Legal
Privacy Notice
This notice is maintained by OutLead Me and explains how we collect, use, share, retain, and protect personal information. It covers our website, our sales process, and the outbound campaigns we run on behalf of clients. It is an app-owner statement, not an independent certification.
1. Who we are
OutLead Me ("we", "us", "our") is a done-for-you B2B outbound service. For the purposes of GDPR and UK-GDPR we act as a data controller for our own website and sales activities, and as a data processor for personal data we handle inside a client's GoHighLevel sub-account on their instructions.
OutLead Me is based in New Zealand. We do not currently have an establishment in the EU or UK and are not required to appoint an Article 27 GDPR / UK-GDPR representative on the basis that our processing of EU/UK personal data is occasional, low-risk, and does not include special-category data. This position is reviewed regularly and will be updated if our processing changes.
Contact for privacy queries: admin@outleadme.com.
2. What we collect
- Website enquiries. Name, work email, company, website, monthly revenue range, current outbound situation, and message you submit through our contact form.
- Technical + campaign data. IP address, referrer, UTM parameters, and the page you submitted from, used to measure marketing performance.
- Prospect data (client campaigns). Business contact details (name, role, work email, company, LinkedIn URL) sourced from lawful B2B data providers and enriched from publicly available sources, on behalf of the client whose sub-account holds the record.
- Reply + engagement data. Email opens, clicks, replies, bounces, and unsubscribes generated by outbound sequences.
We do not knowingly collect personal information from children under 16. If you believe a child has provided us data, contact us and we will delete it.
3. Lawful basis (UK/EU)
- Contract, to respond to your enquiry and deliver services you engage us for.
- Legitimate interest, to contact business roles at target companies with relevant B2B offers (Art. 6(1)(f) GDPR). We assess the balance against your rights and honour objections immediately.
- Consent, where required by local law (e.g. certain EU member states, PECR-covered marketing in the UK, CASL in Canada). Consent can be withdrawn at any time.
- Legal obligation, to keep records required for tax, accounting, and dispute resolution.
4. How we use it
- Reply to enquiries and schedule strategy calls.
- Deliver client engagements (build CRMs, run campaigns, report results).
- Improve website content, conversion, and campaign performance.
- Meet CAN-SPAM, CASL, PECR, UK-GDPR, and GDPR obligations for our own outreach.
5. Who we share it with (sub-processors)
We use a small stack of vetted sub-processors. Each is bound by contract to appropriate security and confidentiality terms:
- GoHighLevel, CRM, outbound campaigns, calendar (client sub-account).
- Supabase (via Lovable Cloud), website enquiry storage and site hosting.
- Email deliverability infrastructure, sending, warmup, and reputation monitoring.
- Google Workspace, internal email and file storage.
- Analytics, privacy-friendly page analytics (aggregate only, no cross-site tracking).
A full list is available on request to admin@outleadme.com.
6. International transfers
Some sub-processors are located outside the UK / EEA (primarily in the United States). Transfers are covered by Standard Contractual Clauses (SCCs) and the UK IDTA where applicable, plus supplementary technical measures (encryption in transit and at rest, access controls).
7. Retention
- Website enquiries: retained for 24 months after last contact so we can respond to follow-ups and evidence marketing consent, then deleted or anonymised.
- Client data: lives inside the client's own GoHighLevel sub-account. On wind-down we transfer sub-account ownership; we do not keep copies.
- Suppression / unsubscribe records: retained indefinitely as required to honour opt-outs.
- Records required by law: invoices, tax, and dispute records are retained for the period required by applicable law (typically 5–7 years).
8. Your rights
Depending on where you live you may have the right to: access, rectify, erase, restrict processing, port, or object to processing of your personal data, withdraw consent where processing is based on consent, and to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK, OAIC in Australia, EU member-state DPAs, IPC/OPC in Canada, OPC in New Zealand).
US residents (including California under the CCPA/CPRA): you may request to know, delete, or correct personal information we hold about you, and to opt out of any "sale" or "sharing" of personal information. We do not sell personal information and do not share it for cross-context behavioural advertising.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.
Every outbound email we send on our own or a client's behalf includes a one-click unsubscribe. To exercise any other right, email admin@outleadme.com. We respond within 30 days and will verify your identity before actioning the request. There is no fee unless the request is manifestly unfounded or excessive.
9. Cookies + analytics
We use a small number of essential cookies for site functionality and privacy-friendly analytics that do not profile users across sites. We do not run behavioural ad tracking. We do not sell personal information.
10. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access is role-based and limited to team members who need it to deliver services. We review access quarterly and revoke on offboarding within one business day.
11. Changes
Material changes will be posted here with a revised "last updated" date. See our Data Processing Addendum for the terms that govern data we process on behalf of clients.
Last updated: July 2026.
