Business Contacts Notice
Parka group (Parka Lausnir ehf., Parka Technologies Ltd and Parka Global Ventures Limited)
Effective 18 September 2026
This notice explains how Parka handles the personal data of people we deal with in a business capacity: staff of councils and other public bodies, car park operators, landowners, suppliers, and people at organisations we believe may benefit from our parking services. It sits alongside our Privacy Policy at smartparka.com/privacy, which covers drivers and app users.
1. Who is responsible
The Parka company you are dealing with is the controller. For organisations in the United Kingdom that is Parka Technologies Ltd (England and Wales, company 17406342, registered office 57A Broadway, Leigh-on-Sea, Essex SS9 1PE, ICO registration ZC227117). For organisations in Ireland and the rest of the EEA it is Parka Global Ventures Limited (Ireland, company 785665, Mespil House, Sussex Road, Dublin 4, D04 T4A6). For organisations in Iceland it is Parka Lausnir ehf. (company ID 480616-2270, Kringlunni 4-6, 103 Reykjavík). Contact for data protection matters: [email protected].
2. What we collect, and where it comes from
We hold your name, job title, organisation, business email address, business phone number, professional profile, the content of our correspondence and meetings with you, and, once your organisation works with us, the onboarding documents and records of that relationship.
Some of this you give us directly. Some of it we collect from publicly accessible sources before we first contact you: your organisation's website, professional networking sites such as LinkedIn, public procurement portals and published tender documents, and public registers. Where we have collected your details this way, this notice is how we tell you about it, and we provide it no later than the first time we contact you.
3. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| To contact you about parking technology that may be relevant to your organisation, including by email, phone and professional networking messages | Our legitimate interest in promoting our services to organisations likely to be interested (Article 6(1)(f)). UK law expressly recognises direct marketing as a type of processing that may be necessary for a legitimate interest (UK GDPR Article 6(11)(a)). We have carried out and recorded a legitimate interests assessment. |
| To respond to your enquiries and to negotiate, agree and deliver contracts with your organisation | Legitimate interests in running our business, and, where you contract with us personally as a sole trader, performance of a contract (Article 6(1)(b)) |
| To keep records of our business relationship, including onboarding documents and correspondence | Legitimate interests, and legal obligation for accounting records (Article 6(1)(c)) |
| To verify that a business email address is deliverable before we write to it | Legitimate interests in accurate, low volume outreach that does not bounce |
We balance our interests against yours. We only contact people whose role suggests our services are relevant to their organisation, we do not contact you about anything unrelated to that role, and we stop the moment you ask.
4. Country rules we follow when we email you
The rules on unsolicited business email differ by country, and we apply the stricter reading in each case:
- United Kingdom. We may email named staff of companies, councils and other corporate bodies about our services without prior consent. We do not email sole traders or unincorporated partnerships unless they have consented or are existing customers. Every message identifies Parka and includes a valid address to opt out (Privacy and Electronic Communications Regulations 2003, regulations 22 and 23).
- Ireland. We may email a work address about matters relating to your organisation's commercial or official activity without prior consent, and we honour any opt out immediately (S.I. No. 336/2011, regulation 13).
- Iceland. We do not send marketing email to a named individual's work address without their prior consent. We may write to general organisational mailboxes (for example info@ or parking@ addresses) (Electronic Communications Act No. 70/2022, Article 94).
5. Who processes it for us
We use a small set of service providers to run our sales, onboarding and support work. Each acts only on our instructions under a data processing agreement.
| Provider | What it does for us | Where | Transfer safeguard |
|---|---|---|---|
| Google Workspace | Email, calendar and documents | Google Ireland Limited; Google LLC | Google LLC is certified under the EU-US and UK-US Data Privacy Framework |
| ClickUp | Work management and onboarding records | ClickUp Ireland Limited | Standard contractual clauses with the UK addendum |
| Missive | Shared inbox for business correspondence | Heliom Inc., Canada | Canada is recognised as adequate for the organisations covered by its federal privacy law; onward transfers under the provider's data processing agreement |
| Render and Neon | Hosting and database for our sales workflow system | United States | Data Privacy Framework certification with the UK extension, or standard contractual clauses where the contracting entity is not covered |
| Clerk | Sign in for our internal users | United States | Data Privacy Framework certification with the UK extension |
| Cloudflare | Network security | United States | Data Privacy Framework certification with the UK extension |
| MillionVerifier | Checks that a business email address is deliverable before we write to it | Hungary, with some processing by its sub processors outside the EEA | Standard contractual clauses; uploaded addresses are deleted by the provider within 30 days |
| Anthropic | AI assisted classification and drafting of business correspondence | United States | Standard contractual clauses with the UK addendum under Anthropic's data processing addendum. Our data is not used to train its models |
We do not sell business contact data and we do not share it with anyone for their own marketing. We may disclose it to our professional advisers, to authorities where the law requires, and to a successor if our business is transferred.
6. International transfers
Data moves between the 3 Parka companies in Iceland, the United Kingdom and Ireland under the adequacy arrangements in force in each direction. Where a provider processes data in the United States or elsewhere outside the UK and EEA, we rely on the safeguard shown in section 5. You can request a copy from [email protected].
7. How long we keep it
| Record | Period |
|---|---|
| Prospect details where we have had no reply or no engagement | Deleted no later than 24 months after our last contact |
| Details of people who have asked us not to contact them | A minimal suppression record (name and email) is kept so that we do not contact you again |
| Records of an active or past customer relationship | The life of the relationship, then as long as accounting law requires (7 years in Iceland, 6 years in the United Kingdom and Ireland) |
| Correspondence | As long as needed to handle the matter and any follow up, then deleted with the relationship record |
8. Your rights
You can ask us to access, correct or erase your data, to restrict or object to processing, and to receive a copy in a portable format where that applies. You can object to marketing at any time, and we will stop. Reply to any message from us, or email [email protected]. We respond within 1 month.
You can also complain to us directly about how we handle your data, and to a supervisory authority: the Information Commissioner's Office (United Kingdom, ico.org.uk), the Data Protection Commission (Ireland, dataprotection.ie) or Persónuvernd (Iceland, personuvernd.is).
9. Changes
This notice is published at smartparka.com/business-contacts and updated there as needed. Questions: [email protected].
