How we collect, use, store, and protect personal data, and how you exercise your rights over it. Written to be read rather than to be skipped.
Effective August 2026
KAT-i ("we", "us", "our") is a premium sales intelligence partner providing custom B2B contact research, data enhancement, and sales intelligence services. We are committed to protecting the privacy and personal data of the individuals whose information we process, including the people we research on behalf of our clients, who did not choose to deal with us.
This policy applies to:
When you contact us, request a feasibility study, or engage our services, we may collect your name and job title, work email address, work phone number, company name and address, the requirements and briefs you send us for research projects, and our records of the communication between us.
When you engage us for B2B contact research, we research and process business contact information about third parties: full name, job title and role, work email address, work phone numbers including direct dial, extension, switchboard and mobile, company name and address, and professional information relevant to your brief.
This is business contact information only. We do not process consumer data, sensitive personal data, or special category data.
Under the GDPR, business contact data is personal data. We treat it as such, and this policy applies to it in full.
When you visit our website we may collect your IP address, browser type and version, the pages you visited and time spent, the referring website, and device information. We use this for website analytics and improvement. We do not use it to identify individual visitors unless they submit a form.
Every purpose we process personal data for, and the lawful basis for each.
| Whose data | Purpose | Lawful basis |
|---|---|---|
| Prospective clients | Responding to enquiries | Legitimate interest, prospective business relationship |
| Prospective clients | Sending feasibility studies and proposals | Legitimate interest |
| Prospective clients | Marketing communications | Consent |
| Clients | Delivering research services | Contract performance |
| Clients | Communicating about projects | Contract performance |
| Clients | Invoicing and payment | Contract performance and legal obligation |
| Clients | Service improvement | Legitimate interest |
| Researched contacts | Researching and verifying business contact details | Legitimate interest, Article 6(1)(f) |
| Researched contacts | Seeking opt-in consent for email marketing | Consent, Article 6(1)(a) |
| Researched contacts | Delivering verified data to our client | Contract performance, on the client's instruction |
For most B2B contact research we rely on legitimate interest under Article 6(1)(f). We have conducted a Legitimate Interest Assessment balancing our clients' commercial interests against the rights and freedoms of the data subject. That assessment turns on the following:
Where we seek opt-in permission on behalf of a client, consent is specific, informed, and freely given. We explain who is asking, on whose behalf, for what purpose, how the data will be used, and how to withdraw. Consent is captured by telephone and confirmed by email. Every consent is date-stamped and backed by a voice recording retained for eighteen months.
We make up to twelve attempts to reach a contact. If we cannot speak with them the record is marked as no answer. Silence is not consent and we do not treat it as consent.
For our direct clients, processing is necessary to perform our contract with you.
When you engage us for research, the verified data is delivered to you and becomes your property. We do not share it with anyone else.
We use the following sub-processors for infrastructure and communication only. We do not outsource research or verification to third-party data brokers.
| Sub-processor | Purpose | Safeguard |
|---|---|---|
| Microsoft | Secure file storage and communication | Standard Contractual Clauses where required |
| Box.com | Secure file transfer | Standard Contractual Clauses where required |
| Google Workspace | Email and document collaboration | Standard Contractual Clauses where required |
A full and current list is available on request, and is updated whenever a new sub-processor is engaged. We do not sell, rent, or trade personal data to third parties for marketing purposes.
We may disclose personal data where required by law, court order, or a regulatory authority.
| Category | Retention period |
|---|---|
| Research data, active project | Duration of the project plus the 75-day guarantee period |
| Research data, post-delivery | Deleted from active systems immediately after the guarantee period |
| Opt-in voice recordings | 18 months from the date of consent, then purged |
| Backup copies | Held for operational recovery only, then purged on the backup cycle |
| Client contact details | Duration of the relationship, then as long as tax and company law in the jurisdictions we operate in requires |
| Financial records | As long as tax and company law in the jurisdictions we operate in requires |
| Website analytics | The retention period configured in our analytics tool, after which it is deleted automatically |
| Aggregated contact database | Not held. Never assembled |
There is no product database. Nothing is aggregated, nothing is resold, and no historical archive accumulates. Client data is retained only for the 75-day guarantee period and then deleted. Consent recordings are held for eighteen months because a consent record that cannot be produced is worthless.
This is not an exception, it is how we operate. We cannot resell what we do not retain, and we cannot lose in a breach an archive that was never assembled. The narrow set of things we do hold is listed in full in the table above rather than summarised in a phrase.
Under the GDPR you have the following rights. They apply whether you are a client, a prospective client, or a person we researched on a client's behalf.
Write to us and say which right you want to exercise. You do not need to use particular wording, quote an article number, or explain why.
We will respond within 30 days of receiving your request. We may need to verify your identity first, and we will only ask for what is necessary to do that.
If you were researched rather than a client. You can ask us who commissioned the research that included you. Because we delete client data after the guarantee period, a request that arrives long after a project has closed may find that we no longer hold anything about you at all. We will tell you that plainly rather than leave you wondering.
We implement appropriate technical and organisational measures to protect personal data:
Our information security management system is independently certified to ISO 27001:2022. The controls above are set out in more detail on our compliance page.
Our research and verification teams work from our offices in San Francisco, Pune, and Kolkata. Personal data we process is therefore processed outside the European Economic Area, including personal data researched for clients marketing into Europe.
Where a transfer requires a safeguard under Chapter V of the GDPR, we put one in place, including Standard Contractual Clauses approved by the European Commission with the sub-processors listed in section 05. We do not transfer personal data to a party that cannot meet an adequate standard of protection.
The transfer mechanism that applies to a specific engagement is set out in the data processing agreement we sign with the client, so that it is a contractual commitment rather than a statement on a web page. Our full position is on the compliance page.
Cookies are small text files placed on your device when you visit a website.
| Type | Purpose | Duration |
|---|---|---|
| Essential | Website functionality | Session only |
| Analytics | Understanding how visitors use the site | The retention period configured in our analytics tool |
We do not use cookies for advertising, and we do not track you across other websites.
You can manage or disable cookies through your browser settings. Disabling essential cookies may affect how the site works.
Our services are not directed at children under 16, and we do not knowingly collect personal data from children. We research business contacts in a professional capacity only.
We may update this policy from time to time. The current version is always on this page with its effective date at the top, and significant changes are communicated to clients directly.
Before anything is stored
This site sets nothing on your device unless you say yes. We would like to set one cookie that tells us which pages are read, so we know what to write next. Nothing is shared with advertisers, and we do not run ads. What this means.