Legal

Business Contacts Notice

Parka group (Parka Lausnir ehf., Parka Technologies Ltd and Parka Global Ventures Limited)

Effective 18 September 2026

This notice explains how Parka handles the personal data of people we deal with in a business capacity: staff of councils and other public bodies, car park operators, landowners, suppliers, and people at organisations we believe may benefit from our parking services. It sits alongside our Privacy Policy at smartparka.com/privacy, which covers drivers and app users.

1. Who is responsible

The Parka company you are dealing with is the controller. For organisations in the United Kingdom that is Parka Technologies Ltd (England and Wales, company 17406342, registered office 57A Broadway, Leigh-on-Sea, Essex SS9 1PE, ICO registration ZC227117). For organisations in Ireland and the rest of the EEA it is Parka Global Ventures Limited (Ireland, company 785665, Mespil House, Sussex Road, Dublin 4, D04 T4A6). For organisations in Iceland it is Parka Lausnir ehf. (company ID 480616-2270, Kringlunni 4-6, 103 Reykjavík). Contact for data protection matters: [email protected].

2. What we collect, and where it comes from

We hold your name, job title, organisation, business email address, business phone number, professional profile, the content of our correspondence and meetings with you, and, once your organisation works with us, the onboarding documents and records of that relationship.

Some of this you give us directly. Some of it we collect from publicly accessible sources before we first contact you: your organisation's website, professional networking sites such as LinkedIn, public procurement portals and published tender documents, and public registers. Where we have collected your details this way, this notice is how we tell you about it, and we provide it no later than the first time we contact you.

3. Why we use it, and our legal basis

PurposeLegal basis
To contact you about parking technology that may be relevant to your organisation, including by email, phone and professional networking messagesOur legitimate interest in promoting our services to organisations likely to be interested (Article 6(1)(f)). UK law expressly recognises direct marketing as a type of processing that may be necessary for a legitimate interest (UK GDPR Article 6(11)(a)). We have carried out and recorded a legitimate interests assessment.
To respond to your enquiries and to negotiate, agree and deliver contracts with your organisationLegitimate interests in running our business, and, where you contract with us personally as a sole trader, performance of a contract (Article 6(1)(b))
To keep records of our business relationship, including onboarding documents and correspondenceLegitimate interests, and legal obligation for accounting records (Article 6(1)(c))
To verify that a business email address is deliverable before we write to itLegitimate interests in accurate, low volume outreach that does not bounce

We balance our interests against yours. We only contact people whose role suggests our services are relevant to their organisation, we do not contact you about anything unrelated to that role, and we stop the moment you ask.

4. Country rules we follow when we email you

The rules on unsolicited business email differ by country, and we apply the stricter reading in each case:

  1. United Kingdom. We may email named staff of companies, councils and other corporate bodies about our services without prior consent. We do not email sole traders or unincorporated partnerships unless they have consented or are existing customers. Every message identifies Parka and includes a valid address to opt out (Privacy and Electronic Communications Regulations 2003, regulations 22 and 23).
  2. Ireland. We may email a work address about matters relating to your organisation's commercial or official activity without prior consent, and we honour any opt out immediately (S.I. No. 336/2011, regulation 13).
  3. Iceland. We do not send marketing email to a named individual's work address without their prior consent. We may write to general organisational mailboxes (for example info@ or parking@ addresses) (Electronic Communications Act No. 70/2022, Article 94).

5. Who processes it for us

We use a small set of service providers to run our sales, onboarding and support work. Each acts only on our instructions under a data processing agreement.

ProviderWhat it does for usWhereTransfer safeguard
Google WorkspaceEmail, calendar and documentsGoogle Ireland Limited; Google LLCGoogle LLC is certified under the EU-US and UK-US Data Privacy Framework
ClickUpWork management and onboarding recordsClickUp Ireland LimitedStandard contractual clauses with the UK addendum
MissiveShared inbox for business correspondenceHeliom Inc., CanadaCanada is recognised as adequate for the organisations covered by its federal privacy law; onward transfers under the provider's data processing agreement
Render and NeonHosting and database for our sales workflow systemUnited StatesData Privacy Framework certification with the UK extension, or standard contractual clauses where the contracting entity is not covered
ClerkSign in for our internal usersUnited StatesData Privacy Framework certification with the UK extension
CloudflareNetwork securityUnited StatesData Privacy Framework certification with the UK extension
MillionVerifierChecks that a business email address is deliverable before we write to itHungary, with some processing by its sub processors outside the EEAStandard contractual clauses; uploaded addresses are deleted by the provider within 30 days
AnthropicAI assisted classification and drafting of business correspondenceUnited StatesStandard contractual clauses with the UK addendum under Anthropic's data processing addendum. Our data is not used to train its models

We do not sell business contact data and we do not share it with anyone for their own marketing. We may disclose it to our professional advisers, to authorities where the law requires, and to a successor if our business is transferred.

6. International transfers

Data moves between the 3 Parka companies in Iceland, the United Kingdom and Ireland under the adequacy arrangements in force in each direction. Where a provider processes data in the United States or elsewhere outside the UK and EEA, we rely on the safeguard shown in section 5. You can request a copy from [email protected].

7. How long we keep it

RecordPeriod
Prospect details where we have had no reply or no engagementDeleted no later than 24 months after our last contact
Details of people who have asked us not to contact themA minimal suppression record (name and email) is kept so that we do not contact you again
Records of an active or past customer relationshipThe life of the relationship, then as long as accounting law requires (7 years in Iceland, 6 years in the United Kingdom and Ireland)
CorrespondenceAs long as needed to handle the matter and any follow up, then deleted with the relationship record

8. Your rights

You can ask us to access, correct or erase your data, to restrict or object to processing, and to receive a copy in a portable format where that applies. You can object to marketing at any time, and we will stop. Reply to any message from us, or email [email protected]. We respond within 1 month.

You can also complain to us directly about how we handle your data, and to a supervisory authority: the Information Commissioner's Office (United Kingdom, ico.org.uk), the Data Protection Commission (Ireland, dataprotection.ie) or Persónuvernd (Iceland, personuvernd.is).

9. Changes

This notice is published at smartparka.com/business-contacts and updated there as needed. Questions: [email protected].