Privacy, Data Governance & Responsible Use
LastDatabase Compliance Framework
LastDatabase approaches compliance as a data lifecycle involving sourcing, provenance, verification, suppression, privacy rights, security and responsible customer use.
Different laws can apply depending on the person, jurisdiction, data type, communication channel, processing purpose and customer use case. Technical verification is therefore only one component of responsible data processing.
Effective date: 1 January 2026 · Last updated: 19 September 2026
1. Our Compliance Framework
LastDatabase provides business-data discovery, verification and delivery functionality. Our compliance framework separates several controls that address different parts of the data lifecycle.
2. Business Partner Network and Opt-In Information
LastDatabase works with a global network of approximately 2 million opt-in business partners. Partners can submit business data through the LastDatabase Partner Portal together with source and opt-in information.
Partner submission does not mean that a record automatically becomes production inventory. Submitted data can undergo applicable validation, normalization, duplicate detection, suppression screening, verification and quality classification before eligible records are accepted.
Partner-provided source and opt-in information documents information associated with the submission. It is distinct from technical contact verification performed by LastDatabase.
3. Source, Provenance and Verification
LastDatabase processes business information from multiple source categories. These can include the business partner network, public business information, company-published information, business and professional directories, appropriately supplied or licensed datasets, enrichment processes, research, corrections and other applicable business-data sources.
The source and processing history can differ by dataset and record. Not every record necessarily has identical provenance, age, field population or verification history.
LastDatabase therefore distinguishes:
- Source provenance — information about where or how data was supplied or obtained.
- Opt-in information — available information associated with a submitted permission or opt-in status.
- Technical verification — applicable checks concerning contact or technical characteristics.
- Suppression status — whether an identifier is subject to applicable internal suppression controls.
- Customer-use compliance — the customer's responsibility to determine whether its intended processing or communication is permitted.
4. GDPR and European Privacy Requirements
Where the GDPR or related European privacy requirements apply, the appropriate legal role, lawful basis, transparency obligations, data minimization requirements and individual rights depend on the relevant processing activity.
For certain business-profile processing activities, legitimate interests under GDPR Article 6(1)(f) may be relevant, subject to applicable necessity, balancing, transparency, objection and other legal requirements.
Other processing activities or relationships may require a different legal basis or additional safeguards. Depending on the particular activity, LastDatabase may act as a controller or process information on behalf of another business.
- Business-data processing should be relevant to the stated purpose.
- Data minimization should be considered when determining which attributes are necessary.
- Applicable transparency requirements should be respected.
- Objection, correction, deletion and other applicable data-subject rights should be handled appropriately.
- Cross-border processing may require applicable transfer safeguards.
5. California and U.S. Privacy Requirements
U.S. privacy requirements vary by jurisdiction, data category, business role and processing activity.
Where applicable, rights and obligations may arise under the California Consumer Privacy Act as amended by the California Privacy Rights Act, as well as other applicable U.S. state privacy laws.
Depending on the applicable law and circumstances, individuals may have rights concerning access, deletion, correction, opt-out or other processing activities.
LastDatabase provides privacy-request and suppression mechanisms to support applicable rights. A specific request may require verification before action is completed.
6. JIT Verification and Suppression
LastDatabase's Just-In-Time verification architecture is designed to perform applicable verification and suppression controls close to the point at which supported data is prepared for export, delivery or synchronization.
Depending on the supported data type and workflow, JIT processing can include normalization, suppression checks, domain or MX checks, SMTP or mailbox-related signals, risk classification and replacement workflows.
Internal suppression identifiers can be standardized so formatting differences are less likely to cause a previously suppressed identifier to be unintentionally reintroduced into an eligible delivery.
7. Email, Telephone and Marketing Requirements
Email Communications
Customers using data for email communications are responsible for complying with laws applicable to their sender, recipient, jurisdiction and campaign. Requirements can include accurate sender identification, non-deceptive messaging, required disclosures, unsubscribe mechanisms and honoring applicable opt-out requests.
Telephone, Mobile and SMS Communications
Telephone and mobile communications can be subject to additional consent, do-not-contact, telemarketing, automated-dialing and messaging requirements.
The availability of a telephone number in a database does not itself establish permission to call or send a message. Customers must evaluate the rules applicable to their intended channel, jurisdiction and use case.
International Communications
Customers conducting campaigns across multiple countries must evaluate the requirements that apply in each relevant jurisdiction rather than assuming that one country's rules apply globally.
8. Privacy Rights, Opt-Out and Suppression
Depending on location and applicable law, individuals may have rights concerning personal information associated with them.
Access / Know
Request applicable information about personal information maintained or processed.
Correction
Request correction of qualifying inaccurate personal information where applicable.
Deletion
Request deletion of qualifying personal information, subject to applicable exceptions.
Opt-Out
Submit an applicable request concerning qualifying sale, sharing or processing activities.
Object
Where applicable, object to certain processing activities subject to the relevant legal conditions.
Non-Discrimination
Where required, exercising applicable privacy rights will not result in unlawful discriminatory treatment.
Suppression After a Request
LastDatabase may retain limited suppression identifiers where necessary to honor an applicable opt-out or deletion-related suppression. This can reduce the risk that the same identifier is unintentionally reintroduced into future eligible deliveries.
9. Retention, Security and Service Providers
LastDatabase uses administrative and technical safeguards appropriate to the platform and processing environment.
Depending on the system and workflow, safeguards can include encrypted network transport, authentication, access controls, rate limiting, monitoring and protections intended to reduce unauthorized access and automated abuse.
No internet-connected system can guarantee absolute security. Security controls are therefore reviewed as platform architecture and operational risks evolve.
LastDatabase may use infrastructure and service providers where necessary to operate, secure, verify, maintain or deliver platform functionality. Applicable processor, contractual and transfer requirements should be addressed where legally required.
10. Customer Responsibilities
Purchasing, accessing or receiving business data does not transfer responsibility for a customer's marketing practices, communications or legal obligations to LastDatabase.
Customers are responsible for evaluating the laws and requirements applicable to their intended use. This can include determining an appropriate legal basis, providing required notices, maintaining required consent, honoring opt-outs and complying with communication-channel rules.
Customers should not assume that technical verification, source availability, an opt-in indicator or inclusion in a business database independently authorizes every possible use.
11. Prohibited and Restricted Uses
LastDatabase data and platform functionality must not be used for unlawful activity, harassment, discrimination, deception, fraud, unauthorized surveillance or other prohibited processing.
Customers must also avoid using business-data products in ways that violate applicable privacy, marketing, communications or consumer-protection requirements.
LastDatabase does not intentionally offer sensitive personal information, financial account details, personal health information or data relating to minors as B2B lead-list targeting categories.
12. Compliance Documentation and Transparency
Compliance should be read together with the LastDatabase documentation covering data sources, methodology, data quality, privacy, responsible use, verification and editorial standards.
13. Data Protection Contact
For privacy questions, data-subject requests, regulatory inquiries or concerns about information associated with you, contact the LastDatabase data protection team.
| Brand / Platform | LastDatabase |
|---|---|
| Registered Business Name | WORLD DIGITAL MARKETING SERVICES |
| Registration Authority | Philippine Department of Trade and Industry (DTI) |
| DTI Business Name No. | 7909580 |
| Registration Valid Through | 9 February 2031 |
| Data Protection Contact | protection@lastdatabase.com |
| Phone | +63 985 808 5805 |
| City | Bacolod City |
| Province | Negros Occidental |
| Region | Negros Island Region (NIR) |
| Postal / ZIP Code | 6100 |
| Country | Philippines |
Important Compliance Notice
This page describes LastDatabase platform practices and general compliance considerations. It is not legal advice and does not determine the legal requirements applicable to a customer's particular campaign, jurisdiction, processing purpose or business.
Customers should obtain appropriate professional advice when necessary to determine their own legal obligations.