> For the complete documentation index, see [llms.txt](https://help.bizmachine.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.bizmachine.com/en/security-and-gdpr/gdpr-and-using-prospector-data.md).

# GDPR and using data from Prospector

Where the data in Prospector comes from, how you can process it, and what to prepare for your lawyer or DPO.

*Updated: 6 October 2026*

GDPR protects the personal data of individuals. In B2B, it applies in exactly the same way. It is not only about privacy. GDPR also makes sure that information about people is correct and up to date, and it gives everyone (among other things) the right to have inaccurate data corrected or deleted.

BizMachine builds its products so that you can work with data and respect these rules at the same time. This page explains where the personal data in Prospector comes from and how you can work with it.

### Where personal data about individuals comes from

The BizMachine platform contains data from public sources, and also its own non-public analytics, signals, microsegments and other data layers about legal entities. But **personal data**, meaning data that identifies or can identify a specific individual, comes only from publicly available sources, in particular:

* Public registers (the Commercial Register, the Trade Register)
* Company websites
* Online company lists and directories
* Professional social networks (LinkedIn)
* Map services
* Job ads

BizMachine connects this scattered information, structures it and regularly verifies it against the original sources. Data that disappears from its source (for example, when a company removes a contact from its website or from an online directory) is then also removed from Prospector.

### Can I use data from Prospector to contact companies?

Before you contact companies, you need to consider two separate questions: whether you can *process* the personal data (GDPR covers this) and whether you can *contact* the person (anti-spam legislation covers this). GDPR states explicitly that processing personal data for direct marketing purposes may be regarded as processing carried out for a legitimate interest (Recital 47). But this does not mean that you can automatically send an email or make a call. The rules for the contact itself come from anti-spam legislation and differ by country and channel. We recommend that you discuss both GDPR and anti-spam legislation with your legal team for your specific case.

#### What BizMachine takes care of

The legal basis for processing personal data at BizMachine is **legitimate interest** (Article 6(1)(f) GDPR). In practice, this means:

* We carried out a legitimate interest assessment (LIA). Based on it, we concluded that our processing can rely on Article 6(1)(f) GDPR. We update this assessment regularly.
* The personal data in Prospector comes only from publicly available sources and relates to business activity, not to people's private lives.
* Prospector contains no sensitive data (special categories of personal data).
* How do the people concerned find out about the processing? BizMachine describes it in its publicly available [Personal Data Processing Policy](https://www.bizmachine.com/en/personal-data-processing).
* Data goes through a two-step process (search and verification). BizMachine regularly checks the data against the original sources. How often depends on how often the source is updated. Data that cannot be verified or that has disappeared from the source is deleted.

  We cannot guarantee complete accuracy in real time, but we do everything we can to keep the data in Prospector current and correct. This is also what GDPR requires for data accuracy (Article 5(1)(d)).

**Why does it matter that the data is publicly available?** Legitimate interest is not automatic. It requires an assessment of whether the controller's interest outweighs the interests or fundamental rights of the individual. The nature of the data matters here. If the data is publicly available, for example in the Commercial Register or on a company website, processing it further is not a significant intrusion into privacy, because the information is already easy to find in public sources. The impact on privacy is much smaller than with data that is not public. In addition, a person who acts as a managing director, sales director or another representative of a company can reasonably expect that their professional data will be processed in business dealings. These two factors, public availability and professional context, strengthen legitimate interest as the legal basis for working with B2B data.

#### What you are responsible for

Here it is important to separate several things:

**1. Processing data (GDPR)**

When you save data from Prospector to your CRM or use it to segment the market, this does not automatically mean that you are processing personal data. It depends on the type of data:

| Type of data                                      | Example                                                                                   | Personal data?                                            |
| ------------------------------------------------- | ----------------------------------------------------------------------------------------- | --------------------------------------------------------- |
| Legal entity (not linked to an individual)        | Company name, Company ID, registered office, revenue, <info@example.com>, reception phone | No - GDPR does not apply (but anti-spam legislation does) |
| Sole trader                                       | Name, Company ID, business premises address                                               | Yes                                                       |
| Statutory representatives and owners              | Managing director, board member, shareholders                                             | Yes                                                       |
| Contact details of specific people in the company | Name, email, phone, position                                                              | Yes                                                       |

If you process personal data, you become a data controller under GDPR and you need your own legal basis. In B2B, this is most often **legitimate interest** (Article 6(1)(f) GDPR): you work with business data in the context of business activity, not with private data. A simple internal assessment (LIA) is enough. It does not have to be a long legal document, but it should exist in writing.

Important: there are two things that BizMachine cannot do for you.

* **Consent of the people in the database.** BizMachine does not collect people's consent to the processing of their data or to being contacted. The legal basis for BizMachine is legitimate interest, not consent. If you need consent for your processing or for contacting someone, you have to get it yourself.
* **Duty to inform.** When you become a controller of personal data (for example, by saving the data to your CRM), you must inform the people concerned about who you are, why you process their data and what rights they have (Article 14 GDPR). If you plan to contact these people (in line with anti-spam legislation), you must meet this duty at the latest when you first contact them.

  But note: you should inform them within a reasonable period after you obtain the data, at the latest within one month. This is another reason why it makes no sense to download large lists of contacts "for later". The longer the data stays in your CRM without you working with it, the longer your duty to inform stays unmet. BizMachine meets this duty for its own processing mainly through its Personal Data Processing Policy, but it cannot meet it for your processing.

**Accurate and up-to-date data: you take care of it, BizMachine helps**

GDPR requires personal data to be accurate and up to date (Article 5(1)(d)). If you save contacts to your CRM, it is your responsibility to keep them up to date and to delete outdated data. BizMachine makes this easier:

* **Source and verification date for every contact.** For every personal contact in Prospector, you can see where the data comes from (the specific URL) and when it was last verified. Email and phone can have different sources and different last verification dates.

![Personal contacts in a company profile in Prospector, with the Last check and Source columns highlighted](https://247275268-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYkl7SJ14Nk0vzhVx7upl%2Fuploads%2Fgit-blob-f8449d87dc7605abc835a23ea2ac81240408dfd4%2Fgdpr-pouziti-dat-kontakt-zdroj-verifikace.png?alt=media)

* **Every export includes the source and the date.** When you download contacts to XLSX, the export automatically includes the source URL and the date of the last verification. This means that you can show at any time that a contact comes from a publicly available source and how recent it is.

![XLSX export from Prospector with the Email Source and Email Last Checked At columns for each email contact](https://247275268-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYkl7SJ14Nk0vzhVx7upl%2Fuploads%2Fgit-blob-bfa971d70ab3e64eee72b3446deabeb09d30add7%2Fgdpr-pouziti-dat-export-zdroj-verifikace.png?alt=media)

The columns for phone and LinkedIn have the same structure (source and verification date).

* **The API provides the same information.** The endpoint for personal contacts returns the source URL and the date of the last verification (separately for email and phone, if they come from different sources). You can use this to build an automated process that removes outdated contacts from your CRM.

```json
{
  "company": {
    "name": "Firma s.r.o."
  },
  "person": {
    "name": { "firstName": "Jan", "lastName": "Novák" },
    "roles": [{ "text": "Obchodní ředitel" }]
  },
  "contact": {
    "type": "Email",
    "value": "jan.novak@firma.cz",
    "isPersonal": true,
    "updatedAt": "2026-02-20T18:07:32+00:00",
    "confidence": 0.7,
    "sources": [
      {
        "name": "Firma.cz",
        "url": "https://www.firma.cz/tym",
        "lastCheckedAt": "2026-02-20T18:07:32+00:00"
      }
    ]
  }
}
```

* **BizMachine automatically removes contacts that disappear from their source, within set time limits.**

An example from practice: some outbound teams check a contact from Prospector once more just before a phone call. They look at the source URL and check whether the contact is still there. They move the data to their CRM only after they have made contact with the person. For these teams, even data that is one day old is not fresh enough, and this process gives them certainty.

**2. Contacting people (anti-spam legislation)**

Whether you can send someone an email or call them is not a GDPR question. It is covered by the rules for unsolicited commercial communication. In the Czech Republic, this is mainly Act No. 480/2004 Coll. Other countries have similar rules based on the European ePrivacy Directive. The rules differ by country and channel (email, phone), so we recommend that you discuss your specific case with your legal team.

#### In practice: what to consider when you contact people

* Document the legal basis under GDPR on which you process the personal data. A short internal record is enough.
* Check which rules for contacting people apply in your country and for your channel (email, phone). In some countries, prior consent is required. In others, an option to opt out is enough.
* Do not download large lists of contacts in bulk. Contact details change within weeks: people change positions, and companies change email addresses. If you download thousands of contacts to your CRM once and then do not update them for months, you end up with outdated data. Under GDPR, this is a problem, because you are processing inaccurate personal data.
* Make every contact relevant: the right company, the right person, the right reason.
* Tell the person you contact where you got their data. Be transparent that it is a business offer and that the data comes from publicly available sources.
* If someone says "I'm not interested, don't contact me", respect it and add them to your internal unsubscribe list.
* Do not sell right away. Bring value first. Instead of asking for a meeting at the first contact, share useful content, for example an interesting article, relevant market data or an invitation to a webinar. Build the relationship step by step. This approach is more effective, and it is also closer to how people want to be contacted.

#### What to tell your lawyer or DPO

If your legal team is assessing whether you can use data from BizMachine, here is the key information:

1. **Personal data comes from publicly available sources.** All personal data in Prospector comes from public registers, company websites, LinkedIn and other open sources. The platform also contains its own analytics and data layers about companies, but these are not personal data. From a GDPR point of view, the key point is that anyone can find the same personal data in public sources.
2. **BizMachine has its own LIA (legitimate interest assessment).** The legitimate interest assessment was prepared by a legal team and is reviewed regularly. It is available on request.
3. **The data relates to business activity, not to private life.** These are business contacts, company data and roles in a company: information that people published themselves in a professional context.
4. **Processing business data based on legitimate interest is common practice.** Legitimate interest is a commonly used legal basis for processing publicly available B2B data in the EU and in the Czech Republic. The contact itself then falls under the rules for commercial communication (anti-spam legislation), not under GDPR.
5. **Data is verified regularly, and outdated data is deleted.** GDPR requires personal data to be accurate and up to date. BizMachine regularly checks the data against the original sources and removes data that cannot be verified or no longer exists. When information disappears from the source, it also disappears from Prospector.

{% hint style="info" %}
BizMachine does not provide legal advice. The information above summarizes how BizMachine works with data, and you can use it as input for your own legal assessment. If you are not sure, we recommend that you consult your legal team.
{% endhint %}

### What if someone in the database exercises their GDPR rights?

A person whose data is in Prospector may ask for access to their data, for its correction or for its deletion. BizMachine handles these requests:

* **Request for deletion:** BizMachine deletes the data.
* **Request for correction:** BizMachine checks where the inaccuracy came from. If the error is in the original source (for example, in an online directory), the fastest way is to correct it there. BizMachine then loads the corrected data at the next synchronization. In exceptional cases, we can also correct the data manually on our side. We always try to find a solution.
* **Objection to processing:** BizMachine assesses the request. If it cannot demonstrate an overriding legitimate interest, it stops the processing.

These rights and other rights under GDPR can be exercised through this contact: **<osobniudaje@bizmachine.com>**

### More information

* [Personal Data Processing Policy](https://www.bizmachine.com/en/personal-data-processing): full information for data subjects
* [Where do the contacts in Prospector come from?](/en/security-and-gdpr/contact-sources.md): how the Contact Aggregator in Prospector works
* Questions about GDPR: **<osobniudaje@bizmachine.com>**

If you are not sure about anything, get in touch. We are happy to help.
