Security and GDPR

The real list, without badges we do not have.

You work with third-party personal data and need to know exactly what the platform protects. We do not hold ISO or SOC 2 certifications: here is what we do today and what comes next.

What we do today

  • Each company has its own account: every record carries the account it belongs to and no one from another account sees what your team creates.
  • Securely hashed passwords, strong password policy on sign-up and recovery, and sign-out after 15 minutes of inactivity.
  • Roles and permissions by person, cloud, object and action.
  • Personal data masked in the lead directory, API inspector, exports and email contact base. We do not export leads in clear text.
  • Your own AI keys stored encrypted.
  • Daily backups with tested restores.
  • Encrypted connection (HTTPS).

What comes next

  • Landing pages with consent on record: exact text, version, IP and frozen recipients (Lead Gen Cloud).
  • Time records with chained hashes and inspector access (People Cloud).
GDPR

Who is responsible for what.

You, the controller

You decide which data you process and why. Your legal texts are yours: the platform checks they have no gaps or foreign domains, but does not write them.

Us, the processor

We process your account data only on your behalf. We sign the data processing agreement (DPA) with you before any data is loaded.

Published sub-processors

Hosting, email, company data and AI: the full list, with location and safeguards, is in the privacy policy.

Consent

Consent records on your landing pages.

Coming soon: on Lead Gen Cloud landing pages every consent will be recorded with the exact text the user saw, the version, the IP and the list of recipient companies frozen at that moment.

Limits: it does not cover affiliate API leads, the hash covers each checkbox text and there is no trusted third-party timestamp yet.

See Lead Gen Cloud

What we do not do

  • We do not hold ISO 27001 or SOC 2 certifications.
  • We do not detect fraud in real time or block VPNs.
  • We do not sell or share data for commercial purposes.