1. Who we are and when this notice applies
Auctaris is the trading name of Ghulam Mustafa Mahmood, a sole trader based in England. Auctaris provides business-to-business sales, prospect-research, lead-generation, outreach, qualification and meeting-booking services.
For some activities, Auctaris acts as a Controller because it decides why and how personal data is processed. For example, Auctaris acts as a Controller for its own enquiries, contracts, invoices, website operations, security, business contacts, legal compliance and suppression records.
For some client campaigns, Auctaris may act as a Processor where the client determines the purpose and essential means of processing and Auctaris acts only on the client’s lawful documented instructions. In those circumstances, the client’s privacy notice and the applicable data-processing agreement may also apply.
The legal role of each party depends on what each party actually decides and does in relation to the relevant processing activity, rather than on the label used in a document.
2. Contact details
- Business
- Ghulam Mustafa Mahmood trading as Auctaris
- Address
- 9 Rydall Terrace, Leeds, West Yorkshire, England, LS11 9LD
- info@auctaris.co.uk
- Website
- https://auctaris.co.uk
3. Personal data we may collect
Depending on the relationship and activity, Auctaris may collect and process:
- Names, job titles, professional roles and employer or organisation details.
- Professional email addresses, business telephone numbers and business addresses.
- LinkedIn and other professional-profile information.
- Information about professional responsibilities, seniority, business interests and potential relevance to a campaign.
- Communication records, replies, preferences, objections and suppression information.
- Meeting, appointment, calendar and scheduling information.
- Prospect qualification information and campaign engagement records.
- Client, prospective-client, supplier and professional-contact information.
- Proposal, contract, invoice, payment and accounting information.
- Website technical information, including IP address, browser and device information, page requests, security information and server logs.
- Chatbot messages, session information and associated technical records when a visitor chooses to use the chatbot.
- Cookie, local-storage and similar technology information where relevant.
- Other information reasonably necessary for a business enquiry, service delivery, lawful outreach or the management of a professional relationship.
Special-category and criminal-offence data. Auctaris does not intend to collect special-category personal data or criminal-offence data as part of its ordinary activities. Individuals and clients should not provide this information unless it is genuinely necessary, lawful and specifically requested.
4. How we obtain personal data
- Directly from individuals through the website, email, telephone, social media, meetings, consultation bookings, chatbot conversations or other business communications.
- From clients who provide information about employees, representatives, customers or prospective customers for the delivery of agreed services.
- From publicly available business sources, including company websites, professional networking platforms such as LinkedIn, Companies House and business directories.
- From reputable business-data, prospecting, verification, data-enrichment and lead-generation providers.
- From referrals, suppliers, professional advisers and other legitimate business contacts.
- Automatically through website hosting, security tools, server logs and storage or access technologies used to operate the website and connected services.
Information obtained indirectly. Where Auctaris obtains personal data from a source other than the individual, Auctaris will provide or make this Privacy Notice available within a reasonable period and no later than one month after obtaining the information. If Auctaris communicates with the individual or discloses the information earlier, the notice will be provided or made available by the time of the first communication or disclosure, whichever occurs first, unless a lawful exception applies.
In practice, an appropriate outreach communication may contain a direct link to this Privacy Notice.
5. Why we use personal data
- To respond to enquiries and arrange consultations.
- To prepare proposals, enter into agreements and manage client relationships.
- To provide, manage, monitor and improve Auctaris’s services.
- To research and identify suitable businesses and professional contacts for targeted business-to-business campaigns.
- To conduct lawful business-to-business outreach by email, LinkedIn, telephone or another appropriate channel.
- To qualify prospective customers and arrange meetings between prospects and Auctaris clients.
- To maintain campaign records, measure performance and prepare reports.
- To communicate with clients, prospective clients, suppliers, advisers and other professional contacts.
- To manage calendars, meetings, reminders and follow-up communications.
- To manage invoices, payments, accounting, tax and business administration.
- To operate, maintain, troubleshoot and protect the website, chatbot, email, CRM and other systems.
- To prevent fraud, spam, misuse, cyber incidents and other unlawful activity.
- To comply with legal, regulatory, tax, accounting and record-keeping obligations.
- To establish, exercise or defend legal rights and claims.
- To maintain suppression and do-not-contact records.
- To promote Auctaris’s own services to relevant professional contacts where permitted by law.
- To support a genuine business sale, restructuring, investment or transfer, subject to appropriate safeguards.
Auctaris will not use personal data for a purpose that is incompatible with the purpose for which it was collected unless the new use is permitted or required by law.
6. Lawful bases for processing
Auctaris identifies and documents an appropriate lawful basis before processing personal data. The basis may vary according to the activity and the relationship involved.
| Processing activity | Lawful basis or legal position |
|---|---|
| Responding to enquiries and taking steps requested before entering into an agreement | Contract and legitimate interests. |
| Providing services directly to an individual or sole-trader client | Contract. |
| Communicating with employees, directors or representatives of a corporate client | Legitimate interests. |
| Managing client, supplier and professional relationships | Contract, legitimate interests and legal obligation, depending on the circumstances. |
| Prospect research and targeted outreach involving professional contacts at corporate subscribers, such as limited companies and limited liability partnerships | Legitimate interests, subject to the applicable direct-marketing rules and an appropriate balancing assessment. |
| Electronic marketing to individual subscribers, including sole traders and certain partnerships | Consent or a valid statutory soft opt-in where required by the Privacy and Electronic Communications Regulations. |
| Permitted live telephone marketing | Legitimate interests, subject to preference-service screening and applicable telephone-marketing restrictions. |
| Booking and managing a consultation requested by a prospective client | Legitimate interests in responding to prospective clients and developing business relationships; contract may also apply where steps are requested before an agreement. |
| Invoicing, accounting, tax and statutory records | Legal obligation and legitimate interests. |
| Security, fraud prevention, spam prevention and service integrity | Legitimate interests and, where applicable, legal obligation. |
| Establishing, exercising or defending legal claims | Legitimate interests and legal obligation. |
| Non-essential cookies or similar technologies | Consent. |
| Processing undertaken by Auctaris as a Processor | The relevant client, acting as Controller, is responsible for establishing and documenting the lawful basis. Auctaris processes the data only under lawful documented instructions and the applicable data-processing agreement. |
Important: A client’s instruction is not itself a lawful basis. When Auctaris acts as a Processor, the client remains responsible for identifying the lawful basis applying to the Controller’s processing.
7. Legitimate interests and business-to-business outreach
Auctaris may rely on legitimate interests when processing professional contact information for targeted prospect research, lead qualification, campaign delivery, business development, security and relationship management.
Before relying on legitimate interests, Auctaris considers:
- Whether there is a genuine and lawful interest.
- Whether the processing is necessary and proportionate.
- The nature of the personal data and how it was obtained.
- The individual’s role, expectations and relationship with their organisation.
- The likely effect of the processing on the individual.
- Whether the individual’s rights and interests override the proposed interest.
- Whether additional safeguards, targeting restrictions or data minimisation are appropriate.
Where appropriate, Auctaris documents the assessment in a Legitimate Interests Assessment. Legitimate interests do not override separate consent requirements that may apply under electronic-marketing or cookie legislation.
Direct marketing and the right to object
Individuals have an absolute right to object to the use of their personal data for direct marketing at any time.
- Electronic messages will identify the sender, provide valid contact information and include a clear, straightforward method of opting out where required.
- Auctaris will not knowingly send unsolicited electronic marketing to a sole trader or another individual subscriber unless valid consent, a valid soft opt-in or another lawful exception applies.
- Before permitted live marketing calls, Auctaris will screen relevant numbers against the Telephone Preference Service, the Corporate Telephone Preference Service and relevant suppression records, where applicable.
- When a person objects or opts out, Auctaris will stop direct marketing and retain only the minimum information required to maintain a suppression or do-not-contact record.
- Suppression information will not be used for marketing and future campaigns will be screened against relevant suppression records.
An individual may object by using the unsubscribe or opt-out method in a communication, replying to the relevant message or contacting info@auctaris.co.uk.
8. Website, enquiry form, booking page and chat services
Auctaris reviewed the website’s storage and network activity on 4 August 2026. The website and connected services operated as described below at the date of this notice. Auctaris will update this notice and its Cookie Policy if the technology changes materially.
Website hosting and server records
Netlify hosts the main Auctaris website. Website hosting and security systems may process technical information such as IP address, browser details, requested pages, timestamps, error data and security events in order to deliver, protect and troubleshoot the website.
Enquiry form
The main website enquiry form opens the visitor’s own email application with a prepared message. The form does not submit the entered information to a website form database. Auctaris receives the information only if the visitor chooses to send the email through their email provider.
Google Fonts
The main website currently loads font files from Google Fonts. When a browser requests those files, Google may receive technical connection information such as the visitor’s IP address, browser information and the requested resource.
Auctaris website chatbot
The main website includes an optional chatbot. The website creates a chatbot session identifier in local storage only after the visitor opens the chatbot. The identifier is used to maintain the requested conversation and is treated as expired after 30 days of inactivity and is removed when the website is next used, or earlier if the visitor clears website data or the session is replaced or removed by the system.
Chatbot messages and associated technical records may be processed to provide responses, maintain the conversation, monitor quality, prevent misuse and allow appropriate human review. Visitors should avoid submitting special-category data, confidential information or information that is not necessary for their enquiry.
HubSpot consultation booking page
The “Book a consultation” button opens the HubSpot-hosted scheduling page at meetings.auctaris.co.uk. HubSpot processes the details entered to display available times, arrange the requested meeting, create calendar invitations, send relevant confirmations or reminders and maintain the scheduling service.
The scheduling page uses security and functional technologies supplied by HubSpot, Cloudflare and Google reCAPTCHA. The booking form explains that Auctaris relies on legitimate interests to arrange and manage the consultation and respond to the enquiry, and it links to this Privacy Notice.
Optional HubSpot chat
The separate HubSpot booking page may display an optional chat feature. The chat asks the visitor to agree before enabling the chat and its chat-history technology. HubSpot may monitor and record the chat for quality assurance as explained in the notice displayed in the chat interface.
Analytics and advertising
At the date of the website audit, Auctaris did not identify advertising pixels, social-media tracking pixels or conventional analytics cookies loading automatically on the main Auctaris website. If Auctaris introduces non-essential analytics, advertising or similar technologies, it will provide appropriate information and obtain consent where required before those technologies are used.
Further details about the names, purposes and durations of cookies, local-storage items and similar technologies are provided in the Auctaris Cookie Policy.
10. International transfers
Some service providers or their subprocessors may store, process or access personal data outside the United Kingdom.
Where an international transfer is restricted under UK data-protection law, Auctaris will use an appropriate transfer mechanism, which may include:
- United Kingdom adequacy regulations.
- The United Kingdom International Data Transfer Agreement.
- The United Kingdom Addendum to the European Commission’s Standard Contractual Clauses.
- Another lawful transfer mechanism permitted under applicable data-protection law.
Where required, Auctaris will complete and document an appropriate transfer risk assessment, data-protection test or equivalent assessment and will take reasonable steps to ensure suitable contractual, organisational and technical safeguards.
Individuals may contact Auctaris for further information about the safeguards relevant to a particular transfer.
11. How long we retain personal data
Auctaris retains personal data only for as long as reasonably necessary for the relevant purpose, taking account of legal, accounting, contractual, security and claims-related requirements.
Prospects, enquiries and prospective clients
Auctaris will normally retain prospect and prospective-client personal data for up to 12 months after the most recent meaningful interaction or the end of the relevant outreach campaign, whichever occurs later.
Information may be retained for longer where:
- The person remains actively engaged in business discussions.
- The information becomes part of an ongoing client relationship.
- Retention is necessary to comply with a legal obligation.
- Retention is necessary to establish, exercise or defend legal claims.
- A client lawfully instructs Auctaris to retain or delete Processor-held information under the applicable agreement.
Clients, suppliers, contracts and financial records
Client, supplier, contractual, invoicing, accounting and payment information may be retained for the duration of the relationship and for the applicable legal, tax, accounting and claims periods afterwards.
Website and chatbot information
Website server logs and security records are retained according to the relevant provider configuration and for the period reasonably required for website delivery, security, troubleshooting and abuse prevention. Where chatbot messages contain personal data, Auctaris applies the relevant enquiry, prospect, client, security or legal retention period described in this notice.
The local-storage identifier used by the main website chatbot is treated as expired after 30 days of inactivity and is removed when the website is next used. It may be removed earlier if website data is cleared or the identifier is replaced or removed by the system. The Cookie Policy provides further details about browser storage and third-party technologies.
Suppression records
Where an individual opts out or objects to direct marketing, Auctaris may retain the minimum information necessary on a suppression or do-not-contact list for as long as required to respect that preference. Suppression information will not be used for marketing.
When personal data is no longer required, Auctaris will securely delete or anonymise it, subject to lawful backup cycles and retention obligations.
12. How we protect personal data
Auctaris uses appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, alteration, disclosure or destruction. Measures may include:
- Reputable CRM, email, hosting, cloud-storage and technology providers with appropriate security protections.
- Strong, unique passwords and multi-factor authentication where available.
- Access restrictions based on legitimate business need.
- Encryption in transit and, where supported by the provider, encryption at rest.
- Password-protected and encrypted devices, screen locks, firewalls and security software.
- Software updating, patching and secure configuration.
- Controlled sharing of client, prospect and campaign information.
- Backups and appropriate recovery arrangements.
- Data minimisation, retention review and secure deletion or anonymisation.
- Provider due diligence and appropriate contractual safeguards.
- Confidentiality obligations and data-protection procedures for authorised persons.
- Incident-identification, management, recording and notification procedures.
No electronic transmission or storage system can be guaranteed to be completely secure. Auctaris reviews its measures where appropriate, taking account of the nature of the information and the risks associated with the processing.
13. Automated decision-making
Auctaris does not currently use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.
Auctaris may use software or artificial-intelligence-assisted tools for routine activities such as organising prospect information, scheduling communications, identifying potentially relevant businesses, prioritising outreach, managing campaign records and generating chatbot responses. Appropriate human involvement and oversight will be maintained where a decision could materially affect an individual.
If Auctaris introduces qualifying solely automated decision-making in the future, it will update this Privacy Notice and implement the safeguards required by applicable law.
14. Individual data-protection rights
Depending on the circumstances and the lawful basis, individuals may have the following rights:
- The right to be informed about how personal data is collected and used.
- The right of access to personal data and certain supplementary information.
- The right to rectification of inaccurate or incomplete personal data.
- The right to erasure in certain circumstances.
- The right to restriction of processing in certain circumstances.
- The right to data portability where the legal requirements apply.
- The right to object to processing based on legitimate interests.
- The absolute right to object to direct marketing.
- The right to withdraw consent at any time where processing is based on consent.
- Rights relating to automated decision-making and profiling where applicable.
These rights are not all absolute and may depend on the purpose, lawful basis and any applicable legal exemption. Auctaris may request reasonable information to confirm identity before acting on a request.
Requests may be sent to info@auctaris.co.uk.
Auctaris will respond without undue delay and normally within one month after receiving a valid request. Where permitted by law, that period may be extended by up to two further months because of the complexity or number of requests. If an extension is required, Auctaris will inform the individual within the initial one-month period and explain the reason.
15. Data-protection complaints
Individuals who have concerns about Auctaris’s use of personal data should contact Auctaris first so that the matter can be investigated.
Complaints may be submitted by email to info@auctaris.co.uk or by post to the address in section 2.
Auctaris will:
- Provide an accessible method for submitting a complaint.
- Acknowledge receipt within 30 days.
- Take appropriate steps to investigate and respond without undue delay.
- Keep the complainant informed where additional time is reasonably required.
- Communicate the outcome of the investigation without undue delay.
Complaining to the Information Commissioner’s Office
Individuals also have the right to complain to the Information Commissioner’s Office, the United Kingdom supervisory authority:
- Website
- https://www.ico.org.uk
- Address
- Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Helpline
- 0303 123 1113
- Note
- A complaint to the ICO does not prevent an individual from contacting Auctaris first.
16. Children’s personal data
Auctaris’s services and business-to-business outreach are not directed at children. Auctaris does not knowingly collect children’s personal data as part of its ordinary business activities. If Auctaris becomes aware that children’s personal data has been collected unnecessarily, it will take appropriate steps to delete or otherwise handle it lawfully.
17. Changes to this Privacy Notice
Auctaris may update this Privacy Notice where its services, systems, providers, processing activities or legal obligations change, or where an update is needed to improve transparency or accuracy.
The current version will display a revised “last updated” date. Where a change materially affects how personal data is used, Auctaris will take reasonable steps to bring the change to the attention of affected individuals before beginning the new processing, where required.