Privacy Policy

Do you have any questions about data protection?
Contact us at : office@leadrealizer.com
- We will be happy to help you.

Privacy Policy

Leadrealizer Solutions GmbH – Website and Application

Effective: March 2026

1. Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit our website or use our application. Personal data is any data that can be used to personally identify you. For detailed information on data protection, please refer to the sections below.

Who Is Responsible?

Data processing on this website and in the application is carried out by Leadrealizer Solutions GmbH. Contact details can be found in Section 2 and in our legal notice (Imprint).

How Do We Collect Your Data?

Your data is collected when you provide it to us (e.g., during registration, in contact forms). Other data is collected automatically or with your consent by our IT systems (e.g., technical data such as browser, operating system, or access time). As part of B2B lead generation, business contact data is also collected from publicly available sources.

What Are Your Rights?

You have the right to access, rectify, delete, and restrict the processing of your data at any time. You can revoke consent and object to processing based on legitimate interests. Details can be found in Section 14.

2. Data Controller and Contact Information

The data controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:

Leadrealizer Solutions GmbHIndustriestraße 17050999 CologneGermany

Commercial Register: HRB 120020, Cologne District CourtVAT ID: DE400181258

Represented by Managing Directors:Thorsten Rolf Orendi, Moussa Bdeir, Christian Wilhelm Roth(Each managing director has sole power of representation.)

Phone: +49 (0) 221 7726660Email: office@leadrealizer.com

Digital Services Act (DSA) Contact Point:Email: office@leadrealizer.comCommunication may be conducted in German and English.

3. Data Protection Officer

A Data Protection Officer has not currently been appointed. Should an appointment become necessary under Art. 37 GDPR or § 38 BDSG (German Federal Data Protection Act), we will promptly appoint one and publish the contact details here.

For data protection inquiries, please contact: privacy@leadrealizer.com or write to the postal address above with the note "Data Protection."

4. Scope

This privacy policy applies to the processing of personal data in connection with:

  • the website at www.leadrealizer.com (hosted on Webflow),
  • the Leadrealizer application (web app and mobile app, backend hosted on Bubble.io), available via the Apple App Store and Google Play Store,
  • all related services, features, and communication channels.

5. Legal Bases for Processing

Legal BasisScopeArt. 6(1)(a) GDPR (Consent)Cookies and tracking, marketing, newsletters, certain analytics toolsArt. 6(1)(b) GDPR (Performance of Contract)User account, app functionality, payment processing, contact inquiriesArt. 6(1)(c) GDPR (Legal Obligation)Tax retention obligations, statutory archivingArt. 6(1)(f) GDPR (Legitimate Interest)B2B lead generation, web analytics (where consent is not required), IT security, website operation

6. General Notes

Note on Data Transfers to the USA

Our website and application use tools from companies based in the USA. When these tools are active, your personal data may be transferred to US servers. Where the respective company is certified under the EU-US Data Privacy Framework (DPF), this provides an adequate level of data protection. For companies not certified under the DPF, we use Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR and additional technical and organizational measures.

SSL/TLS Encryption

This website and application use SSL/TLS encryption for security purposes. An encrypted connection is indicated by "https://" in the browser address bar and the lock icon.

Right to Withdraw Consent

Many data processing operations require your explicit consent. You may withdraw your consent at any time with effect for the future. The lawfulness of data processing carried out before the withdrawal remains unaffected.

Right to Object (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS.

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING FOR SUCH MARKETING PURPOSES; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING.

7. Hosting, CDN, and Infrastructure

7.1 Webflow (Website Hosting)

Our website is hosted by Webflow, Inc. (USA). When you visit the website, personal data (IP address, access data, meta and communication data) is processed on Webflow's servers.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in secure, efficient delivery).

We have concluded a Data Processing Agreement with Webflow.

Privacy Policy: https://webflow.com/legal/privacy

7.2 Bubble.io (App Backend)

Our application backend is hosted on Bubble Group, Inc. (USA). All data processed in the app is stored on Bubble.io servers in the USA.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

We have concluded a Data Processing Agreement with Bubble.io. Data transfers to the USA are based on the EU-US Data Privacy Framework and/or Standard Contractual Clauses.

7.3 Cloudflare (CDN and Security)

We use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) as a Content Delivery Network (CDN) and for DDoS protection. Cloudflare routes traffic between your browser and our website through its global network and may use cookies or similar technologies.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and reliable delivery).

We have concluded a Data Processing Agreement with Cloudflare.

Privacy Policy: https://www.cloudflare.com/privacypolicy/

7.4 Server Log Files

The hosting provider automatically collects and stores information in server log files:

  • Browser type and version
  • Operating system
  • Referrer URL
  • Hostname of the accessing computer
  • Time of server request
  • IP address

This data is not combined with other data sources and is deleted after 30 days.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technically error-free delivery and security).

8. Data Processing on the Website

8.1 Contact Form

When you submit inquiries via our contact form, your form data and contact details are stored for the purpose of processing the inquiry and for follow-up questions.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures / performance of contract) or Art. 6(1)(f) GDPR (legitimate interest in effective processing).

Retention: Until you request deletion, withdraw consent, or the storage purpose ceases. Statutory retention periods remain unaffected.

8.2 Inquiries by Email or Phone

When you contact us by email or phone, your inquiry and all associated personal data are stored for processing purposes.

Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.

8.3 Google reCAPTCHA

We use Google reCAPTCHA (Google Ireland Limited) to check whether data input is made by a human or an automated program. IP address, time spent, and mouse movements are analyzed and transmitted to Google.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protection against spam and abuse). Where consent has been obtained, Art. 6(1)(a) GDPR.

8.4 Google Maps

We use Google Maps (Google Ireland Limited). Your IP address is transmitted to Google servers (potentially in the USA) to use this service.

Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(f) GDPR (legitimate interest).

8.5 Embedded Videos

YouTube (Enhanced Privacy Mode)We embed videos from YouTube (Google Ireland Limited) in enhanced privacy mode. YouTube does not store information about visitors before the video is started.

LoomWe embed videos from Loom, Inc. (USA). Loading a Loom video establishes a connection to Loom servers and transmits your IP address.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest) or Art. 6(1)(a) GDPR (consent).

8.6 Google Web Fonts

We use Google Web Fonts for consistent font display. When other Google services are used, a connection to Google servers may be established, potentially capturing your IP address.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

8.7 Newsletter (Brevo)

We use Brevo (Sendinblue GmbH, Germany / Sendinblue SAS, France) for newsletter distribution.

When you subscribe, your email address and optionally your name are stored. We use the double opt-in procedure. Brevo enables analysis of newsletter campaigns (open rates, click rates).

Legal basis: Art. 6(1)(a) GDPR (consent). You may unsubscribe at any time.

We have concluded a Data Processing Agreement with Brevo.

9. Data Processing in the Application

9.1 User Registration and Account Management

During registration we collect:

  • First name and last name
  • Email address
  • Password (stored encrypted)
  • Company name and company size
  • Job title / position
  • Phone number (optional)
  • Company website (optional)
  • Industry (optional)

Registration is also possible via Google Sign-In (Google Ireland Limited) or Microsoft Sign-In (Microsoft Ireland Operations Limited) using OAuth 2.0. In this case, we receive your name, email address, and optionally your profile picture from the respective provider. Your password is not transmitted to us.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

Retention: Duration of the user relationship + 12 months after account deletion.

9.2 B2B Lead Generation

Automatically Generated Leads

The core function of the application is generating B2B leads. The following business contact data is processed:

  • Name, job title, company name
  • Business email address and phone number
  • Company information (industry, size, location, website)
  • Publicly available profile information

Sources:

  • AI-based identification of potential business contacts
  • Web scraping of publicly available business information (company websites, industry directories, public profiles)
  • Third-party API integrations (business databases)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in B2B business initiation).

The legitimate interest lies in facilitating business contact initiation between companies. We process exclusively business contact data and ensure that:

  • only data from publicly available business sources is used,
  • data subjects can object at any time (opt-out),
  • a documented balancing of interests exists,
  • processing is limited to the business context.

Note: The legality of automated B2B lead generation should be reviewed by legal counsel on a case-by-case basis, particularly regarding national implementations of the GDPR and applicable unfair competition laws.

User-Imported Leads

Users may import their own contact data (e.g., via CSV upload or CRM integration). For this data, Leadrealizer acts as a data processor within the meaning of Art. 28 GDPR. The user, as the data controller, is responsible for the lawfulness of data collection.

9.3 Automated Outreach

Email Integration (Google Gmail and Microsoft Outlook)

The App integrates with Google Gmail (Google Ireland Limited / Google LLC) and Microsoft Outlook (Microsoft Ireland Operations Limited / Microsoft Corporation) via OAuth authorization. The following data is processed:

  • Email messages (receiving and sending)
  • Contact data of communication partners
  • Email metadata (sender, recipient, subject, timestamps)

Access to the email account is limited to the scope approved by the user and can be revoked at any time in the respective account settings.

WhatsApp Integration (WasenderAPI)

For WhatsApp integration, we use the service WasenderAPI. Through this integration, WhatsApp messages are received and sent. The following data is processed:

  • WhatsApp messages and their content
  • Contact data (phone number, name)
  • Message metadata (timestamps, delivery status)

Additional Channels

  • Instagram, Facebook (via Meta platform integrations)
  • LinkedIn (planned for future versions)
  • Additional channels (planned)

Automated Outreach

The application enables automated contact with leads via the channels mentioned above. Additional data processed includes: delivery data, open/click rates (for email), replies, and interactions.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR in conjunction with applicable electronic direct marketing regulations (EU ePrivacy Directive, CAN-SPAM Act in the USA).

Important: Automated email contact for advertising purposes is subject to strict regulations (EU ePrivacy Directive Art. 13, CAN-SPAM Act in the USA, § 7 UWG in Germany). Users are solely responsible for ensuring their outreach activities comply with applicable laws.

9.4 AI Processing (Claude API and OpenAI API)

We use the Claude API (Anthropic, PBC, USA) and the OpenAI API (OpenAI, L.L.C., USA) for AI-powered features:

  • Lead qualification and scoring
  • Generation of personalized message templates
  • Data analysis and recommendations
  • Contact data research and enrichment
  • AI Sales Companion ("Leady AI")

Business contact data and user inputs are transmitted to the respective API during AI processing. Processing is governed by our Data Processing Agreements with Anthropic and OpenAI.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest).

9.5 Backend Automation (N8N)

We use N8N for automated backend processes and workflow automation. Personal data may be processed within the purposes described in this privacy policy.

9.6 Customer Support and Feedback (Featurebase)

We use Featurebase for support, feedback, and feature requests. Name, email address, inquiry content, and interaction data are processed.

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

9.7 Payment Processing

Payment processing for subscriptions is handled by:

  • Apple App Store (Apple Inc., USA) – for iOS users
  • Google Play Store (Google LLC, USA) – for Android users
  • Stripe (Stripe, Inc., USA) – planned for future versions

We do not store credit card or bank details. Payment processing occurs directly through the respective payment service providers. We only receive information about payment status and billing data.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

9.8 Video Conferencing (Google Meet)

We use Google Meet (Google Ireland Limited) for customer communication. Email address, IP address, device/browser information, and conference data (duration, number of participants, metadata) are processed.

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

We have concluded a Data Processing Agreement with Google.

10. Cookies and Tracking Technologies

10.1 General Information About Cookies

Our website uses cookies. Cookies are small text files stored on your device. They do not cause harm. Session cookies are automatically deleted after your visit; persistent cookies remain until you delete them or they expire.

Technically necessary cookies are stored on the basis of Art. 6(1)(f) GDPR. For all other cookies, we require your consent (Art. 6(1)(a) GDPR).

10.2 Cookie Consent Management (Cookiebot)

We use Cookiebot (Cybot A/S, Denmark) as our Consent Management Platform (CMP). On your first visit, you will be asked to set your cookie preferences. Cookiebot stores a cookie to assign your consent(s) or their withdrawal.

Data transmitted to Cookiebot: your consent(s), IP address (anonymized), browser/device information, time of visit.

Legal basis: Art. 6(1)(c) GDPR (legal obligation to obtain and document consent).

You can adjust your preferences at any time via the cookie banner or under [Cookie Settings].

10.3 Google Analytics 4

We use Google Analytics 4 (Google Ireland Limited) for web analytics. GA4 uses technologies for user recognition (cookies, device fingerprinting). Information collected is generally transmitted to Google servers in the USA.

Data processed: pseudonymized usage data, page views, time on site, device/browser information, interaction data, IP address (anonymized).

Retention: Up to 14 months.

You can prevent data collection by Google Analytics by downloading the browser add-on: https://tools.google.com/dlpage/gaoptout

Legal basis: Art. 6(1)(a) GDPR (consent).

We have concluded a Data Processing Agreement with Google.

10.4 Google Tag Manager

We use Google Tag Manager (Google Ireland Limited) for website tag management. Google Tag Manager itself does not collect personal data but enables the integration of other tags that may collect data.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

10.5 Meta Pixel (Facebook Pixel)

We use the Meta Pixel (Meta Platforms Ireland Ltd.) for conversion measurement and retargeting for Facebook/Instagram advertising.

Data processed: page views, interaction data, device information.

Data is processed by Meta and may be transferred to the USA. Meta may link data to your Facebook/Instagram profile.

You can deactivate remarketing in Facebook ad settings: https://www.facebook.com/ads/preferences/

Legal basis: Art. 6(1)(a) GDPR (consent).

Privacy Policy: https://www.facebook.com/privacy/policy/

10.6 LinkedIn Insight Tag

We use the LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company) for conversion tracking and retargeting for LinkedIn advertising.

Data processed: page views, professional profile information (aggregated), device information.

Legal basis: Art. 6(1)(a) GDPR (consent).

Privacy Policy: https://www.linkedin.com/legal/privacy-policy

10.7 Google Ads Conversion Tracking

We use Google Ads Conversion Tracking (Google Ireland Limited) to measure the effectiveness of Google Ads campaigns. A cookie is set when you click on a Google ad.

Data processed: IP address, user behavior, browser information, conversion data.

Legal basis: Art. 6(1)(a) GDPR (consent).

10.8 Hotjar / Microsoft Clarity

We use Hotjar (Hotjar Ltd, Malta) and/or Microsoft Clarity for UX analysis (heatmaps, session recordings, conversion funnels).

Data processed: anonymized click, scroll, and interaction data, device information, time spent.

You can deactivate Hotjar at: https://www.hotjar.com/opt-out

Legal basis: Art. 6(1)(a) GDPR (consent).

We have concluded a Data Processing Agreement with Hotjar.

11. Role as Controller and Processor

11.1 Leadrealizer as Controller

Leadrealizer is the data controller for:

  • User data (registration, account management, payment processing)
  • Website visitor data (access data, cookies, tracking)
  • Automatically generated lead data (AI-generated, web scraping, third-party APIs)
  • Own marketing activities and newsletters

11.2 Leadrealizer as Processor

Leadrealizer acts as data processor for:

  • Contact and lead data imported by users
  • Outreach activities carried out on behalf of the customer

For these processing activities, we conclude a Data Processing Agreement (DPA) with our customers pursuant to Art. 28 GDPR. The customer remains responsible as the data controller for the lawfulness of data collection.

12. International Data Transfers

Service ProviderLocationPurposeTransfer MechanismBubble.ioUSAApp backendDPF / SCCsCloudflareUSACDN, securityDPF / SCCsGoogle (Analytics, Ads, GTM, Maps, Meet, reCAPTCHA)USA (via Ireland)Analytics, marketing, communicationDPFMeta PlatformsUSA (via Ireland)Marketing, retargetingDPFLinkedInUSA (via Ireland)Marketing, retargetingDPFAnthropic (Claude API)USAAI processingSCCsOpenAI (GPT API)USAAI processingDPF / SCCsWasenderAPIVariesWhatsApp integrationSCCsMicrosoft (Outlook, Sign-In)USA (via Ireland)Email, authenticationDPFGoogle (Gmail, Sign-In, Cloud)USA (via Ireland)Email, authentication, cloud servicesDPFApple Inc.USAApp Store, paymentsDPFHotjarMalta/EUUX analysisEU internalMicrosoft (Clarity)USAUX analysisDPF / SCCsLoomUSAVideo embedsDPF / SCCsCookiebot (Cybot)Denmark/EUConsent managementEU internalBrevoGermany/FranceNewsletterEU internalFeaturebaseVariesSupport, feedbackSCCs

DPF = EU-US Data Privacy Framework; SCCs = Standard Contractual Clauses (Art. 46(2)(c) GDPR)

We have concluded Data Processing Agreements with all processors pursuant to Art. 28 GDPR.

13. Data Retention and Deletion

Data Category

Retention Period

User account data

Duration of user relationship + 12 months after account deletion

Automatically generated lead data

Until objection by the data subject or deletion by the user

Imported lead data

As instructed by the customer (as processor)

Payment and billing data

10 years (German statutory retention: § 147 AO, § 257 HGB)

Server log files

30 days

Cookie consent data

12 months

Support/feedback data

Duration of user relationship + 12 months

Newsletter data

Until unsubscription

Applicant data

6 months after conclusion of the process (unless otherwise agreed)

14. Rights of Data Subjects

14.1 Your Rights Under GDPR

Right of Access (Art. 15 GDPR): Information about stored data, processing purposes, recipients, and retention periods.

Right to Rectification (Art. 16 GDPR): Correction of inaccurate or completion of incomplete data.

Right to Erasure (Art. 17 GDPR): Deletion of your data, provided no statutory retention obligations apply.

Right to Restriction (Art. 18 GDPR): Restriction of processing, e.g., when contesting accuracy.

Right to Data Portability (Art. 20 GDPR): Provision of your data in a structured, machine-readable format.

Right to Object (Art. 21 GDPR): Objection to processing based on legitimate interests. This specifically includes the right to object to B2B lead generation.

Right to Withdraw Consent (Art. 7(3) GDPR): Withdrawal of consent with effect for the future.

Right to Lodge a Complaint (Art. 77 GDPR): Complaint with a supervisory authority. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)Postfach 20 04 44, 40102 Düsseldorf, Germanyhttps://www.ldi.nrw.de

14.2 Exercising Your Rights

  • Email: privacy@leadrealizer.com
  • Post: Leadrealizer Solutions GmbH, Data Protection, Industriestraße 170, 50999 Cologne, Germany

We will respond within 30 days (extendable to 90 days for complex requests).

14.3 Special Rights for Data Subjects of Lead Generation

If your business contact data is processed through our lead generation, you additionally have the right to:

  • be informed about the source of your data,
  • object to further processing (opt-out),
  • request immediate deletion of your data.

Contact: privacy@leadrealizer.com or use the opt-out link in automated messages.

15. Additional Rights for California Residents (CCPA/CPRA)

Residents of California have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

15.1 Categories of Personal Information Collected

We may collect the following categories of personal information:

  • Identifiers: Name, email address, phone number, IP address, account name
  • Professional/Employment Information: Job title, company name, industry
  • Internet Activity: Browsing history, search history, information regarding interactions with our website/app
  • Commercial Information: Subscription records, purchasing history
  • Geolocation Data: Approximate location derived from IP address

15.2 Your CCPA Rights

Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell about you.

Right to Delete: You can request the deletion of your personal information, subject to certain exceptions.

Right to Correct: You can request the correction of inaccurate personal information.

Right to Opt-Out of Sale/Sharing: We do not "sell" your personal information in the traditional sense. To the extent that sharing data for cross-context behavioral advertising (e.g., via tracking pixels) constitutes a "sale" or "sharing" under the CCPA, you have the right to opt out. You can exercise this right via our cookie consent banner.

Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide our services.

Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

15.3 How to Exercise Your CCPA Rights

Submit a verifiable consumer request by emailing us at: privacy@leadrealizer.com

We will verify your identity before processing your request. We will respond within 45 days (extendable to 90 days with notice).

15.4 Authorized Agents

You may designate an authorized agent to submit requests on your behalf. We may require proof of written authorization and identity verification.

15.5 Financial Incentives

We do not offer financial incentives related to the collection of personal information.

16. Additional Rights for UK Residents

For residents of the United Kingdom, the provisions of the UK GDPR and the Data Protection Act 2018 apply. Your rights are substantially the same as those described in Section 14 under the GDPR.

Supervisory authority: Information Commissioner's Office (ICO), https://ico.org.uk

17. Additional Rights for Swiss Residents

For residents of Switzerland, the provisions of the revised Swiss Federal Act on Data Protection (revFADP/revDSG) apply. Your rights are substantially the same as those described in Section 14, supplemented by specific provisions of the revFADP.

Supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), https://www.edoeb.admin.ch

18. Data Security

We implement appropriate technical and organizational measures:

  • Encrypted data transmission (TLS/SSL)
  • Encrypted storage of sensitive data
  • Access control and authorization management
  • Regular security reviews
  • Backup and recovery procedures
  • Employee training in data protection

We note that data transmission over the internet may have security gaps. Complete protection against third-party access is not possible.

19. Minors

Our services are intended for businesses and business customers (B2B) and are not intended for use by persons under 16 years of age. We do not knowingly collect personal data from minors.

20. Objection to Advertising Emails

The use of contact data published as part of the legal notice obligation for sending unsolicited advertising and information materials is hereby objected to. We expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.

21. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in legal requirements, technical developments, or changes to our services. The current version is always available on our website and in the application. Registered users will be notified by email of material changes.

Last updated: March 2026

Leadrealizer Solutions GmbH – Industriestraße 170, 50999 Cologne, Germany