LeadGen-Agent

Privacy

LeadGen-Agent | Version 1.0 | Effective: May 21, 2026

1. Identity of the Data Controller

Controller: Sergio Jauregui Trading name: LeadGen-Agent Website: leadgen-agent.com Domicile: Bogotá D.C., Colombia Privacy email: privacy@leadgen-agent.com

LeadGen-Agent acts in two distinct roles depending on the type of data:

  • Data Controller: with respect to registration, billing and Platform usage data of Users.
  • Data Processor: with respect to lead data that the User extracts, stores and manages through the Platform. This data is processed under the User's instructions, with the User acting as the controller. See the Data Processing Agreement (DPA) for details under GDPR.

2. Personal Data We Collect

2.1 Account and Registration Data

  • Full name, email address, phone number and agency or company name.
  • Identity verification data, if required.
  • Language preferences and account settings.

2.2 Usage and Interaction Data

  • Access logs: IP address, date, time, device type and browser.
  • Actions within the Platform: jobs executed, leads created, emails sent, features used.
  • Error events and performance metrics for service operations.

2.3 Billing Data

  • Payment method holder name and billing country (processed directly by Paddle).
  • LeadGen-Agent does not store credit card numbers, banking data or complete payment information. We receive from Paddle only the subscription history, active plan and payment status.

2.4 Integration Tokens (Gmail OAuth)

  • Access and refresh tokens from Google OAuth, generated when the User connects their Gmail account.
  • Stored encrypted in the database and used exclusively to send emails under the User's explicit instruction.
  • We do not read, store, analyze or share the content of the User's mailbox.

2.5 Lead Data (processed as data processor)

  • Business name, phone, address, category and website URL, obtained from Google Maps/Places.
  • Business contact email, when publicly available.
  • Visual data from the business website: color palette, description, partial screenshot.
  • This data is owned by the User and processed under their instruction. We do not use it for any purpose of our own.

2.6 Technical Data and Cookies

  • Session authentication cookies, CSRF tokens and interface preferences.
  • See the Cookie Policy for detailed information about each cookie.

3. Purposes and Legal Bases for Processing

Data Category Main Purpose Legal Basis
Account data Service delivery, authentication, support, account communications Contract performance (GDPR Art. 6.1.b; Colombia Law 1581)
Billing data Subscription management, fraud prevention, tax compliance Contract performance + Legal obligation
Usage and access logs Service security, abuse detection, platform improvement Legitimate interest (GDPR Art. 6.1.f)
OAuth tokens (Gmail) Email sending under User's instruction Contract performance
Lead data Processing under User's instruction and control (data processor) Contract with User (GDPR Art. 28)
Marketing communications Updates about new features, improvements and offers Consent (GDPR Art. 6.1.a) — only if User opted in

4. Lead Data Processing (Processor Role)

When the User extracts, enriches or manages third-party data (businesses/leads) through the Platform, LeadGen-Agent acts exclusively as a data processor, processing such data solely under the User's instruction, who is the data controller.

Accordingly, the User guarantees:

  • Having the appropriate legal basis (B2B legitimate interest, consent or other) to process their leads' data.
  • Complying with applicable data protection laws in their jurisdiction and in the jurisdiction of the recipient of their communications.
  • Not using the Platform to process special category data (health, religious beliefs, sexual orientation, biometric data, racial or ethnic origin, etc.).
  • Not processing data of persons under 18 years of age.

The Data Processing Agreement (DPA) available on this site sets out the specific commitments as data processor under GDPR and automatically applies to all Users in the European Economic Area (EEA) and United Kingdom.


5. Sharing Data with Third Parties

We do not sell personal data. We share data only in the following circumstances:

5.1 Service Providers (Sub-processors)

Provider Country Function Protection Guarantee
Paddle BV Netherlands (EU) Payment processing and tax management Native GDPR — subject to adequacy
Google LLC United States Google Maps/Places API; Gmail OAuth Standard Contractual Clauses (SCCs)
AI Providers United States Proposal content generation SCCs / specific DPA
VPS Infrastructure Provider Per server region Hosting, database, network Data processing contract

5.2 Legal Compliance

We may disclose personal data when required by law, court order, a competent authority or to protect the rights, safety or property of the Provider or third parties, to the minimum extent necessary.

5.3 Transfer through Reorganization

In the event of a merger, acquisition or asset sale, data may be transferred to the acquirer, who will be bound by this Privacy Policy or will notify users of any material changes.


6. International Data Transfers

Personal data may be processed in countries other than Colombia. To ensure an adequate level of protection we apply the following mechanisms:

  • EU/EEA → Colombia: Transfers under the frameworks of Colombia Law 1581 of 2012 and Decree 1377 of 2013, with the processing contracts required by the SIC.
  • Colombia/LATAM → USA (Google, AI providers): Standard Contractual Clauses approved by the European Commission (Decision 2021/914/EU).
  • Colombia → Netherlands (Paddle): Country within the EEA with native GDPR protection.

7. Data Retention

Data Type Retention Period
Active account data While the account remains active
Cancelled or deleted account data 30 days after cancellation, then permanent deletion
User's lead data While subscription is active + 30 days after cancellation
Billing records 7 years (Colombian tax obligation — Tax Code)
Server and access logs 90 days
Email activity logs 12 months (abuse prevention and detection)
OAuth tokens (Gmail) Until User disconnects their Gmail account or cancels subscription

After these periods, data is permanently deleted or irreversibly anonymized.


8. Data Security

We apply technical and organizational measures appropriate to the risk, including:

  • TLS 1.2/1.3 encryption in transit and encryption at rest for sensitive data (OAuth tokens, passwords).
  • Passwords stored exclusively as hashed with salt (bcrypt/argon2).
  • Role-based access control with principle of least privilege.
  • Multi-factor authentication available for User accounts.
  • Monitoring of unauthorized access and anomaly alerts.
  • Regular encrypted backups with integrity verification.
  • Documented incident response procedure for security events.

In the event of a security breach affecting personal data, we will notify affected Users and competent authorities within the deadlines established by applicable law: 72 hours under GDPR (Art. 33); within the reasonable period required by the SIC under Law 1581.


9. Data Subject Rights

Users in Colombia — Law 1581 of 2012 (Habeas Data)

  • Know: access the personal data we hold about you.
  • Update: request correction of inaccurate or outdated data.
  • Rectify: correct incorrect or incomplete information.
  • Delete: request deletion of your data where there is no legal obligation to retain it.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time.
  • File a complaint with the SIC: contact the Superintendencia de Industria y Comercio at www.sic.gov.co.

Users in the European Union / EEA — GDPR (Regulation EU 2016/679)

  • Access (Art. 15): obtain confirmation of whether we process your data and a copy of it.
  • Rectification (Art. 16): correct inaccurate or incomplete data.
  • Erasure (Art. 17, "right to be forgotten"): request deletion of your data.
  • Restriction of processing (Art. 18): restrict processing of your data in certain circumstances.
  • Portability (Art. 20): receive your data in a structured, machine-readable format.
  • Objection (Art. 21): object to processing based on legitimate interest.
  • Not to be subject to automated decision-making (Art. 22): without human intervention producing legal effects.
  • Lodge a complaint with the supervisory authority: you may contact the data protection authority in your Member State.

Responses within 30 days (extendable by 2 additional months for complex requests, with prior notification).

Users in California, USA — CCPA/CPRA

  • Know: what personal information we collect, use, disclose or sell.
  • Delete: request deletion of your personal information.
  • Correct: request correction of inaccurate data.
  • Opt out of sale or sharing: LeadGen-Agent does not sell personal data or share it for advertising purposes.
  • Non-discrimination: you will not receive different treatment for exercising these rights.

For CCPA requests, use the "Do Not Sell or Share My Personal Information" link on our website or write to privacy@leadgen-agent.com.


10. How to Exercise Your Rights

Send your request to privacy@leadgen-agent.com with the subject:

  • Colombia: "Solicitud derechos ARCO"
  • EU/EEA: "GDPR Data Request"
  • California: "CCPA Privacy Request"

Include: full name, registered email, description of the right you wish to exercise, and a copy of your identity document if needed to verify your identity. We will respond within 15 business days (Colombia) / 30 calendar days (GDPR) / 45 calendar days (CCPA).


11. Minors

The Platform is directed exclusively to professionals aged 18 and over. We do not intentionally collect data from minors. If we detect that we have collected data from a minor, we will delete it immediately. If you are aware that a minor has provided their data, please write to privacy@leadgen-agent.com.


12. Changes to this Policy

We will notify material changes to this Policy at least 30 days in advance by email to the registered address. The updated version will be available at leadgen-agent.com/en/legal/privacy with the new effective date. Continued use of the Service after the effective date implies acceptance of the changes.


13. Contact

Sergio Jauregui — LeadGen-Agent Privacy email: privacy@leadgen-agent.com Bogotá D.C., Colombia

For users in the EU: you may also contact the data protection authority in your country.