Data Protection Impact Assessment

Last updated: 2 April 2026  |  Tentrois Ltd

1. Overview

This Data Protection Impact Assessment (DPIA) evaluates the privacy risks arising from Tentrois Ltd's 6-stage B2B lead intelligence pipeline. This assessment is conducted in accordance with Article 35 of UK GDPR.

FieldDetail
Data ControllerTentrois Ltd
Assessment Date2 April 2026
Processing PurposeB2B lead intelligence — scoring, enriching, and delivering qualified business leads
Lawful BasisLegitimate Interest (Art. 6(1)(f)) — see LIA
Data SubjectsBusiness professionals at mid-market companies (employees at companies with fewer than 5,000 staff)

2. Description of Processing

2.1 Pipeline Stages

StageProcessing ActivityData Involved
1. ExtractionCollect data from 54 public sources (job boards, RSS feeds, government registries, APIs)Company names, domains, job titles, news mentions, filing data
2. TransformationNormalise, deduplicate, and verify data qualitySame as above, cleaned and merged
3. Signal IntersectionScore companies on 5 signal vectors (hiring, funding, tech stack, growth, registration). Filter enterprises (5,000+ employees)Signal scores, company metadata
4. XGBoost ScoringMachine learning propensity scoring to rank leadsFeature vectors derived from signals
5. AI EnrichmentLLM generates 12 intelligence layers per lead (company summary, pain points, outreach scripts)Company name, domain, signals, contact title sent to LLM API
6. DeliveryRoute leads to subscribed clients by nicheEnriched lead data delivered via dashboard

2.2 Data Sources

All data is sourced from publicly available endpoints:

3. Risk Assessment

RiskLikelihoodSeverityOverallMitigation
Inaccurate data delivered to clientsMediumLowLowMulti-stage validation, deduplication, signal threshold (3+ signals required)
Excessive data collection beyond purposeLowMediumLowEnterprise blocklist (5,000+ employees filtered), data minimisation at extraction
Unauthorised access to lead dataLowHighMediumJWT authentication, bcrypt passwords, role-based access, TLS encryption
Data breach at infrastructure providerLowHighMediumSOC 2 compliant providers (Supabase, Render), encrypted at rest
LLM provider retaining prompt dataLowMediumLowPrompts contain only business-context data (company name, domain, signals). No personal identifiers beyond business title. API terms reviewed.
Data subject unable to exercise rightsLowMediumLowClear contact mechanism (privacy@tentrois.com), 30-day response commitment
Re-identification from enriched profilesLowLowLowEnrichment is company-level analysis, not individual profiling

4. Automated Decision-Making

Our pipeline includes automated scoring (XGBoost propensity model) and AI-generated enrichment. However:

This processing therefore does not fall within the scope of Article 22 (automated individual decision-making).

5. Data Transfers

ProviderLocationPurposeSafeguard
SupabaseEU (AWS eu-west-2)Database hostingEU adequacy, SCCs
RenderUS/EUApplication hostingSCCs
Google (Gemini API)USAI enrichmentSCCs, data processing terms

6. Measures to Address Risks

7. Consultation

This DPIA has been reviewed internally. Given that residual risks are assessed as low to medium after mitigations, prior consultation with the ICO under Article 36 is not required at this stage.

8. Review Schedule

This DPIA will be reviewed: