Where Lead Seeker's data comes from, how we keep it lawful and accurate, and the rights every person whose information appears in the Service can exercise.
GDPR & CCPA compliant. Built on a SOC 2 Type 2-certified data infrastructure. We do not sell personal data.
Our compliance posture
How we source data
Source validation & supplier due diligence
Data subject rights
Sensitive data we never collect
Documents available on request
Lead Seeker is built for B2B revenue teams operating across the United States, Canada, the United Kingdom, the European Economic Area, and Australia. Our policies, contracts, and data-handling practices are designed to satisfy the strictest of those regimes by default rather than the loosest.
GDPR compliant
We operate as a GDPR-compliant business. Our Privacy Policy sets out the legal bases we rely on for each processing purpose, our roles as Controller of account and Prospect Data and Processor of Customer Content, sub-processor categories, international-transfer mechanisms (Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum where applicable), retention periods, and the rights of data subjects in the EEA, UK, and Switzerland. A Data Processing Addendum is available on request to any Customer that needs one to satisfy its own GDPR obligations.
CCPA / CPRA compliant
We honour the California Consumer Privacy Act as amended by the CPRA, and the comparable consumer-privacy laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other US states with similar rules in force. We do not sell or share Personal Information for cross-context behavioural advertising. California and other US-state residents can exercise the rights described in the Your rights section of our Privacy Policy.
SOC 2 Type 2-certified data infrastructure
Lead Seeker is built on a SOC 2 Type 2-certified data infrastructure and aligns its operational controls with NIST SP 800-53 Rev 5. The SOC 2 Type 2 report covering the underlying platform that powers our prospect index can be reviewed under NDA on request — see Documents available on request below.
Prospect Data — the business-context information about decision makers and the companies they work for that we surface inside the Service — is compiled from a mixture of proprietary signals, publicly available sources, and lawfully licensed providers. We do not scrape gated platforms in violation of their terms, we do not buy bulk lists from unverified resellers, and we do not collect data from sources that we cannot trace back to a public origin or a contract.
Proprietary sources
We operate our own ingestion pipelines that watch a defined catalogue of public events — funding announcements, executive moves, posted roles, technology changes, regulatory filings, earnings transcripts, and similar operational signals. These pipelines feed the signal-detection layer behind Lead Compass and Trigger Signals.
Public data sources
We compile professional-context information — work email addresses, role titles, employers, role-based phone numbers, and public profile URLs — from openly available sources such as company websites, press releases, regulatory filings, hiring boards, and the public APIs of professional networks where access is permitted.
Job-posting sourcing
Hiring data is collected from publicly accessible career sites, applicant-tracking system feeds where access is permitted, and aggregator APIs that authorise commercial reuse. Postings are deduped, normalised against a canonical role taxonomy, and tagged to the right company so that “they just opened a role for this” is a signal you can act on, not a stale rumour.
Every record we surface carries the date its underlying claim was last verified. Contact details are passed through deliverability and validity checks before being returned in a search result, and signal events are linked back to a public source URL where one exists so reviewers can read the original event before relying on it.
Where we work with third-party data, search, AI, hosting, payment, or observability providers, each one is bound by a written contract with confidentiality, security, breach-notification, and data-protection obligations consistent with our Privacy Policy and, where applicable, with GDPR Art. 28. We diligence each supplier on certifications (SOC 2 / ISO 27001 / equivalent), sub-processor disclosure, security posture, and data-source provenance before onboarding, and we re-review on a recurring cadence. We do not authorise any provider to use customer-identifiable workspace data to train AI or machine-learning models without your separate written permission.
Whether you are a Lead Seeker customer, an authorised user inside a customer workspace, or a person whose business contact information appears in the Service as Prospect Data, you have rights over your Personal Data. The full list — access, rectification, erasure, restriction, portability, objection, withdrawal of consent, opt-out of sale or sharing, correction, and limit-use of sensitive information, plus the right to lodge a complaint with a supervisory authority — lives in our Privacy Policy §9.
To exercise any right, email privacy@theleadseeker.com with the right you wish to exercise and enough detail to identify your records, or use our contact page. We acknowledge requests within 10 business days and respond on the merits within 30 days, with a possible extension to 45 days where the request is complex, in line with GDPR and CCPA timing rules. Records flagged by an opt-out, an unsubscribe, a deletion request, or a confirmed bounce are removed across the index and suppressed from re-collection.
Prospect Data is intentionally limited to professional context. Lead Seeker does not collect, infer, or store the following categories of sensitive personal information about prospects:
Government-issued identifiers (Social Security, passport, driver's licence).
Financial-account numbers, payment-card data, or credit information.
Precise (sub-city) geolocation derived from a device.
Health, medical, or biometric and genetic data.
Racial or ethnic origin, religious or philosophical beliefs, union membership.
Sexual orientation, sex life, or sex-life inferences.
Criminal records or alleged offences.
Data of children under 16.
Contents of private communications (email bodies, DMs, call transcripts).
Lead Seeker is not a consumer reporting agency and Prospect Data is not a consumer report. The Service must not be used to make decisions about consumer credit, housing, insurance, employment, education, or other eligibility determinations covered by the US Fair Credit Reporting Act (FCRA) or comparable laws — see Terms §6.
The following documents are available to customers and qualified prospects under NDA. Email privacy@theleadseeker.com or use our contact page with the document you need and a short note about your use case.
Data Processing Addendum (DPA) for customers needing a signed Art. 28 instrument.
Sub-processor list with the categories of data each one processes.
Security overview covering encryption in transit and at rest, access controls, backups, and incident response.
SOC 2 Type 2 report for the underlying data infrastructure that powers our prospect index, available under NDA.
This page is informational and does not modify our Privacy Policy or Terms of Service, which control in case of conflict.