How we handle your data
Most people arrive here from a line in an email we sent. This page answers that in order: where the address came from, why we were allowed to write, and how to make it stop.
Last updated 12 August 2026
Reply “no” to any message we sent you, or write to hello@spicegtm.com. We stop within the hour and add you to a permanent suppression list, which is the one record we keep so that no campaign of ours reaches you again. No reason needed, and nothing is asked in return.
Who we are
Spice GTM builds outbound systems inside our clients’ companies. For the contact data we hold in our own prospecting, we are the data controller. Written contact: hello@spicegtm.com. A postal address is available on request.
When we run outbound for a client, their contact signs the message while the list, the tooling and the sending domains stay ours. We remain the controller for that contact data and this page covers those campaigns too, so one removal request here takes you out of every campaign we run, whoever signed the email. Where a client sends from their own systems instead, they are the controller and their own privacy page applies.
What we hold
Business contact data about people in their professional role, and nothing about their private life.
- Name, job title, employer, and country or city of work.
- A business email address and a public professional profile URL.
- Public company facts we use to decide whether writing makes sense: funding, hiring, product launches, reported revenue band, technology in use.
- The messages exchanged with us, and the fact that a message was opened or answered.
We do not collect personal addresses, private phone numbers, financial data, or any special category data under GDPR Art. 9.
Where it comes from
GDPR Art. 14(2)(f) requires the source to be named, so here it is in full.
Why we are allowed to hold it
Our legal basis for prospecting is legitimate interest, GDPR Art. 6(1)(f), which Recital 47 confirms can cover direct marketing. The interest is straightforward: reaching people whose job is the one our service exists for. We keep a written assessment weighing that interest against the recipient’s rights, and it rests on three facts we can show for any message we send.
- The address is a business address at the employer whose work the message concerns.
- The message relates to the recipient’s stated professional responsibilities.
- Every message names its source and carries a way out that we honour permanently.
Where consent is the required basis instead, we ask for it or do not send. We do not run email prospecting into Germany or Austria, whose national rules require prior consent for business email, and we do not email private individuals, sole traders or personal mailboxes anywhere.
For clients, suppliers and applicants, the basis is contract performance or our legitimate interest in running the business.
Your rights
Under GDPR and UK GDPR you can ask us to show what we hold, correct it, delete it, restrict or export it, and you can complain to your national supervisory authority. Two rights matter most here.
Objection to direct marketing, Art. 21(2)
This one is unconditional. The moment you object, we stop, and there is no balancing test to argue about. One word in a reply is enough.
Deletion, Art. 17
We delete on request. One record survives: your email address in a suppression list, held so that a future campaign cannot reach you by accident. That is the only lawful way to guarantee the silence you asked for, and it is used for nothing else.
If you are in California, the CCPA gives you the same access and deletion rights over business contact data, plus the right to know what is disclosed. We do not sell or share personal information as those terms are defined there.
Who else touches it
Processors under contract, each holding the data only to do the job we ask.
- Sending and sequencing: SmartLead, and mailbox providers on the sending domains.
- Enrichment and verification: Apollo.io, Clay and email verification services.
- CRM and analytics: HubSpot and our own systems on managed infrastructure.
- Meetings and calls: Calendly, Google Workspace, and Fireflies for meeting notes when every participant has been told the call is recorded.
Several sit in the United States, so transfers out of the EEA and UK run on Standard Contractual Clauses or an adequacy decision. We never sell contact data, and we never pass it to another company for their own marketing.
How long we keep it
- Prospect data: 24 months from the last contact, then deleted.
- Objections and unsubscribes: kept indefinitely, because forgetting them would break the promise.
- Client records: for the life of the engagement plus the retention that accounting and tax law require.
This website
The site sets no advertising or analytics cookies of its own. Two third parties are loaded on the marketing pages: web fonts served by Google, and RB2B, a visitor identification service that attempts to match a visitor to a company and, for United States traffic, to a person. Its script runs on the home page and the marketing sections, and it does not run on this page. If you would rather not be seen by it, browser tracking protection or an ad blocker stops it, and writing to us has the same effect on anything already recorded.
Changes and contact
Material changes are stamped with a new date at the top of this page. Anything at all about your data, including a request to see the legitimate interest assessment behind a message we sent you, goes to hello@spicegtm.com and is answered within 30 days, usually the same day.