GDPR
GDPR is the EU regulation governing personal data. A named business address like anna@clinic.com is personal data under it, even though it belongs to a company — which is the point most lead-generation advice gets wrong.
Public availability does not remove data from the regulation's scope. That a phone number is printed on a shopfront does not create permission to load it into a CRM; it only means collecting it was not itself unlawful access.
For B2B outreach the usual lawful basis is legitimate interest, which is real but conditional. It requires that you assess and can document the balance between your interest and the recipient's expectations, that you tell people where you got their data on first contact, and that you can act on a deletion request across every system holding it.
Generic addresses sit differently. info@clinic.com identifies a function rather than a person, so it is weaker as personal data — though a regulator will still look at whether a single individual is obviously behind it, which at a two-person business they usually are.
None of this is legal advice. It is a map of what the questions are, so you can ask a lawyer the right one.
Goes deeper: Is Scraping Google Maps Legal?