Open Profile InMail is live , reach 100+ extra prospects per seat, at no InMail cost FREE CHANNEL See how it works
Pricing Log in
Get Started Free Book a Demo
Trust Center

Where our compliance stands, stated plainly

What is done, what is in progress and what we do not claim. Updated as each item completes, so a security review never has to take our word for it.

GDPR: compliant, verify TLS 1.2+ and AES-256

Last reviewed September 2026

Compliant

GDPR

Quicklead is a processor for the prospect data in a customer workspace, and a controller for its own website, account records and Email Finder database. The GDPR Center sets out which role applies to each activity.

Completed
  • Records of processing activities, published
  • DPIA for AI personalisation and ICP scoring, published
  • Legitimate interests assessment for the Email Finder, published
  • Article 14 notice and self-serve removal for people we hold data about
  • Data Processing Agreement published in full
  • Application sub-processor list published, with 30 days’ change notice
  • Standard Contractual Clauses and the UK Addendum for transfers
  • Data-subject request process with a one-month response commitment
  • Consent-first cookie banner with equal accept and reject, Google Consent Mode v2
  • EU and UK Article 27 representative appointed: Euverify
In place

Security practices

The controls we run today to protect customer data and every connected LinkedIn account.

Completed
  • Role-based access with least privilege and audited admin actions
  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Change management with peer review on every production change
  • Centralised logging and alerting on infrastructure and application
  • Vendor review before any new sub-processor is added
In progress
  • Formal penetration test with a published summary
  • Business continuity and disaster recovery test evidence
Your data

How personal data moves through Quicklead

Your account

Name, work email, company and billing details, held to run your account and invoice you. Quicklead is the controller. Deleted on request or after the post-cancellation retention window.

LinkedIn sessions

We never ask for or store your LinkedIn password — you log into LinkedIn yourself and we hold only the resulting session token, used solely to run your account's cloud session. Each account runs in an isolated cloud session with a dedicated IP, and nothing is shared between customers.

Your prospects

Lead lists, messages and replies belong to you. You are the controller and Quicklead the processor under the DPA. Never sold, never shared, never used to train models for anyone else. Export or delete at any time.

Were you contacted through Quicklead?If one of our customers messaged you on LinkedIn, or your details are in our Email Finder database, the prospect privacy page explains what we hold, where it came from and how to have it deleted and permanently suppressed. No account needed, no charge.
Sub-processors

Who else touches data on this website

Third parties involved in serving quicklead.io. Sub-processors for the Quicklead application itself, including every AI provider, are on the full sub-processor page, with 30 days’ notice before any change.

ProviderPurposeLocationWhen it runs
CloudflareCDN, DDoS protection and bot management for quicklead.ioGlobalNecessary
DigitalOceanHosting for this marketing websiteRegional data centreNecessary
Google (Analytics 4, Ads, Tag Manager)Website analytics and campaign measurementUSA and EUOnly with your consent
CrispLive support chatEU (France)On every page
CalendlyDemo booking, opens in a new tabUSAWhen you book
YouTube (privacy-enhanced)Product videos, load only when you press playUSA and EUWhen you play a video
ipwho.isCountry lookup on the pricing page to pick your currency, after a time-zone checkEUNecessary, no cookie set
Documents

Available on request

Data Processing Agreement, published in full, or we review yours
Records of processing and the AI DPIA, published
Completed security questionnaire (CAIQ or your own), on request
Penetration test summary, when the test completes

Usually returned within two business days

Controls you can see

Already live on this site

No optional cookie or tag until you accept, with reject one click away
Google tags run under Consent Mode v2 and honour Global Privacy Control
Fonts and icons served from our own domain
Videos load only when you press play, on the privacy-enhanced YouTube domain
Every form asks for explicit consent before it collects anything
Change your cookie choice from the footer of any page
FAQ

Trust questions

Yes. Here is what that rests on, all published: our records of processing, the DPIA on the AI features, the legitimate interests assessment for the Email Finder, the DPA in full, the application sub-processor list and an Article 14 notice with self-serve removal. Our EU and UK Article 27 representative is Euverify, and you can verify the appointment directly. The GDPR Center sets all of it out, and this page is updated as each item lands.
Yes. Email [email protected] and we will send our standard Data Processing Agreement or review yours, usually within two business days.
Email [email protected] with the subject "Privacy request". We confirm receipt within two business days and respond within one month. If you were contacted by a Quicklead customer, we forward the request to them and confirm the outcome to you.
Primary application hosting, including the managed database, is on DigitalOcean in the United States, and Quicklead Technology Private Limited is established in India. We state that plainly rather than imply an EU footprint we do not have. Transfers rely on Standard Contractual Clauses with the UK Addendum and a transfer impact assessment. If EU residency is a hard requirement, raise it before signing and we will scope it properly.

Running a vendor review?

Send us the questionnaire. You will get complete answers, the DPA and the sub-processor list, and an honest "not yet" wherever that is the truth.

No credit card required · Full product trial · Cancel any time