Legal

Privacy Policy

How we collect, use, store, and protect personal data, and how you exercise your rights over it. Written to be read rather than to be skipped.

Effective August 2026

01 · Introduction

Who we are and what this covers

KAT-i ("we", "us", "our") is a premium sales intelligence partner providing custom B2B contact research, data enhancement, and sales intelligence services. We are committed to protecting the privacy and personal data of the individuals whose information we process, including the people we research on behalf of our clients, who did not choose to deal with us.

This policy applies to:

  • Visitors to our website, kat-i.com
  • Prospective clients who contact us
  • Our clients and their representatives
  • The business contacts we research on behalf of our clients
Controller
KAT-i
Contact
compliance@kat-i.com
Offices
51 Seward Street, San Francisco, CA 94114, USA
Unit No-05, Sinhagad Road, Pune 411051, India
28/A/1, Haramohan Ghosh Lane, Phool Bagan, Kolkata 700085, West Bengal, India
Telephone
+91 628 942 3558 · +91 877 709 5698
02 · What we collect

What data we collect

2.1Data you provide to us

When you contact us, request a feasibility study, or engage our services, we may collect your name and job title, work email address, work phone number, company name and address, the requirements and briefs you send us for research projects, and our records of the communication between us.

2.2Data we research on your behalf

When you engage us for B2B contact research, we research and process business contact information about third parties: full name, job title and role, work email address, work phone numbers including direct dial, extension, switchboard and mobile, company name and address, and professional information relevant to your brief.

This is business contact information only. We do not process consumer data, sensitive personal data, or special category data.

Under the GDPR, business contact data is personal data. We treat it as such, and this policy applies to it in full.

2.3Website usage data

When you visit our website we may collect your IP address, browser type and version, the pages you visited and time spent, the referring website, and device information. We use this for website analytics and improvement. We do not use it to identify individual visitors unless they submit a form.

03 · How we use it

How we use your data

Every purpose we process personal data for, and the lawful basis for each.

Whose dataPurposeLawful basis
Prospective clientsResponding to enquiriesLegitimate interest, prospective business relationship
Prospective clientsSending feasibility studies and proposalsLegitimate interest
Prospective clientsMarketing communicationsConsent
ClientsDelivering research servicesContract performance
ClientsCommunicating about projectsContract performance
ClientsInvoicing and paymentContract performance and legal obligation
ClientsService improvementLegitimate interest
Researched contactsResearching and verifying business contact detailsLegitimate interest, Article 6(1)(f)
Researched contactsSeeking opt-in consent for email marketingConsent, Article 6(1)(a)
Researched contactsDelivering verified data to our clientContract performance, on the client's instruction
04 · Lawful basis

Lawful basis for processing

4.1Legitimate interest

For most B2B contact research we rely on legitimate interest under Article 6(1)(f). We have conducted a Legitimate Interest Assessment balancing our clients' commercial interests against the rights and freedoms of the data subject. That assessment turns on the following:

  • The data is business contact information, not sensitive personal data or special category data
  • The data is already in the public domain, or is obtainable by contacting the organisation directly
  • The processing is limited to what is necessary for the specific brief
  • A data subject can object at any time, and we act on it
  • We hold no aggregated database, and client data is deleted after the guarantee period, so nothing accumulates

4.2Consent

Where we seek opt-in permission on behalf of a client, consent is specific, informed, and freely given. We explain who is asking, on whose behalf, for what purpose, how the data will be used, and how to withdraw. Consent is captured by telephone and confirmed by email. Every consent is date-stamped and backed by a voice recording retained for eighteen months.

We make up to twelve attempts to reach a contact. If we cannot speak with them the record is marked as no answer. Silence is not consent and we do not treat it as consent.

4.3Contract performance

For our direct clients, processing is necessary to perform our contract with you.

05 · Sharing

How we share your data

5.1With our clients

When you engage us for research, the verified data is delivered to you and becomes your property. We do not share it with anyone else.

5.2With sub-processors

We use the following sub-processors for infrastructure and communication only. We do not outsource research or verification to third-party data brokers.

Sub-processorPurposeSafeguard
MicrosoftSecure file storage and communicationStandard Contractual Clauses where required
Box.comSecure file transferStandard Contractual Clauses where required
Google WorkspaceEmail and document collaborationStandard Contractual Clauses where required

A full and current list is available on request, and is updated whenever a new sub-processor is engaged. We do not sell, rent, or trade personal data to third parties for marketing purposes.

5.3Legal requirements

We may disclose personal data where required by law, court order, or a regulatory authority.

06 · Retention

How long we keep data

CategoryRetention period
Research data, active projectDuration of the project plus the 75-day guarantee period
Research data, post-deliveryDeleted from active systems immediately after the guarantee period
Opt-in voice recordings18 months from the date of consent, then purged
Backup copiesHeld for operational recovery only, then purged on the backup cycle
Client contact detailsDuration of the relationship, then as long as tax and company law in the jurisdictions we operate in requires
Financial recordsAs long as tax and company law in the jurisdictions we operate in requires
Website analyticsThe retention period configured in our analytics tool, after which it is deleted automatically
Aggregated contact databaseNot held. Never assembled

Our deletion practice

There is no product database. Nothing is aggregated, nothing is resold, and no historical archive accumulates. Client data is retained only for the 75-day guarantee period and then deleted. Consent recordings are held for eighteen months because a consent record that cannot be produced is worthless.

This is not an exception, it is how we operate. We cannot resell what we do not retain, and we cannot lose in a breach an archive that was never assembled. The narrow set of things we do hold is listed in full in the table above rather than summarised in a phrase.

07 · Your rights

Your rights over your data

Under the GDPR you have the following rights. They apply whether you are a client, a prospective client, or a person we researched on a client's behalf.

  • Access. You can request a copy of the personal data we hold about you.
  • Rectification. You can request that we correct inaccurate or incomplete data.
  • Erasure. You can request deletion where there is no compelling reason for us to continue processing.
  • Restriction. You can request that we restrict processing in certain circumstances.
  • Portability. You can request that we transfer your data to another controller in a structured, machine-readable format.
  • Objection. You can object to processing based on legitimate interest. We will stop unless we can demonstrate compelling legitimate grounds that override your rights.
  • Withdraw consent. Where processing is based on consent you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
  • Complain. You can lodge a complaint with a supervisory authority. If you are in the EEA, that is the authority in the country where you live or work, or where you believe the issue occurred.
08 · Exercising them

How to exercise your rights

Write to us and say which right you want to exercise. You do not need to use particular wording, quote an article number, or explain why.

Email
compliance@kat-i.com
By post
KAT-i, 28/A/1, Haramohan Ghosh Lane, Phool Bagan, Kolkata 700085, West Bengal, India

We will respond within 30 days of receiving your request. We may need to verify your identity first, and we will only ask for what is necessary to do that.

If you were researched rather than a client. You can ask us who commissioned the research that included you. Because we delete client data after the guarantee period, a request that arrives long after a project has closed may find that we no longer hold anything about you at all. We will tell you that plainly rather than leave you wondering.

09 · Security

How we protect data

We implement appropriate technical and organisational measures to protect personal data:

  • Encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest on every system that holds client data
  • Multi-factor authentication on all systems
  • Role-based access control, so researchers see only the projects they are assigned to
  • Regular security assessments and vulnerability scanning
  • Staff training on data protection
  • Documented incident response procedures, tested annually

Our information security management system is independently certified to ISO 27001:2022. The controls above are set out in more detail on our compliance page.

10 · Transfers

International transfers

Our research and verification teams work from our offices in San Francisco, Pune, and Kolkata. Personal data we process is therefore processed outside the European Economic Area, including personal data researched for clients marketing into Europe.

Where a transfer requires a safeguard under Chapter V of the GDPR, we put one in place, including Standard Contractual Clauses approved by the European Commission with the sub-processors listed in section 05. We do not transfer personal data to a party that cannot meet an adequate standard of protection.

The transfer mechanism that applies to a specific engagement is set out in the data processing agreement we sign with the client, so that it is a contractual commitment rather than a statement on a web page. Our full position is on the compliance page.

11 · Cookies

Cookies and tracking

Cookies are small text files placed on your device when you visit a website.

TypePurposeDuration
EssentialWebsite functionalitySession only
AnalyticsUnderstanding how visitors use the siteThe retention period configured in our analytics tool

We do not use cookies for advertising, and we do not track you across other websites.

You can manage or disable cookies through your browser settings. Disabling essential cookies may affect how the site works.

12 · Children

Children's privacy

Our services are not directed at children under 16, and we do not knowingly collect personal data from children. We research business contacts in a professional capacity only.

13 · Changes and contact

Changes to this policy, and how to reach us

We may update this policy from time to time. The current version is always on this page with its effective date at the top, and significant changes are communicated to clients directly.

Email
compliance@kat-i.com
Telephone
+91 628 942 3558 · +91 877 709 5698
By post
KAT-i, 28/A/1, Haramohan Ghosh Lane, Phool Bagan, Kolkata 700085, West Bengal, India