What we collect when you use this site, work with us, or get an email from a campaign we run — why we hold it, who we share it with, and how to have it removed. Written to be read, not skimmed past.
Last updated 10 September 2026
Irongate Outbound is a B2B lead generation and appointment-setting agency based in Lahore, Punjab, Pakistan. Our clients are mainly in the United States and the United Kingdom. This policy covers irongateoutbound.com, the inquiries and calls that come through it, and the outbound campaigns we run for clients.
Plain version: we hold very little personal data about anyone, we never sell it, and we only email people at work about work. The sections below say exactly how that works and what you can ask us to do.
Where we are the controller. For our website visitors, people who send us an inquiry or book a call, and our own client contacts and business records, we decide what is collected and why. That data is ours to look after and this policy is your notice for it.
Where we are the processor. For prospect lists, campaign sending, and replies handled on behalf of a client, the client is the controller and we act strictly on their documented instructions. We do not use that data for our own marketing, do not merge it into our own lists, and delete or return it when the engagement ends. If you were contacted by a campaign and want your data removed, we will action the suppression immediately and pass the request to the client who is responsible for it.
Site visitors. Standard server and security logs from our host, including IP address, approximate location, referrer, and user agent. We do not run advertising or cross-site tracking.
Inquiries and calls. Whatever you type into the inquiry form or the booking page: name, work email, company, website, what you sell, who you sell to, budget range, and any notes. Plus our own notes from the call.
Clients. Contact details for the people we work with, campaign settings, invoicing and payment records, and correspondence.
Prospects, on behalf of clients. Business contact data only: full name, job title, employer, business email address, company size and industry, public company information, and public professional profile details such as a LinkedIn URL. Plus campaign metadata: sends, opens, replies, bounces, opt-outs, and meeting bookings. We do not collect personal email addresses, home addresses, phone numbers scraped from personal profiles, or any special category data.
Children's data. Our site and services are exclusively for businesses and professionals. We do not knowingly collect personal data from anyone under the age of 18. If we learn that we hold data about a minor, we delete it.
Prospect data is sourced from public professional profiles, company websites, public registers, and licensed business data providers, then verified before use. Lists are built to a defined ideal customer profile and bounce-checked; they are not bought in bulk or resold.
Under the UK GDPR our lawful basis for this processing is legitimate interests: B2B direct marketing, sent to a named business role, at a business address, about a proposition relevant to that person's work. We keep a legitimate interests assessment on file, balance it against the rights of the people contacted, keep volumes and data minimal, and stop immediately on objection.
For email specifically we rely on the corporate subscriber position under PECR: marketing email may be sent to corporate bodies such as limited companies, LLPs, and public bodies without prior consent, provided the sender is identified and an opt-out is offered. Sole traders, individual partnerships, and personal mailboxes are treated as individual subscribers and are screened out of our lists. In the US we operate on a CAN-SPAM basis: accurate headers, honest subject lines, a valid postal address, and opt-outs honoured within ten business days at the latest.
Every email tells you who is writing, why you are being contacted, and how to stop it. Reply with "no thanks", or use the opt-out link, and that is the end of it.
To answer your inquiry and hold a first call; to run, monitor, and report on campaigns for clients; to keep sending infrastructure healthy and compliant; to invoice and keep accounting records; to maintain suppression lists so that people who opted out are not contacted again; and to protect our systems against abuse.
We do not use any of this to build advertising profiles, and we do not make automated decisions that have a legal or similarly significant effect on anyone.
We use a small number of trusted providers to run the service. They process data on our instructions under contract, only for the purpose we engaged them for.
Instantly.ai — campaign sending, sequencing, and reply tracking. Zoho Mail — our workspace, sending mailboxes, and correspondence. Netlify — website hosting, forms, and security logs. Calendly — call booking. Anthropic (Claude) and n8n — AI drafting and workflow automation used to research and personalise campaign copy; prospect data sent to these tools is limited to business contact and company information, and is not used to train third-party models. Domain registrars, DNS, and data enrichment providers where a campaign needs them, plus our accountants and, if we ever have to, our lawyers.
We tell clients before we add or replace a sub-processor that touches their data, so they can object. We never sell personal information, and we do not share it for cross-context behavioural advertising.
Our clients and the people we contact are mainly in the US and UK; our team works from Lahore, Pakistan, and some of our providers are in the US and the EU. That means personal data is transferred outside the UK and EEA.
For UK and EEA data we protect those transfers using the UK International Data Transfer Agreement, or the European Commission's Standard Contractual Clauses together with the UK Addendum, backed by a transfer risk assessment and technical measures including encryption in transit and at rest, access limited to the people working on the engagement, and multi-factor authentication. Copies of the relevant transfer instruments are available to clients on request.
Inquiries that do not become engagements: up to 12 months. Client records and correspondence: for the engagement plus 7 years, where tax and accounting law requires it. Prospect and campaign data processed for a client: for the engagement, then deleted or returned within 30 days of termination unless the client instructs otherwise.
Suppression lists are the exception. We keep the minimum record needed, usually an email address or its hash, for as long as we operate, because that is the only way to guarantee someone who opted out is never contacted again.
Wherever you are, you can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to direct marketing, or ask for your data in a portable format. Email hello@irongateoutbound.com and we will respond within 30 days.
UK and EEA. These are your rights under the UK GDPR and the Data Protection Act 2018, including the right to object to processing based on legitimate interests. You can complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority.
California and other US states. You have the right to know what we collect and why, to access and delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of on that front. We will not treat you differently for exercising a right, and an authorised agent may act for you with written proof.
Where we hold data as a processor for a client, we will forward your request to that client and action it on their instruction, and we will tell you who they are.
We may ask for enough information to confirm who you are before we act, but never more than we need.
Every campaign email includes an opt-out. You can also reply with a single line asking us to stop, or email hello@irongateoutbound.com.
Opt-outs go onto a master suppression list that applies across every sending domain and mailbox we operate, for that client and for us. It is applied immediately on receipt, and always well inside the ten business days CAN-SPAM allows. You do not need to give a reason, and you will not be added back by a later list build.
The site sets no advertising or tracking cookies. A single local preference is stored in your browser to remember whether you chose light or dark mode; it never leaves your device and identifies nobody. Our host keeps short-lived security and traffic logs. Booking a call loads Calendly, which sets its own cookies under its own policy.
The site is served over HTTPS. Access to inquiry data, mailboxes, and campaign platforms is limited to the people working on the engagement, protected by multi-factor authentication and unique credentials. Data is encrypted in transit and at rest by our providers.
No system is perfectly secure. If a breach affects your personal data we will notify you and, where the law requires it, the relevant regulator, without undue delay and within 72 hours of becoming aware where UK GDPR applies.
If this policy changes materially we will update the date at the top of the page and, for clients, tell you directly. Continuing to use the site after a change means the revised version applies.
Privacy requests, questions, and complaints: hello@irongateoutbound.com. We answer these ourselves; there is no ticket queue.
Postal address: Amir Road, Shad Bagh, Lahore 56000, Punjab, Pakistan. This is the address published in our campaign email footers, as CAN-SPAM requires.
We are not currently required to appoint a UK or EU representative or a statutory data protection officer. If that changes, the details will be published here.
Questions about this page? Email hello@irongateoutbound.com. This page describes how we operate and is not legal advice.