Privacy Policy
Effective date: April 10, 2026 | Last updated: September 29, 2026
1 — Who We Are
LeadOS is operated by Kristine Bjørgan Østby, a sole trader (enkeltpersonforetak) based in Norway. We are the data controller for personal data processed through this service.
Contact: hello@leados.tech
2 — Legal Basis for Processing (GDPR Article 6)
We process your personal data on the following legal bases:
- ·Contract performance (Art. 6(1)(b)) — processing your account data, ICP configuration, and leads is necessary to provide the service you signed up for.
- ·Legitimate interest (Art. 6(1)(f)) — usage analytics to improve the service.
- ·Legal obligation (Art. 6(1)(c)) — retaining transaction records for tax and accounting purposes.
- ·Consent (Art. 6(1)(a)) — cookies that are not strictly necessary.
3 — What Personal Data We Collect
Data you provide directly:
- ·Name and email address (account registration)
- ·Company URL and business description (onboarding)
- ·ICP configuration (target customer profile, signals, disqualifiers)
Data generated by the service:
- ·Lead records including company names, contact names, email addresses, phone numbers, and LinkedIn URLs sourced from third-party databases
- ·Outreach drafts you create
- ·Reply notes and pipeline status you set
Technical data collected automatically:
- ·IP address and browser/device information
- ·Pages visited and features used (analytics)
- ·Cookie identifiers (see Section 10)
4 — How We Use Your Data
- ·To create and manage your account
- ·To run the AI lead generation agent on your behalf
- ·To store and display your leads, pipeline, and outreach history
- ·To process payments and manage your subscription
- ·To send transactional emails (account confirmation, receipts)
- ·To improve and debug the service
- ·To comply with legal obligations
We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described in Section 5.
5 — Third-Party Data Processors
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Database and authentication | EU (West EU region) | GDPR compliant, DPA in place |
| Anthropic | AI processing of website content and lead scoring | USA | Standard Contractual Clauses (SCCs) |
| Vercel | Application hosting and edge delivery | USA (Washington D.C. — iad1 region) | Standard Contractual Clauses (SCCs) |
| Lemonsqueezy | Payment processing and subscription management | USA | Standard Contractual Clauses (SCCs) |
| Serper.dev | Google search API for lead discovery | USA | Standard Contractual Clauses (SCCs) |
| Apollo.io | Contact enrichment (email, phone, LinkedIn) — secondary / conditional; used for non-Norway markets only | USA | Standard Contractual Clauses (SCCs) |
| FullEnrich | Contact enrichment (name, domain, LinkedIn → email/phone) | USA | Standard Contractual Clauses (SCCs) |
| Hunter.io | Email finding and verification (name, domain) | USA | Standard Contractual Clauses (SCCs) |
| Prospeo | Email lookup (name, company, domain, LinkedIn) | USA | Standard Contractual Clauses (SCCs) |
| Brreg | Norwegian company registry (company name/org number → director name) | Norway | Public government data |
| Resend | Transactional and summary emails (user and lead data) | USA | Standard Contractual Clauses (SCCs) |
6 — International Data Transfers
Some of our processors are based in the United States. When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in accordance with GDPR Chapter V, specifically Standard Contractual Clauses (SCCs) as approved by the European Commission.
7 — Data About Your Leads and Prospects
When you use LeadOS to discover and enrich potential business contacts ("leads"), we process personal data about individuals who are not our direct customers — for example, a company's business development manager or sales director. This section explains how we handle that data.
What we collect
For each lead, we may process: name, business email address, phone number, job title, employer, and publicly available business information (e.g. from LinkedIn, company websites, or public business registries such as Brønnøysundregistrene). We do not knowingly collect personal data unrelated to a person's professional role.
Where this data comes from
We do not collect this data directly from the individual. It is sourced from publicly available web content and third-party enrichment providers (see Section 5) based on criteria you configure (your Ideal Customer Profile).
Our legal basis
We process lead data on the basis of legitimate interest (GDPR Art. 6(1)(f)) — specifically, facilitating lawful B2B sales prospecting on behalf of our customers, which is a recognised legitimate interest under GDPR Recital 47. We only process business contact information reasonably necessary for this purpose, and we do not process this data for any purpose beyond enabling our customers' outreach.
Notice to leads
Because we collect this data indirectly rather than from the individual, GDPR Article 14 requires that affected individuals be informed. We rely on our customers to include a clear, easy way to opt out in their first outreach communication, and our outreach-generation features are designed to support this.
Your rights if you are a lead
If you have received outreach generated using LeadOS and believe your data has been processed, you have the same rights described in Section 11 of this policy (access, rectification, erasure, objection, and others). To exercise these rights regarding data processed on behalf of one of our customers, you may contact us directly at hello@leados.tech, or contact the business that reached out to you, who acts as the independent data controller for their own outreach activities (see Section 6 of our Terms of Service).
Objecting to processing
You have the right to object at any time to processing based on legitimate interest, including for prospecting purposes. If you object, we will stop processing your data for this purpose unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for legal claims.
8 — Automated Decision-Making
LeadOS uses AI (Claude by Anthropic) to automatically score leads based on your ICP configuration. This constitutes automated processing under GDPR Article 22. However, this scoring is not a legally or similarly significant decision — it is an advisory ranking to help you prioritise outreach. You retain full control and can override or ignore any score. No leads are contacted without your explicit approval.
9 — Data Retention
- ·Account data — retained for the duration of your subscription. To request deletion, email hello@leados.tech and we will delete your data within 30 business days.
- ·Lead data — retained for the duration of your subscription. To request deletion, email hello@leados.tech and we will delete your data within 30 business days.
- ·Payment records — retained for 5 years to comply with Norwegian accounting law (Bokføringsloven).
- ·Backup data — may persist in encrypted backups for up to 90 days after deletion.
- ·Analytics data — retained in aggregate, anonymised form indefinitely.
10 — Cookies
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| Supabase auth token | Keeps you logged in | Strictly necessary | Session |
| Consent cookie | Remembers your cookie preferences | Strictly necessary | 1 year |
We do not currently use non-essential or analytics cookies. If this changes, we will update this policy and request your consent before any such cookies are set.
11 — Your Rights Under GDPR
- ·Right of access (Art. 15) — request a copy of all data we hold about you.
- ·Right to rectification (Art. 16) — request correction of inaccurate data.
- ·Right to erasure (Art. 17) — request deletion of your data (“right to be forgotten”) by emailing hello@leados.tech. There is no self-service deletion button; erasure requests are handled via email.
- ·Right to restriction of processing (Art. 18) — request we limit how we use your data.
- ·Right to data portability (Art. 20) — receive your data in a machine-readable format.
- ·Right to object (Art. 21) — object to processing based on legitimate interest.
- ·Right to withdraw consent — where processing is based on consent, you can withdraw at any time.
To exercise any of these rights, email hello@leados.tech. We will respond within 30 days.
12 — Data Security
We implement appropriate technical and organisational measures to protect your data including:
- ·Encrypted data storage (Supabase with encryption at rest)
- ·HTTPS/TLS encryption in transit
- ·Row-level security on all database tables
- ·API keys stored as environment variables, never in code
- ·Access limited to the data controller only
13 — Children's Privacy
LeadOS is a B2B service intended for business use only. We do not knowingly collect data from anyone under the age of 18.
14 — Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email at least 14 days before any material changes take effect. Continued use of the service after that date constitutes acceptance of the updated policy.
15 — Complaints
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Norwegian data protection authority:
16 — Contact
For any privacy-related questions or to exercise your rights: hello@leados.tech