Privacy policy
How LeadRadar processes data, on which legal basis, for how long, and which rights you have. Written for the companies we analyse, the professionals we may contact, and the customers who use the platform.
Who we are
The controller for the processing described here is LeadRadar [legal entity, registration number, registered address]. Data protection officer: dpo@leadradar.example. This policy applies to the LeadRadar platform, this website and any communication we prepare for our customers.
What LeadRadar does
LeadRadar reads public, authorised sources (public-procurement portals, company registries, company websites and annual reports, press and job boards), extracts evidence about companies, scores each company for a specific service with an inspectable formula, and prepares a Decision Case that a person at our customer reviews before any action. LeadRadar never sends a message itself.
Data we process
| Category | Fields | Nature |
|---|---|---|
| Company facts | Name, registry ID (CUI / IDNO), sector (CAEN), size, turnover, addresses, public tenders, published news and job postings | Not personal data (legal entities). Sole traders: treated as personal data. |
| Professional contacts (customer-enabled feature) | Name, role, professional e-mail or phone as published by the company, the public source and date of collection | Personal data. Minimised to what is needed to route a role-relevant message. |
| Customer users | Name, work e-mail, role, log-in and audit events | Personal data of our customers' staff. |
| Website visitors | Technical logs (IP, user agent, timestamps) kept for security; no advertising cookies | Personal data, short retention. |
Legal bases
- Company-level intelligence: not personal data; where a sole trader or a named person appears in a public source, legitimate interest (Art. 6(1)(f)) with a documented balancing test, see the Legitimate Interest Assessment.
- Professional contact data used to prepare outreach: legitimate interest, limited to roles relevant to the service offered, with transparency at first contact and a working objection mechanism. Sending a commercial message follows the rules of the recipient's country (Legea 506/2004 in Romania, Legea 195/2024 in Moldova); LeadRadar prepares, a person at the customer sends.
- Customer accounts and audit logs: performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
- Security logs: legitimate interest in protecting the service.
Automated decisions and scoring
Scores are advisory. They rank companies for human review and produce no decision with legal or similarly significant effect on a person (Art. 22 GDPR). A human approval gate is part of the architecture, not only of policy. Where a professional contact is involved, the score is about the company, never a profile of the person.
Retention
| Data | Retention |
|---|---|
| Evidence (claims, quotes, source, date) | 24 months from collection, then deleted or anonymised; earlier if the source removes it or a rights request applies |
| Professional contact records | 12 months from last purposeful use; deleted immediately on objection (the suppression entry is kept) |
| Suppression list (objections) | Kept for as long as needed to honour the objection |
| Audit trail of decisions and CRM writes | 5 years (accountability) |
| Security logs | 90 days |
| Backups | Deleted data leaves backups within 35 days |
Your rights
Access, rectification, erasure, restriction, portability and objection, including objection to direct marketing, which we honour immediately and across every workflow. Write to dpo@leadradar.example; we answer within one month. You may also complain to your supervisory authority (ANSPDCP in Romania, CNPDCP in Moldova).
Recipients and transfers
Data is hosted in the EU (see the EU hosting statement) and processed by the sub-processors listed on the Security & sub-processors page. We do not sell data, do not buy contact lists and do not build individual audiences from news items.
Changes
This policy is versioned. Last updated 27 September 2026. Material changes are announced to customers 30 days in advance.
Items highlighted like this are filled in per customer or before launch. We describe controls we operate; we do not present GDPR compliance, AI Act conformity or ISO certification as achieved results until verified.