1. Who we are
LEADSMIND AI LTD (trading as XP ONE), a company incorporated in England and Wales under number 17014114, 167-169 Great Portland Street, London W1W 5PF, United Kingdom.
Data protection contact: contact@xp-one.io
We comply with the UK GDPR, the Data Protection Act 2018 and, for individuals located in the European Union, Regulation (EU) 2016/679 (GDPR).
2. Our two roles — an essential distinction
| Situation | Our role |
|---|---|
| Your account data (sign-up, billing, support, security, usage) | Controller |
| Prospect data you collect, import or enrich through the Service | Processor, acting on your instructions. You are the controller. See the DPA. |
| Prospect data we source ourselves for Pulsar/Quasar, up to delivery | Controller, after which you become the controller on delivery |
This policy describes the processing for which we are the controller.
3. Data we collect
Account data — first name, last name, email address, password (stored as an irreversible hash).
Billing data — plan subscribed, payment history, transaction identifiers. We neither collect nor store card numbers: payments are processed directly by Stripe.
Technical and security data — IP address, session data, error and performance logs, browser type, push notification identifiers.
Usage data — actions performed in the Service, for billing, support and improvement purposes.
Data processed at your request — business profiles, engagement signals, contact details obtained through enrichment. This data is processed only when you trigger the action.
We do not access your LinkedIn credentials, your private messages outside the scope you explicitly connect, or your browser cookies beyond the scope necessary for the extension to work.
4. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Provide the Service, manage your account and subscription | Performance of a contract |
| Billing and payment fraud prevention | Performance of a contract / legal obligation |
| Security, abuse prevention, incident logging | Legitimate interests |
| Improving and fixing the Service | Legitimate interests |
| Customer support | Performance of a contract |
| Prospecting new business customers by email | Legitimate interests (B2B), with opt-out at any time |
| Analytics and advertising cookies | Consent |
| Accounting retention | Legal obligation |
We do not sell your data and we do not monetise it.
5. Hosting and data location
- Application servers: DigitalOcean — London, United Kingdom
- Database: Amazon Web Services — Frankfurt, European Union
Transfers between the United Kingdom and the European Union rely on the European Commission's adequacy decision for the United Kingdom. Any other transfer outside the EU/UK is made under standard contractual clauses (SCCs / UK IDTA).
6. Processors and providers
| Provider | Role |
|---|---|
| Stripe | Payment and fraud prevention |
| DigitalOcean | Application hosting (UK) |
| Amazon Web Services | Database hosting (EU) |
| Sentry | Error detection and technical monitoring |
| Mailjet | Email sending and verification |
| Unipile | Technical connection to LinkedIn and WhatsApp messaging |
| Enrichment providers (including FullEnrich, Checknumber) | Business contact detail lookup |
Each provider is bound by a data processing agreement and acts only on our instructions. An up-to-date list is available on request.
7. Retention periods
| Data | Period |
|---|---|
| Account and associated content | Term of the subscription, then 30 days |
| Accounting records and invoices | 6 years (legal obligation) |
| Security and error logs | 12 months maximum |
| Support correspondence | 3 years after last contact |
| Cookie consent records | 13 months |
8. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw consent at any time.
To exercise them: contact@xp-one.io. We respond within one month, extendable by two months for complex requests.
Complaints: you may lodge a complaint with the competent supervisory authority — in the United Kingdom, the Information Commissioner's Office (ico.org.uk); in the European Union, the authority of your country of residence (in France, the CNIL — cnil.fr).
9. Individuals prospected through XP ONE
If you were contacted by an XP ONE user and wish to be removed from our databases, write to contact@xp-one.io. We handle the request within 30 days, remove your data from future deliveries and forward the request to the relevant customer where we act as processor.
10. Security
Encryption of communications (TLS), irreversible password hashing, access segregation, token-based authentication of sessions and of the extension, logging of administrative access, regular backups.
As no system is infallible, in the event of a personal data breach presenting a risk we notify the supervisory authority within 72 hours and, where the risk is high, the individuals concerned.
11. Third-party platforms
The XP ONE extension interacts with LinkedIn and other platforms. We are not affiliated with any of them. You are responsible for complying with their terms of use.
12. Eligibility
The Service is intended exclusively for business users aged 18 and over. We do not knowingly collect data relating to minors.
13. Changes
Any change is signalled by updating the date at the top of this document and, where material, by a message in the Service or by email.
14. Contact
contact@xp-one.io — LEADSMIND AI LTD, 167-169 Great Portland Street, London W1W 5PF, United Kingdom.