Privacy Policy
Effective date: September 24, 2026Last updated: September 24, 2026
1. Who We Are and How to Contact Us
UHNWI Direct is a service operated by UHNWI data, trading as UHNWI Data, at 55 Broadway, New York, NY 10006, United States. In this Policy, “we”, “us” and “our” refer to that operator. Contact our privacy team at privacy@uhnwidata.com. Legal notices may be sent to legal@uhnwidata.com.
This Policy explains how we handle information about website visitors, account holders, customer contacts submitted for matching, and individuals researched or contacted through our service. We are responsible for our account administration, independent research, campaign operations and security. A customer is responsible for the data it supplies and its subsequent use of recipient replies. Where we process information solely on a customer’s documented instructions, the applicable data-processing terms govern that activity.
This is a privacy notice, not a request for blanket consent. Visiting the site, accepting commercial terms or appearing in a public source does not by itself authorise every use of personal information. Mandatory privacy rights are not waived by our Terms of Service.
2. Information About Visitors and Account Holders
We process information you supply when registering, buying or using the service: your name, verified email address, optional phone number and country code, company and role, billing details, account preferences, orders, payment references, campaign settings, materials, verified campaign notification addresses, support messages and instructions. Country codes help format phone numbers; they are not proof of residence.
Email sign-in uses a temporary verification code. Where you choose Google sign-in, we receive the account identifier, email and available name needed for authentication. Connecting Google Contacts is a separate permission; signing in does not grant access to your address book. Provider sign-in and contact imports are optional alternatives to the available email and file workflows.
We also process operational information needed to serve and secure requests, such as session identifiers, IP addresses where available, error information, security events, timestamps and records of changes. The current website does not enable advertising trackers or Google Analytics. Browser storage is explained in our Cookie Policy.
Stripe processes payment details in its checkout and billing portal. We retain the order, amount, payment and refund status, provider references and billing information needed to administer the transaction. Our application does not store full payment-card numbers or card security codes.
3. Research Profiles and Sources
Our administrators maintain structured research about adult prospective recipients. Records may include names, business roles, affiliated companies, industries, country and more detailed residence information, birth year or age estimates, gender, estimated wealth, education and qualifications, professional associations, interests, publicly reported assets and purchase information, and relevant source notes or links. Operational contact records can include email addresses, telephone numbers and social or professional links.
We select relevant information from sources we reasonably regard as credible and lawfully usable, such as official biographies, company publications, corporate and regulatory filings, professional profiles, reputable reporting, direct correspondence and substantiated corrections. We do not treat everything found online as accurate or suitable for inclusion. Public availability does not remove our obligation to assess purpose, proportionality, accuracy and applicable law.
To the best of our knowledge at the time of review, an operational email address is attributed to the named person. Our primary standard is that person’s individual corporate or business address. A personal address on Gmail, Yahoo, Outlook or another public service is included as a Contact Route only if we previously received a reply from that person using it. Authorised assistants or other trusted people may nevertheless access the mailbox.
Profiles may also contain family context, including relationship status, names of spouses or partners, marriage years, and optional names, birth years and gender of children. Family details may concern minors. They are private administrative fields, not displayed in customer recipient lists, and children are not campaign targets. Unnecessary identifying details about minors should not be collected or retained.
Private legal-history fields can record reported allegations, dismissal or acquittal, convictions, historical imprisonment, current custody and contextual notes. An allegation is not a conviction. Current unavailability may exclude a person from sending without exposing the private reason to customers. Criminal-offence information and other legally restricted categories require a separate applicable legal condition and safeguards; a public report or this notice alone does not supply that authority. These fields are not enabled as customer-facing PRO targeting filters.
The current customer targeting controls use country, age bands, gender and wealth categories. Additional administrative fields are not a promise of available targeting. We do not offer health, ethnicity, religious belief, political opinion, sexual orientation, genetic or biometric targeting. Research classifications are estimates and are not certified financial, legal, creditworthiness or ownership findings.
4. Purposes and Legal Grounds
We use account and order information to provide requested services, authenticate users, prepare and manage campaigns, process payments and refunds, respond to enquiries and document instructions. Where the individual is our contracting customer, processing necessary for that service may be based on the contract. For representatives of a business customer, administration may instead rely on legitimate interests in managing that business relationship.
Independent research, relevant business correspondence, fraud prevention, security, duplicate-outreach prevention and service improvement may rely on legitimate interests where those interests are not overridden by the person’s rights and expectations. Accounting, legally required disclosures and other statutory duties rely on applicable legal obligations. We assess the purpose and circumstances; legitimate interests are not a universal permission to contact anyone.
Where consent is required, including for optional browser storage or particular electronic marketing, it must be obtained before the activity. Consent can be withdrawn for the future without making earlier lawful processing unlawful. A saved preference or a pre-enabled setting is not itself evidence of valid consent.
A corporate email address remains personal information when it identifies an individual. Business-to-business communications still require an appropriate legal basis and compliance with the rules applicable to the sender, recipient and destination. Our service terms do not replace those requirements.
5. What Customers Can See
Before purchase, the public audience tools show aggregate availability and pricing rather than research contact records. Eligible paid customers can review limited recipient information, such as name, country, age or age band, wealth classification, company and professional role, to administer their purchased campaigns.
Customer views do not provide our research email addresses, phone numbers, private source notes, family details or other private administrative fields. Administrators can access operational contact information for research and manual campaign delivery, including controlled export of an approved distribution list. That administrative export is not available to customers.
Customer contact tables may block ordinary copying and printing and display a repeating UHNWI Direct watermark with a client identifier. The identifier associates the displayed list with an account; it is not an email address. We do not claim to detect screenshots, and this feature does not generate screenshot alerts in Enquiries. Access controls and technical restrictions cannot prevent every form of capture.
6. Campaign Messages, Replies and Support
Campaign content identifies the customer or authorised sender. We process recipient selection, delivery activity, refusals, objections, replies and follow-up status to carry out and report on the campaign. Relevant feedback can be shown to the customer and may inform recommendations for a later list. Customer-specific refusals and exclusions are distinguished from broader delivery suppressions.
When a recipient replies to continue a specific conversation, we may forward the response and the contact information voluntarily included in it to the customer identified in the original message. This can include email, signature, telephone number and attachments. The customer is responsible for its further handling. A reply does not give unlimited permission for unrelated marketing, resale or disclosure.
We use the verified campaign notification email for essential campaign notices, including a request to replace an unavailable recipient. The same replacement request is available in Campaign manager. Internal campaign-manager conversations are stored in the account. General contact enquiries and administrator-initiated account emails may be handled by email, with replies recorded in Enquiries for continued support.
Objections and unsubscribe requests are used to prevent further communication within the relevant scope. We can retain minimal suppression information to honour those requests. An invalid contact discovered during a campaign is handled through the notification and equal-quantity replacement procedure described in our Terms of Service.
7. Marketing and Database Update Emails
Account settings contain separate preferences for Marketing and Database updates. Marketing covers our services and promotions; Database updates describe material changes in audience availability. Both are optional email categories, even if a database update may be useful to a customer. They are distinct from essential account, security, payment and campaign messages.
The current account interface initially enables both preference settings unless an opt-out has already been recorded. That interface default does not replace any consent or other legal permission required before a message is sent. You can change each category in Profile & settings → Notifications or use the email preference link. A provider-level unsubscribe may override both local settings.
Resend Broadcasts is used to prepare and deliver these newsletters to registered account holders. It receives the relevant email address, available name, subscription topics and audience membership. Available delivery and engagement reports depend on the provider and sending configuration. Newsletter processing is separate from the managed recipient campaigns; the standard recipient service does not supply open or click tracking. We do not currently use website advertising or analytics trackers.
8. Contact Matching: Files and Connected Services
Contact matching is available to eligible customers with paid order history and active account access. You may upload CSV, TSV or XLSX data or connect Google Contacts, Outlook / Microsoft 365, HubSpot, Salesforce or Microsoft Dynamics 365. You must be authorised to supply the data and provide required notices or permissions to the people concerned.
First name, last name and email are required for an imported row. Optional mapped values include telephone numbers, country, birth year, gender, job title, company and other relevant labelled information. Columns marked Skip are not included in the upload. The original spreadsheet is parsed in the browser; the mapped values and upload metadata are sent to our application when you confirm. The preview lets you review validation results first.
Connected imports retrieve available names, email addresses, phone numbers, country, work details and birth information supported by that provider. Some providers also return account identifiers or basic account details needed to identify the connection. Outlook import covers saved contacts and supported contact folders; it does not read messages. Google contact import does not read Gmail.
Our connector code reads contacts when you request a preview and does not change external CRM records or send our research lists to the connected service. Google and Outlook use contact-read permissions. Salesforce and Dynamics permissions can technically be broader and operate within the connected user’s rights, although our implemented import only reads. The provider’s consent screen states the actual permission grant. We retain encrypted access or refresh credentials on the server to maintain the connection, not in a browser-storage preference.
Preview data returned to the browser is not saved as an import until you confirm it. Saved uploads are kept separately from research records and used for your identity comparison, chosen exclusions and service support. They are not used to enrich our research database, supply another customer’s audience, or build a separate marketing list. Authorised administrators can inspect and download the specific upload for this service after the confirmation shown in the import workflow. Other customers cannot access it.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Connected contact data is not sold, used for advertising, used to enrich research profiles, or used to train general-purpose AI models. Access, human review and permitted transfers remain subject to the applicable provider restrictions.
Matching compares supplied identity information with our records. A name-only resemblance or conflicting identity is not automatically treated as a confirmed person. Uncertain matches require administrator review before affecting targeting. Customer results do not reveal our hidden contact details. Chosen exclusions affect that customer’s future selections and may also resolve when an unambiguous matching record is later added. Importing a list does not silently replace recipients in a confirmed campaign.
You can reverse exclusions, delete an upload or disconnect a service in Contact matching. Deleting an upload removes its stored values, matches and exclusions from the active application; another retained upload may still support the same exclusion. Disconnecting removes active application credentials and stops further reads, but does not delete previously saved uploads. You may also revoke permission in the provider account. Completed account closure removes saved matching uploads and connector credentials.
Minimal audit records record operations without copying uploaded values. Administrator-downloaded support copies and backups require a controlled deletion process rather than a remote browser deletion. Contact privacy@uhnwidata.com about those copies or assistance with deletion. The optional setting to remember column mappings stores column configuration on your device, not the imported contact values.
9. Providers, Recipients and International Processing
We disclose information only as needed for the relevant function: to authorised staff and service providers operating the application, to Stripe for payments, to Resend for application email and newsletters, to the identity or contact service you connect, and to a named campaign customer receiving a relevant reply. Professional advisers and competent authorities may receive information where necessary and lawful.
Application hosting, database and file-storage providers support delivery of the service; Cloudflare is the configured deployment infrastructure. The providers involved in a particular function process information under their applicable terms and, where relevant, our data-processing arrangements. Contact us for details relevant to your information.
Providers and authorised personnel may process information in the United States or other countries outside the person’s location. Where applicable law requires safeguards for such transfers, the relevant processing must be covered by an appropriate mechanism, such as an adequacy decision or approved contractual clauses and any necessary supplementary measures. You may ask our privacy team for information about safeguards relevant to your data.
We do not provide customer downloads of our operational email or telephone database. A restricted recipient view or a forwarded reply is described above; legal definitions of a sale, sharing or controller role depend on the actual processing and applicable law, not the label given to the service. Contact us to exercise an applicable opt-out right.
A business reorganisation or transfer may involve information under confidentiality and applicable legal safeguards. Connected-service data remains subject to its provider-specific restrictions, including any required consent. We may disclose information to comply with valid legal process, investigate abuse, protect rights or address a security incident; disclosures should be limited to what is necessary.
10. Retention and Account Closure
We retain information for its stated purpose rather than indefinitely merely because it may be useful. Account and campaign records support the relationship, paid services, reporting and enquiries. Transaction, contract and dispute records may need to remain after closure for applicable accounting, legal and claims requirements. Retention depends on the record category, jurisdiction, outstanding work and any legal hold; we do not promise a single deletion deadline for all records.
Research records are reviewed for continued relevance and accuracy. Material inaccuracies should be corrected, qualified or removed as appropriate. Suppression records are limited to information needed to honour objections and avoid accidental reintroduction. Deletion of a larger profile need not remove the minimal suppression record.
Saved matching uploads remain until you delete them or account closure is completed, subject to the limits and controls described in Section 8. Connector credentials remain until disconnection or completed closure. Authentication challenges expire quickly, and browser session lifetimes are listed in the Cookie Policy. Expiry of a credential is not a promise that every security or audit log is simultaneously erased.
Account closure may require resolution of active paid services or a manager-assisted closure request. Restricting access is not the same as deleting all records. Historical orders, accounting evidence, necessary correspondence and justified audit records may be retained with restricted use. Copies in backups or downloaded for authorised support require the applicable deletion and retention process. You may request an explanation of the categories retained and the reason at privacy@uhnwidata.com.
11. Security
Application safeguards include authenticated access, administrative access controls, customer ownership checks, server-side validation, protected sessions, encrypted connector credentials and audit records for relevant administrative operations. Downloaded operational files also require restricted access and appropriate handling.
No system is immune to failure or unauthorised access. We assess and respond to security incidents and provide notifications where required by applicable law. Users should protect their devices and accounts and report suspected compromise promptly. Copy restrictions and watermarks are supplementary controls, not a guarantee against disclosure.
12. Your Choices and Privacy Rights
You can edit available account details, change newsletter topics, manage matching uploads and exclusions, disconnect external services, change Cookie Preferences and request account closure through the available account tools. For other requests, contact privacy@uhnwidata.com.
Depending on applicable law, you may have rights to access your personal data, correct inaccuracies, request deletion or restriction, receive eligible data in a portable form, object to processing, withdraw consent, and complain to the relevant privacy authority. Applicable rights to opt out of a sale, sharing or certain profiling can also be raised with us. We will not penalise you for exercising a protected privacy right.
You may object to direct marketing at any time. Where such an objection applies, we stop the relevant marketing use and may retain a minimal suppression record. For other processing based on legitimate interests, we assess your circumstances and the applicable legal test. Withdrawal of consent does not affect other processing that has a separate lawful basis.
We may ask for proportionate information to verify identity, authority or locate a record. We respond within applicable statutory deadlines and explain any permitted extension, limitation or refusal and available complaint options. Requests are ordinarily free; an exception or fee applies only where law permits. Verification is not a reason to demand irrelevant personal information.
Rights are subject to lawful exceptions, including protection of another person, legal privilege, security and required retention. Those exceptions do not create a blanket exemption for proprietary research. If a full document cannot be disclosed, we consider an appropriate extract or redaction. Research subjects are not required to accept our customer arbitration terms to exercise privacy rights.
13. Selection, Matching and Automated Processing
The system calculates audience counts, applies selected filters, prioritises eligible recipients using internal ranking and checks duplicates, suppressions and customer exclusions. Matching uses supplied identity fields and flags uncertain results for review. These tools support human campaign administration and the customer’s review; they do not determine credit, employment, insurance or similar eligibility.
The service is not designed to make solely automated decisions producing legal or similarly significant effects about individuals. If an automated selection or match appears wrong, contact us for review and correction. Additional PRO targeting would require its own assessment and appropriate disclosure before being enabled.
14. Children and Restricted Information
The service is for adult business users, not children. We do not knowingly permit children to register or purchase campaigns. An adult research profile can contain family context as described in Section 3, which is distinct from offering a service to children or targeting them.
Customers should not upload unnecessary information about minors, criminal allegations, health or other sensitive matters into matching files or campaign materials. Contact our privacy team if such information has been supplied in error or if you believe an inappropriate family or research record is held. Restricted-category data requires a specific lawful justification and safeguards beyond ordinary account administration.
15. Cookies and Similar Storage
Our Cookie Policy explains authentication and connection cookies, temporary message drafts, saved privacy choices and optional campaign or import-mapping preferences. Optional persistent preferences are off until selected. Cookie Preferences lets you save a choice or reject optional storage. Account newsletter preferences are separate from browser-storage choices.
The current website does not enable analytics or advertising cookies. External sign-in, CRM and payment pages may use their own storage when you visit them; our controls do not change those providers’ settings. Introducing materially different tracking requires an updated notice and any legally required consent.
16. Updates and Contact
We update this Policy when the service or its data practices change. The date above identifies this version. We will give additional notice or obtain consent where a material change requires it; continued use is not treated as blanket consent to a new purpose.
Privacy enquiries, corrections, objections and requests: privacy@uhnwidata.com. UHNWI Data / UHNWI Direct 55 Broadway, New York, NY 10006, United States. Legal correspondence: legal@uhnwidata.com.