Privacy Policy
Last updated: May 25, 2026
This Privacy Policy explains what personal data AgencyLeads (“AgencyLeads,” “we,” “us”) collects, how we use it, who we share it with, and what rights you have. This policy applies to (a) visitors to our website, (b) account holders using our platform, and (c) individuals whose contact details our customers process through the platform.
1. Roles Under GDPR
For account holders and website visitors, AgencyLeads is the data controller of your personal information.
For lead and recipient data uploaded or sourced by customers, the customer is the controller and AgencyLeads is the data processor acting on the customer's instructions. The terms of that processing are set out in our Data Processing Agreement.
2. What We Collect
From account holders
- Identifiers: name, email, workspace name, profile photo (via Google OAuth).
- Authentication: Google OAuth tokens, session cookies, login timestamps, IP address.
- Mailbox connection: when you connect Gmail through Smartlead, scopes for sending and reading the connected account are granted to our infrastructure provider.
- Billing: handled by Whop; we receive subscription state but not payment-card data.
- Usage: pages visited, features used, credit consumption, errors.
From lead and recipient data
- Names, email addresses, job titles, company names, LinkedIn URLs, locations, employment history — sourced from third-party data providers (CoreSignal) or uploaded by the customer.
- Email-finder results and verification status (Findymail, Better Contact, MillionVerifier).
- Email reply content, classification labels, and pipeline outcomes when a recipient responds to a customer's cold campaign.
Technical data
- Cookies, browser/device information, IP address, referrer.
- Logs from our infrastructure providers (Vercel, Supabase).
3. Why We Process Personal Data
- To provide the Service: create accounts, authenticate, route data between providers, send emails, score replies, surface results in your dashboard.
- To bill you: manage subscriptions, calculate credit usage, issue receipts.
- To improve the Service: aggregate usage analytics, A/B-test prompts, monitor errors and abuse.
- To comply with law: respond to lawful requests, retain records as required, defend legal claims.
- To communicate: send service notifications, security alerts, and (where consent applies) product updates.
4. Legal Bases Under GDPR
- Contract: processing necessary to provide the Service you signed up for.
- Legitimate interest: security, fraud prevention, product analytics, defending claims.
- Consent: non-essential cookies, marketing emails (where applicable).
- Legal obligation: tax, accounting, anti-money-laundering, lawful authority requests.
5. How Long We Keep It
- Account data: while the account is active, plus 12 months after closure for dispute / audit reasons.
- Lead / recipient data uploaded by a customer: deleted on the customer's instruction or within 90 days of account closure, whichever is sooner.
- Billing records: 10 years (legal retention).
- Logs: 90 days.
6. Who We Share It With
We share personal data only with the following categories of recipients:
- Infrastructure providers: Vercel (hosting), Supabase (database), Cloudflare (CDN/security where applicable).
- Data providers we route requests to: CoreSignal, Findymail, Better Contact, MillionVerifier — to enrich/source/verify leads on the customer's instruction.
- Email infrastructure: Smartlead.ai — to send outbound campaigns and ingest replies.
- AI processor: Anthropic (Claude API) — to generate personalized email content, classify replies, suggest filters. Anthropic does not train on data sent via our API key.
- Authentication: Google (OAuth) for login and mailbox connection.
- Billing: Whop — for subscription management and payments.
- Authorities and successors: if required by law, in connection with legal claims, or as part of a corporate transaction (merger / acquisition / asset sale), in which case we will notify affected users.
We do not sell personal data.
7. International Transfers
Some of our providers process data in the United States. Where personal data of EU/UK data subjects is transferred outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) and on equivalent UK provisions. Copies of SCCs in force with key sub-processors are available on request to privacy@agencyleads.com.
8. Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete data (“right to be forgotten”);
- Restrict or object to certain processing;
- Receive a portable copy of your data;
- Withdraw consent at any time (for processing based on consent);
- Lodge a complaint with your supervisory authority (in the EU, your national DPA).
To exercise these rights, email privacy@agencyleads.com. We will respond within 30 days. If you are the recipient of a cold email sent through our platform and want your data removed from a customer's campaign, contact the sender directly; we can also help by suppressing your email address from future sends across the platform — write to the address above.
9. Security
We use industry-standard measures to protect personal data: TLS encryption in transit, encryption at rest for our database and credential storage, role-based access controls, audit logging, and regular dependency updates. No method of transmission or storage is 100% secure; if a breach occurs, we will notify affected users and the appropriate authority as required by GDPR.
10. Children
The Service is not directed at individuals under 18. If you believe we have collected personal data from a minor, contact us and we will delete it.
11. Changes
We may update this policy from time to time. Material changes will be communicated by email or in-app notice. The “last updated” date at the top reflects the most recent revision.
12. Contact
Privacy: privacy@agencyleads.com
Legal: legal@agencyleads.com
[REGISTERED COMPANY NAME / ADDRESS TO BE FILLED IN]