Legal basis: legitimate interest
GDPR Art. 6(1)(f)For B2B prospecting, the legal basis is legitimate interest. Every recipient has the right to object (Art. 21). We stop immediately when they do.
How we handle it
- We carry out a Legitimate Interest Assessment (LIA) before each campaign and keep it on file.
- We document why the offer is relevant to the recipient's role and company.
- We add objecting recipients to the opt-out list without delay.
How we find and obtain contact data
We only process data about professionals in their business role. Data is obtained through a small number of defined routes, each using GDPR-compliant tools that act as our sub-processors (see section 8).
Data we collect
- Full name, job title, company, work email, work phone (where published or available from a licensed provider), LinkedIn profile URL, country.
- Company-level facts: industry, size, location, products, public news and initiatives.
Licensed B2B data and enrichment through Clay
- We use licensed B2B data through Clay.com, a data platform used by companies ranging from small businesses to Fortune 500 enterprises.
- Clay (Clay Labs Inc.) holds SOC 2 Type II and ISO 27001 certifications. A Data Processing Agreement (DPA) is in place.
- Clay connects to third-party B2B data providers, such as email-finding and email-verification services. These providers act as Clay's sub-processors and are listed in Clay's Trust Center: https://trust.clay.com/
- We use this only to find and verify the work email of named decision makers at accounts that match the client's approved target criteria. We do not buy bulk or consumer lists.
AI research agent (Clay)
- Clay's AI research agent reads publicly accessible web pages: company websites, news, job postings, and contact details that the prospect company itself lists on its website.
- It extracts company-level facts and, where the company itself publishes it, the business role of relevant people. The output is used to qualify accounts and personalise the first message.
- The agent works only on publicly accessible pages. It does not log in to any website or access gated content, and it is not used to research private life.
Public professional profiles
- We review public professional profiles on LinkedIn to confirm a person's current role and company. LinkedIn is used under its own terms as an independent controller (see section 8).
Client-provided data
- Where a client provides lists, CRM exports or suppression files, we process them only on the client's instructions, as processor (see section 3).
Controls across all routes
- No special category data (Art. 9), no private or personal contact details, no data from closed groups or login-only sources.
- Every researched record is reviewed by a team member. The client approves the target list and message copy before any contact is made.
- We record the source category of each contact so we can answer "where did you get my data?" requests (section 5).
Roles per engagement
GDPR Art. 4, 28GDPR distinguishes controllers (decide why and how data is processed) from processors (act on the controller's instructions). Our role depends on where the data comes from.
How we handle it
- When we source contacts ourselves (routes A to C in section 2), we act as an independent controller for the sourcing. The client is a separate controller once leads are handed over.
- When the client provides lists, suppression files, or CRM data (route D), we act as processor on the client's instructions.
- Roles are fixed in a Data Processing Agreement (DPA) signed before the campaign. We provide our DPA template on request.
Application of the ePrivacy Directive (differences between countries)
Electronic marketing is governed by the ePrivacy Directive (2002/58/EC), implemented through national laws.
- Some member states require strict consent (opt-in), for example Lithuania, Italy, Spain.
- Others permit B2B opt-out, for example the Netherlands.
- The "soft opt-in" exception applies everywhere: existing customers, similar services, easy unsubscribe.
How we handle it
- We check the target country's rules before the campaign.
- In strict-consent countries we use LinkedIn or consent-based lists.
First-contact notice
GDPR Art. 14When contacts are obtained indirectly (section 2), we must provide the full GDPR information at the point of first contact, not only when asked.
How we handle it
- Every first email includes a one-line notice with a link to our public privacy notice:First emailTo: Lukas Brandt, Nordhafen LogistikWe found your contact details in publicly available professional sources. Read how we process your data and how to opt out: [link].
- This page is our public privacy notice (leansales.tech/data-processing). It covers: who we are, what data we hold, legal basis, retention, recipients, transfers, and data subject rights.
- If a contact asks how we obtained their details, we answer within 5 working days with the source category.
Data minimisation and retention
GDPR Art. 5(1)(c), 5(1)(e)We keep only the data that is necessary, for only as long as necessary. No sensitive data.
How we handle it
- We collect only the fields listed in section 2.
- We do not store personal notes that could be sensitive. We never store special category data (Art. 9).
- Contact data is deleted 30 days after the engagement ends, or after 12 months without any interaction, whichever comes first.
- The opt-out list is retained beyond the engagement. It contains the email address only. This is necessary to honor the objection permanently and prevent repeat contact.
Sub-processors and tools
GDPR Art. 28(2), 28(4)Any tool that stores or processes personal data on our behalf is a sub-processor. Each must be under a DPA, and clients must be able to see the list.
| Sub-processor | Location | Purpose | Transfer mechanism |
|---|---|---|---|
| Clay (Clay Labs Inc.) | USA | Contact discovery, enrichment and verification; AI research agent on public websites. Clay's own sub-processors (data providers and AI models) are listed at https://trust.clay.com/ | SCCs / DPF, per Clay DPA |
| Reply.io (Reply, Inc.) | USA | Email and LinkedIn sequencing | SCCs / DPF, per vendor DPA |
| Google Workspace incl. Google Sheets (Google Ireland Ltd.) | EU / global | Mailboxes, document and sheet storage, shared deliverables | SCCs |
- Data providers and AI models used inside Clay (for example email-finding services or LLM providers) act as Clay's sub-processors under Clay's DPA. They are listed at https://trust.clay.com/ and are not repeated here.
- Underlying infrastructure for these providers is AWS or Google Cloud, as documented by each vendor.
- LinkedIn (Microsoft) is a data source and messaging channel under its own terms. It is an independent controller, not a sub-processor.
- Sub-processors are reviewed annually. Clients are notified before any change and may object.
International transfers
GDPR Chapter VPersonal data of EU residents leaves the EEA when stored in US-based tools. Each transfer needs a legal safeguard.
How we handle it
- Transfers rely on Standard Contractual Clauses (SCCs) or EU-US Data Privacy Framework certification, as stated in each sub-processor's DPA.
- We prefer EU hosting regions where the tool offers one.
- All laptops that touch client data use full-disk encryption (BitLocker or FileVault). No client data on personal devices or personal cloud accounts.
Data subject requests
GDPR Art. 15 to 22Any person whose data we hold can ask what we have, ask us to delete it, or object to processing. We must respond within one month and pass the request to our sub-processors.
How we handle it
- Requests come to info@leansales.tech, stated in our privacy notice and email footers.
- We acknowledge within 5 working days and complete within 30 days.
- Objection or erasure: contact removed from all active tools (Clay, Reply.io, Google Workspace and Drive exports), added to the opt-out list, and the request is forwarded to sub-processors holding a copy.
- Access requests: we send the fields we hold and the source category.
- Requests concerning client-provided data are forwarded to the client within 2 working days.
- A log of requests and completion dates is kept.
Automated decisions and AI tools
GDPR Art. 22GDPR restricts decisions made solely by automated means that have legal or similarly significant effects on a person.
How we handle it
- We use AI tools for account research (including the Clay research agent in section 2), contact enrichment, lead prioritisation, and message drafting.
- No decision affecting an individual's legal position or access to a service is made automatically. Outreach prioritisation affects only whether and when a business contact receives a message.
- Every AI output is reviewed by a team member before use.
- AI models are used through Clay or through API or enterprise tiers that do not train on our inputs.
- No client or contact data is entered into consumer AI chatbots, free translation sites, or file conversion sites.
Access control and offboarding
GDPR Art. 32Access to personal data is limited to people who need it for the engagement. Access ends when the person leaves.
How we handle it
- Each client has a separate workspace or segment in every tool. Team members receive access only to the clients they work on.
- Two-factor authentication is required on all tools that support it.
- Offboarding checklist, completed on the person's last working day: Clay, Reply.io, Google Workspace, shared mailboxes, password manager entries.
- Access is reviewed quarterly.
Client data separation
Data collected or provided for one client is used for that client only.
How we handle it
- No reuse of one client's lists, ICP definitions, suppression files, or campaign results for another client.
- Clients in the same vertical are handled in separate workspaces with separate sequences and separate research outputs.
- Personal data is not used for any purpose other than the agreed campaign.
Security incident protocol
GDPR Art. 33, 28(3)(f)A controller must notify its regulator within 72 hours of becoming aware of a breach. As processor or partner, we must notify the client fast enough for them to meet that deadline.
How we handle it
- If we detect or are notified of unauthorised access to, loss of, or disclosure of client personal data, we notify the client's named contact by email within 24 hours of confirmation. The notice states what happened, which data and how many records, and containment steps taken.
- A follow-up report is sent within 72 hours.
- Sub-processors are contractually required to notify us of incidents affecting our data.
- Each client names a security contact in the DPA. Incidents are logged internally.
End of engagement
When the campaign ends, the client's data must be returned or deleted.
How we handle it
- Within 30 days of contract end, we return final lead data to the client and delete personal data from all tools, including exports, automation logs, and enrichment tables.
- The opt-out list is retained (email only, see section 7).
- A signed certificate of destruction is provided on request.
Training
People handling personal data must know these rules.
How we handle it
- Every team member and contractor completes a privacy session within their first month and annually thereafter.
- The session covers: legal basis, data sources, opt-out handling, data minimisation, approved tools, incident reporting.
- A log with date and attendees is kept.
Client onboarding checklist
Annex ABefore launching a campaign we confirm these points with the client:
- DPA signed, roles defined (section 3)
- Named privacy and security contact at the client
- Target countries confirmed and ePrivacy rules checked (section 4)
- LIA completed and filed (section 1)
- Data sources agreed (section 2)
- Client-provided data, if any, received through an approved channel
- Suppression list from the client loaded or will be done manually by the client
- Sub-processor list shared with the client (section 8)
- Retention period confirmed (default: 30 days after contract end)