Version 2.0. In force from 8 September 2026. This replaces the version published 21 March 2024. Earlier versions are available from dataprivacy@tami.ai.

SalesOptimize Limited, trading as TAMI, is the controller of the personal data described in this policy. We are registered in Ireland at 9 Meath Street, The Liberties, Dublin, D08 Y6XD. Our United Kingdom subsidiary, SalesOptimize (UK) Limited, is named below where it is involved.

We comply with the Data Protection Acts of Ireland, the General Data Protection Regulation of the European Union, and the Data Protection Act 2018 of the United Kingdom.

Any question about this policy, and any request about your own personal data, goes to dataprivacy@tami.ai. That is the only address you need.

1. Our business contact database

TAMI AI holds a database of businesses and the people who work at them. Companies subscribe to it to find their future customers.

 

Where the records come from

We crawl publicly accessible websites and read what is publicly visible on them. We do not collect anything behind a login. Business contact details come from public sources and from licensed commercial data providers. We do not scrape social platforms.

 

What we hold

For a company, we hold its website, industry, size, location, and the technologies that website runs on.

For a person who works there, we hold their name, job title, seniority, department, work email address and company direct dial.

We do not hold home addresses and we do not hold personal telephone numbers.

 

Our lawful basis

We process and disclose this information based on the legitimate interests of our clients and the broader business-to-business community in accessing market intelligence data at both the company and individual employee levels. As the data controller, we have balanced these third-party commercial interests against your individual rights, freedoms, and privacy expectations. You may object to this processing at any time by contacting us at dataprivacy@tami.ai.

 

Telling you that we hold your record

When we add a person to the database we email a publishing notice to their work address. It tells them that we hold a record and how to have it removed.

 

Who receives it

Records in the database are made available to TAMI AI customers as part of the service they subscribe to. We do not sell, trade or license the database to any other third party, and we do not share it with our own marketing or advertising partners.

2. If your details are protected by law

If you are a judge, law enforcement officer, public official, or state employee whose personal information is subject to legal protection or elevated privacy standards, whether under state statutes (such as New Jersey’s Daniel’s Law or the Oklahoma Judicial Security and Privacy Act), European data protection rights, or equivalent international laws, please contact us at dataprivacy@tami.ai. We will honour your request and remove your record within ten business days.

We will stop disclosing your record from that point, although we cannot recall data already delivered to a customer before your request.

TAMI AI holds business contact details drawn from public sources. We do not collect or hold home addresses or personal telephone numbers.

3. Removing your record

You can ask us to remove you from the database at any time, using the removal form on our website or by writing to dataprivacy@tami.ai.

When you ask us to remove you, we delete your individual record and stop disclosing it. Where you are a sole trader, and the company record and the individual record describe the same person, we remove both.

We cannot recall data already delivered to a customer, or already transmitted to an AI assistant, before your request.

4. Personal data we collect from you directly

When you order, register, subscribe, respond to a survey, fill in a form on our website, or become a customer, we may ask for your name, email address, postal address, telephone number, your website, and your payment details where you are buying from us.

We use it to answer your enquiry, to provide and administer the service you have bought, to process payments, to send you information about our products and services, and to improve our website.

5. Automated processing

Some free text written by an individual, such as a profile summary or a published post, is processed by an automated language model before it is returned through our connector. The model condenses that text to its professional content and is designed to remove personal life detail and contact details. It cannot add a fact that the source text did not state. It produces no decision about the individual and has no legal or similarly significant effect on them.

6. The TAMI AI connector for AI assistants

TAMI AI offers a connector, an MCP (Model Context Protocol) server at mcp.tami.ai, that lets you use TAMI AI from within AI assistants such as Claude, ChatGPT, Gemini and Copilot.

When a customer requests data through that connection, the data they request, which may include business contact details, is transmitted to the provider of that assistant and processed on their systems under their terms. The customer directs those requests and acts as controller of the data they retrieve. This happens only where a customer has connected an assistant, and only for the requests they make through it.

Before any free text written by an individual is returned through the connector, it is condensed to its professional content as described in section 5. Detail relating to health, family, age, religion, political or trade union affiliation, sexual orientation, racial or ethnic origin and other personal matters is removed, along with contact details, and is not transmitted.

This step is designed to remove that detail before anything leaves TAMI AI. If you believe something has been passed through that should not have been, tell us at dataprivacy@tami.ai and we will investigate and correct it.

Results retrieved through the connector are held in a temporary cache to avoid repeated lookups and are not retained beyond that purpose. No content of a customer's conversation with their assistant is received or stored by TAMI AI.

If you ask us to remove you, we delete your record and stop disclosing it. We cannot recall data already delivered to a customer, or transmitted to an assistant, before your request.

7. Who we share personal data with

When you fill in a form, subscribe, or browse our website, your details are shared with the platforms we use to run our marketing and manage our customer relationships. These are listed in the Trusted Third Parties table and include HubSpot, LinkedIn, Meta and Google. You can opt out of marketing at any time using the unsubscribe link in any message, or by contacting us.

Records in our business contact database are made available to TAMI AI customers as part of the service they subscribe to. We do not sell, trade or license that database to any other third party, and we do not share it with our own marketing or advertising partners.

We may also disclose personal data where the law requires it, where we need to enforce our terms, or where we need to protect our rights or the rights and safety of others. If the company is merged or acquired, the personal data we hold would be one of the transferred assets.

8. Where your data is held

Our infrastructure is hosted in the European Union. Company and contact data is processed and stored in Microsoft Azure in North Europe, which is Dublin, and West Europe, which is Amsterdam, with machine learning workloads running in Amazon Web Services in Ireland. Transfers between those environments are encrypted in transit and encrypted at rest.

Data leaves that footprint in two circumstances. When a customer outside the European Union uses TAMI AI, the data they request is delivered to them in their own country. Where a customer has connected an AI assistant, the data they request is transmitted to that assistant's provider and processed on their systems.

Personal data is also transferred between SalesOptimize (UK) Limited, our United Kingdom subsidiary, and SalesOptimize Limited in Ireland, under Standard Contractual Clauses and a Data Processing Agreement between the two.

9. Security

We hold ISO 27001 certification for our information security management system, first certified in May 2025.

Personal data is encrypted at rest to AES-256 and in transit using TLS 1.2 or above, with encryption keys held in a managed key vault. Access is granted on least privilege, protected by multi-factor authentication and role based permissions, reviewed twice a year, and revoked within 24 hours when someone leaves. Shared accounts are not permitted.

Our infrastructure is scanned for vulnerabilities daily, sits behind a web application firewall with denial of service protection, and is subject to annual application penetration testing. Audit logs are retained for at least 12 months. We maintain an incident response plan and test it at least once a year.

No system is completely secure. If you believe your data has been exposed, contact dataprivacy@tami.ai.

10. If there is a breach

We report breaches requiring notification to the Office of the Data Protection Commissioner in Ireland within two working days of becoming aware, and to the Information Commissioner's Office in the United Kingdom within 72 hours. We tell affected individuals promptly.

If a security incident affects a customer's data or their users, we notify that customer within 24 hours of discovering it. We tell them what happened, which categories of data were involved, how far it reached, what we have done to contain it, and what happens next.

11. Cookies, advertising and tracking

We use cookies and similar technologies to make the website work, to remember your preferences, and to understand how the site is used. Cookies are optional except where they are strictly necessary for the site to function.

Some of the cookies and similar technologies on our site come from the third parties listed in this policy, and some of those track browsing behaviour across websites for advertising and analytics. You control this through the cookie banner, and you can change or withdraw your choices at any time from the cookie declaration on our website.

The browser Do Not Track setting was never adopted as a standard and we do not rely on it. Your cookie choices are the control we act on.

Our use of cookies complies with the United Kingdom Privacy and Electronic Communications Regulations and the EU ePrivacy Directive.

12. Consent

This policy explains how we handle personal data. Where we rely on your consent, which is for non essential cookies and for marketing email, we ask for it separately and you can withdraw it at any time from the cookie declaration on our website or by using the unsubscribe link in any message. Continuing to browse this site is not treated as consent.

13. How long we keep personal data

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires.

Records in the business contact database are held while they remain accurate and in use, and are deleted on request. Customer account and contract records are kept for the life of the contract and for a period afterwards to meet our legal and accounting obligations. Marketing contact details are deleted within 30 days of you withdrawing consent. Financial records are kept for seven years.

14. Your rights

You can ask us for a copy of the personal data we hold about you. You can ask us to correct it if it is wrong. You can ask us to delete it. You can ask us to restrict what we use it for. You can object to processing we carry out on the basis of legitimate interests, including holding your record in the database. Where we rely on your consent, you can withdraw it.

We provide the first copy free of charge. There are limited cases where we cannot act on a request, for example where the law requires us to keep something, or where acting would adversely affect the rights of another person. We will always tell you when that applies.

Write to dataprivacy@tami.ai.

15. Third party websites

Our website links to websites we do not run. Those sites have their own privacy policies and we are not responsible for them. Please read them before giving them your personal data.

16. Changes to this policy

When we make a material change we publish the new version here with a new version number and effective date, and we tell customers with an active contract in advance.

17. Contacting us

Data Privacy Officer, SalesOptimize Limited trading as TAMI, 9 Meath Street, The Liberties, Dublin, D08 Y6XD, Ireland.

dataprivacy@tami.ai

18. If you want to complain

You can complain to the supervisory authority in the country where you live, where you work, or where you think a breach of data protection law took place. In Ireland that is the Data Protection Commission at dataprotection.ie. In the United Kingdom it is the Information Commissioner's Office at ico.org.uk.