Privacy Policy

DATA DIRECT PRIVACY NOTICE

United Kingdom

Effective Date: 18 May 2026

Last Updated: 18 May 2026

 

  1. About this Privacy Notice

At Data Direct Pte Ltd (“Data Direct”, “we”, “us” or “our”), we are committed to protecting your privacy and handling your personal information in a transparent, secure and responsible manner.

This Privacy Notice explains how we collect, use, store, disclose and otherwise process personal information relating to individuals in the United Kingdom. It applies whenever you interact with Data Direct, including when you visit one of our websites, participate in a promotional campaign or competition, complete an online registration form, subscribe to marketing communications, request information about our services, or where we receive your personal information from trusted third-party sources in accordance with applicable law.

We recognise that your personal information is important. We are committed to processing it fairly, lawfully and transparently in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and, where applicable, the Privacy and Electronic Communications Regulations (PECR).

Please read this Privacy Notice carefully as it explains:

        • what personal information we collect;
        • how we collect it;
        • why we use it;
        • who we may share it with;
        • how long we keep it;
        • the safeguards we apply to protect it; and
        • the rights available to you under UK data protection law.

If you do not understand any part of this Privacy Notice, please contact us using the details provided below.

 

  1. Who We Are

Data Direct Pte Ltd is an international provider of data, identity verification, audience insights and data-driven marketing solutions.

Depending on the nature of a particular campaign, promotion or service, we may collect personal information directly from individuals or receive personal information from carefully selected commercial partners who have represented that the information has been collected lawfully and may be disclosed for the purposes described in this Privacy Notice.

Our services help organisations verify identity, improve the accuracy of customer information, better understand consumer audiences, reduce fraud, support regulatory compliance and deliver more relevant marketing communications.

For the purposes of the UK GDPR, Data Direct Pte Ltd is the data controller in relation to personal information collected through our own websites, promotional campaigns and other direct interactions with individuals.

Where we process information solely on behalf of a client, we may instead act as a data processor, with that client remaining the data controller. In those circumstances, the client’s own privacy notice will also apply to the processing of your personal information.

Our details are:

Data Direct Pte Ltd

39 Robinson Road

#11-01

Singapore 068911

Email: info@datadirect.com.sg

Telephone: +65 685 05055

If you have any questions regarding this Privacy Notice or how your personal information is handled, please contact us using the details above.

 

  1. Contacting Us

If you have any questions about this Privacy Notice, wish to exercise your privacy rights, or would like more information about how we process your personal information, please contact us using the details below.

Data Direct Pte Ltd

39 Robinson Road

#11-01

Singapore 068911

Email: info@datadirect.com.sg

Telephone: +65 685 05055

Where appropriate, we may ask you to verify your identity before responding to requests relating to your personal information. This helps us protect your privacy and ensure that personal information is only disclosed to the correct individual.

We aim to respond to all legitimate requests as soon as reasonably practicable and, where required by law, within the timeframes prescribed by the UK GDPR.

 

  1. Personal Information We Collect

The personal information we collect depends on the nature of your interaction with us, the campaign or promotion you participate in, and the services being provided.

Depending on the circumstances, we may collect the following categories of personal information:

 

Identity Information

This may include:

    • Full name
    • Title
    • Gender (where voluntarily provided)
    • Date of birth
    • Nationality (where relevant)
    • Government-issued identification details where required for identity verification or regulatory purposes

 

Contact Information

This may include:

    • Residential address
    • Postal address
    • Email address
    • Telephone or mobile number

 

Campaign and Registration Information

Where you participate in competitions, promotions, surveys, prize draws or marketing campaigns, we may collect information such as:

    • Competition entries
    • Survey responses
    • Registration information
    • Marketing preferences
    • Communication preferences
    • Prize fulfilment information

 

Identity Verification Information 

Where identity verification services are provided, we may collect or receive information necessary to verify your identity, prevent fraud, validate customer information or comply with legal obligations.

Depending on the relevant service, this may include identifiers supplied by you or by authorised commercial partners.

 

Technical Information

When you visit one of our websites, we may automatically collect certain technical information, including:

    • IP address
    • Browser type
    • Operating system
    • Device identifiers
    • Cookie identifiers
    • Website usage information
    • Referring websites
    • Session information
    • Approximate geographic location derived from your IP address

 

Marketing Information

We may collect information about:

    • Marketing preferences
    • Products or services that interest you
    • Responses to promotional campaigns
    • Email engagement
    • Website interactions
    • Audience segmentation information

 

Information Received from Third Parties

Where permitted by law, we may also receive personal information from trusted commercial partners, data providers, clients, publicly available sources and other organisations that have represented they have collected and shared personal information lawfully.

We undertake reasonable contractual and governance measures designed to ensure that information obtained from third parties has been collected and disclosed in accordance with applicable privacy laws.

 

Special Category Data

We do not intentionally collect or process special category personal data (such as information relating to health, ethnicity, religion, political opinions, trade union membership, genetic or biometric information for identification purposes, or sexual orientation) unless:

    • permitted or required by law;
    • appropriate safeguards are in place; and
    • the processing is necessary for a lawful purpose.

 

  1. How We Collect Your Information

We collect personal information in several different ways.

Information You Provide Directly

You may provide information directly to us when you:

    • enter a competition or prize draw;
    • complete an online registration form;
    • participate in a survey or promotional campaign;
    • request information from us;
    • subscribe to marketing communications;
    • contact our customer support team;
    • participate in market research;
    • update your preferences; or
    • otherwise communicate with us.

 

Information Collected Automatically

When you use our websites, we may automatically collect certain technical information through cookies and similar technologies.

This helps us understand how our websites are used, improve website performance, maintain security, remember user preferences and, where appropriate, deliver more relevant advertising.

Further information is available in our Cookie Policy.

Information Received from Third Parties

We may also receive personal information from carefully selected third-party organisations, including:

    • commercial data partners;
    • identity verification providers;
    • fraud prevention service providers;
    • licensed data suppliers;
    • publicly available sources;
    • business partners;
    • clients acting as data controllers; and
    • other organisations that are authorised to disclose personal information to us.

Before acquiring personal information from third parties, we undertake appropriate due diligence and require contractual commitments designed to ensure that information has been collected and shared lawfully.

 

  1. Why We Collect and Use Your Information

We collect and use personal information for legitimate business purposes, including to:

    • administer competitions, promotions and prize draws;
    • verify identity where appropriate;
    • prevent and detect fraud;
    • maintain the accuracy of customer information;
    • provide identity verification services;
    • undertake customer matching and data validation;
    • provide audience insights and analytics;
    • deliver marketing campaigns;
    • measure campaign effectiveness;
    • personalise communications;
    • improve our products and services;
    • conduct research and statistical analysis;
    • comply with legal and regulatory obligations;
    • establish, exercise or defend legal claims;
    • protect the security of our systems; and
    • operate and improve our business.

Where personal information is used for marketing purposes, we will do so in accordance with applicable privacy and electronic marketing laws.

Individuals may opt out of receiving marketing communications at any time by following the unsubscribe instructions provided in those communications or by contacting us directly.

 

  1. Lawful Bases for Processing Personal Information

Data Direct will only process your personal information where we have a lawful basis for doing so under the UK General Data Protection Regulation (“UK GDPR”).

Depending on the circumstances in which your personal information is collected and the services being provided, we may rely on one or more of the following lawful bases:

Consent

Where required by law, we will obtain your consent before collecting or using your personal information.

This may apply where you voluntarily provide your information through one of our campaign websites, competitions, prize draws, surveys, registration forms or other promotional activities and agree to receive marketing communications or for your information to be used for specified purposes.

Where processing is based on your consent, you may withdraw that consent at any time. Any withdrawal will not affect the lawfulness of processing undertaken before your consent was withdrawn.

Performance of a Contract

We may process your personal information where it is necessary to:

    • administer competitions, promotions or prize draws;
    • verify eligibility;
    • deliver prizes or rewards;
    • respond to requests you make; or
    • provide products or services that you have requested.

Legitimate Interests

In many cases, we process personal information where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.

Our legitimate interests may include:

    • operating and improving our business;
    • maintaining accurate and reliable information;
    • verifying identity where appropriate;
    • preventing and detecting fraud;
    • improving data quality and integrity;
    • undertaking customer analytics and research;
    • providing audience insights and data-driven services;
    • maintaining the security of our systems and networks;
    • responding to enquiries and customer requests; and
    • protecting our legal rights and business interests.

Where we rely on legitimate interests, we assess the impact on individuals and implement appropriate safeguards to ensure that your privacy rights remain protected.

Compliance with Legal Obligations

We may also process personal information where necessary to comply with applicable laws, regulatory requirements, court orders or lawful requests from government authorities or law enforcement agencies.

 

  1. Who We Share Personal Information With

We may disclose personal information where it is lawful, appropriate and necessary to do so for the purposes described in this Privacy Notice.

Depending on the services being provided, personal information may be shared with the following categories of recipients:

Our Clients

Where Data Direct provides identity verification, audience, analytics, marketing or other data-related services, we may disclose personal information to our clients where there is an appropriate legal basis and the disclosure is consistent with the purposes for which the information was collected.

Trusted Business Partners

We work with carefully selected business partners who assist us in delivering our services, operating promotional campaigns and supporting our business activities.

Before sharing personal information, we undertake appropriate due diligence and require contractual commitments designed to ensure that personal information is handled in accordance with applicable privacy laws.

Service Providers

We engage specialist service providers to support the operation of our business, including providers of:

    • cloud hosting and infrastructure;
    • website hosting;
    • technology platforms;
    • communications services;
    • analytics;
    • customer support;
    • information security;
    • data storage;
    • professional advisory services; and
    • other business support services.

Where these organisations process personal information on our behalf, they are contractually required to act only on our instructions and to implement appropriate technical and organisational measures to protect personal information.

Identity Verification and Fraud Prevention Providers

Where appropriate, we may share information with organisations that assist us in verifying identity, validating information, detecting fraud, managing risk and complying with legal or regulatory requirements.

Professional Advisers

We may disclose personal information to lawyers, accountants, auditors, insurers and other professional advisers where necessary to obtain professional advice or protect our legal interests.

Regulatory Authorities and Law Enforcement

We may disclose personal information where required or authorised by law, including in response to lawful requests from courts, regulatory authorities, government agencies or law enforcement bodies.

Business Transactions

If Data Direct is involved in a merger, acquisition, corporate restructure, investment, sale of assets or similar business transaction, personal information may be transferred as part of that transaction, subject to appropriate confidentiality obligations and applicable legal requirements.

 

  1. International Transfers of Personal Information

Data Direct operates internationally and, as a result, personal information may be transferred to or accessed from countries outside the United Kingdom, including Singapore, Australia and other jurisdictions in which Data Direct, its affiliates or trusted service providers operate.

Where personal information is transferred internationally, we take appropriate steps to ensure that it continues to receive a level of protection that is substantially equivalent to that required under UK data protection law.

Depending on the circumstances, these safeguards may include:

    • transfers to countries recognised by the UK Government as providing an adequate level of data protection;
    • the UK International Data Transfer Agreement (IDTA);
    • the UK Addendum to the European Commission’s Standard Contractual Clauses;
    • contractual obligations requiring appropriate privacy and security standards;
    • technical and organisational security measures;
    • encryption and secure methods of transmission;
    • access controls and authentication measures; and
    • transfer risk assessments where required by law.

We require organisations receiving personal information to protect it using appropriate security measures and to process it only for authorised purposes.

 

  1. Protecting Your Personal Information

Data Direct is committed to protecting the confidentiality, integrity and availability of the personal information entrusted to us.

We maintain appropriate technical, organisational and administrative safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

Our security measures include, where appropriate:

    • encryption of personal information during transmission and, where appropriate, at rest;
    • role-based access controls;
    • user authentication and password management;
    • secure network infrastructure and firewalls;
    • system monitoring and audit logging;
    • vulnerability management and security testing;
    • incident detection and response procedures;
    • staff training and confidentiality obligations;
    • contractual security requirements for service providers; and
    • regular review of our information security practices.

While no method of transmitting or storing information can be guaranteed to be completely secure, we continually review and enhance our security controls to reduce risk and help protect the personal information we hold.

 

  1. Data Retention

Data Direct retains personal information only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal and regulatory obligations, resolve disputes, enforce agreements and protect our legitimate business interests.

The length of time we retain personal information depends on a number of factors, including:

    • the nature and purpose of the processing;
    • the type of information involved;
    • whether there is an ongoing business or legal requirement to retain the information;
    • applicable regulatory requirements; and
    • our internal data retention policies and procedures.

Where personal information is no longer required, we take reasonable steps to securely delete, anonymise or otherwise dispose of it in accordance with applicable laws and our information governance practices.

In some circumstances, we may retain limited information where necessary to:

    • maintain suppression or opt-out records;
    • demonstrate compliance with legal obligations;
    • prevent fraud or misuse of our services;
    • establish, exercise or defend legal claims; or
    • maintain accurate records of processing activities.

 

  1. Your Rights Under UK Data Protection Law

Under UK data protection law, you have certain rights in relation to your personal information. These rights may be subject to certain legal limitations and exemptions.

Depending on the circumstances, you may have the right to:

Access your personal information
You may request a copy of the personal information we hold about you and information about how we process it.

Request correction of inaccurate information
You may ask us to correct personal information that you believe is inaccurate or incomplete.

Request deletion of your personal information
You may ask us to delete your personal information where there is no valid reason for us to continue processing it.

Object to processing
You may object to certain processing activities, including processing based on our legitimate interests and certain direct marketing activities.

Restrict processing
You may ask us to restrict the use of your personal information in certain circumstances, such as while we investigate a concern about accuracy or lawful processing.

Request data portability
Where applicable, you may request that certain personal information you have provided to us is transferred to another organisation in a structured, commonly used and machine-readable format.

Withdraw consent
Where we rely on consent as the legal basis for processing, you may withdraw your consent at any time. Withdrawal of consent does not affect processing carried out before consent was withdrawn.

To exercise any of these rights, please contact us using the details provided in Section 3.

We may request additional information to confirm your identity before responding to a request. This is a security measure designed to ensure personal information is not disclosed to an unauthorised person.

We aim to respond to all valid requests within the timeframes required under applicable data protection laws.

 

  1. Marketing Communications

Where permitted by applicable law, Data Direct may use personal information to provide information about products, services, promotions, research opportunities or other communications that may be relevant to you.

We may communicate with you through channels such as:

    • email;
    • SMS;
    • telephone;
    • online advertising;
    • digital marketing channels; or
    • other communication methods where permitted.

Where required, we will obtain appropriate consent before sending direct marketing communications.

You can opt out of receiving marketing communications at any time by:

    • clicking the unsubscribe link included in marketing emails;
    • following opt-out instructions included in communications; or
    • contacting us directly using the details provided in this Privacy Notice.

Please note that opting out of marketing communications does not prevent us from sending important service-related or administrative communications where necessary.

Where Data Direct provides services to clients that involve their own marketing activities, those clients may have their own privacy notices and opt-out processes which also apply.

 

  1. Cookies and Similar Technologies

Our websites may use cookies and similar technologies to improve functionality, analyse website usage, maintain security and support our services.

Cookies are small text files placed on your device when you visit a website. They allow websites to recognise your device and remember certain information about your visit.

We may use cookies for purposes including:

    • ensuring websites operate correctly;
    • improving website performance;
    • understanding how visitors use our websites;
    • maintaining security;
    • remembering preferences; and
    • supporting relevant advertising and analytics activities where permitted.

Where required by law, we will request your consent before placing non-essential cookies on your device.

You can control or delete cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our websites.

Further information about the cookies we use and how to manage your preferences may be provided in our Cookie Policy.

 

  1. Data Protection Complaints

We take privacy concerns seriously and encourage you to contact us first if you have any questions, concerns or complaints about how we handle your personal information.

We will investigate your concern and aim to provide a response within a reasonable timeframe and in accordance with applicable data protection requirements.

If you are located in the United Kingdom and remain dissatisfied with our response, you have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner’s Office (ICO)

The ICO can be contacted through its official website or complaint channels.

Making a complaint to the ICO does not affect any other legal rights or remedies available to you.

 

  1. Children’s Privacy

Our services are generally intended for individuals aged 18 years and over unless a specific campaign or promotion expressly states otherwise.

We do not knowingly collect personal information from children without appropriate safeguards and, where required, parental or guardian consent.

If you believe that we may have collected personal information relating to a child without appropriate authorisation, please contact us and we will investigate the matter.

 

  1. Automated Decision-Making and Profiling

Data Direct may use data analysis, audience segmentation and similar technologies to improve services, understand consumer preferences, verify information and support marketing activities.

We do not make decisions that produce legal or similarly significant effects on individuals solely through automated processing unless permitted by applicable law and appropriate safeguards are implemented.

Where automated decision-making is used in circumstances requiring additional information or safeguards, we will provide the relevant information required under applicable data protection law.

 

  1. Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our business practices, services, technology, legal requirements or regulatory guidance.

Any updated version will be published on our website with the revised effective date.

We encourage you to review this Privacy Notice periodically to remain informed about how we protect and process personal information.

 

  1. UK Privacy Representative

Data Direct Pte Ltd has appointed a UK-based privacy representative to act as a point of contact for individuals in the United Kingdom and the UK Information Commissioner’s Office (“ICO”) in relation to applicable data protection matters.

Our UK privacy representative may assist with:

    • receiving privacy-related enquiries from individuals;
    • supporting individuals who wish to exercise their rights under UK data protection law;
    • assisting with communications with the ICO where required; and
    • acting as a local point of contact regarding Data Direct’s processing of personal information relating to individuals in the United Kingdom.

Our UK privacy representative details are:

Hayden Ried

6 Outernet Place, London
WC2H 0LA
United Kingdom

Email:UKcompliance@datadirect.com.sg

Data Direct Pte Ltd remains responsible for ensuring that personal information is processed fairly, lawfully and transparently and in accordance with applicable UK data protection requirements.

 

  1. Contact Details

If you have any questions about this Privacy Notice, our privacy practices, wish to exercise your privacy rights, or would like further information about how we process personal information, please contact us using the details below:

Data Direct Pte Ltd
39 Robinson Road
#11-01
Singapore 068911

Email: info@datadirect.com.sg
Telephone: +65 685 05055

Where appropriate, we may ask you to verify your identity before responding to requests relating to your personal information. This helps us protect your privacy and ensure that personal information is only disclosed to the correct individual.

We aim to respond to all legitimate requests as soon as reasonably practicable and, where required by law, within the timeframes prescribed by the UK GDPR.

 

  1. Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our business practices, services, technology, legal requirements or regulatory guidance.

Any updated version of this Privacy Notice will be published on our website with the revised effective date.

We encourage you to review this Privacy Notice periodically to remain informed about how we protect and process your personal information.