Privacy Policy
Last updated: September 25, 2026
How lead credits work
The prepaid lead-credit terms below apply only when you buy that offer. References elsewhere to billing for verified replies apply only to existing reply-based PAYG agreements; those agreements are unchanged. Mandatory consumer rights remain unaffected.
For prepaid lead billing we record payment references, credit movements, delivery times and hashed identity references to prevent duplicate charges. Reply content is not required to charge for lead delivery. Existing reply-based PAYG agreements retain their separate verification rules.
Privacy Policy
Effective Date: September 25, 2026
Last Updated: September 25, 2026
ȘTIURIUC MARIUS-GABRIEL PERSOANĂ FIZICĂ AUTORIZATĂ ("EvenLeads", "we", "us") operates the EvenLeads lead discovery, enrichment, outreach, CRM, WhatsApp, browser extension, AI assistance, and analytics platform. This policy explains how we process personal data when you use EvenLeads, when a customer uses EvenLeads to find or contact business leads, and when a person uses our Privacy Hub or Transparency Hub.
Controller contact:
ȘTIURIUC MARIUS-GABRIEL PERSOANĂ FIZICĂ AUTORIZATĂ
B-dul Bucureștii Noi, 136, et. Parter, ap. 5, SECTOR 1, BUCURESTI
Registration: CUI: 52908297
Email: contact@evenleads.com
1. Our Roles
For account, billing, website, security, product analytics, marketing, cookies, Privacy Hub, and Transparency Hub processing, EvenLeads is generally the controller. When a customer uses lead discovery, monitoring, enrichment, messaging, conversation tracking, exports, or integrations for its own purposes, the customer is generally the controller for those activities. Where EvenLeads processes data only on that customer's documented instructions, it acts as processor. The actual processing determines these roles; an account setting or agreement cannot transfer EvenLeads' own statutory responsibilities to a customer.
Customers must provide accurate controller identity and lawful-basis information and fulfil their transparency and objection duties. Where EvenLeads acts as processor, an Article 28-compliant data processing agreement is required. This policy does not replace that agreement or establish that all required agreements or assessments have been completed. Contact contact@evenleads.com about the arrangements applicable to your use.
2. Data We Process
- Account and workspace data: name, email address, password hash, company details, organization membership, role, controller identity, settings, preferences, authentication data, and support messages.
- Billing data: subscription status, invoices, billing address, tax details, payment metadata, provider identifiers, usage reservations, verified outreach and qualifying-reply evidence used for outcome billing, and chargeback or support records processed with Stripe, Dodo Payments, or configured payment providers.
- Campaign, CRM, and integration data: product descriptions, keywords, targeting settings, selected platforms, connected account metadata, mailbox/CRM settings, OAuth/API tokens, sync logs, exports, and action audit trails.
- Lead discovery and monitoring data: post or listing text, title, source platform, source URL, group or community reference, timestamp, handle/name shown by the source, profile URL, relevance score, status, and campaign match metadata from public sources or sources a customer has authorized the extension to access.
- Enrichment data: business contact details, company name, domain, role/title, professional profile URL, business email or phone, source/provider metadata, confidence scores, verification results, and suppression state.
- Outreach, conversations, and WhatsApp data: draft, sent, and received message content; participant names and platform identifiers; conversation and message identifiers; direction, timestamps, delivery or read status where available; comment/DM action status; phone numbers; WhatsApp contacts imported by a user; bridge state; AI WhatsApp consent timestamps; and opt-out/suppression signals. Social conversation collection is limited to people contacted through EvenLeads, rather than importing unrelated personal inbox history.
- Browser extension data: extension authentication, action identifiers, platform page context needed for the requested task, monitoring and outreach status updates, reply-tracking results, local extension storage on your device, automation choices and acknowledgement timestamps, and non-retry signals such as
privacy_suppressed. Optional interaction-style training may record timing, pointer movement, scrolling, and typing patterns for the chosen interaction style. - AI data: prompts, redacted lead context, generated replies, translations, summaries, classifications, relevance scoring, model metadata, and token usage.
- Suppression and rights data: Privacy Hub requests, signed references, verification events, hashed email or phone identifiers, blocked URLs, restriction or erasure records, audit timestamps, and correspondence.
- Technical, analytics, and security data: IP address, device/browser data, log events, queue/job metadata, error reports, rate-limit signals, cookie preferences, analytics events, heatmaps/session replay, advertising events, and referral attribution where enabled by consent.
3. Sources of Data
We receive data from you, your organization, public web pages and platform content, connected accounts you authorize, enrichment providers, AI providers, CRM/mailbox providers, payment providers, analytics providers, browser extension interactions, WhatsApp bridge infrastructure, and people who submit Privacy Hub or rights requests. Browser monitoring may read the groups or communities you select using your logged-in platform session. Access to a group does not by itself establish a lawful basis to collect or contact its members.
Lead discovery is separate from conversation tracking. When reply tracking is enabled, the extension may read and transmit sent and received content from supported conversations with people contacted through EvenLeads. Private message content can therefore be stored and processed for the requested inbox and reply-tracking functions. This is not authorization to collect unrelated conversations, private friend lists, or content by bypassing access restrictions.
4. Purposes and Legal Bases
- Contract performance: account creation, authentication, subscriptions, dashboard features, extension access, customer-requested integrations, exports, CRM sync, and support where necessary to perform our contract with the person concerned. A customer's subscription does not itself provide a lawful basis for processing another person's data.
- Legal obligations: tax, accounting, billing, consumer protection, sanctions, fraud prevention, rights-response handling, and data breach obligations.
- Consent where required: non-essential cookies, Google Analytics, Microsoft Clarity, PostHog through
e.evenleads.com, Meta Pixel, optional chat widgets, and marketing emails. Authorization to connect an account or activate an AI feature is a product permission, not automatically the consent of every person whose data the feature processes. - Legitimate interests - public lead discovery: identifying public requests for products or services and organizing them for relevant business users, subject to minimisation, retention limits, suppression checks, and objection controls.
- Legitimate interests - B2B enrichment: verifying proportionate business contact details for customer-requested B2B outreach, with source metadata, suppression checks, retention limits, and transparency links.
- Legitimate interests - AI assistance: classifying, translating, scoring, summarizing, and drafting customer-requested content, with redaction where feasible and suppression checks before AI use.
- Legitimate interests - security and reliability: preventing abuse, enforcing limits, maintaining logs, resolving errors, operating queues, protecting accounts, and investigating incidents.
For customer-directed monitoring and conversation tracking where we act as processor, the customer determines and documents the applicable lawful basis. For our own outcome-billing administration, we process the evidence necessary to check whether verified outreach received a reply meeting the agreed billing definition, resolve disputes, and prevent duplicate or abusive charges. Finding a lead alone is not evidence of a billable reply. The lawful basis for a particular activity must be assessed for the people affected; public availability or a customer's acceptance of terms does not remove that requirement.
5. Legitimate Interest Balancing
Reliance on legitimate interests requires a documented assessment of the purpose, necessity, and impact on affected people. This policy is not evidence that a particular assessment has been completed. Controls supporting that assessment include data minimisation, retention settings, hashed suppression identifiers where possible, verified suppression flows, source references, access controls, AI redaction where feasible, and suppression checks. Hashed identifiers remain pseudonymous personal data where they can be matched to a person; they are not necessarily anonymous. A direct-marketing objection must stop processing for that purpose.
6. Articles 13 and 14 Notices
This policy and feature-specific notices explain our processing. For indirectly collected data, EvenLeads provides notice tools covering controller identity, data categories, sources, purposes, legal basis, retention, recipients, and rights. A generated notice or Privacy Hub link does not by itself prove that the notice reached everyone entitled to receive it. Customers must deliver the required information for their own processing; EvenLeads remains responsible for its own notice duties.
7. Privacy Hub, Erasure, Restriction, and Objection
You can use the Privacy Hub or Transparency Hub at https://evenleads.com/privacy-hub to request removal of copied public content, object to future processing, restrict verified identifiers, or contact us about access, rectification, erasure, portability, or other rights. Permanent email or phone suppression requires a verified match or signed reference to prevent someone else from suppressing another person. Suppression records may be retained longer because they are needed to honor objections and prevent re-ingestion.
You may also contact contact@evenleads.com; using a particular form is not mandatory. We ask only for verification proportionate to reasonable doubts about identity. When a request affects disclosures to other recipients, the responsible controller must inform those recipients where the law requires. Exports and third-party copies are not necessarily removed by deleting a record in EvenLeads.
8. Enrichment, Export, CRM Sync, Outreach, and Extension Controls
Enrichment, export, CRM sync, outreach, WhatsApp actions, extension-managed actions, and AI generation are checked against suppression records before processing or disclosure. If an action is blocked as privacy_suppressed, EvenLeads records the block and the extension is expected not to retry that action. Customers remain responsible for ensuring their outreach complies with GDPR, UK GDPR, ePrivacy, CAN-SPAM, platform rules, WhatsApp rules, and local direct-marketing requirements.
Monitoring, automatic sending, and reply tracking have separate controls. Pausing monitoring or sending does not necessarily stop enabled reply tracking; review that setting separately. Browser-dependent work requires an available browser, extension, authorized session, and accessible platform content. Offline periods, session expiry, platform changes, and rate limits can delay or prevent collection. Trained interaction patterns and slower actions do not make automation undetectable, authorized, or risk-free.
9. AI Processing
We use OpenAI, Groq, and configured AI providers to classify, translate, score, summarize, draft replies, and assist support or search workflows. Where feasible, emails, phone numbers, author names, handles, profile URLs, and known contact fields are stripped or minimized before AI calls. Message or post text may still identify someone, so redaction is not a guarantee of anonymity. Required provider contracts, data processing terms, and transfer safeguards must be in place for the processing involved.
AI output can be inaccurate; users must review it before outreach. Outcome-billing checks may use AI to assess reply content against the agreed definition, alongside verified outreach and message evidence. A classification can be wrong. Customers can request a human review of a classification or related charge at contact@evenleads.com. These checks do not make finding a lead alone chargeable as a reply.
10. Cookies, Analytics, and Advertising
Essential cookies support login, security, checkout, language, and consent storage. Functional cookies enable optional features such as chat and saved preferences. Analytics cookies cover Google Analytics, Microsoft Clarity, and PostHog product analytics through the first-party reverse proxy e.evenleads.com. Marketing cookies cover Meta Pixel, advertising attribution, and advanced matching where enabled. Non-essential cookies are loaded only after your consent. You can change choices from Cookie Preferences or the Cookie Policy page.
11. Recipients and Processors
We use processors and service providers for hosting, storage, payment, tax, email, analytics, PostHog proxy analytics, Microsoft Clarity, Meta Pixel, AI, enrichment, crawling, CRM/mailbox integrations, WhatsApp bridge operations, browser extension APIs, queue processing, logs, security, and support. Customers may export or sync lead data to their chosen CRM, mailbox, or workflow tools. We may disclose data where required by law, to protect rights and safety, or during a corporate transaction. We do not sell suppression data.
12. International Transfers
Data may be processed in the EEA, United Kingdom, United States, and other countries where the selected providers operate. A restricted international transfer requires an applicable legal mechanism and any necessary assessment or supplementary protection before it takes place. Depending on the transfer, this may include an adequacy decision or Standard Contractual Clauses. Naming these mechanisms does not establish that a particular provider or transfer has been approved. Contact contact@evenleads.com for information about the destinations and safeguards applicable to your data.
13. Retention
Lead discovery records are retained according to the active retention setting, currently 29 days, unless removed earlier through deletion, suppression, customer action, or a Privacy Hub request. Conversation content and related metadata must be limited to what is necessary for the requested inbox, reply tracking, and any unresolved rights or billing matter. A lead-retention setting is not a promise that every other data category uses the same period.
Account data is retained while needed to provide the account and thereafter only for justified purposes such as security, disputes, and legal compliance. Billing records may need to remain for applicable tax and accounting duties. Minimal suppression and restriction records may remain to honor objections and prevent re-ingestion. Backups and third-party copies require their own retention and deletion arrangements; this policy does not promise their immediate removal. Contact us for the period or criteria applicable to a particular record and any lawful reason for retaining it.
14. Security and Breach Handling
Technical controls include encrypted connections, authenticated access, permission checks, hashing where appropriate, audit events, and rate limits. Effective security also requires operational review of access, providers, backups, recovery, and deployment isolation; listing these requirements is not a certification that every control has been independently verified. No service can guarantee that incidents will never occur. EvenLeads retains its incident-handling responsibilities, including notifying customers, authorities, or affected people as required by its role and applicable law.
15. Your Rights
Depending on your location, you may have rights to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. You may object to legitimate-interest processing and direct marketing at any time. You may withdraw cookie consent without affecting prior lawful processing. Contact contact@evenleads.com or use the Privacy Hub.
We respond to GDPR rights requests within one month, subject to legally permitted extensions which we explain within that period. If we cannot fulfil a request, we explain the reason and available complaint routes. Customer agreements and automation acknowledgements do not remove these rights or EvenLeads' own responsibilities.
16. US and California Notice
For US residents, including California residents, the categories of personal information we may collect include identifiers, commercial information, internet or electronic activity, geolocation approximations from IP, professional or employment-related information, inferences, and sensitive account credentials where used for authentication or connected accounts. Sources, purposes, recipients, and retention are described above. We do not sell personal information for money. We may "share" data for cross-context advertising when marketing cookies or pixels are enabled. Use Do Not Sell or Share or Cookie Preferences to disable marketing cookies. California residents may request access, correction, deletion, portability, opt-out, limitation of sensitive data use where applicable, and non-discrimination.
17. Direct Marketing and ePrivacy
Electronic marketing and outreach must comply with ePrivacy, PECR, CAN-SPAM, CASL, platform policies, and other applicable rules. EvenLeads customers are responsible for determining whether consent, soft opt-in, legitimate interest, or another lawful basis applies to their outreach. EvenLeads provides suppression and objection tools, but customers must honor opt-outs and avoid spam, harassment, or unlawful automated messaging.
18. Children
EvenLeads is not intended for children and does not knowingly target or collect data from children.
19. Supervisory Authority
If you are in the EEA or UK and believe your concern has not been resolved, you may lodge a complaint with your local data protection supervisory authority.
20. Changes
We may update this policy as our product, providers, laws, or safeguards change. The date above shows the latest update.