Leebry B2B Sales Privacy Policy
This Privacy Policy explains how MacPaw Way Ltd. (“MacPaw”, “we”, “us” or “our”), collects and processes the personal data of business professionals in the course of our business-to-business (B2B) sales activities. It describes the personal data we process, why and on what legal basis we process it, the tools and service providers involved, how long we keep it, where it is transferred, and the rights available to the individuals whose data we process.
It is dedicated solely to our sales operations. It does not cover MacPaw’s consumer products or any other processing activity, which are addressed in separate policies.
It is dedicated solely to our sales operations. It does not cover MacPaw’s consumer products or any other processing activity, which are addressed in separate policies.
Scope and Applicability
This Policy applies to the personal data of business professionals - such as named employees, decision-makers, founders and other representatives of organisations - that we process to identify, contact and engage prospective business customers. Throughout this Policy we refer to such individuals as “prospects” or “business contacts”.
We process personal data in our capacity as a data controller for these sales activities, meaning we determine the purposes and means of the processing.
Personal Data We Collect and Receive
Because our activities are limited to B2B outreach, we deliberately confine ourselves to professional, work-related data. We process the following categories of personal data:
- Identification data: first and last name, job title or role, employer and company name.
- Business contact details: business email address (including email-address variants generated from a name and company domain), business phone number, and LinkedIn or other professional profile URLs.
- Company data: company domain, size, industry, funding information and other firmographic details used to identify and prioritise target accounts.
- Verification data: the result of email validity checks.
- Engagement data: records of outreach sent, opens, clicks, replies, call outcomes.
- Communication data: meeting notes and, where applicable, call recordings and AI-generated summaries of scheduled meetings.
- Qualification and CRM data: lifecycle stage, qualification status, deal information and communication history held in our CRM.
- Suppression and preference data: opt-out status, do-not-contact flags and unsubscribe records.
We obtain this data from a combination of sources: directly from the business contact (for example when they reply, book a meeting or provide details), from publicly available professional sources (such as company websites and professional networking profiles), and from B2B data and enrichment providers.
How and Why We Use Personal Data
We use personal data only for the outbound sales purposes described below, and we rely on the legal bases set out in the table. Our principal legal basis is our legitimate interest in carrying out direct B2B marketing and developing business relationships, which we balance against the rights and interests of the business contact.
Purpose of processing | Categories of personal data | Lawful basis |
|---|---|---|
Identifying and qualifying prospective business contacts; building and enriching prospect lists | Identification data, Business contact details and Company data. | Legitimate interests (Art. 6(1)(f)) |
Sending B2B outreach by email or LinkedIn | Identification data, Business contact details, Engagement data | Legitimate interests (Art. 6(1)(f)) where required by law, consent (Art. 6(1)(a)) |
To respond to inquiries and develop business opportunities arising from web form submissions or connections made at conferences | Identification data, Business contact details | Legitimate interests (Art. 6(1)(f)) |
Cold calling of business prospects | Identification data, Business contact details | Legitimate interests (Art. 6(1)(f)) |
Recording and summarising scheduled calls and meetings | Identification data, Communication data | Consent of participants (Art. 6(1)(a)) and/or legitimate interests for record-keeping and training |
Managing suppression, opt-out and 'do not contact' records | Business contact details, Suppression and preference data | Legal obligation (Art. 6(1)(c)) and legitimate interests in honouring objections |
Operating our CRM, automation and internal coordination | Business contact details, Engagement data, Qualification and CRM data | Legitimate interests (Art. 6(1)(f)) in running the sales function |
To analyse interactions, segment our audience, and generate reports | Business contact details, Engagement data, Communication data, Company data, Qualification and CRM data | Legitimate interests (Art. 6(1)(f)) in analysing and improving our sales activities |
Complying with legal, accounting and regulatory obligations | Records reasonably necessary to evidence compliance | Legal obligation (Art. 6(1)(c)) |
How We Share And Disclose Information
We may share your personal data in the following ways:
- Within MacPaw: different departments within MacPaw may access data as needed to operate our service, preserve its stability and functionality, and for internal analytics. Such access is on a need-to-know basis and subject to the same internal data-protection and access controls described in this Policy.
- Service providers: we use trusted service providers as explained below. All such providers are bound by confidentiality and data-protection obligations through contracts.
- Legal requirements: we may disclose your data, or allow government and law-enforcement officials to access it, in response to a subpoena, search warrant, court order or similar requirement, or in compliance with applicable laws and regulations. Such disclosure or access may occur where we believe in good faith that: (a) we are legally compelled to do so; (b) disclosure is appropriate in connection with efforts to investigate, prevent or take action regarding actual or suspected illegal activity, fraud or other wrongdoing; or (c) such disclosure is necessary to protect our legitimate business interests, including the security or integrity of our products and services.
- Merger or acquisition: if our company is ever involved in a merger, financing, reorganisation or sale, your data may be transferred as part of that transaction, under appropriate confidentiality and legal safeguards. You would be notified of any resulting change in how your data is handled.
Service provider | Services | Transfer Mechanism |
|---|---|---|
Reply App Inc. d/b/a Name2Email (USA) | Email generation | EU Standard Contractual Clauses |
Tagis, Inc. d/b/a Amplemarket | Sales engagement and outbound automation tool | EU-US Data Privacy Framework |
ZenLeads, Inc. d/b/a Apollo.io (USA) | B2B contact database | EU-US Data Privacy Framework |
Snovio Inc. (USA) | Email finder and verification | EU Standard Contractual Clauses |
PhantomBuster SAS (France) | Automation and scraping | N/A |
Bouncer Sp. z o.o. (Poland) | Email verification | N/A |
Google LLC d/b/a Google Workspace (USA) | Data storage | EU-US Data Privacy Framework |
Lemlist SAS (France) | Outreach execution | N/A |
Read AI, Inc. (USA) | Call recording and AI-generated meeting summaries | EU-US Data Privacy Framework |
Zapier, Inc. (USA) | Workflow automation | EU-US Data Privacy Framework |
Crunchbase, Inc. (USA) | Company research and enrichment | EU Standard Contractual Clauses |
Atlassian Corporation Plc d/b/a Trello (USA) | Project management | EU-US Data Privacy Framework |
HubSpot, Inc. (USA) | CRM system | EU-US Data Privacy Framework |
Anthropic Ireland Limited d/b/a Claude (Ireland) | AI provider | N/A |
OpenAI Inc d/b/a ChatGPT (USA) | AI provider | EU Standard Contractual Clauses |
Several providers act as our processors and process personal data only on our documented instructions. Some providers, including contact-database and company-research providers - also act as independent controllers of their own datasets, which they compile and license independently of us; in respect of that activity their own privacy notices apply.
AI providers
Our AI providers may be connected directly to certain of the tools listed above to query and analyse data on our behalf. Where this connection is enabled, the AI provider acts as our processor under a DPA and accesses data only to perform the tasks we instruct. We use these connections to analyse interactions, segment our audience, generate reports, etc.
We do not permit an AI provider to use personal data accessed through them to train its models.
Data Storage and International Transfers
Some of our tools and providers store and process personal data outside the European Economic Area (EEA), including in the United States. Where personal data is transferred outside the EEA or UK, we rely on an appropriate transfer mechanism - an adequacy decision where one applies, or the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) together with any supplementary measures needed to ensure an essentially equivalent level of protection. Information about these safeguards and how to obtain a copy of them can be made available upon request.
Retention periods
We retain personal data only for as long as necessary for the sales purposes for which it was collected. The table below sets out the retention periods we apply by contact category.
Category | Data retention period |
Cold prospects who do not reply | 24 months from the date of collection |
Engaged prospects (replied but no deal) | 24 months from the last interaction |
Inbound contacts who do not engage | 36 months from submission |
Inbound contacts who engage (but no deal) | 24 months from the last interaction |
Customers (closed won): | 5 years after the contract ends, in line with our contractual and legal obligations |
Closed-lost contacts | 24 months from the date the deal was lost. |
Suppressed contacts (unsubscribed or opted out) | Indefinite (we keep only a minimal record such as the email address and suppression status) |
Erasure requests | 3 years from the request data |
Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access or disclosure.
Your Rights
Depending on your location, you have rights in relation to the personal data we hold about you. These may include the right to:
- be informed about how we process your data (which this Policy provides);
- access the personal data we hold about you;
- have inaccurate data corrected or incomplete data completed;
- have your data erased;
- restrict or object to our processing, including objecting to direct marketing at any time - if you object to direct marketing, we will stop processing your data for that purpose;
- data portability, where applicable;
- ask us how we obtained your data - on request we will identify the source category from which your data was acquired; and
- lodge a complaint with a supervisory authority.
Because much of our processing relies on legitimate interests for direct B2B marketing, you can object at any time and we will suppress your details from further outreach. You can opt out using the unsubscribe link in any email we send, by replying to ask us to stop, or by contacting us using the details below.
Children
Our sales activities are directed exclusively at business professionals and are not intended for, or directed at, children. We do not knowingly collect personal data of children. If we learn that we have inadvertently collected such data, we will delete it.
Contact Us
You may contact us with any questions relating to this Privacy Policy by e-mailing: [email protected] .
To communicate with our Data Protection Officer, please email [email protected].
Changes to This Policy
We may update this Policy from time to time to reflect changes in our tools, processes or applicable law. We will revise the “Last updated” date above when we do so, and where changes are material we will take reasonable steps to communicate them. We encourage you to review this Policy periodically.