Arista Demand is dedicated to maintaining the highest standards of data security, privacy, and regulatory compliance. This General Data Protection Regulation (“GDPR”) Notice outlines how we process personal data of individuals located within the European Union (EU), European Economic Area (EEA), and United Kingdom (UK) under Regulation (EU) 2016/679 (EU GDPR) and the UK Data Protection Act 2018 (UK GDPR).
As a modern B2B demand generation and intelligence engine, our operations are designed with privacy-by-design principles at their core. We ensure that all processing of business professional contact data and buying cohort intelligence is conducted lawfully, transparently, and securely.
2. Data Controller vs. Data Processor Roles
Depending on the nature of your interaction with Arista Demand, we may act in one of two capacities under European data protection legislation:
- Data Controller: When you browse Our Site (www.aristademand.com), register for our webinars, subscribe to our newsletters, or when we independently curate and maintain our proprietary B2B cohort intelligence database, Arista Demand acts as a Data Controller deciding the purposes and means of processing.
- Data Processor: When we deliver customized lead generation campaigns, content syndication programs, or tele-verification services on behalf of our enterprise clients using client-provided criteria or account lists, Arista Demand acts as a Data Processor pursuant to Article 28 Data Processing Agreements (DPAs) executed with those clients.
3. Lawful Bases for Data Processing
Under Article 6 of the GDPR, Arista Demand only processes personal data where a valid legal basis exists:
- Legitimate Interests (Art. 6(1)(f)): Processing B2B corporate contact information for relevant commercial communications, market research, and audience cohort modeling where our commercial interests do not override individual fundamental rights and freedoms.
- Consent (Art. 6(1)(a)): When you voluntarily register to download sponsored whitepapers, opt into direct email newsletters, or agree to non-essential website tracking cookies. You may withdraw consent at any time.
- Contractual Necessity (Art. 6(1)(b)): Where processing is essential for the performance of a service agreement, client insertion order, or vendor contract to which you are party.
- Legal Obligation (Art. 6(1)(c)): Retaining transaction history, accounting records, or compliance suppression files to satisfy statutory legal and fiscal requirements.
4. Categories of B2B Data Processed
Arista Demand specializes strictly in corporate B2B intelligence. We do not gather consumer personal data or special category data. The data elements we maintain include:
- Professional Full Name
- Corporate Business Email Address
- Direct or Corporate Switchboard Telephone Number
- Current Employer / Organization Name & Website
- Job Title, Department, and Management Level (Seniority)
- Company Industry, Employee Headcount, and Office City/Country
- Topical B2B Content Consumption and Intent Engagement Signals
No Special Category Data: We never collect or process data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic/biometric data, health information, or sexual orientation.
5. Legitimate Interest Assessment (LIA) for B2B Direct Marketing
Recital 47 of the GDPR explicitly recognizes that the processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest. Arista Demand conducts comprehensive Legitimate Interest Assessments (LIAs) encompassing a three-part test:
- Purpose Test: Establishing that the B2B demand generation, content syndication, and cohort intelligence serve legitimate commercial objectives.
- Necessity Test: Confirming that the processing is proportionate and necessary to connect relevant technology vendors with interested business decision-makers.
- Balancing Test: Evaluating individual impact to confirm that professional data subjects within business roles reasonably expect relevant industry communications, accompanied by prominent, hassle-free opt-out mechanisms in every communication.
6. Your Rights Under the GDPR
EU and UK data subjects possess robust statutory rights regarding their personal data under Chapter III of the GDPR:
- Right of Access (Art. 15): Request confirmation whether your personal data is being processed and obtain a copy of the specific records we hold.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete corporate contact data without undue delay.
- Right to Erasure / “Right to be Forgotten” (Art. 17): Request deletion of your personal data when it is no longer necessary or when you withdraw consent.
- Right to Restriction of Processing (Art. 18): Restrict processing during verification periods or disputes over accuracy.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing at any time. Upon objection, we will immediately cease marketing communications.
- Right not to be Subject to Automated Decision-Making (Art. 22): Protect against decisions based solely on automated processing that significantly affect you.
7. How to Exercise Your Rights (30-Day Response)
You can exercise any of your GDPR rights free of charge by contacting our Data Protection Officer at [email protected].
We respond to all verified data subject requests as quickly as possible, and in any case within thirty (30) calendar days from receipt of your request. If the request is unusually complex or involves high volume, this period may be extended by up to an additional two months, with formal written notification provided within the initial 30 days.
When an erasure request is executed, your email address is added to an internal suppression list to ensure you are never re-contacted in future client campaigns.
8. International Data Transfers & Standard Contractual Clauses (SCCs)
Arista Demand’s cloud infrastructure is securely hosted on Amazon Web Services (AWS) facilities. Where personal data originating in the EU/EEA or UK is transferred to or accessed from countries outside the European Economic Area, we implement robust transfer mechanisms recognized under Chapter V of the GDPR:
- European Commission approved Standard Contractual Clauses (SCCs) (Module 1 and Module 2).
- The UK International Data Transfer Addendum (IDTA) for transfers governed by UK law.
- Transfer Impact Assessments (TIAs) confirming destination countries provide adequate legal safeguards.
- Technical encryption at rest (AES-256) and in transit (TLS 1.3) across all cloud repositories.
9. Technical & Organizational Security Measures (TOMs)
Pursuant to Article 32 of the GDPR, Arista Demand enforces state-of-the-art technical and organizational measures to ensure a level of security appropriate to data risk:
- High-grade encryption of all databases, backups, and transmissions.
- Role-based access controls (RBAC) and mandatory multi-factor authentication (MFA).
- Regular penetration testing, vulnerability scanning, and routine security patching.
- Comprehensive security awareness and GDPR compliance training for all employees.
- Strict vendor risk management and mandatory DPAs for all sub-processors.
10. Data Breach Notification Procedures
Arista Demand maintains an Incident Response Protocol. In the unlikely event of a personal data breach posing risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33. Affected data subjects will be notified without undue delay when required under Article 34.
11. Role of the Data Protection Officer (DPO)
To oversee ongoing regulatory adherence, Arista Demand has appointed a qualified Data Protection Officer (DPO). Our DPO monitors compliance with the GDPR, advises internal stakeholders on data protection impact assessments, and acts as the official liaison point for supervisory authorities and data subjects.
12. Right to Lodge a Complaint with a Supervisory Authority
If you believe that our processing of your personal data infringes the GDPR, you have the statutory right under Article 77 to lodge a formal complaint with an EU data protection supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement. In the UK, you may lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
13. Contact Our Data Protection Officer
For inquiries regarding GDPR compliance, data subject access requests, or Data Processing Agreements (DPAs), please contact our compliance team:
EU & UK Data Protection Inquiries
Submit data subject access requests, erasure notices, or DPA inquiries directly to our Data Protection Officer.
Email [email protected]