01Overview & summary
Leadvaro, Inc. ("Leadvaro," "we," or "us") is committed to processing personal data in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the UK GDPR. This page explains the roles we play when handling personal data, the lawful bases we rely on, the rights you have as a data subject, and the safeguards we use to protect data.
If you are a Leadvaro customer, you are typically the controller of the B2B contact data you process through our platform, and Leadvaro acts as your processor. For Leadvaro account holders themselves, we are the controller of your account information. Both relationships are governed by our Data Processing Addendum (DPA), available at leadvaro.io/dpa.
02Roles & responsibilities
Under GDPR we operate in two distinct roles depending on the data involved. Understanding which role applies is important because it determines who is responsible for what.
- Controller — for personal data about Leadvaro account holders (name, work email, billing information, usage data). We decide why and how this data is processed.
- Processor — for B2B contact data you upload, search, or enrich through the Leadvaro platform on behalf of your own customers or prospects. You remain the controller of that data; we process it under your instructions and our DPA.
- Joint controller arrangements — none currently apply. If that ever changes, we will notify customers in writing and publish updated terms.
- Independent controller — for the publicly available business contact data we license, verify, and offer to customers via the search and enrichment endpoints, Leadvaro acts as an independent controller and complies with the GDPR's transparency and legitimate-interests obligations.
- Sub-processors — we use a limited set of vetted sub-processors (listed in section 07) to deliver the service. Customers receive 30 days' advance notice of any changes.
03Lawful bases for processing
GDPR requires a lawful basis for every processing activity. Leadvaro relies on the following bases depending on the context: (a) performance of a contract — for account and billing data needed to deliver the platform; (b) legitimate interests — for product analytics, security monitoring, and processing publicly available business contact data for B2B outreach purposes; (c) legal obligation — for tax, accounting, and lawful-request compliance; and (d) consent — only where legally required, such as for non-essential cookies and marketing emails (which you can withdraw at any time).
We conduct documented Legitimate Interests Assessments (LIAs) for each processing activity that relies on legitimate interests as its basis. You can request a summary of the relevant LIA by emailing dpo@leadvaro.io.
04Personal data we process
Leadvaro processes the following categories of personal data. None of these are special categories under GDPR Article 9 (sensitive data).
- Account identifiers — name, work email, organization, role, and password (hashed).
- Business contact data — name, job title, work email, business phone, company, location, and LinkedIn URL of decision-makers, sourced from public records and verified by our pipeline.
- Usage telemetry — IP address, browser/device identifiers, feature interactions, and credit-usage metrics — collected for security, fraud detection, and product improvement.
- Billing data — handled by Stripe; we receive only a token, last-four digits, and billing address. Full card numbers are never stored on Leadvaro servers.
05Your data subject rights
Under GDPR Articles 15–22, individuals located in the EU or UK have specific rights regarding their personal data. Leadvaro honors all of them, free of charge, within 30 days of receiving a verifiable request (extendable by 60 days for complex requests, with written notice).
Rights include: access (Article 15), rectification (16), erasure / right to be forgotten (17), restriction of processing (18), data portability (20), objection — including to direct marketing (21), and rights related to automated decision-making (22). Leadvaro does not engage in automated decision-making with legal effects on individuals. To exercise any right, email dpo@leadvaro.io or use the in-app privacy controls under Settings → Privacy. If you are listed in our B2B contact database and wish to opt out, visit leadvaro.io/opt-out — no Leadvaro account is required.
06Transfers outside the EEA
Leadvaro is headquartered in the United States. Personal data of EEA and UK residents may be transferred to the US and other countries where our sub-processors operate. For each such transfer we rely on appropriate safeguards: Standard Contractual Clauses (SCCs) 2021/914, the UK International Data Transfer Addendum (IDTA), and supplementary measures including encryption in transit and at rest. EEA / UK customers can request a copy of the SCCs by emailing dpo@leadvaro.io.
EU customers who require EU-only data residency are offered our EU region (Frankfurt) on Scale plans. Customer content stays in-region; metadata necessary for billing and authentication is replicated globally.
07Sub-processors
We use a small, vetted list of sub-processors to operate the platform — primarily AWS (hosting), Stripe (billing), Postmark (transactional email), Sentry (error monitoring), and Customer.io (customer communications). The full list with locations and purposes is maintained at leadvaro.io/subprocessors. Customers can subscribe to a notification feed; we give 30 days' advance notice of any additions and you may object before they take effect.
08Data Processing Addendum
Our standard Data Processing Addendum (DPA) is pre-signed and available at leadvaro.io/dpa. It incorporates the EU SCCs and UK IDTA by reference, names Leadvaro as your processor for B2B data you handle through our platform, and sets out our security, sub-processor, and breach-notification obligations. Customers with custom DPA requirements can upload their template via our Trust Center; turnaround is typically 3 business days.
09Security & incidents
Leadvaro is SOC 2 Type II certified and aligned with ISO 27001 controls. Protections include encryption in transit (TLS 1.2+) and at rest (AES-256), single sign-on with SCIM provisioning, role-based access controls, vendor security reviews, annual third-party penetration testing, and continuous monitoring. Personal data breaches are reported to affected customers within 72 hours, in line with GDPR Article 33, and to supervisory authorities where required.
REPORT Security or data-breach concerns can be reported to security@leadvaro.io. We acknowledge reports within 24 hours and triage critical issues immediately. Responsible disclosure terms are published at leadvaro.io/security.
10Contact our DPO
Leadvaro has appointed a Data Protection Officer (DPO) to oversee GDPR compliance. The DPO can be reached at dpo@leadvaro.io. EU/UK data subjects may also lodge complaints with their local supervisory authority — for EU residents, a list is maintained by the European Data Protection Board at edpb.europa.eu; for UK residents, contact the Information Commissioner's Office at ico.org.uk.
Postal correspondence for the DPO: Leadvaro, Inc., Attn: Data Protection Officer, 112 Broadway, New York, NY 10005, United States. For EU customers, our designated EU representative under Article 27 GDPR is available via the same channel.
100+ Happy Clients
Start finding your next 100 customers today
Build your first targeted list in under 10 minutes. Free forever on your first 50 leads.