1. Who we are

Controller: LeadKing Ltd (Company No. pending · ICO reg pending).
Contact: [email protected] (or [email protected] pre-launch).

2. Data we collect & why

Waitlist data

Email (required), company name (optional), revenue band (optional), IP hash, user agent, timestamps.

Account data (post-launch)

Email, password hash, org data, ICP descriptions, marked outcomes, usage logs.

Cookie data

See /cookies.

3. How we use your data

4. Data about third parties (lead subjects)

LeadKing processes public UK data about businesses (not individual consumer data). Sources: Companies House, public job boards, public news, public social, SERP.

Legal basis for processing business contacts: UK GDPR Art 6(1)(f) legitimate interest + PECR B2B exemption.

Data subjects can request access (DSAR, Art 15), rectification (Art 16), erasure (Art 17, subject to legal retention requirements), or object (Art 21). Request email: [email protected].

5. Sub-processors

DPAs in place with all sub-processors. Full DPA available on request to UK business customers.

Sub-processorPurposeLocation
Neon (Postgres)Primary databaseEU (Frankfurt)
Fly.ioApplication hostingEU (LHR London)
CloudflareCDN, DNS, WAF, TurnstileGlobal (UK POPs)
Bird (MessageBird)Transactional emailEU
StripePayment processingUK + EU + US (SCCs)
OpenRouterAI inferenceUS (with EU preference)
LangfuseLLM observabilityEU (self-hosted on Fly)
Grafana CloudMetrics + logsEU
SentryError trackingEU

6. International transfers

OpenRouter US: Standard Contractual Clauses in place; inference routed to EU providers where available. Stripe US: SCCs; payment data minimised. All other sub-processors: UK/EU only.

7. Security

8. Your rights (UK GDPR Arts 15–22)

Access, rectify, erase, restrict processing, data portability, object, withdraw consent, not be subject to solely-automated decisions.

Exercise via [email protected]. Response within 1 month (extendable to 3 months for complex requests).

ICO complaint right: ico.org.uk/make-a-complaint.

9. Automated decisions + AI

LeadKing uses AI (LLMs) to score leads. Scoring is not an "automated decision producing legal effects" under Art 22 — it is advisory, not auto-executed. Users retain full control.

10. Data retention

DataRetentionBasis
Waitlist24 months post-confirmLegitimate interest
Account data7 years post-closureUK accounting regs
Billing data7 years post-closureHMRC VAT records
Lead data90 days post-run OR account closureService minimum
Log data30 daysSecurity + debug

11. Children

LeadKing is not directed to children. We don't knowingly collect data from under-18s.

12. Changes to this policy

Material changes: 30 days notice + email to active users. Minor changes: last-updated date refresh.

13. Contact & DPA

Email: [email protected]. DPA available on request to UK business customers. ICO complaint: ico.org.uk/make-a-complaint.