may include a named individual, e.g. firstname@hotel.co.uk)
- Job title or role, where publicly stated
- Business website address
- Business address, city and country
- Publicly available business information about the property (for example, listing details and publicly visible online presence)
- Records of our communications with you, including whether an email was delivered, opened or replied to, and any opt-out request
We do not seek or process special category data (Article 9 UK GDPR), and we do not process financial data or personal data relating to guests.
4. Where we obtained your data
We did not collect your details from you directly. We obtained them from publicly accessible sources, which typically include:
- Your business’s own website
- Publicly available business listings and directories [SPECIFY: e.g. Google Business Profile, online travel platform listings]
- [ANY OTHER PUBLIC SOURCE]
We use third-party services to compile and verify this information [SPECIFY PROVIDERS: e.g. business data provider, email verification provider]. These providers confirm whether an address is valid and deliverable; they do not add personal information beyond business contact details.
Where practical, our first email to you states the source of your address.
5. Why we process your data
We process your data to send business-to-business marketing communications introducing HotelVisible’s AEO/AI-search visibility service for hotels — that is, to tell you about a product relevant to your commercial role, and to manage any resulting conversation.
We also process it to:
- Maintain accurate contact records and avoid duplicate or repeated contact
- Honour opt-out requests and maintain a suppression list
- Keep records demonstrating our compliance with data protection law
We do not sell your data, and we do not use it to make decisions that produce legal or similarly significant effects about you. [IF SCORING/PRIORITISATION IS USED, ADD: We may prioritise which businesses to contact using publicly available characteristics of the property, such as location and online visibility. This affects only the order in which we make contact and has no legal or similarly significant effect on you.]
6. Our lawful basis
UK GDPR Article 6(1)(f) — legitimate interests.
Our legitimate interest is promoting our services to businesses likely to have a professional interest in them. We have assessed this against your interests and rights in a legitimate interests assessment, considering that the data is limited to business contact details obtained from public sources, that the communication is professional in nature and relevant to your role, that the volume of contact is low, and that opting out is immediate and effortless. You may request a summary of that assessment at [PRIVACY EMAIL].
PECR Regulation 22. Our emails are sent to corporate subscribers, for whom prior consent is not required under the Privacy and Electronic Communications Regulations. [COUNSEL TO CONFIRM WORDING. OPERATIONAL NOTE: the sending list must exclude sole traders and non-LLP partnerships, who are treated as individual subscribers and require consent or the soft opt-in. A screening step is required before this statement can be made truthfully.] Every message identifies us and provides a means of opting out.
7. Who we share your data with
We do not sell or rent your data. We share it only with service providers acting as our processors under written contract, and only as needed to run our outreach:
| Provider | Purpose | Location of processing |
|---|---|---|
| [Smartlead] | Email delivery and campaign management | [LOCATION] |
| [Supabase] | Database and hosting | [REGION — VERIFY] |
| [Email verification provider] | Validating deliverability of business addresses | [LOCATION] |
| [Enrichment / business data provider] | Compiling public business information | [LOCATION] |
We may also disclose data where required by law or to establish, exercise or defend legal claims.
8. International transfers
Your data is stored in [REGION — VERIFY AGAINST ACTUAL CONFIGURATION].
Where a provider processes data outside the United Kingdom, we rely on [SELECT: UK adequacy regulations / the International Data Transfer Agreement (IDTA) / the UK Addendum to the EU Standard Contractual Clauses], together with any additional safeguards required following a transfer risk assessment. You may request further detail at [PRIVACY EMAIL].
9. How long we keep your data
| Data | Retention |
|---|---|
| Contact records where no response is received | [e.g. 12 months from last contact], then deleted |
| Contact records where a conversation begins | [PERIOD] from last contact |
| Suppression (opt-out) list | Retained indefinitely |
We keep the suppression list indefinitely because it is the only reliable way to ensure we do not contact you again. It holds the minimum needed for that purpose — [e.g. a hashed or plain email address and the date of the request] — and is not used for any other purpose.
10. How to opt out
One click. Every email we send contains an unsubscribe link and a List-Unsubscribe header, so your email client may also show an unsubscribe option at the top of the message. Either will stop all further marketing email from us.
By email.Write to [PRIVACY EMAIL] with “unsubscribe” in the subject line.
We action opt-outs promptly and add the address to our suppression list so it is excluded from future campaigns. You do not need to give a reason.
11. Your rights
Under UK GDPR you have the right to:
- Object to direct marketing. This right is absolute — if you object, we will stop, with no assessment or balancing on our part.
- Object to our processing on other grounds relating to your particular situation.
- Be informed about how we use your data — this notice.
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data in certain circumstances.
- Restrict processing in certain circumstances.
Because we rely on legitimate interests rather than consent, the rights to data portability and to withdraw consent do not apply to this processing.
To exercise any right, contact [PRIVACY EMAIL]. We will respond within one month. We do not charge a fee, and we may ask for information to confirm your identity.
12. Security
We apply appropriate technical and organisational measures to protect your data, including [access controls, encryption in transit and at rest, restricted administrative access, and contractual obligations on our processors — ADJUST TO REFLECT ACTUAL MEASURES].
13. Cookies
[IF THE WEBSITE USES ANALYTICS OR NON-ESSENTIAL COOKIES:] Our website uses cookies. See our Cookie Notice for details and to manage your preferences.
[IF NOT:] Our website uses only cookies strictly necessary for it to function.
14. Complaints
If you are unhappy with how we have handled your data, please contact us first at [PRIVACY EMAIL] so we can try to resolve it.
You also have the right to complain to the UK’s supervisory authority:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
15. Contact
Questions or requests about this notice: [PRIVACY EMAIL]
[UK representative, if appointed: NAME / EMAIL]
16. Changes to this notice
We may update this notice from time to time. The current version, and the date it took effect, is always shown at the top of this page. Where changes are significant, we will take reasonable steps to bring them to the attention of people we are in contact with.