1. Introduction
Firmavis is a business-to-business company-intelligence service. We maintain a structured database of European companies and of the business contact details of the people who hold professional roles within them, and we make that information searchable and exportable to our business customers.
This Privacy Policy serves two audiences at once. It is our notice under Article 13 of the GDPR to the visitors and account holders who interact with our website, and it is our notice under Article 14 of the GDPR to the individuals whose business contact information is included in our database because it was drawn from public and other lawfully accessible sources rather than collected from them directly.
Want your record removed? You can ask us to remove your business email address or phone number from the database at any time, without giving a reason, using our self-service portal: Remove your data. We act on verified requests without undue delay and at the latest within one month, as required by Article 12(3) GDPR — typically within 2 business days.
2. Who we are
The data controller responsible for the processing described in this Policy is:
MB Firmavis
Lithuanian company code: 307941710
Registered in the Register of Legal Entities of the Republic of Lithuania (administrator: State Enterprise Centre of Registers)
Registered office: Laisvės al. 85E-5, LT-44297 Kaunas, Lithuania
VAT number: LT100020426112
Privacy matters: [email protected]
General contact: [email protected]
Questions about privacy, and requests to exercise your rights, should be sent to our Privacy Lead at [email protected].
We have assessed that we are not currently required to designate a Data Protection Officer under Article 37(1) GDPR. We keep this assessment under review and will appoint one if our processing changes such that designation becomes mandatory.
Because we are established in the European Union (Lithuania), no Article 27 representative is required for our processing of EEA personal data.
3. The personal data we process
Company-level information
For each company we hold information such as its registered name, registration code, VAT number, registered and office addresses, activity classification codes, published financial filings, and corporate website address. This information is generally about a legal entity and is not personal data. It becomes personal data where a business is carried on by a sole trader or a self-employed professional, because the company is then identified with a natural person.
Business contact information of named role-holders
Where an individual holds a professional role at a company, we may hold their name, role or job title, business email address, business phone number, the country of their office, and an indication of the category of public source the information was drawn from. We process this information only in a person’s professional capacity.
Site visitor and account data
When you visit our website or create an account, we process your name, work email address, your authentication data (handled by our sign-in provider, listed on the Sub-Processors page), any onboarding preferences you choose (such as a target industry or country), your IP address, device and server-log data, usage data (searches run, records revealed, exports performed, credits consumed, and timestamps), and any communications you send us. Where we provide a separate client tool to specific business clients on this domain, we also process those clients’ login and usage records to operate and secure that tool.
Billing, correspondence and rights-request records
When you purchase a paid plan we process billing and invoicing details (entity name, VAT number, billing address, and payment-transaction references — full card details are handled by our payment provider and never touch our systems). When you contact us or exercise a data-protection right, we keep the related correspondence and, where you ask us to suppress an identifier, a one-way hash of that identifier on our suppression list (see §10 and §11).
We do not intentionally collect or use special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR), and no field in our database is designed to record them. Because we index professional roles, a record could in principle indirectly suggest such information — for example, a role at a political, religious or trade-union organisation. We do not use, classify, filter or disclose records by reference to any such characteristic, and where we become aware that a record reveals special-category data we remove that data.
4. Where we get the data
This section is provided in accordance with Article 14(2)(f) GDPR. The business information in our database is aggregated from categories of public and lawfully accessible sources:
- official corporate registries;
- publicly available business information, directories and listings;
- publicly accessible corporate websites — content a company has itself published, such as team, contact and imprint pages.
We consolidate these sources into a single, consistent schema, then validate, standardise and de-duplicate the records so that each company appears once. We do not collect personal data from personal social networks, and we do not purchase consumer data from list brokers.
5. Why we process it
We process the business database for three articulated purposes:
- Facilitating cross-border B2B commerce — helping businesses find and reach other businesses across European markets.
- Enabling corporate due diligence and counterparty verification — allowing organisations to check and understand the companies they deal with.
- Supporting compliant B2B direct outreach — providing professional contact information for lawful business communication by our customers.
6. Legal basis
The legal basis for processing the business-contact data in our database is Article 6(1)(f) GDPR — legitimate interests. We have carried out and documented a Legitimate Interest Assessment. In summary:
- Purpose — the interests set out in §5, including making records available to our paying customers for those purposes, are legitimate commercial interests, recognised for direct marketing purposes by Recital 47 GDPR.
- Necessity — a consolidated, accurate register of professional contact information is necessary to achieve those purposes. We have considered less intrusive alternatives — such as company-level data without named role-holders, or generic mailboxes only — and documented in the assessment why each falls short of the purposes while noting where we adopt them as limits (for example, filtering out personal mailboxes).
- Reasonable expectations — the details we hold were published, or made available, in a professional context (official registers, a company’s own website, business directories), so their use for business-to-business contact is within the range of uses a professional role-holder can reasonably expect. We further limit impact by restricting records to role-relevant fields, filtering out personal mailboxes, metering and logging every disclosure, and enforcing a permanent suppression list.
- Balancing — we process only professional information about individuals acting in a business capacity, we do not enrich it with private or sensitive attributes, and we honour every objection and removal request without requiring a justification. On balance, our interests are not overridden by the interests or fundamental rights of the data subjects.
A summary of the assessment is available on request at [email protected].
For site-visitor and customer-account data, our bases are:
- Article 6(1)(b) — performance of our contract with the customer (providing the Service, billing, support). This basis applies directly to you where you are a sole trader or self-employed professional contracting personally; where you use the Service as the representative or authorised user of a corporate customer, we process your user data under Article 6(1)(f) — our legitimate interest in administering and securing the corporate customer’s account;
- Article 6(1)(c) — compliance with legal obligations (tax and accounting law);
- Article 6(1)(f) — our legitimate interest in the security and integrity of the Service and in preventing fraud and abuse;
- Article 6(1)(a) — your consent, for non-essential cookies.
We do not rely on Article 9 (special categories) or Article 10 (criminal-conviction data).
7. How we apply Article 14(5)(b)
Article 14(3) GDPR requires this information to be provided within a reasonable period after the data are obtained and at the latest within one month — or, if the data are disclosed to a recipient or used to communicate with the person earlier than that, at the latest at that first disclosure or communication. This section explains how we meet that obligation, and where and why we rely on the exception in Article 14(5)(b).
Where we hold a working business email address for a person in our database, we send that person a one-time transparency notice by email, at the latest before their record is first disclosed to a customer, explaining who we are, what we hold and why, and giving a one-click way to object or be removed. These notices are plain informational messages, sent without open- or click-tracking.
For the period between our obtaining a record and its first disclosure, and for records where we hold no email address — for example a role-holder listed in a public register by name only, or a phone-only contact — we rely on Article 14(5)(b) GDPR: individually notifying, at the moment of collection, every person in a database of this size — including the many whose records are never disclosed to any customer — would involve effort disproportionate to the limited risk the processing poses before disclosure, and for no-email records the contact channels we hold (if any) do not permit reliable individual notice: a bare register listing offers no contact route at all, and unsolicited calls or postal letters would themselves be more intrusive than the processing they announce. We assess this exception per source and record cohort, not as a blanket rule, and we do not treat scale or cost alone as sufficient. Where we rely on it, we take the appropriate measures Article 14(5)(b) requires to protect your rights, freedoms and legitimate interests, namely:
- this public Privacy Policy, which is indexable and prominently linked from every page of the site;
- a self-service Data Removal portal reachable from every page;
- filtering that removes personal mailboxes and focuses, particularly in higher-risk jurisdictions, on business-role contact information; and
- enforcement of an email suppression list on every subsequent database rebuild, with phone numbers removed by our team and re-checked against future updates, so a removed identifier is not re-added.
8. Recipients
We disclose personal data only to:
- our customers, under contract, who use revealed or exported data as independent data controllers for their own outreach (see our Terms of Service);
- our sub-processors, who act on our documented instructions under Article 28 GDPR agreements (listed on our Sub-Processors page);
- our payment provider, which also processes payment data as an independent controller for its own regulatory and fraud-prevention purposes; and
- competent public authorities, where we are required to disclose by law.
Plainly put: our customers purchase subscriptions and credits that allow them to view and export the company and business-contact records described in this Policy — that paid disclosure is the product. We do not disclose personal data to unrelated advertisers, data brokers or list resellers outside the Service.
9. International transfers
Most of our processing takes place within the European Economic Area. Where personal data is transferred outside the EEA, we rely on the following safeguards:
- the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023) for transfers to Framework-certified recipients in the United States, as a primary mechanism;
- the 2021 Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supplemented by a transfer impact assessment consistent with Schrems II (Case C-311/18, 2020) and EDPB Recommendations 01/2020, as a fallback;
- adequacy decisions for other recipient countries where applicable (for example, the United Kingdom under the Commission’s renewed UK adequacy decision of 19 December 2025, in force until 27 December 2031 unless extended); and
- where our customers are established outside the EEA or an adequate country, disclosures to them are made under the 2021 Standard Contractual Clauses, Module One (controller-to-controller), incorporated into our Terms of Service.
The validity of the EU-US Data Privacy Framework is the subject of a pending appeal before the Court of Justice of the European Union (Latombe v Commission, Case C-703/25 P). We monitor the proceedings and will update our transfer mechanisms if the legal framework changes. You may request a copy of the safeguards we rely on at [email protected].
10. Retention periods
| Category | Retention |
|---|---|
| Database records (companies and named role-holders) | Company records are retained as long as the underlying public source remains accessible. Contact details are retained only while they continue to pass our periodic deliverability validation; details that no longer validate are dropped from the published dataset at the next rebuild. Deliverability is a floor, not the only test: we also remove or correct records when we learn they are stale or inaccurate (§11), and we remove data that is no longer necessary for the purposes in §5. |
| Suppression list | Indefinite, stored only as a one-way hash of the canonicalised identifier — kept so that we can keep honouring your objection or erasure on every future database rebuild (Articles 6(1)(c), 17 and 21 GDPR). The plaintext identifier is destroyed once suppression is confirmed. |
| Site server access logs | 14 days routinely; up to 90 days for a security or incident investigation; up to 12 months for a documented fraud investigation only. |
| Customer account data | Duration of the customer relationship, plus 3 years for evidentiary and limitation purposes — or the longer period a specific Lithuanian limitation or accounting rule requires for particular records (billing records: see below). |
| Data-removal and rights-request correspondence | 3 years from closure, to demonstrate that requests were handled. |
| Billing records | 10 years, as required by Lithuanian accounting law. |
11. Your rights
Under the GDPR you have the right to access your data (Article 15), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20 — where its conditions are met: it applies to data you provided to us that we process by automated means on the basis of consent or contract), to object to processing based on our legitimate interests (Article 21), not to be subject to solely automated decisions with legal or similarly significant effect (Article 22 — we do not carry out such decision-making), and to lodge a complaint with a supervisory authority (Article 77).
Where processing is based on your consent (for example, non-essential cookies), you may withdraw it at any time with effect for the future; withdrawal does not affect the lawfulness of processing carried out before it (Article 7(3)).
Right to object to direct marketing. Because our database supports our customers’ direct-marketing activity, you may object at any time to the processing of your personal data for these purposes (Article 21(2) GDPR). We honour every such objection unconditionally — no justification is required. The fastest route is the Remove your data portal.
The fastest way to have your business email address or phone number removed, or to object to our processing, is the self-service portal: Remove your data. For any other request, write to [email protected]. If you object to the inclusion of your name and role, we will remove the record and keep an internal exclusion entry so that it is not re-added when the underlying public source is next refreshed. If you are a sole trader or self-employed professional and the company record is therefore about you personally, you may ask us to remove or suppress the whole record on the same no-justification basis.
If you make a verified access request under Article 15 GDPR, we will confirm whether we process personal data about you and provide the information Article 15 requires, including any available information about the specific source of your record. Where your record was disclosed to customers before your erasure or objection request, we communicate the removal to those customers as required by Article 19 GDPR, unless this proves impossible or involves disproportionate effort, and we will tell you which recipients received your data if you ask us at [email protected].
We respond to verified requests without undue delay and at the latest within one month, as required by Article 12(3) GDPR — typically within 2 business days. In exceptional cases the period may be extended by up to two further months under Article 12(3) GDPR, in which case we will tell you and explain why.
12. Right to lodge a complaint
If you consider that our processing infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Lithuanian State Data Protection Inspectorate:
Valstybinė duomenų apsaugos inspekcija (VDAI)
L. Sapiegos str. 17, LT-10312 Vilnius, Lithuania
[email protected] · +370 5 271 2804
You may also complain to the supervisory authority in your country of habitual residence, your place of work, or the place of the alleged infringement.
13. Jurisdiction-specific notices
The substance of this Policy applies across all the markets in which we operate. The following notices address points that arise under particular national laws. They are included for completeness and to support our customers’ own compliance, including where a customer reaches a contact in one of these countries from a record held under another country.
France
Our processing rests on the legitimate-interests basis in Article 6(1)(f) GDPR, applied consistently with CNIL guidance on the large-scale collection of publicly available data. Direct marketing by our customers to individuals in France must comply with Article L.34-5 of the Code des postes et des communications électroniques.
Germany and Austria
Firmavis does not itself initiate commercial communications to data subjects. Customers contacting recipients in Germany or Austria must comply with §7 UWG (Germany) and §174 TKG (Austria). The presence of a contact in our database is not consent to receive electronic marketing.
Italy
Our Legitimate Interest Assessment is documented and dated before processing begins, consistent with the expectations of the Italian supervisory authority. We do not operate a generic telephone directory within the meaning of the Garante’s Order No. 201 of 17 May 2023. Customers marketing to recipients in Italy must comply with Article 130 of the Italian Personal Data Protection Code, which requires prior consent for email and most telephone marketing; the Garante has fined companies that used purchased B2B contact data in reliance on a vendor’s assurances instead of verifying their own legal basis — see §§7-8 of our Terms of Service.
Spain
Customer use of the data for direct marketing in Spain must comply with the LSSI-CE (Ley 34/2002), the General Telecommunications Law, and AEPD guidance.
Poland
In scoping our reliance on Article 14(5)(b), we have taken into account the leading Polish supervisory-authority decision on the transparency obligations of business-data aggregators, as upheld by the Polish Supreme Administrative Court in September 2023, which confirmed that the exemption must be interpreted narrowly — which is why we notify individually wherever we hold a direct channel.
Lithuania
Information about company officers and directors published by the official Lithuanian corporate register is lawfully public; our re-use of it rests on Article 6(1)(f) GDPR. Under Article 81 of the Lithuanian Law on Electronic Communications, as amended in April 2026, direct marketing to contact details assigned to a legal-person subscriber — including a named employee work contact — is permitted on an opt-out basis; customers must still identify themselves, provide a clear, free and easy opt-out in every message, and honour objections promptly, and contacts of natural-person subscribers still require consent.
Other operating jurisdictions
In Estonia, Latvia, Finland, Sweden, Denmark, Norway, the Netherlands, Belgium, the Czech Republic and Ukraine, the substance of this Policy applies, and the self-service removal portal is reachable from every page.
14. Cookies
We use a small number of cookies and similar technologies. How they work, and how to change your choices, is described in our Cookie Policy.
15. Security
We protect personal data with technical and organisational measures appropriate to the risk: industry-standard encryption in transit (TLS 1.2 or higher), hardened role-based access controls with least-privilege defaults, and logging of security-relevant actions. Our primary application and database infrastructure runs in EU data centres (Finland); some supporting services (authentication, email delivery, analytics, error monitoring, payments) involve the transfers described in §9. We review our security measures regularly.
16. Changes to this Policy
We may update this Policy from time to time. The current version is always published at this URL, and the “Last updated” date at the top of the page reflects the most recent revision. Material changes take effect no earlier than 30 days after being posted here; where appropriate we also notify registered users in-product or by email.
17. Contact
For any question about this Policy, or to exercise your rights, contact our Privacy Lead at [email protected], or use the Data Removal portal. The controller is:
MB Firmavis
Lithuanian company code: 307941710
Registered in the Register of Legal Entities of the Republic of Lithuania (administrator: State Enterprise Centre of Registers)
Registered office: Laisvės al. 85E-5, LT-44297 Kaunas, Lithuania
VAT number: LT100020426112
Privacy matters: [email protected]
General contact: [email protected]
This document is published in English. Translations into other supported languages may be published at a corresponding translated URL under /legal. In the event of any discrepancy between the English version and any translation, the English version prevails to the extent permitted by applicable law.