Open Profile InMail is live , reach 100+ extra prospects per seat, at no InMail cost FREE CHANNEL See how it works
Pricing Log in
Get Started Free Book a Demo
Trust Center

Where our compliance stands, stated plainly

What is done, what is in progress and what we do not claim. Updated as each item completes, so a security review never has to take our word for it.

GDPR programme: in progress SOC 2 Type II: in progress ISO 27001: aligned, not certified TLS 1.2+ and AES-256

Last reviewed September 2026

In progress

GDPR programme

Quicklead acts as a processor for customer prospect data and as a controller for its own website and account data. The programme is being completed item by item and each item is listed below.

Completed
  • Data Processing Agreement available on request
  • Consent-first cookie banner with equal accept and reject, Google Consent Mode v2
  • Fonts and icons self-hosted, no visitor IP sent to font CDNs
  • Data-subject request process with a one-month response commitment
  • Standard Contractual Clauses for transfers outside the EU and UK
  • Published cookie policy with every cookie, provider and duration
In progress
  • Records of processing activities for every product feature
  • Data protection impact assessment for AI scoring and personalisation
  • EU and UK representative appointment
  • Full sub-processor list for the application, with change notifications
In progress

SOC 2 Type II

Our controls follow the Trust Services Criteria for security, availability and confidentiality. The audit observation period is under way, and the report date will be published here when it is set.

Completed
  • Role-based access with least privilege and audited admin actions
  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Change management with peer review on every production change
  • Centralised logging and alerting on infrastructure and application
  • Vendor review before any new sub-processor is added
In progress
  • Independent audit observation period
  • Formal penetration test with a published summary
  • Business continuity and disaster recovery test evidence
Aligned, not certified

ISO 27001

Our information security practices follow ISO 27001 controls. We have not sought certification and do not claim it.

Completed
  • Information security policy set, reviewed annually
  • Asset inventory and classification
  • Incident response runbook with a one-business-day acknowledgement commitment
Your data

How personal data moves through Quicklead

Your account

Name, work email, company and billing details, held to run your account and invoice you. Quicklead is the controller. Deleted on request or after the post-cancellation retention window.

LinkedIn sessions

Credentials are encrypted at rest and never visible to staff in plaintext. Each account runs in an isolated cloud session with a dedicated IP, and nothing is shared between customers.

Your prospects

Lead lists, messages and replies belong to you. You are the controller and Quicklead the processor under the DPA. Never sold, never shared, never used to train models for anyone else. Export or delete at any time.

Were you contacted through Quicklead?If one of our customers messaged you on LinkedIn and you want to know what they hold about you, or want it removed, email [email protected]. We pass the request to the customer and confirm to you when it is done.
Sub-processors

Who else touches data on this website

Third parties involved in serving quicklead.io. Sub-processors for the Quicklead application itself are listed in the DPA and available on request, with notice before any change.

ProviderPurposeLocationWhen it runs
CloudflareCDN, DDoS protection and bot management for quicklead.ioGlobalNecessary
DigitalOceanHosting for this marketing websiteRegional data centreNecessary
Google (Analytics 4, Ads, Tag Manager)Website analytics and campaign measurementUSA and EUOnly with your consent
CalendlyDemo booking, opens in a new tabUSAWhen you book
YouTube (privacy-enhanced)Product videos, load only when you press playUSA and EUWhen you play a video
ipwho.isCountry lookup on the pricing page to pick your currency, after a time-zone checkEUNecessary, no cookie set
Documents

Available on request

Data Processing Agreement, ours or a review of yours
Completed security questionnaire (CAIQ or your own)
Architecture and data-flow overview
Application sub-processor list
SOC 2 Type II report, when the audit completes
Penetration test summary, when the test completes

Usually returned within two business days

Controls you can see

Already live on this site

No optional cookie or tag until you accept, with reject one click away
Google tags run under Consent Mode v2 and honour Global Privacy Control
Fonts and icons served from our own domain
Videos load only when you press play, on the privacy-enhanced YouTube domain
Every form asks for explicit consent before it collects anything
Change your cookie choice from the footer of any page
FAQ

Trust questions

Our GDPR programme is in progress, and we would rather show you the list than say yes. A DPA, a consent-first website, a data-subject request process and Standard Contractual Clauses are in place today. Records of processing, a DPIA for the AI features, an EU/UK representative and the full application sub-processor list are still being completed. This page is updated as each one lands.
The Type II observation period is under way. We will publish the report date here as soon as the auditor confirms it, and share the report under NDA once issued. Until then we complete security questionnaires in full, including the answers that are "not yet".
No. Our controls follow ISO 27001 practice, and we say "aligned", not "certified". We have not sought certification.
Yes. Email [email protected] and we will send our standard Data Processing Agreement or review yours, usually within two business days.
Email [email protected] with the subject "Privacy request". We confirm receipt within two business days and respond within one month. If you were contacted by a Quicklead customer, we forward the request to them and confirm the outcome to you.
Customer data is hosted in regional data centres with encryption at rest. Teams with residency requirements can discuss regional pinning with us before signing.

Running a vendor review?

Send us the questionnaire. You will get complete answers, the DPA and the sub-processor list, and an honest "not yet" wherever that is the truth.

No credit card required · Full product trial · Cancel any time