Privacy Policy

Last updated: 12 August 2026

Lead Engine is an internal business tool. It is not a public service and it has no sign-up. This policy is published openly because the service holds information about people who have never used it — business contacts we have researched — and they are entitled to read how it is handled without needing an account.

1. Who we are

The data controller is Barton Technology Ltd, a company registered in England and Wales, company number 03930086.

Registered office: 20 Market Place, Kingston Upon Thames, KT1 1JP
Correspondence address: Suite 652, 124 City Road, London EC1V 2NX
Contact: hello@barttech.co.uk

2. What this service does

Lead Engine takes a brief — a sector, a geography, a company size, a description of a good prospect — and produces a researched list of organisations and the business contacts within them who may be relevant. Access is restricted to authorised staff.

3. Data about people who use this service

For the small number of authorised users, we hold the email address used to sign in, the session that keeps you signed in, and an audit record of significant actions taken in the application. This exists so we can tell who did what, and it is kept for as long as the account exists.

4. Data about business contacts we research

This is the part most likely to concern you if you have received an email from us. We may hold, about a person in their professional capacity: their name, job title, work email address, employer, and publicly available professional information such as a company website or a public business listing.

This information comes from publicly accessible sources and from third-party business-data providers. We do not buy or use consumer data, and we do not seek special category data. Where an email address cannot be verified, or a record appears to belong to an individual rather than to a business role, it is discarded rather than used.

5. Our lawful basis

For researching and holding business contact data, our lawful basis is legitimate interests — specifically, identifying organisations that may have a genuine need for services we offer. We have weighed that against the interests of the people concerned: the data is limited to a professional context, it is not used to build a profile of anyone as an individual, and the intrusion of a single, relevant, clearly-identified business email is low. If you disagree with that balance in your case, you can object and we will stop — see section 8.

Separately, electronic marketing is subject to PECR. We contact corporate subscribers only, every message identifies us and offers a way to opt out, and an opt-out is honoured permanently.

6. Who your data is shared with

We do not sell personal data and we do not share it for anyone else's marketing. We use a small number of processors to run the service:

Some of these providers operate outside the UK. Where that is the case, appropriate transfer safeguards apply.

7. How long we keep it

Research records are kept only while they remain relevant to outreach, and are removed when they are not, or sooner on request.

One exception is deliberate and worth stating plainly: if you opt out or ask us to stop, we keep a suppression record of that indefinitely. That record is the only thing that reliably prevents the same address being researched and contacted again later. Deleting it would undo your request rather than honour it. It holds no more than is needed to recognise the address.

8. Your rights

Under UK data protection law you have the right to:

To exercise any of these, email hello@barttech.co.uk. We will respond within one month. You do not need an account, and you will not be asked to create one.

9. Cookies

This service uses strictly necessary cookies only — the ones that keep you signed in, keep the service secure, and remember your cookie choice. These are always active because the service cannot work without them.

No analytics or advertising cookies are configured on this service, and none are set. It is an internal tool with no public audience, so there is nothing to measure and no advertising to attribute. If that ever changes we will ask for your consent first and update this policy before anything runs. You can review your choice at any time: Cookie settings.

10. Security

Access requires an account and is limited to authorised staff. Data is encrypted in transit, access to the underlying database is restricted, and significant actions are recorded in an audit log.

11. Complaints

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

12. Changes to this policy

If this policy changes we will update the date at the top. Material changes to how we use personal data will be reflected here before they take effect.