Privacy Policy

Last updated: 26 August 2026

This Privacy Policy explains how Greenfield ("we", "us", "our") collects, uses, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data We Collect

We collect the following categories of personal data:

  • Contact details: Name, email address, phone number, mobile number, and LinkedIn profile URL.
  • Professional information: Job title, department, company, industry, buying role, and areas of interest.
  • Activity data: Interaction history, meeting notes, follow-up dates, and campaign engagement.
  • Account data: Login credentials, role assignments, and audit trail of actions taken within the platform.

2. Lawful Basis for Processing

We process your personal data under the following lawful bases:

  • Consent (Article 6(1)(a)) — where you have provided explicit consent to be contacted for marketing or outreach purposes.
  • Legitimate interests (Article 6(1)(f)) — for maintaining business relationships, managing sales pipelines, and providing services.
  • Contract (Article 6(1)(b)) — where processing is necessary to fulfil a contract with you or your organisation.
  • Legal obligation (Article 6(1)(c)) — where we are required to retain records for compliance purposes.

3. How We Use Your Data

Your personal data is used for:

  • Managing customer and prospect relationships
  • Sales pipeline and opportunity tracking
  • Marketing campaign management and outreach
  • Partner and vendor relationship management
  • Platform administration and audit logging
  • Service improvement and analytics

4. Data Sharing

We may share your personal data with:

  • Cloud providers — hosting and infrastructure partners (e.g., AWS) acting as data processors.
  • Partner organisations — where your record is associated with a partner for co-sell purposes.
  • Vendor contacts — where co-sell opportunities require sharing contact details with vendor teams.
  • Legal authorities — where required by law or regulation.

We do not sell your personal data to third parties.

5. Data Retention

We retain personal data for as long as there is a legitimate business relationship or as required by law. Contact records are retained for the duration of the business relationship and may be kept for up to 6 years after the relationship ends for audit and compliance purposes.

6. Your Rights

Under UK GDPR, you have the following rights:

  • Right of access — request a copy of your personal data.
  • Right to rectification — request correction of inaccurate data.
  • Right to erasure — request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing — request that we limit how we use your data.
  • Right to object — object to processing based on legitimate interests.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to withdraw consent — withdraw consent for marketing at any time.

To exercise any of these rights, contact us using the details below. You can also opt out of marketing communications using our opt-out page.

7. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, role-based access controls, and audit logging. See our Security Policy for more details.

8. International Transfers

Your data may be transferred to and processed in countries outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.

9. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact our Data Protection Officer or compliance team. We will respond within 30 days of receiving your request.