Privacy & compliance

    GDPR at Drimble

    Drimble helps sales, marketing and recruitment teams find the right companies and business contacts. We take the General Data Protection Regulation (GDPR) seriously. This page explains, in plain language, which data we process, on what legal grounds, how we protect it and which rights you have.

    Which data we process

    Drimble processes business-to-business data: company names, registration numbers, industry codes, addresses, websites and generic business contact details such as role-based email addresses and direct dials. Where we process professional data relating to an identified person — for example a director or decision-maker — GDPR applies and we treat that data as personal data.

    Our lawful basis: legitimate interest

    We process B2B contact and company data on the basis of legitimate interest (article 6(1)(f) GDPR): helping businesses reach other businesses with relevant propositions. For every processing activity we perform a balancing test between our commercial interest and the privacy of the data subject, and we document that assessment. Where consent is required — for example for our own newsletter — we ask for it explicitly.

    Sources and transparency

    Our data comes from public and licensed sources: national chambers of commerce and company registers, company websites, public filings and carefully selected data partners. On our Data Coverage page you can see per market which sources we use and how fresh the data is.

    Security and retention

    Data is stored on servers within the European Union, encrypted in transit and at rest, with role-based access for a limited team. We retain personal data only as long as it is accurate and relevant; records are re-verified on a rolling basis and removed or corrected when a source changes.

    Your rights

    If your professional data appears in Drimble, you have the following rights under GDPR. We respond to every request within 30 days.

    • Right of access — ask which data we hold about you.
    • Right to rectification — have incorrect data corrected.
    • Right to erasure — have your data removed from our database.
    • Right to object — object to processing based on legitimate interest.
    • Right to restriction and data portability where applicable.

    You can also file a complaint with your national data protection authority, for example the Dutch Autoriteit Persoonsgegevens.

    View our Data Coverage

    Frequently asked questions

    Is B2B contact data covered by GDPR?

    Yes. As soon as data can be linked to an identifiable person — such as a work email address like firstname.lastname@company.com — GDPR applies, even in a business context. Purely anonymous or company-level data (for example number of employees or revenue) is not personal data.

    On what legal ground does Drimble process business contact details?

    Primarily legitimate interest (article 6(1)(f) GDPR). B2B prospecting is a recognised legitimate interest, provided a documented balancing test is performed and people can easily object. We honour every objection and erase data on request.

    How do I remove my data from Drimble?

    Send an email to support@liplyn.com with the email address or name concerned. We confirm removal within 30 days and add the record to our suppression list so it is not re-imported. Remove my data

    Does Drimble sell my data?

    Drimble provides licensed access to B2B company and contact data to business customers under a data processing and license agreement. Customers must use the data lawfully, including having their own lawful basis for outreach and honouring opt-outs.

    Where is Drimble data stored?

    On servers within the European Union, encrypted in transit and at rest. Access is limited to authorised team members on a need-to-know basis.

    Questions about GDPR or your data?

    Email us and our team will help you with access, correction or removal requests.

    Email our privacy team