Privacy policy
This business sends cold email to people in the UK, the EU, the US and Canada. That means it holds personal data about people who never asked to hear from it, so this page is specific about what is held, why, for how long, and how to get it deleted.
Last updated · 30 September 2026
Who the controller is
Firstline is the data controller for everything described on this page. It is operated from India. For any request under this policy, including erasure, use the contact details at the bottom of this page. A person reads that inbox, not a ticket queue.
Personal data held about prospects
If you received a cold email from a Firstline sending domain, this is the complete set of what is held about you:
- Your name.
- Your business email address.
- Your job title.
- Your employer's name, approximate headcount, industry and country.
- Your employer's website, and in some cases a public professional profile URL.
- The record of what was sent to you, when, and whether you replied.
That is all of it. No personal email addresses, no phone numbers unless you sent one, no home addresses, and no special category data as defined in Article 9 — nothing about health, ethnicity, religion, politics, trade union membership, sex life or biometrics. None of it is bought or sold on, and it is never used to train a model.
Sources: publicly available professional information and licensed third-party B2B data providers. Nothing is scraped from behind a login.
Lawful basis
Legitimate interests, under Article 6(1)(f) of the UK and EU GDPR: promoting a business service to a named person whose job involves buying or overseeing that kind of service. A legitimate interests assessment balancing that against your rights is on file and a copy is available on request.
On electronic marketing rules specifically: email is sent to corporate subscribers — companies, LLPs and similar entities — and not to sole traders, partnerships of individuals, or private individuals, which is the distinction PECR and the equivalent national implementations of the ePrivacy Directive draw for B2B email. Every message identifies who sent it and carries a one-line way to opt out. For recipients in the United States the same setup is what satisfies CAN-SPAM.
Consent is not relied on for prospect email, so there is no consent to withdraw — but objecting is absolute and immediate, and is covered below.
How long it is kept
- Prospect records with no engagement: deleted 12 months after the last contact attempt.
- Prospect records where you replied or a meeting happened: kept for the life of the client engagement plus 12 months, because it is the record behind an invoice.
- Suppression list: kept indefinitely, and this one is deliberate. Your email address is retained in a do-not-contact list precisely so that no future list import can reach you again. Deleting it would defeat the opt-out.
- Client contract and billing records: kept for as long as tax and accounting law requires.
How to be removed
Reply to any email with the word "remove", or write to the address at the bottom of this page. No form, no login, no reason required.
What happens then: your address goes onto the permanent suppression list within 24 hours, any active sequence stops immediately, and your record is deleted from the working list. The suppression entry itself stays, for the reason given above. If you would rather every trace including the suppression entry were deleted, say so and it will be done — with the caveat, stated honestly, that this makes it possible for a future list to surface your address again.
Your rights
If you are in the UK or the EU you have the right to access your data, correct it, have it erased, object to processing, restrict processing, and receive it in a portable form. Requests are answered within 30 days and there is no charge.
There is no automated decision-making with legal or similarly significant effect. Which prospects get contacted is filtered by job title, company size and geography — a person reviews the list before anything sends.
You can complain to a supervisory authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority in your country of residence. You are not required to raise it here first, though it will be dealt with faster if you do.
Personal data held about clients
If you are a client: name, work email, phone if you give one, company details, the scheduling and reply-forwarding addresses you provide, billing records, and the campaign data in your shared sheet. Lawful basis is contract performance, and for billing records, legal obligation.
Who else processes it
Processing is kept to the smallest set of tools the work needs. As of the date at the bottom of this page, that is: Google Workspace for sending and receiving email, an email sequencing platform, Google Sheets for the shared client sheet, Loom for the weekly video, Vercel for hosting this website, and Razorpay for payments. Each is used under its own data processing terms. The current list is available on request, and it changes rarely.
This website itself sets no cookies, runs no analytics, loads no fonts or scripts from a third-party domain, and has no chat widget or tracking pixel. Nothing about your visit here is recorded beyond the standard server request logs Vercel keeps to serve the page.
International transfers
Firstline is operated from India, and several of the processors above are based in the United States. Personal data about UK and EU residents is therefore transferred outside the UK and the EEA. Those transfers rely on the Standard Contractual Clauses, or the UK International Data Transfer Addendum where the UK rules apply, in each processor's own data processing terms.
Security, and breaches
Two-factor authentication on every account that holds prospect or client data, a password manager, no shared logins, and no prospect data on unencrypted local storage. Access is limited to one person, which is both the main control and the obvious single point of failure — stated rather than dressed up.
A personal data breach that is likely to risk your rights will be reported to the relevant supervisory authority within 72 hours of discovery, and to you directly where the risk is high.
Changes
If this policy changes in a way that affects how prospect data is handled, the date at the bottom of the page changes with it. There is no mailing list to notify, because collecting addresses to announce privacy changes would be its own joke.