Privacy
Privacy notice
Who we are
Pipepoint is a prospect research service operated by Max Traynor, a sole trader based in Glasgow, United Kingdom. We are the data controller for the personal data described in this notice.
- Contact
- max@pipepoint.io
- Opt out of all contact
- optout@pipepoint.io
What this notice covers
We use personal data for two separate purposes. They involve different people, different data, and different rules, so this notice deals with them separately throughout. Find the one that applies to you.
| Purpose A — Prospect research | Purpose B — Our own marketing | |
|---|---|---|
| Who it is about | People at UK FCA-regulated firms | People at RegTech and compliance software companies |
| What we do | Compile research and disclose it to our clients | Contact you to offer our services |
| Do we contact you? | No. We do not contact or market to you | Yes. This is direct marketing |
This notice also covers data you give us when you contact us or visit this website. It does not cover data held by our clients about their own customers, or what a client does with research after we pass it to them.
Purpose A — Prospect research
This applies to you if you work at a UK FCA-regulated firm. We also monitor EU and EEA regulated firms, but we hold no personal data about anyone at them — see “EU and EEA firms” below.
What we do, and what we do not do
We compile regulatory event data about UK, EU and EEA regulated firms, rank those firms by how relevant they are to a client’s product, and disclose the result to that client. For UK firms this includes business contact details. For EU and EEA firms it does not — those records are company-level only.
We do not contact you and we do not market to you. We do not send you email, call you, or add you to any mailing list of ours. We do not send messages on behalf of our clients, and we do not operate the systems they use to send. If you are contacted about a compliance product, that message came from the client, not from us.
What personal data we process
- Name
- Job title
- Work email address
- Employer name
We also process information about companies — regulatory status, authorisation dates, permissions, company numbers, registered addresses. Most of this is not personal data, but it is linked to the contact records above.
Where we get it
| Source | What we take |
|---|---|
| FCA Financial Services Register | Firm name, reference number, authorisation status and date, permissions, business type |
| Companies House | Company number, incorporation date, registered address, SIC codes, officer appointments |
| Publicly available business sources | Name, job title, work email address (UK firms only) |
| European Banking Authority PSD2 central register (EU / EEA) | Firm name, national reference code, authorisation date, country, town, competent authority and payment service codes. No personal data. |
The EBA register aggregates the national registers of the EU and EEA competent authorities. Reproduced with acknowledgement. The register has no legal significance; responsibility for the accuracy of the underlying information lies with the national competent authorities.
We do not collect any of this from you. We do not buy data from list brokers, and we do not collect data by scraping websites or platforms in breach of their terms of use.
EU and EEA firms — company-level only
Our EU and EEA coverage comes from one source, the EBA register, and we take only institution records from it. Those records describe the firm: its name, its national reference code, the date it was authorised, its country and town, which authority authorised it, and which payment services it is permitted to provide.
We do not hold the name, job title or email address of any individual at an EU or EEA firm. We do not look those up, and we do not enrich EU records from any other source. The register also lists agents, which can be individuals rather than companies — we exclude agent records entirely and never ingest them.
This is why the obligations that would otherwise arise under the EU GDPR do not: they attach to the processing of personal data about people in the EU and EEA, and we process none. Nothing in our EU and EEA data identifies a person, so there is no EU data subject whose rights are engaged, and no requirement for us to appoint a representative in the Union.
If that ever changes — if we begin collecting named contacts at EU or EEA firms — this notice will be updated before that collection starts, not after.
Our lawful basis
Lawful basis: legitimate interests (Article 6(1)(f) UK GDPR).
Our legitimate interest, and our clients’ legitimate interest, is in identifying firms with a relevant business need so that an offer can be directed at firms it is actually useful to, rather than at everyone. We have assessed this against your interests and rights and concluded that the processing is proportionate because:
- The data concerns your professional role, not your private life
- No sensitive personal data is involved
- The subject matter is directly relevant to your stated responsibilities
- The data comes from sources you would reasonably expect to be public
- We do not contact you, so the processing itself causes no intrusion
- You can object at any time, and we will remove you
You can ask us for a copy of our Legitimate Interests Assessment.
Who we disclose it to
We disclose the research to the client it was compiled for. That client decides what happens next — who they contact, how, and how often.
The client becomes a separate and independent controller of that data on receipt. We are not their processor and they are not ours; this is a controller-to-controller disclosure, not a joint controller arrangement. As an independent controller, the client is responsible for having its own lawful basis, issuing its own privacy information to anyone it contacts, and handling requests made to it. This matches clause 8 of our terms.
Article 14 — where the data did not come from you
Because we collect this data from public registers and public business sources rather than from you, Article 14 of the UK GDPR applies. It requires us to give you certain information within a reasonable period, and at the latest within one month of obtaining the data.
We do not contact you for this purpose. Writing to every individual in the research purely to deliver a privacy notice would mean initiating contact we otherwise do not make, at a volume out of proportion to processing that is limited to business contact details and published regulatory facts. We therefore rely on the exemption in Article 14(5)(b), on the ground that individual notification would involve disproportionate effort.
In place of individual notification we:
- publish this notice openly at pipepoint.io/privacy and keep it current
- require every client, by contract, to issue its own privacy information to anyone it contacts
- tell you on request what data we hold about you, where it came from, and which clients we disclosed it to
- remove you from current and future research on request, with no questions asked
Purpose B — Our own marketing
This applies to you if you work at a RegTech or compliance software company — that is, a business that might buy our service.
What we do
We contact you by email to offer our services. This is direct marketing, and we treat it as such.
What personal data we process, and where we get it
- Name
- Job title
- Work email address
- Employer name
We collect this from publicly available business sources — company websites, professional profiles and public business directories. We do not buy data from list brokers.
Our lawful basis
Lawful basis: legitimate interests (Article 6(1)(f) UK GDPR), in marketing our own service to businesses likely to need it.
We also comply with the Privacy and Electronic Communications Regulations 2003 (PECR). We send marketing email only to corporate subscribers — limited companies, LLPs and public bodies. We do not send unsolicited marketing email to sole traders or ordinary partnerships without consent. Every message identifies us and offers a way to stop.
How to stop it
Email optout@pipepoint.io, or reply to any message with “unsubscribe”. We stop immediately and permanently, no questions asked. You do not need to give a reason, and the right to object to direct marketing is absolute.
Data we never process
This applies to both purposes. We do not process special category data. We do not process information about health, race, religion, political opinions, sexual orientation, trade union membership, biometrics, or genetics. We do not process data about criminal convictions or offences. We do not process personal data about anyone under 18.
How long we keep it
| Data | Retention |
|---|---|
| Purpose A — research contact data | Deleted when no longer needed, and in any event within 12 months of collection. A regulatory event stops being a live signal long before then |
| Purpose A — company-level information | Retained while it remains useful for our service. Most of this is not personal data |
| Purpose B — marketing contact data | Deleted when no longer needed, and in any event within 24 months of collection, unless we have an ongoing business relationship with you |
| Opt-out and objection records | Retained indefinitely, for both purposes. We need them to make sure we do not contact you or re-add you to research |
Once we have disclosed research to a client, that client sets its own retention period for its copy. Ours ending does not end theirs.
Who we share it with
We do not sell personal data.
| Recipient | Which purpose | Basis |
|---|---|---|
| Our clients | A only | Independent controller on receipt. This disclosure is the service |
| Google (email and file storage) | A and B | Processor, under contract, acting on our instructions |
| Instantly (email sending) | B only | Processor, under contract. Purpose A data is never loaded into a sending tool, because we do not send for Purpose A |
International transfers
Some of our processors may process data outside the UK. Where they do, transfers are covered by adequacy regulations or by standard contractual clauses. This applies equally to both purposes.
For Purpose A there is one further difference: once we disclose research to a client, any transfer that client makes is theirs, under their own arrangements. We do not control it, and this notice does not cover it.
Your rights
Under UK GDPR you have the right to:
- Object to processing based on legitimate interests. For Purpose B this includes direct marketing, where your right to object is absolute and we stop immediately. For Purpose A we will remove you from current and future research
- Access the personal data we hold about you. For Purpose A this includes telling you where we got it and which clients we disclosed it to
- Correct data that is wrong or incomplete
- Erase your data
- Restrict how we use it
- Portability — receive your data in a machine-readable format
Where these rights differ between the two purposes: for Purpose A, we can act only on our own copy. If we have already disclosed research to a client, that client holds its copy as an independent controller, and you would need to exercise your rights against them as well. We will tell you who they are so you can. For Purpose B everything is held by us, so there is only one place to ask.
To exercise any of these, email max@pipepoint.io. To stop marketing, or to be removed from research, email optout@pipepoint.io — that address works for both purposes.
We respond within one month.
Complaints
If you are unhappy with how we have handled your data, please contact us first at max@pipepoint.io so we can try to put it right.
You also have the right to complain to the Information Commissioner’s Office:
Information Commissioner’s OfficeWycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk
This website
This website does not use cookies, analytics, tracking pixels, or third-party scripts. Fonts are served from our own domain, so no data is sent to third parties when you browse.
Our hosting provider, Cloudflare, processes standard server log data including IP addresses for security and reliability purposes.
Changes
We may update this notice. The date at the top shows when it was last changed. Material changes will be reflected here before they take effect.