Privacy Notice
This notice explains how Vellinx Ltd handles personal information, and which part applies to you.
In short, Vellinx helps business-to-business sellers prepare to approach an organisation they have a genuine reason to contact. It researches the organisation and the roles in it rather than individuals: what the organisation is dealing with now, which role is the right one to approach, and how the seller's offer fits. It describes people by their role, not their name, and it never asks for, keeps or supplies the contact details of the people at the organisations it researches.
Which part applies to you:
- If you work at an organisation that has been researched with Vellinx, read "People at the organisations we research".
- If you use Vellinx, read "People who use Vellinx".
- If we have contacted you about Vellinx itself, read "People we contact about Vellinx".
- If you have visited this website, read "Visitors to this website".
- If you have contacted us or made a complaint, read "People who contact us or make a complaint".
Whichever applies, you have rights over your information, including the right to object, and you can reach us at privacy@vellinx.com. Both are set out below.
Who we are and how to contact us
Vellinx Ltd is the controller of the personal information described in this notice, except where "People who use Vellinx" says that we handle it on behalf of the organisation that provides Vellinx to its users. We are registered in England and Wales, company number 17186897, with our registered office at 97 Gatliff Close, Ebury Bridge Road, London, United Kingdom, SW1W 8QH. We are registered with the Information Commissioner's Office (the ICO), the UK's data protection regulator, under registration reference ZC238683.
For anything to do with your personal information, including exercising your rights or making a complaint, contact us at privacy@vellinx.com.
We have not appointed a data protection officer. We are not required to, given our size and the kind of processing we do, and we have recorded that as a considered decision rather than an oversight; we will appoint one if that position changes.
This notice is version 4 and was last updated on 1 October 2026. It replaces version 3 of 28 September 2026, to give our registration with the Information Commissioner's Office. Version 3 had replaced version 2 of 28 September 2026, to say which information we handle on behalf of the organisation that provides Vellinx to its users, and to give our registered office in full. Version 2 had replaced version 1 of 15 June 2026, to reflect that Vellinx researches roles rather than named people, to add a section for the people who use Vellinx, and to set out how long we keep each kind of information.
People at the organisations we research
What we do. A Vellinx user, usually a seller at a business-to-business company, chooses an organisation they have a genuine business reason to approach. Vellinx researches that organisation from public sources and writes the user a short briefing: what the organisation is dealing with, which role is the right one to approach, and how the user's offer fits. The briefing is the user's starting point for their own judgement, not settled findings: each claim is tied to the page it came from and carries a marker of how current and how confident it is. The user's organisation decides which organisations are researched and what it does with a briefing; we decide how the research is done, and we are responsible to you for the research and for your rights over what we hold.
Roles, not people. We describe an organisation's people by their role, such as "the chief commercial officer", not by name. Our research is instructed to name the role and never the person, so our briefings, suggested approaches and draft messages are written about roles. Draft messages begin "Hi [Name]," so that the user adds a name, if at all, outside Vellinx when they send. We never ask for, keep or supply the contact details of the people at the organisations we research: if a page we read carries an email address or a telephone number, it is removed before we keep the page.
Why this can still be about you. A role at a named organisation is usually held by one person. If you hold a role we write about, what we say about that role, such as the priorities it is likely to have, relates to you, and we treat it as your personal information. The public pages we read can also name people: a leadership page listing the executive team, a news article quoting a director, or the organisation's filings at Companies House, which list its officers. We keep a copy of each page we read, with its address and the date we read it, so that every claim in a briefing can be checked against the page it came from. That copy may include your name, your role and what the page says about you professionally.
What we do not do. We do not build a profile of you as a person, and we do not look at your personal social media or your private life. We do not seek or record anything about anyone's health, genetic or biometric data, religion or beliefs, political opinions, trade union membership, racial or ethnic origin, sex life or sexual orientation, or criminal convictions or offences. Our research is instructed not to, and we screen every briefing and withhold any line the screen flags.
Where it comes from. We do not collect this information from you. It comes from publicly available professional sources, read at the time a user runs the research: the organisation's own website, news and trade press, and public registers such as Companies House. Our AI provider's search and page-reading tools find and read the pages, and we read company filings from the Companies House public data service directly. Because it does not come from you, you may not know about the research until you receive a better-informed approach, which is part of why this notice exists.
Why we are allowed to do this. Our lawful basis is legitimate interests: ours and our users', in enabling a business with a genuine reason to approach an organisation to do so relevantly, and in being able to show where every claim came from. This is ordinary business-to-business practice that a professional in your position would reasonably expect. We have weighed it against your interests and rights, and built in the limits described here to keep it fair. You have the right to object, set out below, and we honour an objection.
Profiling and automated decisions. Working out what a role at an organisation is likely to care about can amount to profiling of the person who holds it. Ours is limited to that role at that organisation. It involves no automated decision about you with a legal or similarly significant effect: the briefing goes to a person, and a person decides whether and how to approach. We use this information only to produce the research and to check and improve its quality, for example by reviewing whether a briefing's claims matched the pages they came from.
People who use Vellinx
What we hold. When you use Vellinx we hold: the details you give us to set up and use your access, such as your name, your work email address and your employer; your seller profile, which describes your company, what you sell, who you sell to and the name and job title you sign messages with; what you tell us about an account, such as the right role to approach, a claim to strike or a note; and the research you ask for, with what it produced, when, and what it cost to run.
Where it lives. Your seller profile is kept in your browser on your device and sent to us each time you run research, so that the research is written for what you sell. Your research is also kept in your browser so that you can reopen it, and you can clear it there at any time. What you tell us about an account is kept against your workspace and is never used in anyone else's research.
Who is responsible for it. Vellinx is provided to an organisation, usually your employer, under our terms of use. That organisation is the controller of your seller profile and of what you tell us about its accounts: we handle them on its behalf and on its instructions, and its own privacy notice applies to them. We are the controller of your access details, the records of the research you run, and our reviews of that research.
Why we are allowed to do this. For what we are the controller of, where you use Vellinx under an agreement with you, our basis is that contract; where you use it through your employer's agreement with us, our basis is our legitimate interests in providing, securing and improving the service your employer asked for. You do not have to give us your seller profile, but Vellinx cannot write research for you without it.
What you tell us about other people. When you tell us about an account, give us roles, not names, and nothing about anyone's private life or any of the kinds of information listed under "What we do not do" above. The research needs roles, and nothing more.
Improving Vellinx. We review research runs to improve the quality, accuracy and cost of what Vellinx produces. We do not use your information to train AI models.
People we contact about Vellinx
If you are a business contact at an organisation that might use Vellinx, we may contact you about the product. This is separate from the research described above.
What we use, and where it comes from. We use business-context contact information: your name, role and employer, and a business contact route such as a work email address. This comes from our own research and from what we already know about the organisation, not from you directly.
Why we are allowed to do this. For contacting named people at companies and limited liability partnerships by business email, our basis is legitimate interests: ordinary business-to-business marketing that a professional would expect, weighed against your interests. For some channels and recipients the rules are different and we rely on your consent instead, for example messages on social platforms, and email to sole traders, unincorporated partnerships, or personal email addresses. Where we make marketing calls, we screen them against the Telephone Preference Service and its corporate equivalent first.
How to stop hearing from us. Every message we send carries a way to opt out, and we honour it. You can object to this marketing at any time, and where we rely on your consent you can withdraw it at any time; in each case we stop. Your rights are set out in full below.
Visitors to this website
This website carries no analytics, no tracking, and no cookies that we set. The only personal information created when you visit is the technical connection data our hosting provider logs to run and secure the site, such as your IP address and basic details of the request your browser makes.
Our basis for this is legitimate interests, in operating and keeping the site secure. You have rights over this information, including a right to object, set out below.
People who contact us or make a complaint
When you contact us, including to exercise a right or to make a complaint about how we handle personal information, we use what you give us to deal with your request and to keep a record of it.
What we hold. Your name and the contact route you use, what you tell us or the substance of your complaint, and any personal information the request or complaint concerns.
Why we are allowed to do this. For handling a complaint, or a request to exercise your rights, our basis is our legal obligation to deal with them. For other enquiries, our basis is our legitimate interest in responding to you.
Who we share information with, and transfers outside the UK
We do not sell personal information, and we do not share it except as set out here.
Who receives it. A briefing is made available to the user who asked for it, which is the point of the research, and our terms of use allow it to be shared only within that user's organisation, with the people who need it to prepare the approach. Beyond that, the only others who handle personal information on our behalf are our service providers, acting on our instructions and under contract: the provider of the AI service that carries out the analysis, the search and the reading of pages, and providers of IT infrastructure such as hosting and email. We do not give any of them the freedom to use the information for their own purposes. Companies House receives no personal information from us: we ask it about a company by the company's name or registration number.
Transfers outside the UK. Some of these providers are based in the United States, so some personal information is transferred there. Where it is, we put appropriate safeguards in place for the transfer, such as the UK International Data Transfer Addendum, and you can ask us for details at privacy@vellinx.com.
How long we keep information
We keep personal information only for as long as we need it for the purpose we collected it for, and then we delete it.
- Research. Everything a research run produces, including the briefing, the suggested approach, the checks of each claim and the copies of the pages read, is deleted six months after the run. A later run on the same organisation starts its own six months; it does not extend an earlier one. After that we keep only figures about a run that name no one, such as how long it took and what it cost. Copies kept in a user's own browser so that they can reopen their research are cleared once they are six months old, the next time Vellinx is opened in that browser. The one exception is a small number of past briefings kept as fixed material for testing Vellinx, which describe roles and name no one.
- What a user tells us about an account. Kept while the user tracks that account, and deleted when they stop tracking it, or within 30 days of their access ending.
- A user's access details and profile. Kept while their access is active, and deleted within 30 days of it ending, apart from anything we must keep for our accounts or to show how we handled a request. A seller profile kept in a user's own browser stays under their control and can be cleared there at any time.
- Complaints and other contact. For as long as we need to handle the matter and to show that we handled it, then reviewed for deletion.
- Website logs. For as long as our hosting provider retains them to run and secure the site.
- Safety copies. When we change our systems we may take a short-lived copy of our database first. It is deleted within seven days, and it is never used to bring back anything we have deleted.
If you object to our research, we keep a minimal record of that objection, your name, your organisation, your role and the date, for as long as we carry out the research, so that we can go on honouring it.
Your rights
You have rights over the personal information we hold about you, and you can exercise any of them by contacting us at privacy@vellinx.com. We may need to confirm your identity first, and we will respond within the time the law allows, normally one month.
If your request is about information we handle on behalf of the organisation that provides Vellinx to you, we will pass it to that organisation and help it respond.
Your rights are:
- Access: to be told whether we hold information about you and to receive a copy.
- Rectification: to have inaccurate information corrected, and incomplete information completed.
- Erasure: to have your information deleted, where the law requires us to.
- Restriction: to ask us to limit how we use your information while a question about it is resolved.
- Objection: dealt with separately below, because it works differently depending on the processing.
- Portability: to receive certain information in a reusable format. This applies where we process on the basis of your consent or a contract with you, which in our case means information you have given us as a user of Vellinx under your own agreement with us.
Your right to object. For the research we carry out and for our own marketing, we treat an objection as final: if you object, we stop. For research, that means we delete what we hold that names you, remove your name from the copies of pages we keep, stop writing about your role at your organisation, tell any organisation that received our research about your role to stop using it and delete its copies, and add you to an exclusion list so that your name is removed from any page we keep in future. Because this works by matching your name, we check the matches by hand, and we may ask for your organisation to be sure we have the right person. For the website logs, you can also object, and we will stop unless we have compelling grounds to continue that override your interests.
Withdrawing consent. Where we rely on your consent, for example for certain marketing channels, you can withdraw it at any time, and we stop. Withdrawing consent does not affect anything we did lawfully before you withdrew it.
If you are unhappy with how we have handled your information or your request, you can complain, as set out below.
How to complain
If you have a concern about how we handle your personal information, please raise it with us first. Email privacy@vellinx.com with "Data protection complaint" in the subject line, and we will acknowledge your complaint within 30 days, keep you informed, and tell you the outcome without undue delay.
You also have the right to complain to the ICO, the UK's data protection regulator, at ico.org.uk. We would appreciate the chance to address your concern first, but you can approach the ICO at any time.
Changes to this notice
We may update this notice from time to time, for example if we change how we handle personal information. When we do, we update the version number and the date on the notice. If a change materially affects you or your rights, we will take reasonable steps to make it prominent, rather than relying on the updated notice alone.
Version 4 · Last updated 1 October 2026.