Skip to content

Where our data comes from. And where it doesn't.

Intent data is only useful if you can trust it. Here's exactly how we source, verify and protect business contact data, and how anyone can opt out.

Your prospect data sits inside a certified security and quality program, so it clears procurement and InfoSec review faster.

ISO/IEC 27001

Information security

An independently audited information security management system covering how we collect, store and deliver data.

SOC 2 Type II

Security controls, tested over time

An independent auditor has tested our security controls in operation over a sustained period, not just on paper.

ISO 9001

Quality management

Documented, audited processes for how programs are specified, verified and delivered, so quality is repeatable.

Need evidence for a vendor review? We share our SOC 2 Type II report and ISO certificates under NDA. Request security documentation.

United States

Consented opt-in on every lead, state-by-state opt-out handling and suppression synced before each delivery.

  • CCPA / CPRA
  • 20 state privacy laws
  • CAN-SPAM
  • TCPA
  • Global Privacy Control

United Kingdom

Lawful basis recorded per record, PECR-compliant email to corporate subscribers, and screened calling lists.

  • UK GDPR
  • Data (Use and Access) Act 2025
  • PECR
  • TPS / CTPS

Canada

Express consent captured for commercial messages, sender identification on every email, and Quebec opt-in rules.

  • PIPEDA
  • Quebec Law 25
  • CASL
  • DNCL

Three sources, all documented

First-party publisher engagement

Readers of IntentBuy, our technology publication, who register for content or newsletters and agree to be contacted about related offers.

Program opt-ins

Professionals who request an asset, register for an event or agree to a call through a BootSoc program, with the consent text and timestamp stored.

Maintained business contact data

Work contact details (name, title, company, business email and phone) compiled from public professional sources and re-verified on a rolling cycle. Used to reach professionals about offers relevant to their role, with an opt-out in every message.

We don't buy scraped personal email lists, and we don't use co-registration or incentivised downloads to inflate lead volume.

Lawful basis, market by market

United States

  • Notice at collection and a clear opt-out in every message (CAN-SPAM, state privacy laws)
  • Opt-in consent recorded for every lead delivered to a client
  • Global Privacy Control and “Do Not Sell or Share” requests honored
  • Calling screened against the National Do Not Call Registry and state lists (TCPA)

United Kingdom

  • Legitimate interests, with a documented balancing test, for B2B outreach to corporate subscribers (UK GDPR, PECR)
  • Consent for any lead passed to a client, identified by name at the point of opt-in
  • Calls screened against TPS and CTPS
  • Data subject rights answered within one month

Canada

  • Express consent for commercial electronic messages, or a documented CASL exemption such as conspicuous publication
  • Sender identification and a working unsubscribe in every message, honored within 10 business days
  • Opt-in for tracking technologies and a named privacy officer for Quebec (Law 25)
  • Calling screened against the National DNCL

Controls that protect people, not just clients

Global suppression

Every opt-out joins a global suppression list checked before each send and each delivery, across all clients.

No sensitive data

We don't collect or infer health, financial account, precise location, children's or other sensitive personal data.

Security by default

ISO/IEC 27001 certified and SOC 2 Type II audited: encryption in transit and at rest, least-privilege access, audit logging and signed data processing terms with every vendor.

Policies and documents

Privacy questions: privacy@bootsoc.com

Can I find out what data BootSoc holds about me?

Yes. Submit a request through our privacy request form or email privacy@bootsoc.com. We verify your identity by email and respond within the time your law requires: 45 days in the US, one month in the UK and EU, and 30 days in Canada.

How do I stop BootSoc from contacting me?

Use the unsubscribe link in any email, tell our caller, or submit an “unsubscribe” request. Your address joins our global suppression list, and we stop contact within 10 business days at the latest.

Can we see your SOC 2 report or ISO certificates?

Yes. We hold ISO/IEC 27001, ISO 9001 and SOC 2 Type II. Email privacy@bootsoc.com and we'll share the SOC 2 Type II report and certificates under NDA for your vendor review.

Is BootSoc a data broker?

Some of our activities, such as maintaining business contact data about people we don't have a direct relationship with, can meet the definition of a data broker under certain US state laws. Where they do, we register with that state and process deletion requests through its official mechanism, including California's Delete Request and Opt-out Platform.

Do you sell personal data?

We deliver leads to clients only when the person has opted in to hear from that client. Under some US state laws, other sharing for advertising may count as a “sale” or “sharing”. You can opt out at any time through Your privacy choices or by using Global Privacy Control.

Let's plan next quarter's pipeline.

A 30-minute call with a strategist. You leave with a target spec, audience size and a program plan, whether or not we work together.

Privacy choices

Choose which optional cookies we may use. You can change this any time from “Your privacy choices” in the footer.