Prospect Data Notice
Information for business contacts whose professional details may appear in Dotless.
Last updated August 7, 2026
1. Who this Notice is for
This Notice provides information required when Dotless obtains business or professional-contact personal data from a source other than the individual. It applies to proprietors, directors, employees, contractors, public professional-profile holders, message recipients, and other business contacts whose information may appear in a Dotless search, enrichment result, saved lead, or suppression record. It supplements the Privacy Policy.
2. Who controls the data
Saem Group s. r. o., Púpavová ulica 4139/37, 900 25 Chorvátsky Grob, Slovakia, IČO 57 600 171, registered in the Commercial Register maintained by Mestský súd Bratislava III (Municipal Court Bratislava III), Section Sro, entry 199008/B, is the controller for a business-contact profile in the Dotless-controlled discovery or enrichment index. Contact support@dotless.co or +421 949 086 278.
A Dotless business customer becomes an independent controller when it selects, saves, combines, exports, or uses contact data for its own prospecting or communications. That customer determines why and whether to contact you, must identify itself in its message, and is responsible for its lawful basis and notice. Dotless processes the customer’s saved copy on its behalf under a DPA while retaining separate responsibility for Dotless’s source index. If you contact us, we will address Dotless-controlled data and, where possible, help identify or notify the relevant Customer without disclosing another party’s confidential data.
3. Categories of personal data
Depending on availability and relevance, a profile may include:
•
name, professional title or role, employer or represented business, business category, and public professional-profile link;
•
business email address, publicly presented business phone number, business website, and social or professional links;
•
business address, service area, city, region, country, language, and time zone;
•
public business facts such as category, rating and review count, domain, source or place identifier, and public listing status;
•
source URL or source category, collection or verification date, confidence or deliverability indicator, and record-matching information;
•
Customer campaign context, message and delivery metadata, bounce, complaint, objection, unsubscribe, suppression, correction, and deletion status; and
•
limited inferences about business relevance, role, likely language, or record match made from the above information.
Dotless does not intend its business-contact index to contain private communications, personal financial accounts, government identifiers, precise private location, children’s data, or special-category data such as health, biometric, political, religious, union, ethnicity, or sexual-life information. Tell us if a profile contains such data so we can investigate and remove it.
4. Sources
Information can come from:
•
the business’s public website, contact page, staff page, or public professional profile;
•
public company, professional, licensing, or business registers and directories;
•
public search and map services and the source pages they identify;
•
licensed business-data, validation, search, collection, and enrichment providers identified by category in our Subprocessor Register;
•
Dotless Customers who upload, correct, suppress, or request validation of their lawfully held business-contact records; and
•
you, including when you respond, object, unsubscribe, or request a correction.
We seek to record enough source information to assess accuracy and rights requests. A source’s public availability does not remove applicable privacy or marketing protections, and inclusion in Dotless is not a statement that any particular communication is lawful.
5. Purposes and legal basis
Dotless processes this data to:
•
enable business users to find and organize relevant businesses and professional contacts;
•
match, validate, update, enrich, deduplicate, and display business-contact records;
•
provide source, confidence, and freshness information so Customers can assess a record;
•
prevent fraud, spam, repeated unwanted contact, and misuse and enforce suppression;
•
respond to access, correction, objection, restriction, and deletion requests; and
•
establish, exercise, or defend legal rights and comply with law.
Dotless generally relies on legitimate interests in providing proportionate B2B discovery, supporting relevant business communications, maintaining accurate public business records, and protecting recipients and the Service. We balance those interests against your privacy by limiting data to business context, excluding intended sensitive categories, tracking sources and age, providing this Notice and rights channels, restricting resale, and honouring direct-marketing objections. We do not rely on legitimate interests where your rights override the interest or local law requires consent.
A Customer must independently determine its lawful basis before contacting you. Dotless does not tell a Customer that a visible email address is consent or that every jurisdiction permits the intended message.
6. Recipients
Data may be disclosed to:
•
authorized Dotless Customers that search for a relevant business, subject to plan, purpose, export, anti-resale, privacy, and acceptable-use restrictions;
•
Dotless hosting, database, security, search, collection, enrichment, validation, AI, and email providers needed for the purposes above;
•
a Customer-directed email or connected-service provider when the Customer initiates an authorized action;
•
professional advisers, auditors, insurers, and transaction counterparties subject to appropriate duties; and
•
authorities, courts, or claimants when required by law or reasonably necessary to protect rights or safety.
Dotless charges for Service plans that can permit business Customers to view or export business-contact data; some privacy laws may define that disclosure as a “sale” even where the charge is for the Service rather than an individual record. Where such a law applies to Dotless, we provide the required notice and opt-out. Dotless does not permit a Customer to resell the data as a standalone database. A Customer can export available records through a permitted feature for its own lawful internal use or an identified agency client, subject to the Terms and source-provider restrictions.
7. International transfers and retention
Dotless is established in Slovakia. Providers and Customers may be in the EEA, United States, or other countries. Where Dotless makes a restricted transfer, it uses an applicable adequacy decision, Standard Contractual Clauses with supplementary measures where required, a valid recognized framework, or another lawful safeguard. Contact us for information about the relevant mechanism.
Dotless reviews, refreshes, or deletes a controller-held profile according to source age, accuracy signals, use, and objections. An unrefreshed profile is targeted for deletion or re-verification within 24 months. A saved Customer copy remains under that Customer’s configured retention while its account is active. Dotless may retain a minimal source, objection, and suppression record longer so removed data is not re-collected or used for renewed contact, and may preserve limited evidence for a legal claim or authority requirement. See the full retention schedule in the Privacy Policy.
8. Your rights and direct-marketing objection
Depending on applicable law, you may request access, source information, correction, deletion, restriction, portability, or objection and may complain to a supervisory authority. You have an unconditional right to object at any time to processing for direct marketing, including related profiling. Use the unsubscribe method in a message to stop that sender and contact Dotless to suppress the address in Dotless-controlled systems.
Email support@dotless.co with the subject “Prospect privacy request”. Include the business email or profile URL to locate the record and state the requested action; do not send identity documents unless we ask for a proportionate verification method. We will respond within the period required by law. An objection may result in deletion from active results plus a minimal hashed or plain suppression record, depending on what is necessary to prevent reappearance.
9. No significant automated decision
Dotless may automatically match, rank, validate, classify, translate, or estimate the relevance of a business record. Dotless does not use this index to make solely automated decisions that produce legal or similarly significant effects about you. Customers are prohibited from using the Service for high-impact decisions without an independently lawful process and meaningful human review.
10. Timing of this Notice
This public Notice is available whenever Dotless holds a controller-managed business-contact profile. Where GDPR Article 14 applies, Dotless or the relevant Customer will provide this information within the required period, generally within one month, at first communication, or before first disclosure, whichever legally applies. Dotless does not rely on publication alone where an individual notice is required. Any permitted exception will be documented and applied narrowly.
