Legal

GDPR Statement

This Statement explains how Leads.Garden approaches its obligations under Regulation (EU) 2016/679 (the 'EU GDPR') and the UK General Data Protection Regulation as retained in UK law (together, 'GDPR'). It is a supplement to, and must be read together with, our Privacy Policy and Terms of Service.

Last updated July 10, 2026

1. Roles

In respect of buyer account data, marketing and support interactions, we act as a Controller. In respect of business contact data included in our Bundles, we act as an independent Controller, and any purchaser of a Bundle who subsequently processes that data acts as a separate independent Controller. Where a Customer uploads Personal Data to the Service in the ordinary course of using it (for example, sending attachments to support), we act as a Processor and the Customer as Controller; our Data Processing Agreement governs that processing.

2. Lawful basis for Bundle data

We rely on legitimate interests (Art. 6(1)(f) GDPR) for the processing of publicly available business contact data for the purposes of business-to-business marketing and sales enablement. We have carried out and maintain a Legitimate Interests Assessment ('LIA') covering purpose, necessity and the balancing test against the interests, rights and freedoms of Data Subjects. The LIA is reviewed at least annually and on any material change to processing. Data Subjects retain an absolute right to object under Art. 21(2) GDPR to processing for direct marketing purposes.

3. Data Subject rights

We uphold the following rights, subject to statutory exceptions:

  • Right of access (Art. 15) — obtain a copy of the personal data we hold about you;
  • Right to rectification (Art. 16) — have inaccurate data corrected;
  • Right to erasure (Art. 17) — have your data deleted where grounds exist;
  • Right to restriction (Art. 18) — limit our processing pending a decision;
  • Right to portability (Art. 20) — receive a machine-readable copy of data you provided;
  • Right to object (Art. 21) — object to processing, absolute for direct marketing;
  • Right to lodge a complaint (Art. 77) — with your competent supervisory authority.

4. How to exercise rights

Email privacy@leads.garden or dpo@leads.garden. We verify identity through the requesting email address and reasonable additional means, and respond within one month (extendable by up to two further months for complex requests, with prior notice).

5. International data transfers

Where personal data leaves the EEA, the UK or Switzerland, we rely on adequacy decisions where available and otherwise on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), the UK IDTA or UK Addendum, and additional supplementary measures identified through transfer impact assessments where necessary.

6. Sub-processors

We use a limited number of sub-processors to operate the Service, including managed database, authentication, object storage, transactional email, payment processing and analytics providers. Each sub-processor is bound by contractual obligations no less protective than those in our own agreements with Customers. A current list is available on request to dpo@leads.garden.

7. Security

We maintain technical and organisational measures appropriate to the risk of the processing, including encryption in transit and at rest, access control based on the principle of least privilege, audit logging, secure software development practices and periodic review of security controls.

8. Personal data breaches

In the event of a personal data breach likely to result in a risk to Data Subjects' rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware. Where the breach is likely to result in a high risk, we will also notify affected Data Subjects and, where applicable, Customers acting as Controllers.

9. Representative and DPO

You can reach our Data Protection Officer at dpo@leads.garden. Where required by Art. 27 GDPR, we will appoint an EU representative; contact details are available on request.

10. Complaints

You have the right to lodge a complaint with a supervisory authority, in particular in the EU or EEA Member State of your habitual residence, place of work or the place of the alleged infringement. In the UK, the competent authority is the Information Commissioner's Office (ICO).