GDPR Compliance

Last updated: March 2, 2026

1. Our Commitment

LeadScoutr ("we," "our," or "us") is committed to protecting the privacy and rights of individuals in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. We have implemented comprehensive technical and organizational measures to ensure that personal data is processed lawfully, fairly, and transparently.

This page outlines how we comply with GDPR requirements and describes your rights as a data subject. For full details on how we collect and process personal data, please see our Privacy Policy.

2. Legal Bases for Processing

We process personal data only when we have a valid legal basis under Article 6 of the GDPR. The legal bases we rely on include:

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you have requested, including account management, lead data delivery, and customer support.
  • Legitimate interests (Art. 6(1)(f)): Processing necessary for our legitimate business interests, such as improving the Service, preventing fraud, and ensuring security, provided these interests are not overridden by your fundamental rights.
  • Consent (Art. 6(1)(a)): Where you have given clear, informed consent for specific processing activities, such as marketing communications or optional analytics.
  • Legal obligation (Art. 6(1)(c)): Processing necessary to comply with applicable legal or regulatory requirements.

3. Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data. You can exercise any of these rights by contacting us at [email protected]. We will respond to your request within 30 days.

3.1 Right of Access (Art. 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with information about the purposes of processing, categories of data, and recipients.

3.2 Right to Rectification (Art. 16)

You have the right to request correction of inaccurate personal data and to have incomplete data completed. You can update most account information directly through your account settings.

3.3 Right to Erasure (Art. 17)

You have the right to request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when the data has been unlawfully processed. Certain data may be retained where we have a legal obligation or legitimate interest to do so.

3.4 Right to Data Portability (Art. 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.

3.5 Right to Object (Art. 21)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

3.6 Right to Restriction of Processing (Art. 18)

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of data or have objected to processing pending verification of our legitimate grounds.

4. Data Protection Officer

For any questions or concerns regarding our data protection practices, or to exercise your rights under the GDPR, please contact our Data Protection team:

Email: [email protected]

Subject line: GDPR Request

You also have the right to lodge a complaint with a supervisory authority in your country of residence if you believe your data protection rights have been violated.

5. International Data Transfers

LeadScoutr may transfer personal data outside the European Economic Area (EEA) to provide the Service. When we do so, we ensure appropriate safeguards are in place to protect your data in accordance with GDPR Chapter V, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission for the recipient country
  • Binding corporate rules where applicable
  • Technical measures such as encryption to protect data in transit and at rest

For details on our sub-processors and their locations, please see our Sub-Processors page.

6. Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR
  • Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34
  • Document the breach, its effects, and the remedial actions taken
  • Implement measures to mitigate the impact and prevent recurrence

7. Data Processing Agreement

For enterprise customers and organizations that require a formal Data Processing Agreement (DPA) under Article 28 of the GDPR, we offer a comprehensive DPA that covers all aspects of our data processing activities.

Please review our Data Processing Agreement for full terms, or contact us to execute a signed copy.

8. Sub-Processors

We engage third-party sub-processors to help deliver the Service. Each sub-processor is bound by contractual obligations to process personal data in accordance with GDPR requirements and our instructions.

A complete list of our current sub-processors, including their purposes and locations, is available on our Sub-Processors page. We provide 30 days' advance notice before adding new sub-processors.

9. Contact Us

If you have questions about our GDPR compliance or wish to exercise your data protection rights, please contact us at:

Email: [email protected]

Related policies: