Privacy Policy
How we protect and process your personal data
Controller within the meaning of the GDPR: Workbase Platforms Sp. z o.o. Franz-Joseph-Str. 11 Munich, Germany Email: legal@leadbase.io Represented by Managing Director: Nils Kröger VAT identification number: PL8992989402 Statistical identification number: 52819974800000 Commercial register entry: 0001096902 D-U-N-S number: 664903637 Data Protection Officer: For questions about data protection, exercising your rights, or complaints, you can contact our Data Protection Officer at: Email: privacy@leadbase.io Post: Data Protection Officer, Franz-Joseph-Str. 11, 80801 Munich, Germany EU establishment: As a Polish company offering services in the EU, we have an EU establishment in Germany at Franz-Joseph-Str. 11, Munich, Germany.
Scope and Fundamental Principles of Data Processing
This Privacy Policy explains how personal data is processed when you use our B2B data-enrichment platform, “Leadbase.” It applies to all services, APIs, integrations, and related services. Our data protection principles:
- Lawfulness: Processing only on the basis of a valid legal ground
- Purpose limitation: Data is processed only for specified, explicit purposes
- Data minimization: Only necessary data is collected and processed
- Accuracy: Appropriate measures ensure data accuracy
- Storage limitation: Data is deleted once retention periods expire
- Integrity and confidentiality: Technical and organizational safeguards
- Accountability: Demonstrable compliance with all data protection principles
Categories of Personal Data and Data Sources
We process different categories of personal data obtained from a range of sources:
Customer Data (Provided by You)
- Account data: Name, email address, phone number, and company information
- Contract data: Billing information, payment data, and billing address
- Technical data: IP address, browser information, and device identifiers
- Usage data: Login times, feature usage, API calls, and search history
- Communications data: Support requests, email correspondence, and chat messages
- Upload data: Lists and contact data that you upload for enrichment
Lead Data (for Enrichment Services)
- Business contacts: Names, positions, email addresses, and phone numbers
- Company data: Company names, addresses, industries, employee counts, and revenue
- Social-media profiles: LinkedIn, XING, and other professional networks
- Website data: Company URLs, technology stack, and online presence
Automatically Collected Data
- Log data: Server logs, error logs, and performance metrics
- Analytics data: Page views, clickstreams, dwell time, and conversion events
- Security data: Failed login attempts and suspicious activities
- Cookie data: Preferences, session management, and tracking parameters
Legal Bases for Data Processing under the GDPR
We process your personal data exclusively on the following legal bases under Article 6 GDPR:
Consent (Article 6(1)(a) GDPR)
- Marketing communications and newsletters
- Non-essential cookies and tracking
- Beta-feature testing and product feedback
- Additional analytics and personalization
Performance of a Contract (Article 6(1)(b) GDPR)
- Account creation and management
- Service provision and lead enrichment
- API access and technical integration support
- Customer support and technical assistance
- Billing and payment processing
Legitimate Interests (Article 6(1)(f) GDPR)
- IT security and fraud prevention
- Service improvement and quality assurance
- Internal analytics and business intelligence
- Legal compliance and audit purposes
- Direct marketing in existing business relationships
Legal Obligation (Article 6(1)(c) GDPR)
- Tax-law retention obligations (10 years)
- Commercial-law documentation obligations
- Anti-money-laundering compliance (KYC/AML)
- Official information requests supported by a legal basis
Detailed Purposes of Data Processing
Service Provision and Operation
- Authentication and account management
- Lead data enrichment and CRM integration
- API provision and rate limiting
- Webhook processing and real-time updates
- Data exports and reporting functions
- Usage tracking for billing purposes
Technical Operation and Maintenance
- System monitoring and performance optimization
- Error diagnosis and technical debugging
- Security monitoring and incident response
- Software updates and feature rollouts
- Backup and disaster recovery
Compliance and Legal Requirements
- GDPR compliance and data-subject rights
- Audit trails and compliance reporting
- Tax and commercial-law documentation
- Anti-spam and anti-fraud measures
- Enforcement in the event of contractual breaches
Business Intelligence and Product Development
- Aggregated analytics and usage statistics
- A/B testing and feature evaluation
- Product improvement and roadmap planning
- Market research and competitive intelligence
- Customer success and churn prevention
Disclosures to Third Parties and International Transfers
Processors (Article 28 GDPR)
We work with carefully selected processors with whom we have concluded the appropriate data processing agreements:
- Cloud hosting: AWS/Google Cloud (EU regions): Server hosting and database
- CDN and performance: Cloudflare: Content delivery and DDoS protection
- Email services: Transactional emails and notifications
- Analytics: Google Analytics 4: Website analytics (IP anonymization enabled)
- Customer support: Intercom: Chat support and ticketing
- Payment processing: Autumn/Stripe: Subscription management and payments
- Monitoring: Sentry: Error tracking and performance monitoring
International Data Transfers
Some of our processors have locations outside the EU. The following safeguards apply to those transfers:
- USA: EU-U.S. Data Privacy Framework (European Commission adequacy decision)
- Other third countries: EU Standard Contractual Clauses (SCCs) under Article 46 GDPR
- Additional safeguards: Encryption, pseudonymization, and data minimization
- Regular assessment: Continuous monitoring of the level of data protection
Disclosure to Public Authorities
Personal data is disclosed to law-enforcement authorities or other public bodies only where there is a corresponding legal basis, such as a court order or official directive.
Retention Periods and Deletion Policy
We retain personal data only for as long as necessary for the relevant purposes:
Account and Contract Data
- Active accounts: For the duration of the business relationship
- After the contract ends: A 30-day transition period, followed by complete deletion
- Billing data: 10 years (tax-law retention obligation)
- Contract documentation: 10 years (commercial-law retention obligation)
Technical and Log Data
- Server logs: 12 months (security and debugging)
- Analytics data: 26 months (Google Analytics standard)
- Error logs: 6 months (technical troubleshooting)
- Session data: Automatically deleted after 30 days of inactivity
Support and Communications Data
- Support tickets: 3 years after closure
- Email correspondence: 3 years after the last contact
- Chat transcripts: 1 year after the conversation ends
Lead and Enrichment Data
- Enriched data: Deleted upon account termination
- Uploaded lists: Deleted after 90 days or at the customer's request
- Search history: 12 months for service optimization
Automated deletion: We use automated deletion routines that regularly identify expired data and securely remove it. Customers receive 30 days’ advance notice before account deletion and have the option to export their data.
Your Comprehensive Rights as a Data Subject under the GDPR
As a data subject, you have the following rights, which you may exercise at any time by contacting privacy@leadbase.io:
Right of Access (Article 15 GDPR)
- Confirmation of whether we process data concerning you
- Information about categories, purposes, recipients, and retention periods
- Information about your rights and complaint options
- A copy of the processed data (first copy free of charge)
- Processing time: Within 30 days after identity verification
Right to Rectification (Article 16 GDPR)
- Correction of inaccurate personal data
- Completion of incomplete data
- Automatic forwarding of corrections to recipients
- Processing time: Without undue delay and no later than 30 days
Right to Erasure / “Right to Be Forgotten” (Article 17 GDPR):
- Erasure when the purpose of processing no longer applies
- Withdrawal of consent where there is no other legal basis
- Objection to processing where there are no overriding interests
- Exceptions: Statutory retention obligations remain unaffected
- Technically secure deletion with confirmation
Right to Restriction of Processing (Article 18 GDPR)
- Blocking while the accuracy of data is disputed
- Restriction in the event of unlawful processing
- Retention for legal claims despite an obligation to erase
- Marking and isolation of the affected data
Right to Data Portability (Article 20 GDPR)
- Export in a structured, machine-readable format (JSON, CSV)
- Applies only to data processed on the basis of consent or a contract
- Direct transfer to another controller where possible
- Free provision through secure download links
Right to Object (Article 21 GDPR)
- Objection to processing based on legitimate interests
- Absolute right to object to direct marketing
- Objection to profiling and automated decision-making
- Assessment of overriding legitimate grounds
Right to Withdraw Consent (Article 7 GDPR)
- Withdrawal is possible at any time without stating reasons
- Simple withdrawal methods such as unsubscribe links and account settings
- The lawfulness of processing carried out before withdrawal remains unaffected
- Information about withdrawal options whenever consent is requested
Procedure for exercising your rights: Requests may be submitted informally by email to privacy@leadbase.io. To verify your identity, we require a copy of your identity document. We acknowledge receipt within 48 hours and process requests within the statutory time limits.
Comprehensive Technical and Organizational Measures (TOMs)
We have implemented extensive technical and organizational measures to ensure the security and protection of personal data:
Technical Security Measures
- Encryption: TLS 1.3 for data in transit and AES-256 for data at rest
- Authentication: Multi-factor authentication for all administrator accounts
- Access control: Role-based authorization under the least-privilege principle
- Network security: Firewalls, VPN access, and intrusion-detection systems
- Monitoring: 24/7 Security Operations Center (SOC) with real-time alerts
- Backup: Encrypted, geographically distributed backups with regular testing
- Endpoint protection: Anti-malware, device management, and remote wipe
Organizational Safeguards
- Employee training: Regular GDPR and security-awareness training
- Access management: Documented authorization concepts and regular reviews
- Confidentiality commitments: For all employees and service providers
- Incident response: Documented processes for data breaches and security incidents
- Compliance management: Regular internal and external audits
- Data governance: Clear responsibilities and approval processes
Physical Security
- High-security data centers with biometric access controls
- 24/7 physical monitoring and security personnel
- Climate control, fire protection, and uninterruptible power supply
- Clean-desk policy and secure storage of physical documents
Data Protection by Design (Privacy by Design)
- Data minimization incorporated into system design
- Privacy-friendly settings by default
- Pseudonymization and anonymization where possible
- Regular Privacy Impact Assessments (PIAs)
Cookies and Tracking Technologies
Our website and services use various cookies and similar technologies. You can adjust your cookie preferences at any time through our cookie banner or your browser settings.
Essential Cookies (No Consent Required)
- Session cookies: User login and authentication
- CSRF tokens: Protection against cross-site request-forgery attacks
- Load balancer: Distribution of server load for optimal performance
- Cookie preferences: Storage of your cookie settings
Functional Cookies (Consent Required)
- UI preferences: Theme, language settings, and dashboard layout
- Form data: Temporary storage in multi-step forms
Analytics Cookies (Consent Required)
- Google Analytics 4: Website usage and visitor behavior (IP-anonymized)
- Hotjar: Heatmaps and session recordings (anonymized)
- Intercom: Customer-support chat and helpdesk integration
Marketing Cookies (Consent Required)
- LinkedIn Insight Tag: Retargeting for LinkedIn campaigns
- Google Ads: Conversion tracking and remarketing
- Facebook Pixel: Social-media advertising (if enabled)
Cookie management: You can disable cookies in your browser settings. Please note that doing so may limit website functionality. Our cookie banner appears on your first visit and can be opened again at any time through the footer.
Automated Decision-Making and Profiling
Leadbase uses limited automated processing, but it does not result in decisions producing legal effects:
Fraud Detection and Security
- Automatic detection of suspicious login attempts
- Rate limiting in the event of API misuse
- Spam filters for support requests
- No legally binding decisions: There is always a manual review
Service Optimization
- Personalization of the user interface based on usage patterns
- Recommendations for relevant features and integrations
- Automated data-quality checks and improvements
- A/B testing for feature rollouts
Lead Scoring and Data Enrichment
- Algorithms for assessing data quality and lead relevance
- Automated data validation and duplicate checks
- Matching algorithms for CRM integration; customers retain control over final decisions at all times
Your rights: You have the right not to be subject to a decision based solely on automated processing (Article 22 GDPR). Because our systems do not make legally significant automated decisions, this right is not applicable at Leadbase. If you have questions, contact privacy@leadbase.io.
Children's Privacy
No services for persons under 16: Leadbase is a B2B platform intended exclusively for business customers and professional users. Our services are not intended for persons under 16, and we do not knowingly collect personal data from children.
Procedure for inadvertently collected data:
- Immediate deletion upon learning that a child's data has been collected
- Notification of the parents or legal guardians
- Review and adjustment of preventive measures
- Documentation for compliance purposes
Parental responsibility: If a child has inadvertently created an account, we ask the parent or legal guardian to contact us immediately at privacy@leadbase.io. We will delete the account and all related data without undue delay.
Data Breaches and Incident Response
Data breaches may occur despite comprehensive security measures. We have established detailed processes for handling security incidents:
Incident Response Process
- Detection: Automated monitoring systems and manual monitoring
- Assessment: Evaluation of severity and affected data
- Containment: Immediate containment to limit harm
- Investigation: Forensic analysis and root-cause investigation
- Remediation: Resolution of vulnerabilities and system hardening
- Communication: Notification of all stakeholders in accordance with legal requirements
GDPR Notification Obligations
- Supervisory authority: Notification to the competent data protection authority within 72 hours
- Data subjects: Notification where there is a high risk to rights and freedoms
- Customers: Notification of all affected business customers
- Public: Transparent communication in the event of major incidents
Preventive Measures
- Regular penetration tests and vulnerability scans
- Security-awareness training for all employees
- Incident-response exercises and tabletop exercises
- Continuous improvement of security measures
Reporting security incidents: If you suspect a security incident or potential data breach, contact us immediately at security@leadbase.io. We take every report seriously and investigate each case thoroughly.
Complaint Rights and Supervisory Authorities
You have the right to lodge complaints about the processing of your personal data with the competent supervisory authorities:
Competent Supervisory Authorities
- Germany (establishment): Bavarian State Office for Data Protection Supervision, Promenade 18, Ansbach, Email: poststelle@lda.bayern.de, Phone: +49 (0) 981 53-1300
- Poland (head office): Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland, Email: kancelaria@uodo.gov.pl, Phone: +48 22 531 03 00
Your Complaint Process
- 1. Direct contact: First contact privacy@leadbase.io
- 2. Internal escalation: If dissatisfied, escalate to the Data Protection Officer
- 3. Supervisory authority: Lodge a complaint with the competent data protection authority
- 4. Judicial remedy: Bring an action before the ordinary courts
International Complaints
EU citizens may also contact the data protection authority in their country of residence. It will cooperate with the lead supervisory authority through the one-stop-shop procedure.
Changes to This Privacy Policy
Amendment Procedure
This Privacy Policy may be amended due to legal changes, new services, or improved data-protection practices:
- Material changes: Email notice 30 days before they take effect
- Minor changes: Website update with a notice
- Emergency updates: Immediate adjustment where required by law
- Version control: All changes recorded with a date and change log
Right to Object to Changes
You may object to continued data processing in the event of material changes. In that case, we may terminate your account in compliance with the applicable notice periods. Your data will then be removed in accordance with the deletion provisions.
Archiving Earlier Versions
We archive earlier versions of this Privacy Policy for 10 years for compliance documentation. Upon request, we can tell you which version was effective at a particular time.
Contact and Further Information
Privacy Contact
For all privacy-related inquiries, complaints, or exercises of your data-subject rights:
- Email: privacy@leadbase.io (response within 48 hours)
- Post: Data Protection Officer, Franz-Joseph-Str. 11, 80801 Munich
- Encryption: PGP key available on request
Additional Privacy Resources
- Cookie Policy: Detailed information about all cookies used
- Processor List: Complete list of all processors
- DPA templates: Sample data processing agreements for enterprise customers
- Privacy Portal: Self-service portal for common privacy requests
Industry-Specific Compliance
For customers in regulated sectors (financial services, healthcare, and the public sector), we provide additional compliance documentation. Contact our compliance team at compliance@leadbase.io.