Data Processing
When you are the controller and we are the processor
This governs data you collect about other people using the platform. It is required by law and applies automatically to every account.
Last updated 10 September 2026
1. Why this exists
When you use The RainMakers to collect and store information about identifiable people, you decide the purpose and we act on your instructions. That makes you the controller and us the processor, and UK GDPR Article 28 requires a written contract between us setting out specific terms. This is that contract.
It applies automatically to every account, forms part of the Terms of Service, and needs no separate signature. If your organisation requires a countersigned copy for its records, ask us.
2. What we process, and for whom
- Subject matter — providing the lead generation, enrichment and outreach platform
- Duration — for as long as your account is open, plus the retention periods in the Terms
- Nature and purpose — collecting, storing, structuring, enriching, exporting and, where you use those features, transmitting outreach on your instruction
- Types of personal data — business contact details, typically names, business email addresses, phone numbers, business addresses, website and social profile URLs, and job titles
- Categories of data subject — the business contacts, sole traders and company representatives you choose to search for
You must not use the platform to process special category data or data relating to criminal convictions. The Acceptable Use Policy prohibits this, and we have not built the platform to handle it.
3. Our obligations
We will:
- process personal data only on your documented instructions, which for most purposes means your use of the platform's features, unless the law requires otherwise — in which case we will tell you first unless prohibited from doing so
- make sure everyone with access is bound by confidentiality
- apply appropriate technical and organisational security measures, including encryption in transit and at rest, access control and logging
- help you respond to requests from data subjects exercising their rights
- help you with data protection impact assessments and with prior consultation of the ICO, so far as is reasonable
- notify you without undue delay, and in any event within 48 hours, if we become aware of a personal data breach affecting your data
- delete or return your data at the end of the agreement, as you choose
- make available the information needed to demonstrate compliance with Article 28, and allow audits as described below
4. Your obligations
You will:
- have and maintain a lawful basis for every category of personal data you process through the platform
- comply with the transparency duties owed to the people whose data you collect — in particular Article 14, which applies when personal data is obtained from a source other than the person themselves
- issue only instructions that comply with data-protection law
- honour data-subject rights requests that come to you as controller
- not collect special category data, data about criminal offences, or data about children
- keep your own record of processing activities where the law requires one
Article 14 deserves a word, because it is the duty most often overlooked. When you collect someone's details without their knowledge, you generally have to tell them within a month that you hold their data, what you are doing with it and what rights they have. There are exemptions, including where notification would involve disproportionate effort, but they are narrower than people assume and you should not simply assume one applies. Take advice if you are unsure.
5. Sub-processors
You give us general authorisation to use sub-processors. Our current list is on the Sub-processors page.
We will give you at least 30 days' notice before adding or replacing one. If you reasonably object on data-protection grounds, tell us within that period and we will either propose an alternative or, if we cannot, let you terminate the affected service and refund the unused part of what you have paid.
Each sub-processor is bound by written terms no less protective than these, and we remain liable to you for their performance.
6. International transfers
Where we or a sub-processor transfer personal data outside the UK, we rely on an adequacy decision, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. The Sub-processors page states which applies to each supplier.
7. Audits
We will provide the information reasonably needed to demonstrate our compliance with this agreement. You may audit us, or appoint an independent auditor to do so, no more than once a year unless a breach or a regulator's requirement makes more necessary.
Audits must be arranged with reasonable notice, conducted during business hours, and carried out so as not to disrupt the service or compromise other customers' confidentiality. You bear your own costs, and ours where the audit goes beyond providing our standard compliance documentation.
8. Liability and duration
This agreement takes effect when you create an account and continues until your account is closed and the retention periods have expired.
Liability under this agreement is subject to the limits in the Terms of Service, except where the law does not permit it — in particular, nothing here limits a data subject's rights or either party's liability to a regulator.
The rest of our policies
Questions about any of this? Email privacy@therainmakers.uk for anything about data, or support@therainmakers.uk for everything else.