GetLeadz

Privacy Policy

Last updated: 2 September 2026  ·  Controller: Dirivian B.V., trading as VoiceHelden  ·  Registered office: Science Park 608, Unit A.08, 1098 XH Amsterdam, Netherlands

The short version. We hold professional contact details so our customers can start B2B conversations. We do not scrape LinkedIn, we do not touch your address book, and you can remove yourself permanently in about thirty seconds — no account, no charge — using the opt-out form.

1. Who we are

GetLeadz is a B2B contact-discovery service operated by Dirivian B.V., trading as VoiceHelden, registered at Science Park 608, Unit A.08, 1098 XH Amsterdam, Netherlands.

Because we are established in the European Union, the GDPR applies to us directly, and our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

We process two distinct categories of personal data, governed differently:

2. Data we collect about our customers

WhatWhyBasis
Email addressAccount identity, billing, service noticesContract
Authentication credentialsVerifying it is youContract
Google account id, name, profile picture (if you use Google sign-in)AuthenticationContract
Session tokenKeeping you signed inContract
Lookups you perform, and their outcomeBilling accuracy, fraud prevention, measuring data qualityLegitimate interest
Credit transactionsBilling records, dispute resolutionLegal obligation

We do not collect your browsing history. The extension activates only on LinkedIn profile pages, and only sends data when you click Reveal email & phone in the side panel.

3. Data we hold about business contacts

We maintain a database of professional contact information — name, employer, job title, work email address, business phone number — for the purpose of enabling legitimate business-to-business communication.

Where it comes from

What we never do

Legal basis (GDPR): legitimate interest under Article 6(1)(f) for B2B professional contact data. Our Legitimate Interest Assessment is available on request. Where we cannot establish a lawful basis, we do not process the data.

Article 14 notice: where we hold your data without collecting it from you directly, you have the right to be informed. Contact us and we will tell you what we hold, where it came from, and who it has been shared with.

4. Your rights

Whoever you are — customer or business contact — you may:

Removing yourself immediately

Use the opt-out form.

This writes to a suppression list checked on every lookup, so the record stops being returned to anyone. It is not merely hidden from search. We keep a minimal hash of the identifier for the sole purpose of ensuring the record is never re-added by a later data refresh — retaining nothing at all would let the next import silently reinstate you.

No account needed. No charge. We respond within 30 days, and usually within 72 hours.

5. Who we share data with

Enrichment partners. When you request a contact we may query licensed partners. They receive only the profile identifier being looked up, never your account details or your other activity.

Infrastructure providers. Hosting, database, authentication and email delivery, under data processing agreements. Account sign-in is operated by Google Firebase Authentication, which holds your credentials on our behalf.

Payment processors. Card details go directly to the processor; we never see or store them.

Legal. Where compelled by valid legal process.

We do not sell customer data. We do not share it for advertising.

6. Retention

DataKept for
Customer accountWhile active, then 90 days after closure
Credit ledger7 years (financial records)
Lookup logs24 months
Business contact recordsWhile accurate; re-verified at least every 90 days and removed when stale
Suppression listIndefinitely — this is what makes a deletion permanent

7. International transfers

Data may be processed outside your country. Transfers out of the EEA/UK rely on UK/EU Standard Contractual Clauses or an adequacy decision.

8. Security

Sign-in and passwords are handled by Google Firebase Authentication — we never see or store your password. All traffic over TLS. Contact-data provider keys are held server-side only and never shipped to the browser. Access to production data is limited to staff who need it and is logged.

No system is perfectly secure. If we suffer a breach affecting your personal data we will notify you and the relevant regulator as required by law.

9. India — DPDP Act 2023

For data principals in India:

Note that the DPDP Act has no legitimate-interest basis equivalent to the GDPR. Where we process personal data of Indian data principals, we rely on the statutory exemption for personal data made publicly available, or on consent.

10. California and other US states

Under the CCPA/CPRA you may know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. We do not sell personal information as defined by the CCPA. We will not discriminate against you for exercising these rights.

Where required, we register as a data broker in California, Vermont, Texas and Oregon.

11. Changes

Material changes will be announced by email to account holders and by updating the date at the top of this page at least 14 days before they take effect.

12. Contact


Requests about data we hold on you as a business contact are handled without charge and without needing an account. If you are unsure which category you fall into, write to us and we will work it out — you do not need to know our internal distinctions to exercise your rights.