Privacy Policy
1. Who we are
GetLeadz is a B2B contact-discovery service operated by Dirivian B.V., trading as VoiceHelden, registered at Science Park 608, Unit A.08, 1098 XH Amsterdam, Netherlands.
Because we are established in the European Union, the GDPR applies to us directly, and our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
We process two distinct categories of personal data, governed differently:
- Customer data — information about people who sign up and use GetLeadz.
- Business contact data — professional contact details of third parties that our customers look up.
2. Data we collect about our customers
| What | Why | Basis |
|---|---|---|
| Email address | Account identity, billing, service notices | Contract |
| Authentication credentials | Verifying it is you | Contract |
| Google account id, name, profile picture (if you use Google sign-in) | Authentication | Contract |
| Session token | Keeping you signed in | Contract |
| Lookups you perform, and their outcome | Billing accuracy, fraud prevention, measuring data quality | Legitimate interest |
| Credit transactions | Billing records, dispute resolution | Legal obligation |
We do not collect your browsing history. The extension activates only on LinkedIn profile pages, and only sends data when you click Reveal email & phone in the side panel.
3. Data we hold about business contacts
We maintain a database of professional contact information — name, employer, job title, work email address, business phone number — for the purpose of enabling legitimate business-to-business communication.
Where it comes from
- Public company filings and statutory registers
- Publicly accessible company websites and professional profiles
- Licensed data partners who warrant they hold the necessary rights
What we never do
- We do not crawl or scrape LinkedIn. Our extension reads only a page the customer has already opened in their own browser; our servers never access LinkedIn.
- We do not collect or share customer address books, contact lists, or CRM records.
- We do not collect special-category data (health, religion, ethnicity, political opinion, biometrics, sexual orientation).
- We do not knowingly hold data on anyone under 18.
- We do not sell personal data as a standalone product to data brokers.
Legal basis (GDPR): legitimate interest under Article 6(1)(f) for B2B professional contact data. Our Legitimate Interest Assessment is available on request. Where we cannot establish a lawful basis, we do not process the data.
Article 14 notice: where we hold your data without collecting it from you directly, you have the right to be informed. Contact us and we will tell you what we hold, where it came from, and who it has been shared with.
4. Your rights
Whoever you are — customer or business contact — you may:
- Access what we hold about you
- Correct anything inaccurate
- Delete your data
- Object to processing based on legitimate interest
- Export your data in a portable format
- Withdraw consent where consent is the basis
- Lodge a complaint with your supervisory authority. Ours is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl); you may also complain to the authority where you live or work.
Removing yourself immediately
Use the opt-out form.
This writes to a suppression list checked on every lookup, so the record stops being returned to anyone. It is not merely hidden from search. We keep a minimal hash of the identifier for the sole purpose of ensuring the record is never re-added by a later data refresh — retaining nothing at all would let the next import silently reinstate you.
No account needed. No charge. We respond within 30 days, and usually within 72 hours.
5. Who we share data with
Enrichment partners. When you request a contact we may query licensed partners. They receive only the profile identifier being looked up, never your account details or your other activity.
Infrastructure providers. Hosting, database, authentication and email delivery, under data processing agreements. Account sign-in is operated by Google Firebase Authentication, which holds your credentials on our behalf.
Payment processors. Card details go directly to the processor; we never see or store them.
Legal. Where compelled by valid legal process.
We do not sell customer data. We do not share it for advertising.
6. Retention
| Data | Kept for |
|---|---|
| Customer account | While active, then 90 days after closure |
| Credit ledger | 7 years (financial records) |
| Lookup logs | 24 months |
| Business contact records | While accurate; re-verified at least every 90 days and removed when stale |
| Suppression list | Indefinitely — this is what makes a deletion permanent |
7. International transfers
Data may be processed outside your country. Transfers out of the EEA/UK rely on UK/EU Standard Contractual Clauses or an adequacy decision.
8. Security
Sign-in and passwords are handled by Google Firebase Authentication — we never see or store your password. All traffic over TLS. Contact-data provider keys are held server-side only and never shipped to the browser. Access to production data is limited to staff who need it and is logged.
No system is perfectly secure. If we suffer a breach affecting your personal data we will notify you and the relevant regulator as required by law.
9. India — DPDP Act 2023
For data principals in India:
- Grievance Officer: support@getleadz.tech
- You may withdraw consent, request erasure, or nominate another person to exercise your rights on your behalf
- Unresolved grievances may be escalated to the Data Protection Board of India
Note that the DPDP Act has no legitimate-interest basis equivalent to the GDPR. Where we process personal data of Indian data principals, we rely on the statutory exemption for personal data made publicly available, or on consent.
10. California and other US states
Under the CCPA/CPRA you may know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. We do not sell personal information as defined by the CCPA. We will not discriminate against you for exercising these rights.
Where required, we register as a data broker in California, Vermont, Texas and Oregon.
11. Changes
Material changes will be announced by email to account holders and by updating the date at the top of this page at least 14 days before they take effect.
12. Contact
- General and privacy requests: support@getleadz.tech
- Remove my data: getleadz.tech/opt-out
- Post: Dirivian B.V., Science Park 608, Unit A.08, 1098 XH Amsterdam, Netherlands
- Telephone: +31 20 782 0049
Requests about data we hold on you as a business contact are handled without charge and without needing an account. If you are unsure which category you fall into, write to us and we will work it out — you do not need to know our internal distinctions to exercise your rights.
