Privacy Notice for Businesses We Contact

Privacy Notice for Businesses We Contact

Version 1.0 — Effective date: 2026-07-18

You are reading this because we sent, or intend to send, a business email about NotSpammy to a publicly listed contact address for your organisation. Because we obtained your details from a public source rather than from you, Article 14 of the EU General Data Protection Regulation (GDPR) requires us to tell you where your details came from, what we do with them, and how to stop it. This notice explains exactly that.

1. Who is contacting you (the controller)

NotSpammy is operated by Egységmester Kft. (Egységmester Korlátolt Felelősségű Társaság), 2330 Dunaharaszti, Gyóni Géza köz 8., Hungary. Company registration number: 13-09-162959. VAT number: 24291608-2-13. We are the data controller for this outreach. You can reach us about anything on this page at hello@practicalapps.studio.

2. Where we got your details (source of the data)

We obtained your business contact details from the public OpenStreetMap database (openstreetmap.org) — an openly licensed, publicly available map database of businesses and places, contributed and maintained by its worldwide community. Where OpenStreetMap listed a website for your business, we may also have taken the general, publicly published business email address from that website. We did not obtain your details from you directly, and we do not buy, rent, or trade marketing lists.

3. What personal data we hold

We hold only limited business contact details: your business or trading name, the business category or type (for example a hotel, guest house or restaurant), the town or city and country, a publicly listed business email address, your website address, and the publicly observable email configuration of your domain (its DNS records — SPF, DKIM, DMARC, MX and similar). We do not seek any special-category data. If a listed email address happens to contain a person's name (for example, firstname@yourbusiness.ie), that name is the only element that identifies an individual, which is why data-protection law applies.

4. What we use it for (purpose)

We use your details to send you an initial, relevant business-to-business message introducing NotSpammy — a monitor that checks, from the outside and using only publicly available information, whether your domain's email authentication (SPF, DKIM and especially DMARC) is set up so that someone could send email that looks like it comes from your business. Without an enforced DMARC policy, anyone can spoof your address — for example sending fake booking confirmations or deposit requests to your guests — and NotSpammy tells you when that exposure exists and alerts you if it changes. If you do not object, we may send a small number of brief follow-up messages about the same subject. This is low-volume outreach; we do not use your details for any other purpose.

5. Our legal basis (Article 6(1)(f) GDPR — legitimate interests)

We rely on legitimate interests under Article 6(1)(f) GDPR: our interest in relevant, proportionate B2B outreach, and the interest of a business that may benefit from learning that its domain can be impersonated. We carried out a balancing assessment before contacting you. We contact businesses (not consumers), at a business address, about a product relevant to their trade, in low volume, and we make opting out easy. We are not relying on your consent for this message, so you do not need to have agreed to anything — but you can object at any time and we will stop (see section 9). Separately from data-protection law, the sending of marketing email is also governed by ePrivacy rules (in Ireland, the ePrivacy Regulations 2011). Consistent with those rules, we contact only business or organisational email addresses that appear to be used in a commercial capacity, we identify ourselves clearly as the sender, we include a working opt-out in every message, and we send nothing further once you object.

6. Who else sees the data (recipients and processors)

To send and manage these emails we use Hostinger International Ltd. as our processor for EEA-based hosting and email delivery (SMTP). If you later choose to become a customer, payment is handled by Stripe as merchant of record. We do not sell, rent, or share your details with any third party for their own marketing.

7. Where your data is processed (international transfers)

These outreach details are stored and processed within the EU/EEA. Where any processor operates outside the EEA, we rely on appropriate safeguards required by Chapter V GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses.

8. How long we keep it (retention)

We keep your business contact details only for as long as is necessary for this outreach. If you do not respond, we delete or anonymise them no later than 12 months after the last message. If you object or ask us to stop, we remove your details from our outreach lists and keep only the minimum record — your email address on a suppression list — needed to make sure we do not contact you again. If you become a customer, your data is then governed by our main Privacy Policy.

9. Your rights — including the right to object

Under the GDPR you have the right to:

To object or exercise any other right, simply reply to our email or write to hello@practicalapps.studio. We will action opt-outs promptly and respond to other requests within 30 days. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.

10. Complaints

If you are in Ireland, you have the right to lodge a complaint with the Irish Data Protection Commission (Data Protection Commission), 6 Pembroke Row, Dublin 2, D02 X963, Ireland — dataprotection.ie. Because the controller is established in Hungary, you may alternatively complain to the Hungarian supervisory authority, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), www.naih.hu, or to the supervisory authority in your EU/EEA country of residence or place of work.

11. Changes to this notice

We may update this notice from time to time. The version number and effective date at the top will always reflect the current version.

Contact

For any privacy request or to object to this outreach, contact the data controller: Egységmester Kft., hello@practicalapps.studio, 2330 Dunaharaszti, Gyóni Géza köz 8., Hungary. See also our full Privacy Policy.

Home · Privacy Policy · Terms of Service · Scanning Policy