// SECURITY & DATA PROTECTION

What we do.
And what we don't claim.

Prospecting touches personal data, so this page is written to be checked rather than admired. It sets out the legal basis we rely on, who is responsible for what, where your data physically sits, how it is deleted, and the certifications we do not hold.

// YOUR SIDE OF THE DEAL

The opt-out
is not optional.

Because you are the controller, some duties are yours and cannot be delegated to a supplier. We would rather write them down here than let you discover them in a complaint.

// DUTY_01

Every message carries a way out.

Each communication you send must give the recipient a clear, simple way to refuse further contact — on every channel, in every template, including the first message. Writing that line into your templates is your responsibility.

// DUTY_02

An objection ends the conversation.

If someone asks not to be contacted again, that request must be honoured immediately and permanently, across all your campaigns and channels — not just the one they replied to.

// DUTY_03

Professional contacts, professional purpose.

Use the platform for B2B outreach that is genuinely relevant to the recipient's role. Consumer marketing, and messages with no plausible link to the person's work, fall outside the legal basis and outside our Terms.

// DUTY_04

You answer data-subject requests.

Access, rectification, erasure and objection requests from people in your lists come to you as controller. We support you on the technical side and act on your instructions, within the terms of the DPA.

This page is a plain-language summary. The binding text is the Privacy Policy and the DPA.

// SUB-PROCESSORS

Every third party
that touches your data.

This is the list annexed to the DPA. Locations are stated as a matter of fact about where each supplier runs, not as a marketing promise about data residency — we run no formal residency programme, and we are not going to imply one.

Sub-processors used by LEADSMIND AI LTD
Sub-processorRoleWhere it runs
Amazon Web ServicesDatabase hostingFrankfurt, Germany
DigitalOceanApplication hostingLondon, United Kingdom
StripePayments and billingAs set out in the DPA
SentryError monitoringAs set out in the DPA
MailjetTransactional email deliveryAs set out in the DPA
UnipileMessaging connectivityAs set out in the DPA
FullEnrichContact data enrichmentAs set out in the DPA
ChecknumberPhone number verificationAs set out in the DPA

Sub-processor list as annexed to the DPA. Transfers, safeguards and notice of changes are governed by that document.

Transport and access

Traffic between your browser, the Chrome extension and our servers runs over HTTPS. Storage, backups and network isolation rely on the managed infrastructure of the two hosting sub-processors above. Access to production data inside the company is limited to the people who need it to operate and support the service.

// WHATSAPP — READ THIS BEFORE YOU BUY

Browser automation.
Not an official channel.

WhatsApp outreach in XP One works by driving a browser session on your own account. It is not an official integration, we are not a WhatsApp partner, and there is no certification behind it. Anyone telling you otherwise about a tool in this category is selling you a word that has no meaning here.

What follows from that, plainly: your WhatsApp account remains subject to WhatsApp's own terms and enforcement, sending behaviour is your responsibility as much as ours, and we will never describe this channel as certified or approved. What we do instead is pace it, restrict it to numbers verified as active, and keep the volumes low enough to look like the human conversation it is meant to be.

If that trade-off is not acceptable for your business, use LinkedIn and email only — they are complete channels in the platform on their own.

// ACCOUNT PROTECTION

Your LinkedIn account
is an asset we protect.

Security is not only about our servers. For a prospecting platform, the most likely damage is a restricted or lost LinkedIn account — so the anti-ban engine is a security control, not a marketing feature, and it cannot be turned off to go faster.

Hard ceilings on invitations per campaign, per day and per rolling week. Randomised delays between actions. A cooldown between campaigns. Quiet hours in both time zones. A watchdog on stuck tasks, a heartbeat that pauses everything if the extension goes silent, and a circuit breaker that stops after five consecutive failures.

// LEAVING

Privacy-first cancellation,
and we mean it.

The honest test of a data policy is what happens when someone leaves. Ours is deliberately boring:

// STEP_01

One click.

Cancellation happens in the app. No retention call, no "are you sure", no support ticket to open, no form to email.

// STEP_02

You take your data.

Your prospects, lists and campaign history are exported as CSV and JSON, in formats you can open with anything.

// STEP_03

We delete ours.

Server-side deletion happens within 7 days of the request — not "eventually", not "on the next cleanup cycle".

// STEP_04

You get a signed receipt.

A signed deletion receipt is issued so the erasure is documented, which is exactly what you will need if a prospect asks you to prove it.

Retention periods for the records we must keep — invoices and accounting documents, for instance — are set out in the Privacy Policy.

// WHAT WE DO NOT CLAIM

The short list
of things we don't have.

Security pages usually inflate. This one deflates, because a claim you cannot evidence in a due-diligence call is worse than no claim at all.

  • — We hold no security certification and no audit report, at any level, in progress or otherwise. If we ever obtain one, the certificate and its date will be published here.
  • — We run no formal data-residency programme. The locations above are facts about our suppliers today, and they can change with notice under the DPA.
  • — We are not a WhatsApp partner and use no official messaging API for that channel.
  • — We run no paid bug bounty. Responsible disclosure is welcome and credited, but there is no reward programme to point you at.
  • — We offer no enterprise single sign-on, and no public API for you to integrate against.

Anything we are working on appears on the roadmap, labelled with its real status.

Found a hole?
Tell us first.

Send the details to contact@xp-one.io. Give us a reasonable window to fix it before publishing, do not access or alter anyone else's data while testing, and we will credit you publicly if you want the credit.