Skip to content

Privacy Policy

How we protect and process your personal data

Controller within the meaning of the GDPR: Workbase Platforms Sp. z o.o. Franz-Joseph-Str. 11 Munich, Germany Email: legal@leadbase.io Represented by Managing Director: Nils Kröger VAT identification number: PL8992989402 Statistical identification number: 52819974800000 Commercial register entry: 0001096902 D-U-N-S number: 664903637 Data Protection Officer: For questions about data protection, exercising your rights, or complaints, you can contact our Data Protection Officer at: Email: privacy@leadbase.io Post: Data Protection Officer, Franz-Joseph-Str. 11, 80801 Munich, Germany EU establishment: As a Polish company offering services in the EU, we have an EU establishment in Germany at Franz-Joseph-Str. 11, Munich, Germany.

Scope and Fundamental Principles of Data Processing

This Privacy Policy explains how personal data is processed when you use our B2B data-enrichment platform, “Leadbase.” It applies to all services, APIs, integrations, and related services. Our data protection principles:

  • Lawfulness: Processing only on the basis of a valid legal ground
  • Purpose limitation: Data is processed only for specified, explicit purposes
  • Data minimization: Only necessary data is collected and processed
  • Accuracy: Appropriate measures ensure data accuracy
  • Storage limitation: Data is deleted once retention periods expire
  • Integrity and confidentiality: Technical and organizational safeguards
  • Accountability: Demonstrable compliance with all data protection principles

Categories of Personal Data and Data Sources

We process different categories of personal data obtained from a range of sources:

Customer Data (Provided by You)

  • Account data: Name, email address, phone number, and company information
  • Contract data: Billing information, payment data, and billing address
  • Technical data: IP address, browser information, and device identifiers
  • Usage data: Login times, feature usage, API calls, and search history
  • Communications data: Support requests, email correspondence, and chat messages
  • Upload data: Lists and contact data that you upload for enrichment

Lead Data (for Enrichment Services)

  • Business contacts: Names, positions, email addresses, and phone numbers
  • Company data: Company names, addresses, industries, employee counts, and revenue
  • Social-media profiles: LinkedIn, XING, and other professional networks
  • Website data: Company URLs, technology stack, and online presence

Automatically Collected Data

  • Log data: Server logs, error logs, and performance metrics
  • Analytics data: Page views, clickstreams, dwell time, and conversion events
  • Security data: Failed login attempts and suspicious activities
  • Cookie data: Preferences, session management, and tracking parameters

We process your personal data exclusively on the following legal bases under Article 6 GDPR:

Consent (Article 6(1)(a) GDPR)

  • Marketing communications and newsletters
  • Non-essential cookies and tracking
  • Beta-feature testing and product feedback
  • Additional analytics and personalization

Performance of a Contract (Article 6(1)(b) GDPR)

  • Account creation and management
  • Service provision and lead enrichment
  • API access and technical integration support
  • Customer support and technical assistance
  • Billing and payment processing

Legitimate Interests (Article 6(1)(f) GDPR)

  • IT security and fraud prevention
  • Service improvement and quality assurance
  • Internal analytics and business intelligence
  • Legal compliance and audit purposes
  • Direct marketing in existing business relationships

Legal Obligation (Article 6(1)(c) GDPR)

  • Tax-law retention obligations (10 years)
  • Commercial-law documentation obligations
  • Anti-money-laundering compliance (KYC/AML)
  • Official information requests supported by a legal basis

Detailed Purposes of Data Processing

Service Provision and Operation

  • Authentication and account management
  • Lead data enrichment and CRM integration
  • API provision and rate limiting
  • Webhook processing and real-time updates
  • Data exports and reporting functions
  • Usage tracking for billing purposes

Technical Operation and Maintenance

  • System monitoring and performance optimization
  • Error diagnosis and technical debugging
  • Security monitoring and incident response
  • Software updates and feature rollouts
  • Backup and disaster recovery
  • GDPR compliance and data-subject rights
  • Audit trails and compliance reporting
  • Tax and commercial-law documentation
  • Anti-spam and anti-fraud measures
  • Enforcement in the event of contractual breaches

Business Intelligence and Product Development

  • Aggregated analytics and usage statistics
  • A/B testing and feature evaluation
  • Product improvement and roadmap planning
  • Market research and competitive intelligence
  • Customer success and churn prevention

Disclosures to Third Parties and International Transfers

Processors (Article 28 GDPR)

We work with carefully selected processors with whom we have concluded the appropriate data processing agreements:

  • Cloud hosting: AWS/Google Cloud (EU regions): Server hosting and database
  • CDN and performance: Cloudflare: Content delivery and DDoS protection
  • Email services: Transactional emails and notifications
  • Analytics: Google Analytics 4: Website analytics (IP anonymization enabled)
  • Customer support: Intercom: Chat support and ticketing
  • Payment processing: Autumn/Stripe: Subscription management and payments
  • Monitoring: Sentry: Error tracking and performance monitoring

International Data Transfers

Some of our processors have locations outside the EU. The following safeguards apply to those transfers:

  • USA: EU-U.S. Data Privacy Framework (European Commission adequacy decision)
  • Other third countries: EU Standard Contractual Clauses (SCCs) under Article 46 GDPR
  • Additional safeguards: Encryption, pseudonymization, and data minimization
  • Regular assessment: Continuous monitoring of the level of data protection

Disclosure to Public Authorities

Personal data is disclosed to law-enforcement authorities or other public bodies only where there is a corresponding legal basis, such as a court order or official directive.

Retention Periods and Deletion Policy

We retain personal data only for as long as necessary for the relevant purposes:

Account and Contract Data

  • Active accounts: For the duration of the business relationship
  • After the contract ends: A 30-day transition period, followed by complete deletion
  • Billing data: 10 years (tax-law retention obligation)
  • Contract documentation: 10 years (commercial-law retention obligation)

Technical and Log Data

  • Server logs: 12 months (security and debugging)
  • Analytics data: 26 months (Google Analytics standard)
  • Error logs: 6 months (technical troubleshooting)
  • Session data: Automatically deleted after 30 days of inactivity

Support and Communications Data

  • Support tickets: 3 years after closure
  • Email correspondence: 3 years after the last contact
  • Chat transcripts: 1 year after the conversation ends

Lead and Enrichment Data

  • Enriched data: Deleted upon account termination
  • Uploaded lists: Deleted after 90 days or at the customer's request
  • Search history: 12 months for service optimization

Automated deletion: We use automated deletion routines that regularly identify expired data and securely remove it. Customers receive 30 days’ advance notice before account deletion and have the option to export their data.

Your Comprehensive Rights as a Data Subject under the GDPR

As a data subject, you have the following rights, which you may exercise at any time by contacting privacy@leadbase.io:

Right of Access (Article 15 GDPR)

  • Confirmation of whether we process data concerning you
  • Information about categories, purposes, recipients, and retention periods
  • Information about your rights and complaint options
  • A copy of the processed data (first copy free of charge)
  • Processing time: Within 30 days after identity verification

Right to Rectification (Article 16 GDPR)

  • Correction of inaccurate personal data
  • Completion of incomplete data
  • Automatic forwarding of corrections to recipients
  • Processing time: Without undue delay and no later than 30 days

Right to Erasure / “Right to Be Forgotten” (Article 17 GDPR):

  • Erasure when the purpose of processing no longer applies
  • Withdrawal of consent where there is no other legal basis
  • Objection to processing where there are no overriding interests
  • Exceptions: Statutory retention obligations remain unaffected
  • Technically secure deletion with confirmation

Right to Restriction of Processing (Article 18 GDPR)

  • Blocking while the accuracy of data is disputed
  • Restriction in the event of unlawful processing
  • Retention for legal claims despite an obligation to erase
  • Marking and isolation of the affected data

Right to Data Portability (Article 20 GDPR)

  • Export in a structured, machine-readable format (JSON, CSV)
  • Applies only to data processed on the basis of consent or a contract
  • Direct transfer to another controller where possible
  • Free provision through secure download links

Right to Object (Article 21 GDPR)

  • Objection to processing based on legitimate interests
  • Absolute right to object to direct marketing
  • Objection to profiling and automated decision-making
  • Assessment of overriding legitimate grounds

Right to Withdraw Consent (Article 7 GDPR)

  • Withdrawal is possible at any time without stating reasons
  • Simple withdrawal methods such as unsubscribe links and account settings
  • The lawfulness of processing carried out before withdrawal remains unaffected
  • Information about withdrawal options whenever consent is requested

Procedure for exercising your rights: Requests may be submitted informally by email to privacy@leadbase.io. To verify your identity, we require a copy of your identity document. We acknowledge receipt within 48 hours and process requests within the statutory time limits.

Comprehensive Technical and Organizational Measures (TOMs)

We have implemented extensive technical and organizational measures to ensure the security and protection of personal data:

Technical Security Measures

  • Encryption: TLS 1.3 for data in transit and AES-256 for data at rest
  • Authentication: Multi-factor authentication for all administrator accounts
  • Access control: Role-based authorization under the least-privilege principle
  • Network security: Firewalls, VPN access, and intrusion-detection systems
  • Monitoring: 24/7 Security Operations Center (SOC) with real-time alerts
  • Backup: Encrypted, geographically distributed backups with regular testing
  • Endpoint protection: Anti-malware, device management, and remote wipe

Organizational Safeguards

  • Employee training: Regular GDPR and security-awareness training
  • Access management: Documented authorization concepts and regular reviews
  • Confidentiality commitments: For all employees and service providers
  • Incident response: Documented processes for data breaches and security incidents
  • Compliance management: Regular internal and external audits
  • Data governance: Clear responsibilities and approval processes

Physical Security

  • High-security data centers with biometric access controls
  • 24/7 physical monitoring and security personnel
  • Climate control, fire protection, and uninterruptible power supply
  • Clean-desk policy and secure storage of physical documents

Data Protection by Design (Privacy by Design)

  • Data minimization incorporated into system design
  • Privacy-friendly settings by default
  • Pseudonymization and anonymization where possible
  • Regular Privacy Impact Assessments (PIAs)

Cookies and Tracking Technologies

Our website and services use various cookies and similar technologies. You can adjust your cookie preferences at any time through our cookie banner or your browser settings.

  • Session cookies: User login and authentication
  • CSRF tokens: Protection against cross-site request-forgery attacks
  • Load balancer: Distribution of server load for optimal performance
  • Cookie preferences: Storage of your cookie settings
  • UI preferences: Theme, language settings, and dashboard layout
  • Form data: Temporary storage in multi-step forms
  • Google Analytics 4: Website usage and visitor behavior (IP-anonymized)
  • Hotjar: Heatmaps and session recordings (anonymized)
  • Intercom: Customer-support chat and helpdesk integration
  • LinkedIn Insight Tag: Retargeting for LinkedIn campaigns
  • Google Ads: Conversion tracking and remarketing
  • Facebook Pixel: Social-media advertising (if enabled)

Cookie management: You can disable cookies in your browser settings. Please note that doing so may limit website functionality. Our cookie banner appears on your first visit and can be opened again at any time through the footer.

Automated Decision-Making and Profiling

Leadbase uses limited automated processing, but it does not result in decisions producing legal effects:

Fraud Detection and Security

  • Automatic detection of suspicious login attempts
  • Rate limiting in the event of API misuse
  • Spam filters for support requests
  • No legally binding decisions: There is always a manual review

Service Optimization

  • Personalization of the user interface based on usage patterns
  • Recommendations for relevant features and integrations
  • Automated data-quality checks and improvements
  • A/B testing for feature rollouts

Lead Scoring and Data Enrichment

  • Algorithms for assessing data quality and lead relevance
  • Automated data validation and duplicate checks
  • Matching algorithms for CRM integration; customers retain control over final decisions at all times

Your rights: You have the right not to be subject to a decision based solely on automated processing (Article 22 GDPR). Because our systems do not make legally significant automated decisions, this right is not applicable at Leadbase. If you have questions, contact privacy@leadbase.io.

Children's Privacy

No services for persons under 16: Leadbase is a B2B platform intended exclusively for business customers and professional users. Our services are not intended for persons under 16, and we do not knowingly collect personal data from children.

Procedure for inadvertently collected data:

  • Immediate deletion upon learning that a child's data has been collected
  • Notification of the parents or legal guardians
  • Review and adjustment of preventive measures
  • Documentation for compliance purposes

Parental responsibility: If a child has inadvertently created an account, we ask the parent or legal guardian to contact us immediately at privacy@leadbase.io. We will delete the account and all related data without undue delay.

Data Breaches and Incident Response

Data breaches may occur despite comprehensive security measures. We have established detailed processes for handling security incidents:

Incident Response Process

  • Detection: Automated monitoring systems and manual monitoring
  • Assessment: Evaluation of severity and affected data
  • Containment: Immediate containment to limit harm
  • Investigation: Forensic analysis and root-cause investigation
  • Remediation: Resolution of vulnerabilities and system hardening
  • Communication: Notification of all stakeholders in accordance with legal requirements

GDPR Notification Obligations

  • Supervisory authority: Notification to the competent data protection authority within 72 hours
  • Data subjects: Notification where there is a high risk to rights and freedoms
  • Customers: Notification of all affected business customers
  • Public: Transparent communication in the event of major incidents

Preventive Measures

  • Regular penetration tests and vulnerability scans
  • Security-awareness training for all employees
  • Incident-response exercises and tabletop exercises
  • Continuous improvement of security measures

Reporting security incidents: If you suspect a security incident or potential data breach, contact us immediately at security@leadbase.io. We take every report seriously and investigate each case thoroughly.

Complaint Rights and Supervisory Authorities

You have the right to lodge complaints about the processing of your personal data with the competent supervisory authorities:

Competent Supervisory Authorities

  • Germany (establishment): Bavarian State Office for Data Protection Supervision, Promenade 18, Ansbach, Email: poststelle@lda.bayern.de, Phone: +49 (0) 981 53-1300
  • Poland (head office): Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland, Email: kancelaria@uodo.gov.pl, Phone: +48 22 531 03 00

Your Complaint Process

  • 1. Direct contact: First contact privacy@leadbase.io
  • 2. Internal escalation: If dissatisfied, escalate to the Data Protection Officer
  • 3. Supervisory authority: Lodge a complaint with the competent data protection authority
  • 4. Judicial remedy: Bring an action before the ordinary courts

International Complaints

EU citizens may also contact the data protection authority in their country of residence. It will cooperate with the lead supervisory authority through the one-stop-shop procedure.

Changes to This Privacy Policy

Amendment Procedure

This Privacy Policy may be amended due to legal changes, new services, or improved data-protection practices:

  • Material changes: Email notice 30 days before they take effect
  • Minor changes: Website update with a notice
  • Emergency updates: Immediate adjustment where required by law
  • Version control: All changes recorded with a date and change log

Right to Object to Changes

You may object to continued data processing in the event of material changes. In that case, we may terminate your account in compliance with the applicable notice periods. Your data will then be removed in accordance with the deletion provisions.

Archiving Earlier Versions

We archive earlier versions of this Privacy Policy for 10 years for compliance documentation. Upon request, we can tell you which version was effective at a particular time.

Contact and Further Information

Privacy Contact

For all privacy-related inquiries, complaints, or exercises of your data-subject rights:

  • Email: privacy@leadbase.io (response within 48 hours)
  • Post: Data Protection Officer, Franz-Joseph-Str. 11, 80801 Munich
  • Encryption: PGP key available on request

Additional Privacy Resources

  • Cookie Policy: Detailed information about all cookies used
  • Processor List: Complete list of all processors
  • DPA templates: Sample data processing agreements for enterprise customers
  • Privacy Portal: Self-service portal for common privacy requests

Industry-Specific Compliance

For customers in regulated sectors (financial services, healthcare, and the public sector), we provide additional compliance documentation. Contact our compliance team at compliance@leadbase.io.