LeadGen-Agent acts in two distinct roles depending on the type of data:
Data Controller: with respect to registration, billing and Platform usage data of Users.
Data Processor: with respect to lead data that the User extracts, stores and manages through the Platform. This data is processed under the User's instructions, with the User acting as the controller. See the Data Processing Agreement (DPA) for details under GDPR.
2. Personal Data We Collect
2.1 Account and Registration Data
Full name, email address, phone number and agency or company name.
Identity verification data, if required.
Language preferences and account settings.
2.2 Usage and Interaction Data
Access logs: IP address, date, time, device type and browser.
Actions within the Platform: jobs executed, leads created, emails sent, features used.
Error events and performance metrics for service operations.
2.3 Billing Data
Payment method holder name and billing country (processed directly by Paddle).
LeadGen-Agent does not store credit card numbers, banking data or complete payment information. We receive from Paddle only the subscription history, active plan and payment status.
2.4 Integration Tokens (Gmail OAuth)
Access and refresh tokens from Google OAuth, generated when the User connects their Gmail account.
Stored encrypted in the database and used exclusively to send emails under the User's explicit instruction.
We do not read, store, analyze or share the content of the User's mailbox.
2.5 Lead Data (processed as data processor)
Business name, phone, address, category and website URL, obtained from Google Maps/Places.
Business contact email, when publicly available.
Visual data from the business website: color palette, description, partial screenshot.
This data is owned by the User and processed under their instruction. We do not use it for any purpose of our own.
2.6 Technical Data and Cookies
Session authentication cookies, CSRF tokens and interface preferences.
See the Cookie Policy for detailed information about each cookie.
3. Purposes and Legal Bases for Processing
Data Category
Main Purpose
Legal Basis
Account data
Service delivery, authentication, support, account communications
Contract performance (GDPR Art. 6.1.b; Colombia Law 1581)
Service security, abuse detection, platform improvement
Legitimate interest (GDPR Art. 6.1.f)
OAuth tokens (Gmail)
Email sending under User's instruction
Contract performance
Lead data
Processing under User's instruction and control (data processor)
Contract with User (GDPR Art. 28)
Marketing communications
Updates about new features, improvements and offers
Consent (GDPR Art. 6.1.a) — only if User opted in
4. Lead Data Processing (Processor Role)
When the User extracts, enriches or manages third-party data (businesses/leads) through the Platform, LeadGen-Agent acts exclusively as a data processor, processing such data solely under the User's instruction, who is the data controller.
Accordingly, the User guarantees:
Having the appropriate legal basis (B2B legitimate interest, consent or other) to process their leads' data.
Complying with applicable data protection laws in their jurisdiction and in the jurisdiction of the recipient of their communications.
Not using the Platform to process special category data (health, religious beliefs, sexual orientation, biometric data, racial or ethnic origin, etc.).
Not processing data of persons under 18 years of age.
The Data Processing Agreement (DPA) available on this site sets out the specific commitments as data processor under GDPR and automatically applies to all Users in the European Economic Area (EEA) and United Kingdom.
5. Sharing Data with Third Parties
We do not sell personal data. We share data only in the following circumstances:
5.1 Service Providers (Sub-processors)
Provider
Country
Function
Protection Guarantee
Paddle BV
Netherlands (EU)
Payment processing and tax management
Native GDPR — subject to adequacy
Google LLC
United States
Google Maps/Places API; Gmail OAuth
Standard Contractual Clauses (SCCs)
AI Providers
United States
Proposal content generation
SCCs / specific DPA
VPS Infrastructure Provider
Per server region
Hosting, database, network
Data processing contract
5.2 Legal Compliance
We may disclose personal data when required by law, court order, a competent authority or to protect the rights, safety or property of the Provider or third parties, to the minimum extent necessary.
5.3 Transfer through Reorganization
In the event of a merger, acquisition or asset sale, data may be transferred to the acquirer, who will be bound by this Privacy Policy or will notify users of any material changes.
6. International Data Transfers
Personal data may be processed in countries other than Colombia. To ensure an adequate level of protection we apply the following mechanisms:
EU/EEA → Colombia: Transfers under the frameworks of Colombia Law 1581 of 2012 and Decree 1377 of 2013, with the processing contracts required by the SIC.
Colombia/LATAM → USA (Google, AI providers): Standard Contractual Clauses approved by the European Commission (Decision 2021/914/EU).
Colombia → Netherlands (Paddle): Country within the EEA with native GDPR protection.
7. Data Retention
Data Type
Retention Period
Active account data
While the account remains active
Cancelled or deleted account data
30 days after cancellation, then permanent deletion
User's lead data
While subscription is active + 30 days after cancellation
Billing records
7 years (Colombian tax obligation — Tax Code)
Server and access logs
90 days
Email activity logs
12 months (abuse prevention and detection)
OAuth tokens (Gmail)
Until User disconnects their Gmail account or cancels subscription
After these periods, data is permanently deleted or irreversibly anonymized.
8. Data Security
We apply technical and organizational measures appropriate to the risk, including:
TLS 1.2/1.3 encryption in transit and encryption at rest for sensitive data (OAuth tokens, passwords).
Passwords stored exclusively as hashed with salt (bcrypt/argon2).
Role-based access control with principle of least privilege.
Multi-factor authentication available for User accounts.
Monitoring of unauthorized access and anomaly alerts.
Regular encrypted backups with integrity verification.
Documented incident response procedure for security events.
In the event of a security breach affecting personal data, we will notify affected Users and competent authorities within the deadlines established by applicable law: 72 hours under GDPR (Art. 33); within the reasonable period required by the SIC under Law 1581.
9. Data Subject Rights
Users in Colombia — Law 1581 of 2012 (Habeas Data)
Know: access the personal data we hold about you.
Update: request correction of inaccurate or outdated data.
Rectify: correct incorrect or incomplete information.
Delete: request deletion of your data where there is no legal obligation to retain it.
Withdraw consent: where processing is based on consent, you may withdraw it at any time.
File a complaint with the SIC: contact the Superintendencia de Industria y Comercio at www.sic.gov.co.
Users in the European Union / EEA — GDPR (Regulation EU 2016/679)
Access (Art. 15): obtain confirmation of whether we process your data and a copy of it.
Rectification (Art. 16): correct inaccurate or incomplete data.
Erasure (Art. 17, "right to be forgotten"): request deletion of your data.
Restriction of processing (Art. 18): restrict processing of your data in certain circumstances.
Portability (Art. 20): receive your data in a structured, machine-readable format.
Objection (Art. 21): object to processing based on legitimate interest.
Not to be subject to automated decision-making (Art. 22): without human intervention producing legal effects.
Lodge a complaint with the supervisory authority: you may contact the data protection authority in your Member State.
Responses within 30 days (extendable by 2 additional months for complex requests, with prior notification).
Users in California, USA — CCPA/CPRA
Know: what personal information we collect, use, disclose or sell.
Delete: request deletion of your personal information.
Correct: request correction of inaccurate data.
Opt out of sale or sharing: LeadGen-Agent does not sell personal data or share it for advertising purposes.
Non-discrimination: you will not receive different treatment for exercising these rights.
For CCPA requests, use the "Do Not Sell or Share My Personal Information" link on our website or write to privacy@leadgen-agent.com.
Include: full name, registered email, description of the right you wish to exercise, and a copy of your identity document if needed to verify your identity. We will respond within 15 business days (Colombia) / 30 calendar days (GDPR) / 45 calendar days (CCPA).
11. Minors
The Platform is directed exclusively to professionals aged 18 and over. We do not intentionally collect data from minors. If we detect that we have collected data from a minor, we will delete it immediately. If you are aware that a minor has provided their data, please write to privacy@leadgen-agent.com.
12. Changes to this Policy
We will notify material changes to this Policy at least 30 days in advance by email to the registered address. The updated version will be available at leadgen-agent.com/en/legal/privacidad with the new effective date. Continued use of the Service after the effective date implies acceptance of the changes.