Build Your Plan
Data Protection

Privacy Policy.

Last updated: 19 August 2026

Penbridge Marketing ("Penbridge", "we", "us" or "our") provides personalised B2B email outreach campaigns designed to connect UK contractors with relevant local council decision-makers. Clients may also choose to add contacts from their own existing database as an additional campaign audience.

This policy explains how we collect, use, disclose, retain and protect personal information in connection with our website, enquiries, client onboarding, campaign services and business operations.

Depending on the circumstances and the applicable law, Penbridge may act as a data controller or processor under UK data protection law and as a responsible party or operator under South African data protection law. The precise role depends on the nature and purpose of the processing involved.

In the United Kingdom, our processing is governed primarily by the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 ("PECR"). In South Africa, where POPIA applies, we process personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and applicable regulations and guidance.

Penbridge is registered with the UK Information Commissioner's Office ("ICO"). Our ICO registration number is ZC168583.

01

Who we are

For UK data protection purposes, the organisation responsible for this website and the relevant processing is:

  • Penbridge Marketing, Office 168558, PO Box 7169, Poole, BH15 9EL, United Kingdom
  • Email: Admin@penbridgemarketing.co.uk
  • Telephone: +44 (0) 20 3996 1447
  • ICO registration number: ZC168583

Where we process contact data supplied by a client solely to deliver that client's campaign and in accordance with the client's documented instructions, our role may be that of a processor under UK GDPR and an operator under POPIA. Where we determine our own purposes and means of processing, including in relation to our own outreach database, Penbridge may act as the relevant controller or responsible party.

02

Data we collect

The information we collect depends on how you interact with Penbridge.

Website enquiries

When you submit a general enquiry through our website, we may collect your name, company name, email address, telephone number and the content of your message.

Bespoke campaign enquiries

When you use our Build Your Plan calculator, we may collect information required to prepare your campaign estimate, including your name, company, contact details, postcode or postcode area, campaign radius, estimated council contact coverage, the number of your own contacts you wish to include, sequence preferences and selected campaign commitment.

Client onboarding and service delivery

If you become a client, we may collect additional business and account information needed to provide the service, manage your campaign, communicate with you, process payments, administer your account and comply with our legal and accounting obligations.

Client-supplied contact data

If you choose to add your own existing contacts to a campaign, we may process the personal data you provide in accordance with the agreed campaign instructions and applicable data protection requirements.

Strategy calls and correspondence

If you contact us by email, telephone or through a scheduling service, we may retain the relevant contact details, booking information and correspondence needed to manage the enquiry or relationship.

03

Council & business contacts used in outreach

Penbridge maintains business-related contact information relating to individuals acting in professional capacities, including relevant local authority and business contacts. This may include names, work email addresses, job titles, organisations and other information relevant to professional outreach.

Where personal data is obtained from publicly accessible sources rather than directly from the individual, we take reasonable steps to ensure the processing is lawful, proportionate and transparent, and that the information is reasonably accurate and relevant to the purpose for which it is used.

  • Source. Information may be obtained from public authority websites, published staff directories, public registers, company websites and other publicly available professional sources.
  • Purpose. We use relevant professional contact information to facilitate targeted B2B outreach relating to services that may reasonably be relevant to the recipient's organisation or professional role.
  • UK lawful basis. Where appropriate, we may rely on legitimate interests under UK GDPR, following an assessment of purpose, necessity and the individual's interests, rights and freedoms.
  • Transparency and objection.Individuals may object to direct marketing at any time. Where an objection or unsubscribe request is received, the relevant contact is suppressed from future campaigns.
If you are a contact we've emailed

You may request access to, correction or deletion of your personal data, or object to its use for direct marketing. You can use the unsubscribe mechanism included in the communication or contact Admin@penbridgemarketing.co.uk.

04

Client-supplied contact data

Clients may optionally provide their own existing contact database for inclusion in a Penbridge campaign.

Where Penbridge processes this information only on the client's documented instructions and does not determine the purposes of that processing, the client remains responsible for establishing an appropriate lawful basis for the processing and for providing any required privacy information to the relevant data subjects.

Penbridge will process client-supplied contact information only as necessary to perform the agreed services, subject to the relevant agreement, data processing terms and applicable law.

Clients must not provide us with special category data or other sensitive information unless its processing is expressly agreed, legally justified and necessary for the service.

05

How we use personal data and lawful bases

Processing activityPotential lawful basis
Responding to website enquiriesLegitimate interests or steps taken at the individual's request prior to entering into a contract, depending on the circumstances.
Preparing bespoke campaign estimatesLegitimate interests and/or steps taken at the individual's request before entering into a contract.
Delivering contracted servicesPerformance of a contract and, where applicable, legitimate interests.
Billing, accounting and legal recordsLegal obligation and, where appropriate, performance of a contract.
UK B2B direct marketingLegitimate interests may apply where lawful under UK GDPR and PECR and supported by an appropriate assessment.
Processing client-supplied contact listsProcessing determined by the client, subject to the relevant contract and data processing terms.
Non-essential website analyticsConsent where required.

We do not sell personal information to third parties for their independent marketing purposes.

06

Direct marketing, UK GDPR, PECR & POPIA

United Kingdom

UK direct marketing is subject to both data protection law and PECR. The rules depend on the type of recipient and communication method. In particular, PECR distinguishes between corporate subscribers and individual subscribers such as sole traders and certain partnerships.

Where personal data is processed for direct marketing, UK GDPR applies even where the communication is made in a business context. Legitimate interests may be an appropriate UK GDPR lawful basis in some circumstances, but it is not a blanket exemption: Penbridge considers the purpose, necessity and balancing elements applicable to the processing and complies with PECR and other applicable marketing requirements.

Our UK outreach is intended to be relevant to the recipient's professional role and organisation, uses work-related contact details where appropriate, identifies the sender, and provides a clear means of objecting to further marketing.

South Africa

Where POPIA applies, direct marketing by unsolicited electronic communication, including email, is subject to section 69 of POPIA. Penbridge does not treat legitimate interests as a general substitute for the consent requirement applicable to unsolicited electronic direct marketing under POPIA. Where consent is required, we will obtain it before sending further electronic marketing, subject to any lawful statutory exception that applies.

Where we process South African personal information on behalf of a client, the parties' respective responsibilities will be documented in the relevant agreement and data-processing terms. We expect clients supplying contact data to have an appropriate lawful basis and to meet their own transparency and consent obligations.

Your right to stop marketing

You may object to direct marketing or withdraw consent at any time where applicable. We will maintain suppression information so that an unsubscribe or objection is respected in future campaigns.

07

Who we share data with

We use selected service providers to operate our website, manage enquiries, deliver campaigns, maintain business systems and support our operations. Where a provider processes personal information on our behalf, we take appropriate contractual and security measures as required by applicable law.

  • Formspree — processes website form submissions.
  • Calendly — may process appointment and scheduling information where used.
  • Framer — hosts the Penbridge website and may process technical information required to provide the service.
  • Operational and technology providers — where necessary to provide the campaign, email, hosting, analytics and related services.
  • Professional advisers — including accountants, lawyers and other advisers where reasonably necessary.
  • Regulators and authorities — where disclosure is required or permitted by applicable law.

We do not sell or rent personal information to third parties for their own independent marketing purposes.

08

International data transfers

Penbridge and its service providers may process personal information in countries outside the United Kingdom or South Africa, including the United States.

Where UK data protection law applies and a transfer is a restricted transfer, we will use an applicable UK adequacy regulation, appropriate safeguards such as approved contractual mechanisms, or another lawful transfer mechanism recognised under UK law.

Where POPIA applies, transfers of personal information outside South Africa will be undertaken in accordance with the requirements applicable to cross-border transfers under POPIA, including section 72 where applicable.

The precise safeguards used may differ depending on the provider, destination, type of data and legal framework applicable to the transfer.

09

How long we keep data

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, to maintain suppression and compliance records, to administer contractual relationships, and to meet applicable legal, accounting and dispute-resolution requirements.

  • Website enquiries: retained for as long as reasonably necessary to respond, manage the relationship and maintain an appropriate business record.
  • Client and financial records:retained for the periods required by applicable tax, accounting and other legal obligations.
  • Outreach contact data: reviewed periodically and removed, corrected or suppressed where it is no longer appropriate or where an objection or unsubscribe request has been received.
  • Suppression records: may need to be retained to ensure that we do not inadvertently contact a person who has previously opted out.
10

How we protect your data

We implement appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, destruction, alteration or disclosure.

Depending on the system and nature of the data, these measures may include access controls, authentication, appropriate platform security, restricted access to personal information, operational procedures and segregation of campaign-related systems from ordinary business communications.

No electronic transmission or storage system can be guaranteed to be completely secure. We therefore continually review our safeguards and respond appropriately to actual or suspected security incidents.

11

Cookies & website analytics

Our website may use cookies or similar technologies that are necessary for the website to function. We may also use non-essential analytics or similar technologies to understand website performance and visitor behaviour.

Where consent is required for non-essential cookies or similar technologies, we will request that consent before placing or using them. Third party embedded services, such as scheduling services, may also use their own cookies or similar technologies subject to their own notices.

12

Your rights

Depending on the applicable law and circumstances, you may have rights including:

  • Access to personal information we hold about you
  • Correction of inaccurate or incomplete information
  • Deletion or destruction of personal information where the applicable legal requirements are met
  • Restriction of certain processing
  • Objection to certain processing, including direct marketing
  • Withdrawal of consent where processing is based on consent
  • Data portability where the applicable legal requirements are met
  • Complaint rights to the relevant supervisory or regulatory authority

If you wish to exercise a right, contact us using the details in Section 16. We may need to verify your identity before acting on a request.

Where UK GDPR applies, we generally respond to valid data subject requests within one month, subject to the applicable statutory extensions and exceptions. Other applicable laws may provide different requirements.

13

Children's data

Our services are intended for businesses, professionals and organisations. We do not knowingly seek or intentionally collect personal information from children through our website or services.

14

Changes to this policy

We may update this policy when our services, processing activities, technology or legal obligations change. The "Last updated" date at the top of the policy identifies the latest revision.

Where legally required, we will take appropriate steps to notify affected individuals of material changes.

15

Complaints

If you have a concern about how Penbridge processes your personal information, please contact us first so that we can investigate and attempt to resolve the matter.

If UK data protection law applies, you may complain to the Information Commissioner's Office (ICO).

  • Website: ico.org.uk
  • Telephone: 0303 123 1113

If POPIA applies, you may also have the right to lodge a complaint with the Information Regulator of South Africa.

Information about POPIA complaints and the prescribed complaint process is available from the Information Regulator of South Africa.

16

Contact us

If you have questions about this policy, wish to exercise a data protection right, wish to withdraw consent where applicable, or wish to object to direct marketing, contact us:

📍
UK Correspondence Address
Penbridge Marketing
Office 168558, PO Box 7169
Poole, BH15 9EL
United Kingdom
🛡️
ICO Registration
Reg No: ZC168583
Penbridge Marketing logo

Connecting UK contractors directly with the councils that need their services.

Helping you reach local council
contacts who commission the work that matters.

UK Office Contact
  • 📞
    Telephone+44 (0) 20 3996 1447
  • 💬
  • 📍
    UK Correspondence AddressPenbridge Marketing
    Office 168558, PO Box 7169
    Poole, BH15 9EL
Data Protection
🛡️
ICO RegisteredPenbridge Marketing operates in strict compliance with UK data laws. Registered with the Information Commissioner's Office (ICO) | Reg No: ZC168583
🔒
Data SecurityAll correspondence data is handled securely and never shared with third parties without consent.