Privacy Policy

ELP Data — B2B Data Intelligence Platform

Last Updated: May 2025

ELP Data ("ELP Data," "we," "us," or "our") is committed to protecting your privacy and handling your personal data with transparency, integrity, and care. This Privacy Policy explains how we collect, use, share, and safeguard information when you visit our website at www.elpdata.com, use our services, or interact with us in any way.

By accessing or using our website and services, you agree to the terms of this Privacy Policy. If you do not agree with any part of this policy, please refrain from using our services. We encourage you to read this policy carefully and contact us if you have any questions or concerns.

This policy applies to all visitors, customers, prospects, and business partners who interact with ELP Data through any channel, including our website, email communications, telephone conversations, and data delivery services. We take our responsibilities as a data controller and processor seriously, and we are committed to full compliance with applicable data protection laws worldwide.

1Data We Collect

ELP Data collects several categories of information depending on how you interact with our platform and services. We collect information you provide to us directly, information we gather automatically, and business data we compile as part of our core B2B data intelligence services.

Information You Provide Directly

When you contact us via our website forms, request a free data sample, place an order, or communicate with our team, you provide us with personal information such as your full name, business email address, company name, job title, phone number, and the nature of your data requirements. This information is used solely to process your request and respond to your inquiry.

Information Collected Automatically

When you visit our website, we automatically collect certain technical data including your IP address, browser type and version, operating system, referring URL, pages viewed, time spent on pages, and other clickstream data. This information is collected through cookies, web beacons, and similar tracking technologies to help us improve our website and understand user behavior.

B2B Contact Data

As a B2B data intelligence company, ELP Data compiles business contact information from publicly available sources, licensed data providers, trade publications, company websites, and professional directories. This data includes business names, job titles, company information, professional email addresses, and business phone numbers. This data relates to individuals in their professional capacity and is used exclusively for legitimate B2B marketing and sales purposes.

2How We Use Your Data

We use the information we collect for specific, legitimate business purposes. We do not sell your personal data to third parties, and we do not use your data for purposes beyond what is described in this policy without your consent.

  • To respond to your inquiries and fulfill your data requests
  • To process transactions and deliver purchased data products
  • To send you important account and service updates
  • To improve and personalize your experience on our website
  • To analyze website traffic and usage patterns for product improvement
  • To send marketing communications where you have consented
  • To comply with legal obligations and regulatory requirements
  • To detect and prevent fraud, abuse, or security incidents
  • To enforce our Terms of Service and other agreements

Our legal basis for processing personal data includes: performance of a contract (when processing is necessary to fulfill a service you have requested), legitimate interests (for analytics, fraud prevention, and marketing to existing customers), consent (where you have explicitly opted in), and compliance with legal obligations. You may withdraw consent at any time by contacting us at info@elpdata.com.

3Data Sharing & Third Parties

ELP Data does not sell, rent, or trade your personal information to third parties for their own marketing purposes. We may share your data only in the limited circumstances described below, and always with appropriate safeguards in place.

Service Providers

We work with carefully selected third-party service providers who assist us in operating our website, processing payments, delivering email communications, providing customer support, and analyzing website usage. These providers are contractually obligated to handle your data only as instructed by ELP Data and to maintain appropriate security measures. Examples include payment processors, email delivery services, and cloud hosting providers.

Legal Requirements

We may disclose your personal data if required to do so by law, court order, or government authority, or if we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of ELP Data, our customers, or the public. We will notify you of such disclosures unless prohibited by law.

Business Transfers

In the event of a merger, acquisition, asset sale, or other business restructuring, your personal data may be transferred to the acquiring entity. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy. You will have the right to object to such a transfer where applicable under law.

4Data Retention

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory obligations, and to resolve disputes and enforce our agreements. The specific retention period depends on the type of data and the purpose for which it is used.

Customer account data and transaction records are retained for a minimum of seven years to comply with financial and tax regulations. Marketing data and communication preferences are retained for up to three years from the date of last meaningful interaction. Website analytics data is retained in aggregated, anonymized form and may be kept indefinitely.

B2B contact data included in our database products is regularly reviewed and updated to maintain accuracy. Records that become outdated, inaccurate, or no longer serve a legitimate business purpose are removed from our active database during quarterly data hygiene processes. We use a combination of automated and manual review procedures to ensure data quality.

If you request deletion of your personal data, we will process your request within 30 days, subject to any legal obligations that require us to retain certain records. Even after deletion from active systems, anonymized or aggregated data derived from your information may be retained for analytical purposes. We will confirm deletion in writing upon completion.

5GDPR Rights — EU/EEA Users

If you are located in the European Union or European Economic Area, you have specific rights under the General Data Protection Regulation (GDPR) regarding your personal data. ELP Data is committed to honoring these rights and has established processes to facilitate your requests promptly and transparently.

Right to Access

Request a copy of all personal data we hold about you

Right to Rectification

Request correction of inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data ('right to be forgotten')

Right to Restrict Processing

Request that we limit how we use your data

Right to Data Portability

Receive your data in a structured, machine-readable format

Right to Object

Object to processing based on legitimate interests or direct marketing

To exercise any of these rights, please submit a written request to info@elpdata.com with the subject line "GDPR Data Request." We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For cross-border data transfers, we use Standard Contractual Clauses approved by the European Commission to ensure adequate protection.

6CCPA Rights — California Users

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights regarding your personal information. These rights apply to consumers and, where applicable, to employees and job applicants in California.

Under the CCPA, you have the right to know what personal information we collect about you, the right to know whether we sell or disclose your personal information and to whom, the right to opt out of the sale of your personal information, the right to request deletion of your personal information, and the right to non-discrimination for exercising these rights.

ELP Data does not sell personal information as defined under the CCPA. We do not discriminate against consumers who exercise their CCPA rights. We will not deny you goods or services, charge you different prices, or provide a different quality of service based on your exercise of these rights.

To submit a CCPA request, please email us at info@elpdata.com with the subject line "CCPA Privacy Request" or use the contact form on our website. We will verify your identity and respond within 45 days. California residents may also designate an authorized agent to submit requests on their behalf by providing written authorization.

7Data Broker Registration & State Compliance

Applies to residents of California, Vermont, Texas, Oregon, and other U.S. states with data broker laws

ELP Data operates as a data broker — we compile, maintain, and license B2B contact and company data for marketing and business intelligence purposes. Several U.S. states have enacted laws requiring data brokers to register with state authorities and provide consumers with rights over their data. ELP Data is committed to full compliance with all applicable state data broker registration requirements.

🏛️

California — CCPA & Data Broker Registry

Under the California Consumer Privacy Act (CCPA) and the Delete Act (SB 362, effective 2024), data brokers that collect and sell personal information about California residents must register annually with the California Privacy Protection Agency (CPPA) and participate in the state's data deletion mechanism.

  • California residents may request access to, correction of, or deletion of their personal data
  • You have the right to opt out of the sale or sharing of your personal information
  • ELP Data does not sell consumer personal data — our database contains professional B2B contact information only
  • To submit a California privacy request: email info@elpdata.com with subject "California Data Request"
🏔️

Vermont — Data Broker Law (9 V.S.A. § 2446)

Vermont's data broker law requires companies that acquire and sell personal data of Vermont residents to register annually with the Vermont Secretary of State and disclose their data collection and opt-out practices. ELP Data complies with Vermont's registration requirements.

  • Vermont residents have the right to opt out of having their personal data sold
  • We provide a clear opt-out mechanism: email info@elpdata.com with subject "Vermont Opt-Out Request"
  • We will process your opt-out within 45 days and confirm in writing

Texas — Texas Data Privacy and Security Act (TDPSA)

The Texas Data Privacy and Security Act (TDPSA), effective July 2024, grants Texas residents rights over their personal data and requires data brokers to maintain registration with the Texas Secretary of State. Controllers and processors of personal data are required to recognize and respond to consumer privacy rights.

  • Texas residents may access, correct, delete, and port their personal data
  • You have the right to opt out of targeted advertising, sale of personal data, and profiling
  • To exercise your rights: email info@elpdata.com with subject "Texas Privacy Request"
  • We will respond within 45 days, with a possible 45-day extension for complex requests
🌲

Oregon — Oregon Consumer Privacy Act (OCPA)

The Oregon Consumer Privacy Act (OCPA), effective July 2024, establishes privacy rights for Oregon residents and imposes obligations on data controllers, including data brokers. Oregon residents are entitled to know what personal data is being processed about them and to request deletion or correction.

  • Oregon residents may request access to the categories of personal data being processed
  • You have the right to correct inaccurate personal data and request deletion
  • You may opt out of the sale of personal data and targeted advertising
  • To submit an Oregon privacy request: email info@elpdata.com with subject "Oregon Privacy Request"
🗺️

Other States — Virginia, Colorado, Connecticut, Montana, Indiana & More

Additional U.S. states have enacted comprehensive consumer privacy laws that may grant you rights over personal data held by data brokers. These include the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Montana Consumer Data Privacy Act (MCDPA), and Indiana Consumer Data Protection Act (INCDPA), among others.

Regardless of your state of residence, ELP Data honors privacy rights requests from all U.S. residents. Contact us at info@elpdata.com and we will respond in accordance with the most protective applicable law in your state.

⚠ How to Submit a Data Broker Opt-Out Request

Email info@elpdata.com with the subject line "Data Broker Opt-Out — [Your State]". Include your full name and, if possible, the email address associated with any data ELP Data may hold about you. We will process all requests within 45 days and confirm removal in writing.

8Cookies Policy

ELP Data uses cookies and similar tracking technologies to enhance your experience on our website, analyze usage patterns, and deliver relevant content. A cookie is a small text file placed on your device when you visit a website. Cookies do not contain personally identifiable information on their own, but they can be combined with other data to identify you.

Cookie TypePurposeDuration
Essential CookiesRequired for website functionality, security, and navigationSession
Analytics CookiesMeasure traffic, page views, and user behavior (Google Analytics)Up to 2 years
Preference CookiesRemember your settings and preferencesUp to 1 year
Marketing CookiesTrack campaign performance and ad effectivenessUp to 90 days

You can control cookie settings through your browser preferences. Most browsers allow you to refuse cookies, delete existing cookies, and set preferences for specific websites. Please note that disabling certain cookies may affect the functionality of our website. For EU users, we display a cookie consent banner that allows you to choose which non-essential cookies you accept. You can update your preferences at any time.

9Security

ELP Data takes the security of your personal data seriously. We implement and maintain a comprehensive set of technical, administrative, and physical security measures designed to protect your information from unauthorized access, disclosure, alteration, or destruction.

Our technical security measures include SSL/TLS encryption for all data transmitted between your browser and our servers, encryption of data at rest for sensitive records, access controls and authentication requirements for all staff who handle personal data, regular security audits and vulnerability assessments, and automated monitoring systems to detect and respond to potential threats.

Our administrative security measures include employee training on data protection and privacy best practices, strict need-to-know access policies, non-disclosure agreements for all staff and contractors, and documented data handling procedures. Physical security measures include secure data centers with restricted access controls, environmental protections, and redundant systems.

Despite our best efforts, no security system is completely impenetrable. In the unlikely event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law, typically within 72 hours of discovery. We will provide you with information about the nature of the breach, what data was affected, and the steps we are taking to address it.

10Children's Privacy

ELP Data's services are designed exclusively for business professionals and are not directed at children under the age of 16. We do not knowingly collect personal information from anyone under the age of 16. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at info@elpdata.com and we will take prompt action to remove that information from our systems.

Our website does not include content designed to attract children, and we do not use any marketing techniques targeted at minors. All of our marketing and data services are targeted exclusively at business decision-makers and professionals in a B2B context. We take our responsibility to protect minors seriously and will cooperate fully with any legal authority regarding the protection of children's privacy rights.

11International Data Transfers

ELP Data operates globally and may transfer your personal data to countries other than the country in which you reside. These countries may have data protection laws that differ from those in your country. When we transfer data internationally, we take steps to ensure that appropriate safeguards are in place to protect your information.

For transfers from the European Economic Area to countries not deemed "adequate" by the European Commission, we rely on Standard Contractual Clauses (SCCs) as our primary transfer mechanism. For transfers from the UK following Brexit, we use UK-approved international data transfer agreements. We conduct transfer impact assessments where required and implement supplementary measures where necessary.

Our primary data storage and processing infrastructure is located in the United States. If you are located outside the United States and choose to use our services, please be aware that your information will be transferred to and processed in the United States. By using our services, you consent to this transfer and processing in accordance with this Privacy Policy.

12Changes to This Policy

ELP Data reserves the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes to this policy, we will notify you by updating the "Last Updated" date at the top of this page and, where appropriate, by sending an email notification to affected users.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website and services after any changes to this Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should discontinue use of our services and contact us to request deletion of your data.

13Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below. We are committed to addressing your concerns promptly and transparently.

ELP Data — Data Privacy Team

Email: info@elpdata.com

Website: www.elpdata.com

Subject Line: "Privacy Policy Inquiry"

For GDPR-related requests, please use subject line "GDPR Data Request." For CCPA requests, use subject line "CCPA Privacy Request." We will acknowledge your request within 2 business days and provide a substantive response within the timeframes required by applicable law.

Contact Us