Legal

Data Processing Agreement

Last updated: June 1, 2025

Who this applies to: This DPA applies to business users who process personal data of third parties (e.g. prospects) through LeadScry in the context of GDPR. If you are an individual user researching leads for your own outreach, the standard Privacy Policy applies.

1. Definitions

ControllerThe LeadScry user or business that determines the purposes of processing personal data through the platform.
ProcessorOIBL Group (operating LeadScry), which processes personal data on behalf of the Controller.
Personal DataAny information relating to an identified or identifiable natural person, as defined under GDPR Article 4(1).
ProcessingAny operation performed on personal data, including collection, analysis, storage, and retrieval.
Sub-processorA third party engaged by the Processor to process personal data in connection with the service (see Section 6).

2. Nature and purpose of processing

The Processor processes personal data on behalf of the Controller for the following purpose:

  • Generating AI-powered lead intelligence reports based on publicly available data about named individuals and companies
  • Storing analysis results in the Controller's account for retrieval and reference
  • Running targeted web searches using prospect identifiers provided by the Controller

3. Types of personal data processed

  • Names of individuals (prospects)
  • Professional information (job titles, company affiliation)
  • Online identifiers (website URLs, LinkedIn profile URLs, social handles)
  • Publicly available professional activity (hiring signals, publications, funding news)

LeadScry does not process special category data (health, biometric, financial, or protected category information) and must not be used for such purposes.

4. Obligations of the Processor

OIBL Group (as Processor) agrees to:

  • Process personal data only on documented instructions from the Controller
  • Ensure persons authorised to process personal data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures (Article 32 GDPR)
  • Not engage sub-processors without prior written authorisation from the Controller (general authorisation is deemed given by accepting these terms for the sub-processors listed in Section 6)
  • Assist the Controller in responding to data subject rights requests
  • Delete or return all personal data upon termination of the service relationship
  • Provide all information necessary to demonstrate compliance with GDPR obligations

5. Obligations of the Controller

The Controller agrees to:

  • Ensure a lawful basis exists for processing prospect personal data through LeadScry (e.g. legitimate interests under GDPR Article 6(1)(f))
  • Provide prospects with appropriate privacy notices where required
  • Use LeadScry only for the purposes described in these terms
  • Not instruct the Processor to process personal data in a way that would violate applicable law

6. Sub-processors

The Processor uses the following sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase & authenticationEU (AWS)
GroqAI model inferenceUSA
VercelApplication hostingGlobal (Edge)
Serper.devGoogle search APIUSA

For transfers to the USA, appropriate safeguards (Standard Contractual Clauses or equivalent) are in place where required.

7. Security measures

Technical and organisational measures include: TLS encryption in transit, AES-256 encryption at rest, row-level security on all database tables, role-based access controls, and regular security reviews.

8. Data breach notification

In the event of a personal data breach, the Processor will notify the Controller without undue delay — and in any case within 72 hours of becoming aware of the breach — where the breach is likely to result in a risk to data subjects.

9. Termination and deletion

Upon termination of the service relationship, the Processor will delete all personal data processed on behalf of the Controller within 30 days, unless required to retain it by applicable law.

10. Governing law

This DPA is governed by the laws of England and Wales, consistent with the main Terms of Service.

11. Contact

To request a signed DPA or for GDPR enquiries: leadscry@gmail.com

This DPA framework should be reviewed and executed with the assistance of a qualified legal professional before use in a regulated context.