Privacy notice
Last updated 26 September 2026
Who we are
Siftdata is a trading name of Sakariya Mahamud, sole trader, Borgergata 3, 1767 Halden, Norway. We are the data controller for the personal data described here. Because we are based in Norway, the GDPR (as it applies in Norway) covers our processing, and the UK GDPR applies to people we deal with in the UK. Contact: [email protected].
The data we sell is about organisations, not people
Our lists come from the Care Quality Commission's public register, reused under the Open Government Licence. We only include services run by companies and other organisations. We leave out services registered to a named individual, and we don't include the names of registered managers or nominated individuals. Our filter works on CQC's ownership details and the provider's name, so it can occasionally miss a case. A service's phone number or address can also relate to a small business run by one person. If you think a row identifies a person, email us and we'll remove it within five working days.
People we contact about Siftdata
We email companies that sell to care providers, to ask whether our list would be useful to them.
- What we hold: the company name, its generic contact address (such as info@ or sales@) or contact form, its website, and our notes on replies. If someone replies to us, we also hold their name, work email address and message.
- Where it comes from: the company's own website and the Companies House register.
- Why and on what basis: to offer our service to businesses it is relevant to. Our lawful basis is legitimate interests (Article 6(1)(f) of the GDPR and the UK GDPR): offering a relevant business service to companies whose customers are care services. We only email limited companies and similar organisations, never sole traders or personal addresses.
- Opting out: reply "no" or "unsubscribe" to any email. We add the address to a suppression list the same day and never email it again. We keep only the address on that list, so we can respect your choice.
- How long: up to 12 months after our last contact, unless you become a customer.
Customers
- What we hold: your name, company name, email, billing address, VAT number if you give one, and your purchase history.
- Why and on what basis: to deliver the lists you buy, send invoices and answer your questions (performance of a contract), and to keep accounting records (legal obligation).
- How long: for as long as you're a customer, then as long as Norwegian bookkeeping law requires for accounting records (currently five years).
Stripe processes card payments. We never see or store your card number.
Who we share data with
We don't sell or share personal data with anyone for their own use. These service providers process data on our behalf:
- Stripe (payments and invoices)
- Google Workspace (email)
- Cloudflare (website hosting and DNS)
Some of these providers process data in the United States. They do so under the safeguards the law requires, such as standard contractual clauses or the EU-US and UK-US data frameworks.
This website
This website sets no cookies and uses no tracking or advertising tools. Its fonts are served from our own site, not from a third party. Our host, Cloudflare, keeps standard technical logs, such as IP addresses, for security.
Your rights
You can ask us for a copy of your personal data, and ask us to correct or delete it, restrict how we use it, or object to our using it, including for direct marketing. Email [email protected] and we'll reply within one month.
You can also complain to a data protection authority: in Norway, where we are based, Datatilsynet; in the UK, the Information Commissioner's Office.