Skip to content
B2B Forge

Legal

Privacy Policy

What we hold, where it came from, why we are allowed to hold it, how long we keep it, and what you can make us do about it.

Effective: 2026-08-01

Last updated: 2026-07-19

Entity: B2B Forge Limited

1.Who we are

B2B Forge Limited ("B2B Forge", "we", "us") supplies business contact data relating to companies that exhibit at trade shows and expos. We are the controller of the personal data described in this policy.

This policy covers two different groups, and the second is the one most privacy policies bury. Sections 2 to 4 cover visitors to this website. Section 5 onwards covers the individuals whose business contact information appears in our database — people who have not contacted us and may not know we exist. If you found your details in a list somebody bought, section 10 is what you want.

2.Information we collect from website visitors

  • Information you submit through a form: name, work email, company, phone number if you provide one, and the content of your message.
  • Aggregate analytics about page views, referring source and approximate region.
  • Technical information your browser sends: IP address, user agent and language.

We do not build advertising profiles from visitor analytics, and we do not sell visitor data.

3.Cookies

We use the minimum set of cookies needed to run the site and understand aggregate traffic. We do not run advertising or cross-site tracking cookies.

You can block or delete cookies in your browser settings. Blocking strictly necessary cookies may prevent forms from submitting.

4.Information in our database

We hold information about companies that exhibit at trade shows, and about individuals at those companies in their professional capacity only.

  • Company name, website domain, registered address, industry and size band.
  • The shows and editions at which a company exhibited, and its stand or booth number where published.
  • Business contact details for commercial roles: name, job title, work email address, direct dial or switchboard number, and public professional profile URL.

We do not knowingly collect information about individuals acting in a personal capacity. We do not collect special category data as defined by the UK and EU GDPR — no health, biometric, genetic, racial or ethnic origin, political opinion, religious belief, trade union membership or sexual orientation data. We do not collect data about children, consumer purchase history, or financial account information.

5.Where the data comes from

Exhibitor information is obtained through commercial arrangements with data partners and supplemented from public business sources — company websites, published exhibitor directories, corporate registries and public professional profiles.

We do not obtain data by circumventing access controls, by scraping services in breach of their terms, or from breach or leak datasets.

6.Why we process it, and our lawful basis

Under the UK GDPR and EU GDPR we must have a lawful basis for each purpose. Ours are set out below.

Purposes and lawful bases
PurposeLawful basis
Compiling and licensing business contact dataLegitimate interests — supplying business information for business-to-business communication
Verifying and correcting recordsLegitimate interests, and compliance with the accuracy principle
Responding to an enquiry or quote requestSteps taken at your request before entering a contract
Delivering and supporting an orderPerformance of a contract
Sending our newsletterConsent, withdrawable at any time in one click
Maintaining a suppression listLegal obligation, and legitimate interests in not re-contacting people who asked us not to
Keeping financial and tax recordsLegal obligation
Preventing fraud and securing the serviceLegitimate interests

Where we rely on legitimate interests we have carried out a balancing assessment weighing our interest against the rights and freedoms of the individuals concerned. We will provide a summary on request.

Legitimate interests is not a blank cheque. It is precisely why an objection under section 10 takes effect immediately rather than being weighed case by case.

7.Who we share it with

  • Customers who licence data from us, under terms that prohibit resale, republication and onward transfer, and that require them to honour suppression requests.
  • Service providers who host our infrastructure, process payments and deliver email on our behalf, under written contract and only to provide that service.
  • Professional advisers, and a regulator, court or law enforcement body where we are legally required to disclose.
  • An acquirer, in the event of a merger or sale of the business, subject to the same protections.

We will name our current processors on request. We do not disclose personal data to anyone else.

8.International transfers

We are established in the United States, and our customers and infrastructure are international, so personal data may be transferred outside the UK and the European Economic Area.

Where we transfer personal data out of the UK or EEA we rely on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with a transfer risk assessment and any additional technical measures it identifies. A copy of the relevant mechanism is available on request.

9.How long we keep it

Retention periods
CategoryRetention period
Enquiry and quote correspondence24 months from last contact
Customer account and order recordsDuration of the contract, then 6 years
Financial and tax records7 years
Newsletter consent recordsUntil consent is withdrawn, then 12 months
Exhibitor database recordsReviewed every 24 months; removed when no longer accurate or relevant
Suppression list entriesRetained indefinitely — see below
Website analytics14 months, in aggregate

Suppression entries are kept indefinitely on purpose. Deleting the record of a removal request is exactly what causes someone to be re-added the next time a source is refreshed. A suppression entry holds the minimum needed to recognise and exclude a record, and nothing else.

When a retention period ends, data is securely deleted or irreversibly anonymised.

10.How we protect it

  • Encryption in transit using TLS, and encryption at rest for stored data.
  • Role-based access control, with multi-factor authentication for administrative access.
  • Access limited to staff who need it, under confidentiality obligations.
  • Logging and monitoring of access to production systems.
  • Written incident response procedures, including notification to the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of a reportable breach.

No system is perfectly secure and we do not claim otherwise. We do not currently hold a SOC 2 or ISO 27001 certification, and we do not display badges implying that we do.

11.Your rights

Depending on where you live you have some or all of the following rights. We honour all of them for everyone regardless of location, because running one process is simpler than running three.

  • Access

    Ask for a copy of the personal data we hold about you.

  • Rectification

    Have inaccurate data corrected or incomplete data completed.

  • Erasure

    Ask us to delete your personal data.

  • Object

    Object to processing based on legitimate interests, including direct marketing.

  • Restriction

    Ask us to limit how we use your data while a query is resolved.

  • Portability

    Receive your data in a structured, machine-readable format.

  • Opt out of sale or sharing

    Direct us not to sell or share your personal information.

  • Appeal

    Ask us to reconsider a refusal, and complain to a regulator.

The fastest route is the suppression form linked at the foot of this page. It requires no account, and we will never make you create one to exercise a right — that friction is exactly what these rules exist to prevent.

We acknowledge every request within 10 days and complete it within 45 days. If a request is genuinely complex we may extend once by a further 45 days and will tell you before the first period ends. We do not charge for this and we will not treat you differently for asking.

An authorised agent may submit on your behalf. We will ask for proof of authorisation before acting.

12.Data already delivered to a customer

When you ask to be removed we suppress the record so it is excluded from everything we deliver in future, and we notify customers who received the affected record that they must remove it. Our Terms and Acceptable Use Policy require them to do so.

We cannot reach into a third party's systems and delete data for them, and any vendor claiming they can is overpromising. If a company keeps contacting you after you have asked us to suppress your record, tell us and we will follow it up with them directly.

13.Data broker status

Licensing personal information about people with whom we have no direct relationship is capable of making us a data broker under California, Texas, Oregon and Vermont law, each of which carries its own registration and request-handling obligations.

We assess our position in each of those jurisdictions and register where required. We will confirm our current registration status on request, and we process deletion requests routed through the California Delete Request and Opt-out Platform within the timescales that regime requires.

14.Complaints

If you are unhappy with how we have handled your personal data, contact us first at privacy@b2bforge.co and we will try to resolve it.

You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. In the EEA it is the authority where you live. In the United States you may contact your state Attorney General.

15.Changes to this policy

We may update this policy. The effective and last-updated dates at the top of this page always reflect the current version.

Where a change materially affects how we use personal data we already hold, we will give at least 14 days notice before it takes effect — by email where we have an address for you, and by notice on this page in every case.

Contact

B2B Forge Limited8 The Green, Ste A, Dover, Delaware 19901, United States
privacy@b2bforge.co

To have your information removed from our database, use the suppression form. It requires no account and reaches the team that actions it.