DELLI Growth — Privacy Policy
Version 1.0 · Effective 8 September 2026
DELLI Limited ("DELLI", "we", "us") is the data controller for the processing described here. Registered in England and Wales, company number 13063011, registered office 9th Floor, 107 Cheapside, London, England, EC2V 6DN.
Data protection contact: data@delli.com — for questions, objections, opt-outs and any request about your data. General support: support@delli.com.
This policy covers DELLI Growth at growth.delli.com, our subscription service that helps independent food and drink brands find and contact trade buyers. The DELLI marketplace at delli.market has its own Privacy Policy.
This policy has two parts. Please read the one that applies to you.
Part A — you are a DELLI Growth customer, or thinking of becoming one.
Part B — your business appears in our Directory, or you have been contacted by a brand that found you through DELLI Growth. This is the part that explains where we got your details and how to tell us to stop. You do not need an account to read it or to act on it.
Part C applies to everyone.
Part A — If you are a DELLI Growth customer
A1. What we collect from you
Account and identity — your name, work email, and the brand or business you represent. Sign-in is passwordless: a one-time emailed link, or Google sign-in. We never hold a password for you. Where you sign in with Google we receive only your email address and Google account identifier.
Business profile — what you make, your product categories, price positioning, location, and who you want to sell to. Where you already have a DELLI Market profile we may derive parts of this automatically from information you have already given DELLI; we show you what we derived so you can correct it.
Subscription and billing — your plan, billing period, Credit balance and transaction history. Card details go directly to Stripe and we never see or store the full number.
Your use of the Service — searches you run, filters you apply, buyer records you view or reveal, lists you build, and feedback you give (including thumbs on contacts and messages you send us through the feedback form). We use this to run the Service, to improve match quality, and to understand which features earn their place.
Technical data — IP address, browser and device information, pages visited, and error diagnostics.
Support communications — what you send us and our replies.
Outreach sending and Connected Mailboxes are not yet available in the Service. When they launch, this policy will be updated first to describe exactly what is collected and how it is protected.
A2. Why we process it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing the Service, your account and your subscription | Performance of a contract |
| Taking payment, invoicing, collecting unpaid fees | Performance of a contract; legal obligation |
| Deriving your brand profile so onboarding needs no long form | Performance of a contract |
| Generating buyer matches and fit scores for you | Performance of a contract |
| Applying anti-abuse and rate controls | Legitimate interests: protecting the Service, our customers, and the businesses in the Directory |
| Improving match quality and the Service, in aggregate | Legitimate interests: operating and improving a product our customers rely on |
| Security, fraud prevention, audit logging | Legitimate interests; legal obligation |
| Statutory records, tax and accounting | Legal obligation |
| Marketing DELLI products to you by email | Legitimate interests, with an opt-out in every message. Consent where the law requires it |
We do not use your data for automated decision-making that has legal or similarly significant effects on you.
A3. Automated processing you should know about
Fit scores, match suggestions and the reasons shown alongside them are produced automatically from data about your brand and about the businesses in the Directory. They are software-generated estimates intended to help you prioritise. They are not advice, they are not a recommendation, and they have no legal effect on anyone. You can see the factors behind any score in the Service.
A4. Google sign-in and Google user data
If you sign in with Google, DELLI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely:
- We request the narrowest scope that does the job: your email address and basic account identifier, used solely to sign you in. We do not request access to your mailbox, contacts, calendar or files.
- We use Google user data solely to provide the sign-in you asked for.
- We do not use it for advertising. We do not sell it.
- We do not transfer it to others except as necessary to provide the Service, for security purposes, or where the law requires it.
- We do not use it to develop, train or improve generalised AI or machine learning models.
You can revoke DELLI's access at any time from your Google account security settings; the emailed sign-in link keeps working regardless.
A5. Who we share your data with
Our sub-processors, listed in C4. We do not sell your data, and we do not share your lists, your reveals or which businesses you are researching with any other customer or with anyone in the Directory.
We may share aggregated, anonymised statistics about Service use. Nothing in them identifies you, your brand, or which businesses you contacted.
A6. How long we keep it
Account and profile data for as long as your account is active, then 12 months. Billing and transaction records for 7 years for tax purposes. Technical and job logs for up to 12 months. Support and feedback correspondence for 24 months.
On termination we keep Your Content available for export for 30 days, then delete or anonymise it.
Part B — If your business is in our Directory
This part is for you if you run or work at a shop, deli, café, farm shop, restaurant, pub, hotel, wholesaler or similar business, and your details appear in DELLI Growth. It also applies if a food or drink brand has contacted you after finding you through us.
You do not need an account, and you do not need to explain yourself, to ask us to stop. See B6.
B1. What we hold
About the business — trading name, registered company name and number, address and postcode, business type, website, social handles, phone number, the product categories it appears to stock, and how recently we have seen signs it is trading.
About individuals at the business — where available: a name, a job title or role, a work email
address, and a link to a public professional profile. Sometimes only a general business address such as
hello@ or orders@, which may not relate to any identifiable individual.
Provenance — for each piece of information, where we got it, when, and the wording it came from. We keep this so we can show our workings and correct mistakes properly.
The Directory contains only businesses we have been able to match to a registered company. Sole traders and businesses we cannot confirm as companies are excluded from the Service entirely — not shown, not searchable, and their contact details not made available.
We do not hold, seek or want: home addresses, personal phone numbers, personal email addresses other than where a business publishes one as its own contact, dates of birth, financial information, or anything about your private life. We do not use special category data, and we do not build profiles about individuals beyond their business role.
B2. Where we got it
- Public registers — Companies House (including the public register of company officers) and the Food Standards Agency's food hygiene rating data.
- Open data — including Ordnance Survey-derived postcode data.
- The business's own published website and social profiles — typically its contact, about, wholesale or trade pages, and its legally required privacy or policy pages.
- Public search results, including public professional profile listings, accessed through a licensed search API. We do not scrape social media or professional networking platforms themselves.
- Licensed data and verification providers, under contracts requiring lawful sourcing.
- Our own records of trade orders processed through DELLI's marketplace, used only to note that a business is an active trade buyer and the broad product categories involved — never which brands it bought from.
- Corrections from our customers, where a brand tells us a contact has changed.
- Inference. Where a business publishes one address in a recognisable format, we may deduce the likely format of another and then test whether it is deliverable. Anything deduced this way is labelled as unconfirmed inside the Service and is never charged for.
We do not buy consumer data, and we do not use data from platforms whose terms prohibit it.
B3. Why we process it, and our lawful basis
Our lawful basis is legitimate interests (UK GDPR Article 6(1)(f)). Our interest, and our customers', is enabling small independent food and drink producers to identify and approach potential trade customers. Trade buyers publish business contact details in order to be contacted about supply, and the processing is limited to business-role information used for a business purpose.
We have carried out and documented a Legitimate Interests Assessment, considering the limited and business-only nature of the data, that it is published or officially registered, the low likelihood of harm, and your right to stop it at any time. You can request a summary of that assessment at data@delli.com.
We are an independent controller for the Directory. When one of our customers reveals or exports your record, that customer becomes an independent controller of it too, and is responsible for its own use of it, including any email it sends you. We require our customers by contract to comply with data protection and marketing law, to identify themselves, to offer an opt-out in every message, and to honour objections.
B4. Who we share it with
Our customers — independent food and drink brands who subscribe to DELLI Growth, for the purpose of contacting your business about supplying it. Access is metered and logged. We record which customer accessed which record and when, so that if you object we can tell you and them.
Our sub-processors — listed in C4.
We do not publish the Directory, sell it, or make it available to anyone other than subscribing customers under contract.
B5. How long we keep it
While the business appears to be trading and relevant to trade supply. We re-check records periodically and let unverified information decay. Where a business appears to have closed, or where we have seen no sign of trading for 24 months, we remove or archive the record.
If you object or ask for erasure we keep a minimal suppression record — typically the email address or domain and the date — indefinitely, for the sole purpose of making sure the record is not added back by a later import. That is the least we can hold and still keep our promise to you.
B6. Your rights, and how to stop us in one step
You have the right to:
- Object to direct marketing. This is absolute. If you tell us, we must stop, and we will. No reasons needed.
- Access the information we hold about you, and be told where we got it.
- Rectification of anything inaccurate.
- Erasure.
- Restriction of processing.
- Object to our processing generally on legitimate-interest grounds.
- Portability, where it applies.
To stop, or to ask us anything: email data@delli.com with "Directory request" in the subject line. One email is enough.
What happens when you object:
- We suppress your record immediately, and stop it being available in the Service.
- We identify every customer who has already accessed it, notify them that you have objected, and require them under our Terms to stop contacting you and to delete or suppress your details.
- We add you to a permanent suppression list so a future import cannot reinstate you.
- We confirm to you in writing, within one month at the latest and usually far sooner.
We do not charge for this and we will not ask you to justify it.
B7. If a brand has emailed you
The brand is the sender and is responsible for that email. Reply to them, or use the opt-out in their message, to stop hearing from them. If you would rather not be in the Directory at all, email data@delli.com and we will remove you regardless of what any individual brand does.
Part C — Applies to everyone
C1. Security
Data is encrypted in transit and at rest. Access is limited to staff who need it and is logged. Sign-in is passwordless, so there is no password database to breach. Row-level security separates each customer's data at the database layer. We maintain an incident response process; where a breach is likely to result in a risk to individuals we will notify the ICO within 72 hours and affected people without undue delay.
No system is perfectly secure, and we do not claim otherwise.
C2. Where data is processed
Primarily in the UK and the European Economic Area — our database and data-processing infrastructure run in London. Some sub-processors process data in the United States. Where data leaves the UK we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment where required.
C3. Cookies and similar technologies
We use strictly necessary cookies only: sign-in and session security. These do not require consent. We do not use analytics cookies, advertising cookies, or third-party trackers in the Service.
C4. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Neon | Application database | UK / EU (London) |
| Vercel | Application hosting | EU / US |
| Google Cloud Platform | Data-processing infrastructure (London); business-listing data (Google Places) | UK / Global |
| Sign-in with Google, at your choice | Global | |
| Stripe | Payments and subscription billing | UK / US |
| Resend | Transactional email (sign-in links, receipts, notices) | US |
| Bouncer | Email address deliverability verification | EU |
| Brave Software | Licensed web search API for business discovery | US |
| Anthropic | Extracting business information from public web pages | US |
Anthropic processes text from public web pages under commercial API terms that do not permit our inputs to be used to train their models.
We will publish material changes to this list here and, for customers, give notice before adding a sub-processor that processes your data.
C5. Complaints
Please raise anything with us first at data@delli.com. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, ico.org.uk, 0303 123 1113. Complaining to us first does not affect that right.
C6. Changes to this policy
We will post updates here with a new version number and effective date. Where a change materially affects customers we will give at least 30 days' notice by email. Where it materially affects people in the Directory we will update Part B before the change takes effect.
C7. Contact
Data protection contact: Ben Doherty, data@delli.com General support: support@delli.com DELLI Limited, 9th Floor, 107 Cheapside, London, England, EC2V 6DN
DELLI Limited · Company number 13063011