Given that the "requests are complex or numerous", I will be responding within three months as recommended by the ICO[1]. Have a nice day.
You now have plenty of time to deal with it properly.
If you have a lot of data on someone, you can enumerate the categories (1) and then request they break it down (specifically request 1c; see Recital 63[2] of the GDPR for the exact language). Almost everything else should be in your privacy policy anyway.
If you do not have a lot of data on someone, then three months should certainly be enough time to properly respond to this.
Most businesses do not have any personal data on anyone beyond what you need for an invoice. If you have a dedicated CRM that contains leads of potential customers, or you use an online service like SalesForce, you can probably get their support in complying.
[1]: https://ico.org.uk/for-organisations/guide-to-the-general-da...
[2]: http://www.privacy-regulation.eu/en/recital-63-GDPR.htm