LeadsFriday
Legal

Policies, Terms and Data Handling

Everything covering how we run the service, what we do with data, and where you stand as a customer. Written to be read, not skimmed past.

Data Handling

This page explains where the data we deliver comes from, what we do and do not collect, and how our obligations and yours divide up. It is the page your legal and procurement teams will want.

Controller and processor

For the B2B records we extract, LeadsFriday acts as a processor and you are the controller: you decide the filters, the purpose and the outreach. You determine why the data is collected, so the lawful basis for contacting those people is yours to establish. We will sign a data processing agreement on request.

Where the data comes from

Publicly accessible business listings and professional profiles on the sources you nominate, such as company directories, professional networks and technology registries. We extract only what is visible without logging into a private account. We do not buy data from brokers of consumer information.

What we deliberately do not collect

No special-category data as defined by GDPR Article 9: no health, ethnicity, religion, political opinion, trade union membership, sexual orientation or biometric data. No consumer records. No data on anyone we can identify as a minor. Personal email finding is limited to publicly discoverable business contact routes and is offered as a separate, clearly labelled tool.

Legitimate interest and B2B outreach

In the EEA and UK, B2B outreach is commonly conducted on the basis of legitimate interest under GDPR Article 6(1)(f). That basis requires you to run and document a balancing test, to keep the message relevant to the professional role of the recipient, and to offer an easy opt-out. We can supply a template balancing test; we cannot complete it for you, because only you know your purpose.

CCPA and US law

Business contact information is treated as personal information under the CCPA. Where a California resident exercises a right against us in relation to data we hold for you, we will forward the request to you as controller and support your response. LeadsFriday does not sell personal information as the CCPA defines selling.

Suppression and deletion requests

If someone asks to be removed, forward the request to support@leadsfriday.com. We add the identifier to a global suppression list, and it is excluded from every future export across all customers. We action these within 5 business days and confirm in writing. You must also delete the record from your own systems, since we cannot reach into your CRM.

Security

Data is encrypted in transit with TLS and at rest. Access to production systems is limited to named staff with multi-factor authentication. Uploaded files and delivered exports are deleted from our servers after 12 months. We will notify you without undue delay, and within 72 hours, of any breach affecting your data.

Sub-processors

Our sub-processors cover cloud hosting, email delivery, payment processing, and the third-party providers used in enrichment waterfalls. A current list is available on request, and we give 30 days notice before adding a new one so you can object.

Retention

Order inputs, such as search URLs and uploaded files, are held for 12 months so orders can be re-run and audited, then deleted. Delivered exports are held for 12 months so you can re-download them. Suppression list entries are held indefinitely, because that is the only way to keep honouring them.

What we ask of you

Verify before you send. Honour every opt-out on first request. Identify your company in every message. Do not use exported data for consumer marketing. Do not enrich a list you obtained unlawfully. If you are unsure whether a use is acceptable, ask us before you order.