1. Who we are

LEADSMIND AI LTD (trading as XP ONE), a company incorporated in England and Wales under number 17014114, 167-169 Great Portland Street, London W1W 5PF, United Kingdom.

Data protection contact: contact@xp-one.io

We comply with the UK GDPR, the Data Protection Act 2018 and, for individuals located in the European Union, Regulation (EU) 2016/679 (GDPR).

2. Our two roles — an essential distinction

SituationOur role
Your account data (sign-up, billing, support, security, usage)Controller
Prospect data you collect, import or enrich through the ServiceProcessor, acting on your instructions. You are the controller. See the DPA.
Prospect data we source ourselves for Pulsar/Quasar, up to deliveryController, after which you become the controller on delivery

This policy describes the processing for which we are the controller.

3. Data we collect

Account data — first name, last name, email address, password (stored as an irreversible hash).

Billing data — plan subscribed, payment history, transaction identifiers. We neither collect nor store card numbers: payments are processed directly by Stripe.

Technical and security data — IP address, session data, error and performance logs, browser type, push notification identifiers.

Usage data — actions performed in the Service, for billing, support and improvement purposes.

Data processed at your request — business profiles, engagement signals, contact details obtained through enrichment. This data is processed only when you trigger the action.

We do not access your LinkedIn credentials, your private messages outside the scope you explicitly connect, or your browser cookies beyond the scope necessary for the extension to work.

4. Purposes and lawful bases

PurposeLawful basis
Provide the Service, manage your account and subscriptionPerformance of a contract
Billing and payment fraud preventionPerformance of a contract / legal obligation
Security, abuse prevention, incident loggingLegitimate interests
Improving and fixing the ServiceLegitimate interests
Customer supportPerformance of a contract
Prospecting new business customers by emailLegitimate interests (B2B), with opt-out at any time
Analytics and advertising cookiesConsent
Accounting retentionLegal obligation

We do not sell your data and we do not monetise it.

5. Hosting and data location

  • Application servers: DigitalOcean — London, United Kingdom
  • Database: Amazon Web Services — Frankfurt, European Union

Transfers between the United Kingdom and the European Union rely on the European Commission's adequacy decision for the United Kingdom. Any other transfer outside the EU/UK is made under standard contractual clauses (SCCs / UK IDTA).

6. Processors and providers

ProviderRole
StripePayment and fraud prevention
DigitalOceanApplication hosting (UK)
Amazon Web ServicesDatabase hosting (EU)
SentryError detection and technical monitoring
MailjetEmail sending and verification
UnipileTechnical connection to LinkedIn and WhatsApp messaging
Enrichment providers (including FullEnrich, Checknumber)Business contact detail lookup

Each provider is bound by a data processing agreement and acts only on our instructions. An up-to-date list is available on request.

7. Retention periods

DataPeriod
Account and associated contentTerm of the subscription, then 30 days
Accounting records and invoices6 years (legal obligation)
Security and error logs12 months maximum
Support correspondence3 years after last contact
Cookie consent records13 months

8. Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw consent at any time.

To exercise them: contact@xp-one.io. We respond within one month, extendable by two months for complex requests.

Complaints: you may lodge a complaint with the competent supervisory authority — in the United Kingdom, the Information Commissioner's Office (ico.org.uk); in the European Union, the authority of your country of residence (in France, the CNIL — cnil.fr).

9. Individuals prospected through XP ONE

If you were contacted by an XP ONE user and wish to be removed from our databases, write to contact@xp-one.io. We handle the request within 30 days, remove your data from future deliveries and forward the request to the relevant customer where we act as processor.

10. Security

Encryption of communications (TLS), irreversible password hashing, access segregation, token-based authentication of sessions and of the extension, logging of administrative access, regular backups.

As no system is infallible, in the event of a personal data breach presenting a risk we notify the supervisory authority within 72 hours and, where the risk is high, the individuals concerned.

11. Third-party platforms

The XP ONE extension interacts with LinkedIn and other platforms. We are not affiliated with any of them. You are responsible for complying with their terms of use.

12. Eligibility

The Service is intended exclusively for business users aged 18 and over. We do not knowingly collect data relating to minors.

13. Changes

Any change is signalled by updating the date at the top of this document and, where material, by a message in the Service or by email.

14. Contact

contact@xp-one.io — LEADSMIND AI LTD, 167-169 Great Portland Street, London W1W 5PF, United Kingdom.