Skip to content
WeProspect
Expert IntelligenceGrowth IntelligenceStandardsAbout
Get in Touch
Expert Intelligence→Growth Intelligence→Standards→About→ For experts → Get in Touch

Emailconsult@weprospect.co

US+1 (732) 307-9081

India+91 93702 99070

LinkedIn

Legal

Privacy Policy

Last updated: 25/09/2026

1. Who we are

WeProspectCo ("WeProspect", "we", "us") operates weprospect.co and provides research-led intelligence services to business clients.

We are responsible for the personal data described in this policy. Where data protection law uses the term, we are the controller (India: Data Fiduciary) except in the limited circumstances set out in section 3.

This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what you can ask us to do about it. It applies to four groups of people, and not every section applies to you:

  • Clients and prospective clients — people at companies that buy, or may buy, our services
  • Experts — professionals in our network who take part in calls, interviews and surveys
  • Business contacts — people we research and may contact in the course of a client engagement (see section 5, which is written for you)
  • Website visitors — anyone who uses weprospect.co

We do not offer services to consumers or to anyone under 18, and we do not knowingly collect data from children.

2. What we collect and where it comes from

CategoryWhat it includesWhere we get it
Identity and contactName, job title, employer, work email, work telephone, business address, professional profile linksFrom you; from your employer where they are our client; from public and professional sources
Professional profileCareer history, sector and functional expertise, seniority, companies and markets you can speak to, languages, availabilityFrom you; from public professional profiles; from what you tell us on a vetting call
ScreeningRecords of expert vetting, conflict-of-interest checks, restrictions notified by an employer or third party, and confirmation that you have accepted our engagement termsFrom you; from public sources; from your employer or a third party who notifies us of a restriction
Engagement contentNotes, recordings and transcripts of calls and interviews where you have consented; survey responses; the views and opinions you give usFrom you
PaymentBank or payment account details, invoices, payment records, and tax information we are required to collect to pay youFrom you
Enquiry and marketingWhat you send us through a form or by email, your communication preferences, and whether you have opted outFrom you
TechnicalIP address, browser and device type, operating system, language, pages visited, referring page, timestampsAutomatically, when you use the site. We set no analytics or advertising cookies — see the Cookie Policy

We do not seek sensitive or special-category data — health, race or ethnicity, religious or political belief, trade union membership, sexual orientation, biometric or genetic data. Please do not send it to us. If it reaches us because you volunteered it in a call or a survey response, we will not use it for any purpose beyond the engagement it appeared in, and we will delete it where we can do so without breaking the record.

We do not run background checks, credit checks, criminal record checks or identity-document verification on experts. Our vetting is a conversation with a researcher plus a check of public professional information.

3. When we are not the controller

For most of what we do we decide why and how personal data is used, and we are the controller.

There is one exception. Where a client commissions a survey or interview programme that the client has designed — the client sets the script, the sample definition and the output format, and we run it to their specification — the client is the controller and we act as processor on their written instructions. In those engagements the client's own privacy practices apply alongside ours, and a complaint about how your responses are used lies against that client. We will always tell you, before you take part, which situation applies. If you ask us who the client is and we are under a confidentiality obligation that prevents us saying, we will tell you that, and we will pass your request to the client and support them in answering it.

Where we design the research ourselves — including all of our own methodology work and the interviews behind our Growth Intelligence engagements — we are the controller and this policy governs.

4. Why we use your data, and our legal basis

What we doWhyLegal basis (UK/EU GDPR)
Respond to an enquiry and discuss whether we can helpTo answer you and, if it goes further, to prepare a contractSteps prior to entering a contract; our legitimate interest in running the business
Deliver a client engagement and manage the relationshipTo perform what we agreedPerformance of a contract; legitimate interest where the contract is with your employer rather than you
Identify, vet and approach expertsTo find people who can genuinely speak to a client's question, and to check they are free to do soOur legitimate interest in operating a governed expert network; your consent where we record a call
Screen for conflicts and honour restrictions notified by an employerTo keep engagements compliant and protect experts from breaching duties they owe elsewhereLegitimate interest; compliance with a legal obligation where one applies
Record and transcribe a call or interviewTo produce an accurate record for the clientYour consent, given before the recording starts, withdrawable at any time
Research and contact business contacts for a client engagementTo carry out account intelligence and buyer research (see section 5)Our legitimate interest, and our client's, in business development, subject to the balancing test described in section 5
Pay expertsTo meet our obligations to you and to tax authoritiesPerformance of a contract; compliance with a legal obligation
Send service and marketing communicationsTo keep clients informed and to tell people about work we think is relevantConsent where required; otherwise legitimate interest, with an opt-out in every message
Operate, secure and improve the siteTo keep the site working and free of automated abuseLegitimate interest
Keep records, handle disputes, meet legal dutiesTo defend claims and comply with lawLegal obligation; establishment, exercise or defence of legal claims

Where we rely on legitimate interests, we have assessed in each case whether our interest is outweighed by your rights and freedoms. You can ask us for a summary of that assessment at the address in section 12.

Where we rely on consent — recording, and certain marketing — you can withdraw it at any time, and withdrawing it does not affect anything we did lawfully beforehand.

5. If we contacted you and you have never dealt with us {#business-contacts}

This section is for people who receive a call, an email or an interview request from us without having approached us first. It is the notice that data protection law requires us to give you.

Where we got your details. From publicly available professional sources — your employer's website, professional networking profiles, published directories, conference and industry listings, public filings, published articles and interviews — and in some cases from a business contact data provider. Where we use a provider, our contract requires them to warrant that the data was collected lawfully and that they will tell us if that changes. If you want to know specifically where your details came from, ask us and we will tell you.

What we hold. Your name, job title, employer, work contact details, and a note of the market or category your role suggests you have a view on. Nothing about your personal life, and nothing we could not have read from a public professional source.

Why. We were commissioned by a client to understand a market, a set of accounts, or the experience of buyers in a category. You appeared relevant. Our legal basis is legitimate interest — ours and our client's — in business research and development. We have weighed that against your interests, and the factors that keep it proportionate are that we contact you in a professional capacity at work about a professional subject, we hold a minimal record, we do not build profiles of you beyond what your role suggests, we do not sell your data, and we stop immediately when asked.

Who sees it. The client who commissioned the work sees the research output. Where that output identifies you — for example, an attributed interview — we will have asked your permission first. Aggregated or anonymised findings do not identify you.

How long. Contact records are reviewed annually and deleted when they are no longer relevant to any live or reasonably anticipated engagement, and in any event within 24 months of last contact. A suppression record — enough to know not to contact you again — is kept indefinitely, because that is the only way to honour your objection.

What you can do. You have an absolute right to object, and we will stop. Email privacy@weprospect.co with "Do not contact" and your name, and we will remove you from all research and outreach, add you to our permanent suppression list, and confirm. You do not have to give a reason. You can also ask for a copy of what we hold, ask us to correct it, or ask us to delete it — see section 10.

6. Experts

If you take part in our network, a few things apply specifically to you.

You decide, each time. Joining the network commits you to nothing. You choose whether to take part in any given project, and you can leave at any point by telling us.

What you must not tell us. Before every engagement you agree not to disclose: information that is confidential to your current or a former employer; material non-public information about any company; personal data about other people; anything covered by a non-disclosure agreement, non-compete or restricted list; and anything you are professionally or legally barred from discussing. We rely on you to hold that line, and we will end an engagement if it is crossed.

Restrictions from your employer. If your current or former employer, or another third party you owe duties to, tells us through an authorised representative that your participation should be restricted, we will honour that restriction and record it against your profile. We may contact an employer or third party to verify information you have given us, or to confirm a consent or approval you need for a specific project. We will not do so without telling you.

Recording. We record and transcribe calls and interviews only where you have agreed in advance, and we tell you before the recording starts. You can decline and still take part. You can ask us to stop recording mid-call, and you can ask us to delete a recording afterwards.

What the client sees. For any project you take part in, the client sees your professional profile, the relevant parts of your background, and the substance of what you said. They see your name unless the engagement is anonymised, which we will tell you at the outset. Clients are contractually bound to keep your information confidential and to use it only for the project.

Payment. Where a project carries an honorarium we collect the payment and tax details we need to pay you, and we keep those records for as long as tax and accounting law requires.

7. Artificial intelligence

We use AI tools in a limited and disclosed way.

  • Transcription and summarisation. Where a call has been recorded with consent, we may use an AI tool to transcribe it and to draft a summary. A researcher reviews the output before it reaches a client.
  • Search and matching. We may use AI to search our own records for experts whose background fits a client's question. A researcher decides who is actually approached — no one is included in or excluded from a project by an automated decision alone.
  • What we do not do. We do not use client data, expert data, engagement transcripts or survey responses to train AI models, our own or anyone else's. Where we use a third-party AI provider, we use it on terms that prohibit the provider from training on our inputs, and we do not send it data that identifies an individual unless the engagement requires it and the individual has consented.

You are not subject to any decision producing legal or similarly significant effects that is based solely on automated processing.

8. Who we share data with

  • Clients — expert profiles and engagement output, under confidentiality obligations in our client agreements.
  • Experts — the client's identity where the engagement requires it and the client has agreed.
  • Service providers, each under a written contract limiting them to our instructions: Google (Google Workspace, including the spreadsheet our forms write to), Cloudflare (site delivery and Turnstile bot prevention), Hostinger (email hosting).
  • Professional advisers — accountants, auditors and lawyers, under confidentiality.
  • Authorities — where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend a legal claim.
  • A buyer — if the business or part of it is sold or reorganised, as part of the assets transferred. We would tell you.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

9. International transfers and where data lives

We are based in India. Our service providers operate internationally, and personal data we hold may be stored or accessed in India, the United States and the European Union.

Where personal data moves from the UK or the EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, together with an assessment of the destination and additional safeguards where the assessment calls for them. You can request a copy of the safeguards in place for a specific transfer at the address in section 12.

Where personal data moves out of India, we do so in accordance with the Digital Personal Data Protection Act, 2023 and the rules made under it.

10. Your rights

Subject to the law that applies to you, you can ask us to:

  • Give you a copy of the personal data we hold about you, and tell you where it came from
  • Correct anything inaccurate or incomplete
  • Delete it, where we have no continuing lawful reason to hold it
  • Restrict what we do with it while a question about it is resolved
  • Object to processing based on legitimate interests — and, for direct marketing and for the outreach described in section 5, that objection is absolute and we will always honour it
  • Port it to you or another organisation in a structured, machine-readable format, where the right applies
  • Withdraw consent you previously gave
  • Nominate another person to exercise these rights for you if you die or become incapacitated (India)

How to ask: email privacy@weprospect.co. We may need to verify your identity before we act, which protects you. We respond within 30 days, and we will tell you if a request is complex enough to need longer. There is no charge unless a request is manifestly unfounded or repetitive.

If we cannot do what you asked, we will tell you why.

Complaints. Please raise it with us first — we would rather fix it. If you are not satisfied: in India, to the Data Protection Board of India; in the UK, to the Information Commissioner's Office at ico.org.uk; in the EEA, to the supervisory authority where you live or work.

California and other US states. We operate on a business-to-business basis and most of what we hold is business contact information, which several US state privacy laws treat differently from consumer data. Where those laws do apply to you, you have rights to know, delete, correct, and opt out of sale or sharing. We do not sell personal information and do not share it for cross-context behavioural advertising. Contact us at the address above and we will treat your request under the law that applies to you.

11. How long we keep things, and how we protect them

WhatHow long
Enquiries that do not become clients24 months from last contact
Client engagement recordsDuration of the engagement, then 7 years for tax, accounting and limitation purposes
Expert profilesWhile you are in the network; 24 months after your last engagement, unless you ask us to remove you sooner
Recordings and transcriptsAs agreed with the client for the engagement; deleted at the end of the agreed period
Business contact research recordsReviewed annually, deleted within 24 months of last contact
Suppression and objection recordsIndefinitely — this is how we honour your objection
Financial and tax recordsAs required by Indian law
Website technical logs12 months

We hold ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certification certified by IAF. In practice that means access to personal data is limited to people who need it, systems require multi-factor authentication, data is encrypted in transit, staff and contractors are bound by confidentiality, and we have a documented process for handling a breach — including notifying you and the relevant regulator where the law requires it.

No system is perfectly secure, and information sent over the internet is never entirely risk-free. We do not ask for passwords, payment card details or identity documents by email, and you should treat any message that does as fraudulent.

12. Contact and grievances

Questions, requests and complaints about this policy or your data:

<u>privacy@weprospect.co</u>, dpo@weprospect.co, General enquiries: consult@weprospect.co · +91 93702 99070 · +1 (732) 307-9081

13. Changes

We update this policy when our practices or the law change. The date at the top tells you when it last changed. Where a change materially affects how we use data about you, we will tell you directly rather than relying on you to notice.

WeProspect

Intelligence, first-hand.

Primary research and vetted experts for B2B technology.

Practices

  • Expert Intelligence
  • Growth Intelligence

Firm

  • Standards
  • About
  • For experts
  • Contact

Contact

  • consult@weprospect.co
  • US +1 (732) 307-9081
  • India +91 93702 99070
  • Manyata Tech Park, Bengaluru
  • LinkedIn (opens in a new tab)
ISO/IEC 27001:2022ISO/IEC 27701:2019Certified EGAC accreditation mark IAF Multilateral Recognition Arrangement member mark

© 2026 WeProspectCo·Privacy·Terms·Cookie Policy