B2B Contact Lists - Verified B2B Data & Technographic Intelligence
Effective Date: January 1, 2026 • Last Updated: Q3 2026

B2B Contact Lists Privacy Policy

This Privacy Policy describes how B2B Contact Lists Inc. ("we", "us", or "our") collects, verifies, uses, and safeguards professional business contact intelligence, and the comprehensive rights individuals have under applicable global data protection laws including GDPR, CCPA/CPRA, and CAN-SPAM. It also discloses our digital advertising, cookie usage, and conversion tracking practices across Google Ads, Meta (Facebook) Ads, and LinkedIn Ads networks.

1. Scope & Fundamental B2B Commitment

B2B Contact Lists Inc. is an enterprise business-to-business (B2B) data intelligence provider. Our service is strictly engineered to facilitate legitimate corporate commerce between commercial organizations.

Strict Professional Exclusion: We do not collect, maintain, process, or distribute private consumer personal data, home residential addresses, personal credit details, personal phone numbers, or sensitive personal data (e.g., religious beliefs, political affiliations, genetic, health, or biometric data). Our datasets are strictly confined to professional business records.

2. Data Controller Identity & Contact Information

The data controller responsible for the processing of corporate intelligence and website telemetry described herein is:

Entity Name: B2B Contact Lists Inc.

Principal Corporate Office: 800 N King Street, Wilmington, DE 19801, United States

Data Protection Desk: [email protected]

Commercial & Sales Inquiries: [email protected]

Website: https://www.b2bcontactlists.com

3. Categories of Data We Collect & Process

We collect and process two categories of data: (a) Information provided directly by website visitors and corporate clients, and (b) Public professional firmographic data compiled for our B2B directories.

A. Information You Submit Directly

When you submit an audience inquiry, request custom counts, or order sample datasets, we collect:

  • Full Name and corporate job title.
  • Corporate work email address (commercial list licensing requires a business email).
  • Company name, corporate website URL, and direct office phone extension.
  • Target audience criteria, geographic filters, and specific campaign requirements.
  • Billing and transaction details (processed via PCI-DSS compliant payment gateways; we never store raw credit card numbers).

B. Professional B2B Directory Data

Our proprietary B2B directories comprise strictly public professional and firmographic attributes:

  • Professional Identity: First name, last name, business salutation.
  • Organizational Role: Professional job title, corporate department, seniority tier.
  • Corporate Contact Point: Verified business work email address (domain-matched to employer).
  • Professional Profiles: Public individual LinkedIn URL and company LinkedIn page.
  • Firmographics: Employer legal entity name, domain URL, corporate headquarters address, city, state, postal code, country.
  • Industry & Scale: 4-digit SIC codes, 6-digit NAICS codes, employee headcount bands, annual revenue tiers.
  • Technographics: Software products, cloud infrastructure (e.g., Salesforce, SAP, AWS, Azure, Snowflake), and technical install footprints.

4. Digital Advertising, Tracking Technologies & Remarketing Disclosures

We partner with third-party digital advertising networks to display relevant commercial advertisements across the web, measure campaign performance, and deliver personalized promotions to business decision-makers. This section provides detailed disclosures required by our advertising partners:

Google Ads & Google Analytics 4 (GA4)

We use Google Ads (including Search, Display, and Performance Max), Google Tag Manager, Google Analytics 4, and Google Ads Conversion Tracking. Google uses first-party cookies (such as GA4) and third-party advertising cookies to inform, optimize, and serve ads based on your prior visits to our website. We may also use Google Customer Match to reach corporate prospects in strict compliance with Google's Customer Match policies.

Opt-Out: You can customize your Google ad settings or opt out of personalized Google advertising by visiting the Google Ad Settings Portal or installing the Google Analytics Opt-out Browser Add-on.

Meta (Facebook & Instagram) Advertising

We use the Meta Pixel and Conversions API (CAPI) to track conversion actions, measure advertising return on investment, and deliver targeted B2B advertisements on Facebook and Instagram. Meta may connect this data to your Facebook or Instagram profile and use it for its own advertising purposes under its Data Policy.

Opt-Out: You can manage or disable interest-based ads on Meta platforms by visiting your Meta Ad Preferences Center.

LinkedIn Ads & LinkedIn Insight Tag

We deploy the LinkedIn Insight Tag to generate website conversion statistics, analyze audience demographics (e.g., job titles, industries, company size), and enable retargeting via LinkedIn Matched Audiences. LinkedIn protects your personal data through cryptographic hashing and IP pseudonymization.

Opt-Out: LinkedIn members can adjust their advertising preferences via the LinkedIn Ad Settings Page.

Universal Industry Ad Opt-Out Portals

You can opt out of interest-based advertising across multiple participating ad networks simultaneously via:

5. Lawful Basis for Processing (GDPR Article 6(1)(f))

For individuals in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland, our primary legal basis for processing corporate contact intelligence is Legitimate Interest pursuant to GDPR Article 6(1)(f).

Recital 47 of the GDPR explicitly acknowledges that "the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." We maintain a formal Legitimate Interest Assessment (LIA) documenting that:

  • Enterprise organizations maintain a legitimate commercial necessity to market relevant products and services to business professionals.
  • Processing is strictly restricted to corporate contact details used solely in the data subject's professional business capacity.
  • We provide immediate, unconditional opt-out mechanisms with zero fees or friction.

6. California Consumer Privacy Rights (CCPA / CPRA)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents are entitled to specific rights regarding their professional information:

  • Right to Know & Access: You may request disclosure of categories and specific pieces of professional data collected.
  • Right to Delete: You may request the permanent erasure of your record from our databases.
  • Right to Correct: You may request the modification of outdated or inaccurate professional attributes.
  • Right to Opt-Out of Sale / Sharing: You may instruct us not to license, share, or disclose your professional business record to third parties.
  • Right to Non-Discrimination: We strictly prohibit discrimination or differential pricing against individuals who exercise their privacy rights.

To submit a California privacy request or exercise your "Do Not Sell or Share My Personal Information" right, visit our Compliance & DSAR Portal or email [email protected] with subject "CCPA Request".

7. Data Retention & Permanent Suppression Registry

We retain professional contact intelligence only for as long as it remains accurate, verified, and relevant to legitimate B2B commerce. When an individual opts out:

  • Their record is suppressed from all active customer files within 24 business hours.
  • Their email address is added to our immutable Master Suppression Registry, ensuring they are never re-harvested or re-added in subsequent automated web sweeps.

8. Security Safeguards & Infrastructure Governance

We employ enterprise-grade technical and organizational safeguards to ensure data integrity and confidentiality:

  • 256-Bit SSL/TLS cryptographic encryption for all data in transit across public networks.
  • AES-256 encryption at rest across all cloud databases, storage buckets, and backups.
  • Strict role-based access control (RBAC) and mandatory multi-factor authentication (MFA) for administrative systems.
  • Continuous vulnerability management, DDoS mitigation, and intrusion prevention monitoring.

9. How to Submit a Privacy Request or Opt-Out

Any business professional may exercise their privacy rights through any of the following verified channels:

1. Interactive Opt-Out Portal: Submit directly via our DSAR Compliance Portal.

2. Direct Email: Email [email protected] with your corporate email address and company domain.

3. Physical Mail: Write to Data Protection Officer, B2B Contact Lists Inc., 800 N King Street, Wilmington, DE 19801, United States.

All verified requests are processed within 24 to 48 business hours free of charge.