PRIVACY POLICY

United Kingdom (UK GDPR Compliant)


Effective Date: 3 June 2026

1. WHO WE ARE

Neon Ace Ltd ("we", "us", "our") is a UK-based B2B outbound sales and commercial pipeline generation company. We work with business clients in the Mechanical & Electrical (M&E) and building services sector, helping identify and engage relevant decision-makers within commercial organisations to support potential maintenance and service contract opportunities. This Privacy Policy explains how we collect, use, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. WHAT DATA WE COLLECT

We only collect and process business-related contact data. This includes:


Business name

Business email address

Business telephone number

Job title / professional role

LinkedIn profile URL (where publicly available)


We do not collect or process:


Special category data (e.g. health, ethnicity, religion, political opinions)

Consumer or household data

Private personal lifestyle or behavioural data

Any sensitive personal information


All data processed is strictly limited to professional business contexts.

3. HOW WE COLLECT DATA

We obtain business contact data from the following sources:


Apollo.io (B2B data sourcing and enrichment platform)

Publicly available company websites

LinkedIn and other professional networking platforms

Corporate directories and publicly accessible business listings

Data enrichment and verification tools used for professional accuracy


We only use data that is relevant to professional roles within B2B organisations.

4. HOW WE USE YOUR DATA

We use business contact data for the following purposes:


B2B outbound sales communication

Initiating professional commercial conversations

Identifying potential maintenance and service contract opportunities

Managing sales pipeline activity within CRM systems

Tracking engagement and communication history

Following up on relevant business enquiries or interactions


All processing is conducted in a professional, role-based B2B context. We do not use personal data for consumer marketing, profiling, or behavioural tracking.

5. LAWFUL BASIS FOR PROCESSING

Our lawful basis for processing personal data under UK GDPR is:


Legitimate Interests (Article 6(1)(f))


Our legitimate interests include:


Operating a B2B outbound sales and commercial engagement business

Identifying and contacting relevant decision-makers within target organisations

Generating commercial maintenance contract opportunities

Building structured sales pipelines for UK M&E contractors

Balancing Assessment

We have balanced our legitimate interests against the rights and freedoms of individuals and consider that:


Data is processed strictly in a professional business context

Individuals are contacted only in their professional roles

The impact on individuals is minimal and non-intrusive

All communications include clear opt-out mechanisms

Processing is limited, proportionate, and role-relevant


Individuals’ rights and freedoms are not overridden by our processing activities.

6. DATA SHARING

We may share data with trusted third-party service providers who support our business operations, including:


Apollo.io (data sourcing and enrichment)

Smartlead (email sequencing and outreach management)

GoHighLevel CRM (customer relationship and pipeline management)

Make.com (automation and system integration)

Google Workspace (email, storage, and operational tools)


We do not sell personal data. All third-party providers act as data processors under appropriate contractual safeguards.

7. DATA RETENTION

We retain personal data only for as long as necessary for the purposes outlined in this policy:


Non-engaged contacts: retained for 12–24 months

Active opportunities: retained for the duration of the commercial relationship or pipeline lifecycle

Opted-out or unsubscribed contacts: immediately suppressed and excluded from future processing

Outdated or irrelevant records: securely deleted or anonymised after retention periods


We regularly review data to ensure it remains accurate and necessary.

8. YOUR DATA PROTECTION RIGHTS

Under UK GDPR, you have the following rights:


The right to access your personal data

The right to correct inaccurate data

The right to request deletion of your data

The right to object to processing

The right to restrict processing

The right to withdraw consent or opt out of communications at any time


To exercise any of these rights, please contact us using the details provided below.

9. SECURITY MEASURES

We take appropriate technical and organisational measures to protect personal data, including:


Role-based access controls in Google Workspace

Secure password management via 1Password

Restricted access permissions within GoHighLevel CRM

Limited and controlled access for internal staff and contractors

Use of secure cloud-based systems with access logging and authentication controls


We aim to ensure data is protected against unauthorised access, loss, or misuse.

10. INTERNATIONAL DATA TRANSFERS

Some of our third-party service providers may process or store data outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, including:


Standard Contractual Clauses (SCCs) or equivalent safeguards

Use of reputable providers with established UK GDPR compliance frameworks

Due diligence on data protection standards of service providers

11. CONTACT US

If you have any questions about this Privacy Policy or wish to exercise your data rights, you can contact us at:


Neon Ace Ltd

66 Paul Street

London

EC2A 4NA

United Kingdom

Email: [email protected]

12. ICO COMPLIANCE STATEMENT

Neon Ace Ltd confirms that:


All personal data processing is based on Legitimate Interests (Article 6(1)(f) UK GDPR)

All communications are conducted strictly in a B2B professional context

Individuals are contacted only in relation to their professional roles within organisations

Data processing is limited, proportionate, and role-based

Opt-out and unsubscribe mechanisms are included in all communications

Neon Ace Ltd operates exclusively as a professional B2B service provider managing business-to-business outreach.


We believe our processing activities are fair, transparent, and compliant with UK GDPR requirements.

END OF POLICY

© 2026 Neon Ace Ltd. All Rights Reserved.

PRIVACY POLICY

United Kingdom (UK GDPR Compliant)

Effective Date: 3 June 2026

1. WHO WE ARE

Neon Ace Ltd ("we", "us", "our") is a UK-based B2B outbound sales and commercial pipeline generation company. We work with business clients in the Mechanical & Electrical (M&E) and building services sector, helping identify and engage relevant decision-makers within commercial organisations to support potential maintenance and service contract opportunities. This Privacy Policy explains how we collect, use, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. WHAT DATA WE COLLECT

We only collect and process business-related contact data. This includes:


Business name

Business email address

Business telephone number

Job title / professional role

LinkedIn profile URL (where publicly available)


We do not collect or process:


Special category data (e.g. health, ethnicity, religion, political opinions)

Consumer or household data

Private personal lifestyle or behavioural data

Any sensitive personal information


All data processed is strictly limited to professional business contexts.

3. HOW WE COLLECT DATA

We obtain business contact data from the following sources:


Apollo.io (B2B data sourcing and enrichment platform)

Publicly available company websites

LinkedIn and other professional networking platforms

Corporate directories and publicly accessible business listings

Data enrichment and verification tools used for professional accuracy


We only use data that is relevant to professional roles within B2B organisations.

4. HOW WE USE YOUR DATA

We use business contact data for the following purposes:


B2B outbound sales communication

Initiating professional commercial conversations

Identifying potential maintenance and service contract opportunities

Managing sales pipeline activity within CRM systems

Tracking engagement and communication history

Following up on relevant business enquiries or interactions


All processing is conducted in a professional, role-based B2B context. We do not use personal data for consumer marketing, profiling, or behavioural tracking.

5. LAWFUL BASIS FOR PROCESSING

Our lawful basis for processing personal data under UK GDPR is:


Legitimate Interests (Article 6(1)(f))


Our legitimate interests include:


Operating a B2B outbound sales and commercial engagement business

Identifying and contacting relevant decision-makers within target organisations

Generating commercial maintenance contract opportunities

Building structured sales pipelines for UK M&E contractors

Balancing Assessment

We have balanced our legitimate interests against the rights and freedoms of individuals and consider that:


Data is processed strictly in a professional business context

Individuals are contacted only in their professional roles

The impact on individuals is minimal and non-intrusive

All communications include clear opt-out mechanisms

Processing is limited, proportionate, and role-relevant


Individuals’ rights and freedoms are not overridden by our processing activities.

6. DATA SHARING

We may share data with trusted third-party service providers who support our business operations, including:


Apollo.io (data sourcing and enrichment)

Smartlead (email sequencing and outreach management)

GoHighLevel CRM (customer relationship and pipeline management)

Make.com (automation and system integration)

Google Workspace (email, storage, and operational tools)


We do not sell personal data. All third-party providers act as data processors under appropriate contractual safeguards.

7. DATA RETENTION

We retain personal data only for as long as necessary for the purposes outlined in this policy:


Non-engaged contacts: retained for 12–24 months

Active opportunities: retained for the duration of the commercial relationship or pipeline lifecycle

Opted-out or unsubscribed contacts: immediately suppressed and excluded from future processing

Outdated or irrelevant records: securely deleted or anonymised after retention periods


We regularly review data to ensure it remains accurate and necessary.

8. YOUR DATA PROTECTION RIGHTS

Under UK GDPR, you have the following rights:


The right to access your personal data

The right to correct inaccurate data

The right to request deletion of your data

The right to object to processing

The right to restrict processing

The right to withdraw consent or opt out of communications at any time


To exercise any of these rights, please contact us using the details provided below.

9. SECURITY MEASURES

We take appropriate technical and organisational measures to protect personal data, including:


Role-based access controls in Google Workspace

Secure password management via 1Password

Restricted access permissions within GoHighLevel CRM

Limited and controlled access for internal staff and contractors

Use of secure cloud-based systems with access logging and authentication controls


We aim to ensure data is protected against unauthorised access, loss, or misuse.

10. INTERNATIONAL DATA TRANSFERS

Some of our third-party service providers may process or store data outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, including:


Standard Contractual Clauses (SCCs) or equivalent safeguards

Use of reputable providers with established UK GDPR compliance frameworks

Due diligence on data protection standards of service providers

11. CONTACT US

If you have any questions about this Privacy Policy or wish to exercise your data rights, you can contact us at:


Neon Ace Ltd

66 Paul Street

London

EC2A 4NA

United Kingdom

Email: [email protected]

12. ICO COMPLIANCE STATEMENT

Neon Ace Ltd confirms that:


All personal data processing is based on Legitimate Interests (Article 6(1)(f) UK GDPR)

All communications are conducted strictly in a B2B professional context

Individuals are contacted only in relation to their professional roles within organisations

Data processing is limited, proportionate, and role-based

Opt-out and unsubscribe mechanisms are included in all communications

Neon Ace Ltd operates exclusively as a professional B2B service provider managing business-to-business outreach.


We believe our processing activities are fair, transparent, and compliant with UK GDPR requirements.

END OF POLICY

© 2026 Neon Ace Ltd. All Rights Reserved.