← Back to leados.tech

Privacy Policy

Effective date: April 10, 2026  |  Last updated: September 29, 2026

1 — Who We Are

LeadOS is operated by Kristine Bjørgan Østby, a sole trader (enkeltpersonforetak) based in Norway. We are the data controller for personal data processed through this service.

Contact: hello@leados.tech

2 — Legal Basis for Processing (GDPR Article 6)

We process your personal data on the following legal bases:

  • ·Contract performance (Art. 6(1)(b)) — processing your account data, ICP configuration, and leads is necessary to provide the service you signed up for.
  • ·Legitimate interest (Art. 6(1)(f)) — usage analytics to improve the service.
  • ·Legal obligation (Art. 6(1)(c)) — retaining transaction records for tax and accounting purposes.
  • ·Consent (Art. 6(1)(a)) — cookies that are not strictly necessary.

3 — What Personal Data We Collect

Data you provide directly:

  • ·Name and email address (account registration)
  • ·Company URL and business description (onboarding)
  • ·ICP configuration (target customer profile, signals, disqualifiers)

Data generated by the service:

  • ·Lead records including company names, contact names, email addresses, phone numbers, and LinkedIn URLs sourced from third-party databases
  • ·Outreach drafts you create
  • ·Reply notes and pipeline status you set

Technical data collected automatically:

  • ·IP address and browser/device information
  • ·Pages visited and features used (analytics)
  • ·Cookie identifiers (see Section 10)

4 — How We Use Your Data

  • ·To create and manage your account
  • ·To run the AI lead generation agent on your behalf
  • ·To store and display your leads, pipeline, and outreach history
  • ·To process payments and manage your subscription
  • ·To send transactional emails (account confirmation, receipts)
  • ·To improve and debug the service
  • ·To comply with legal obligations

We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described in Section 5.

5 — Third-Party Data Processors

ProcessorPurposeLocationSafeguard
SupabaseDatabase and authenticationEU (West EU region)GDPR compliant, DPA in place
AnthropicAI processing of website content and lead scoringUSAStandard Contractual Clauses (SCCs)
VercelApplication hosting and edge deliveryUSA (Washington D.C. — iad1 region)Standard Contractual Clauses (SCCs)
LemonsqueezyPayment processing and subscription managementUSAStandard Contractual Clauses (SCCs)
Serper.devGoogle search API for lead discoveryUSAStandard Contractual Clauses (SCCs)
Apollo.ioContact enrichment (email, phone, LinkedIn) — secondary / conditional; used for non-Norway markets onlyUSAStandard Contractual Clauses (SCCs)
FullEnrichContact enrichment (name, domain, LinkedIn → email/phone)USAStandard Contractual Clauses (SCCs)
Hunter.ioEmail finding and verification (name, domain)USAStandard Contractual Clauses (SCCs)
ProspeoEmail lookup (name, company, domain, LinkedIn)USAStandard Contractual Clauses (SCCs)
BrregNorwegian company registry (company name/org number → director name)NorwayPublic government data
ResendTransactional and summary emails (user and lead data)USAStandard Contractual Clauses (SCCs)

6 — International Data Transfers

Some of our processors are based in the United States. When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in accordance with GDPR Chapter V, specifically Standard Contractual Clauses (SCCs) as approved by the European Commission.

7 — Data About Your Leads and Prospects

When you use LeadOS to discover and enrich potential business contacts ("leads"), we process personal data about individuals who are not our direct customers — for example, a company's business development manager or sales director. This section explains how we handle that data.

What we collect

For each lead, we may process: name, business email address, phone number, job title, employer, and publicly available business information (e.g. from LinkedIn, company websites, or public business registries such as Brønnøysundregistrene). We do not knowingly collect personal data unrelated to a person's professional role.

Where this data comes from

We do not collect this data directly from the individual. It is sourced from publicly available web content and third-party enrichment providers (see Section 5) based on criteria you configure (your Ideal Customer Profile).

Our legal basis

We process lead data on the basis of legitimate interest (GDPR Art. 6(1)(f)) — specifically, facilitating lawful B2B sales prospecting on behalf of our customers, which is a recognised legitimate interest under GDPR Recital 47. We only process business contact information reasonably necessary for this purpose, and we do not process this data for any purpose beyond enabling our customers' outreach.

Notice to leads

Because we collect this data indirectly rather than from the individual, GDPR Article 14 requires that affected individuals be informed. We rely on our customers to include a clear, easy way to opt out in their first outreach communication, and our outreach-generation features are designed to support this.

Your rights if you are a lead

If you have received outreach generated using LeadOS and believe your data has been processed, you have the same rights described in Section 11 of this policy (access, rectification, erasure, objection, and others). To exercise these rights regarding data processed on behalf of one of our customers, you may contact us directly at hello@leados.tech, or contact the business that reached out to you, who acts as the independent data controller for their own outreach activities (see Section 6 of our Terms of Service).

Objecting to processing

You have the right to object at any time to processing based on legitimate interest, including for prospecting purposes. If you object, we will stop processing your data for this purpose unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for legal claims.

8 — Automated Decision-Making

LeadOS uses AI (Claude by Anthropic) to automatically score leads based on your ICP configuration. This constitutes automated processing under GDPR Article 22. However, this scoring is not a legally or similarly significant decision — it is an advisory ranking to help you prioritise outreach. You retain full control and can override or ignore any score. No leads are contacted without your explicit approval.

9 — Data Retention

  • ·Account data — retained for the duration of your subscription. To request deletion, email hello@leados.tech and we will delete your data within 30 business days.
  • ·Lead data — retained for the duration of your subscription. To request deletion, email hello@leados.tech and we will delete your data within 30 business days.
  • ·Payment records — retained for 5 years to comply with Norwegian accounting law (Bokføringsloven).
  • ·Backup data — may persist in encrypted backups for up to 90 days after deletion.
  • ·Analytics data — retained in aggregate, anonymised form indefinitely.

10 — Cookies

CookiePurposeTypeDuration
Supabase auth tokenKeeps you logged inStrictly necessarySession
Consent cookieRemembers your cookie preferencesStrictly necessary1 year

We do not currently use non-essential or analytics cookies. If this changes, we will update this policy and request your consent before any such cookies are set.

11 — Your Rights Under GDPR

  • ·Right of access (Art. 15) — request a copy of all data we hold about you.
  • ·Right to rectification (Art. 16) — request correction of inaccurate data.
  • ·Right to erasure (Art. 17) — request deletion of your data (“right to be forgotten”) by emailing hello@leados.tech. There is no self-service deletion button; erasure requests are handled via email.
  • ·Right to restriction of processing (Art. 18) — request we limit how we use your data.
  • ·Right to data portability (Art. 20) — receive your data in a machine-readable format.
  • ·Right to object (Art. 21) — object to processing based on legitimate interest.
  • ·Right to withdraw consent — where processing is based on consent, you can withdraw at any time.

To exercise any of these rights, email hello@leados.tech. We will respond within 30 days.

12 — Data Security

We implement appropriate technical and organisational measures to protect your data including:

  • ·Encrypted data storage (Supabase with encryption at rest)
  • ·HTTPS/TLS encryption in transit
  • ·Row-level security on all database tables
  • ·API keys stored as environment variables, never in code
  • ·Access limited to the data controller only

13 — Children's Privacy

LeadOS is a B2B service intended for business use only. We do not knowingly collect data from anyone under the age of 18.

14 — Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email at least 14 days before any material changes take effect. Continued use of the service after that date constitutes acceptance of the updated policy.

15 — Complaints

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Norwegian data protection authority:

Datatilsynet

datatilsynet.no

+47 22 39 69 00

Postboks 458 Sentrum, 0105 Oslo

16 — Contact

For any privacy-related questions or to exercise your rights: hello@leados.tech

Terms of ServiceBack to LeadOS