Legal
Two audiences read this: people whose professional details are in our database, and customers who use the API. Both are covered, starting with the first.
Last updated 6 September 2026
Professional, business-context information only: name, current and past job titles, employer and its firmographics, work location at city level, public professional profile URL, work email address and work phone number where available, skills, education and certifications listed publicly, and technical flags such as whether an email is deliverable.
We do not knowingly collect special-category data (health, beliefs, ethnicity, politics, sexual orientation, biometrics), data about children, personal home addresses, personal email addresses or personal mobile numbers, government identifiers, or financial information about individuals.
From publicly accessible professional sources on the web, from our own collection and verification, and from licensed data partners who warrant that they collected it lawfully. We do not buy consumer lists.
Our purpose is business-to-business commercial intelligence: helping companies identify and reach the right professional contacts. Under the UK and EU GDPR our lawful basis is legitimate interests (Article 6(1)(f)) — the interest of businesses in reaching relevant professional contacts, and ours in providing that service. We have assessed that interest against the rights of the people in the database, which is why we limit ourselves to business-context data, publish this notice, and act on objections immediately and without asking for a reason. You can request a summary of that assessment at privacy@leadocean.io.
Our customers, under a contract that requires lawful use and prohibits consumer marketing, discrimination and use for credit, employment or insurance decisions. Customers become independent controllers of any record they retrieve and must honour your rights themselves; we will tell you which customers received your record if you ask, and we notify them of removal requests.
We also use service providers who process data on our behalf: cloud hosting and databases, object storage, payment processing and transactional email. They act on our instructions under contract.
Records are refreshed continuously and removed when a source no longer supports them. Suppression entries from a removal request are kept indefinitely — that is the only way to guarantee the record never returns.
Wherever you live, you may ask us to: confirm whether we hold data about you and give you a copy; correct it; delete it; stop processing it; or object to processing. Use Remove my data or write to privacy@leadocean.io. We answer within 30 days and we never charge for it. If we cannot identify you from what you send us we will ask for the minimum extra detail needed, and nothing more. If you are unhappy with our answer you may complain to your data-protection authority.
Our systems run in the European Union and, for some storage, in Canada. Where data moves outside the UK or EEA we rely on the appropriate safeguards, including standard contractual clauses.
When you create an account we hold your email address, a hashed password, your name and company if you provide them, your API keys (the secret is encrypted), and your usage counts. Payment card details are handled entirely by Stripe; we never see or store them.
To run your account, meter usage against your plan, bill you, keep the service secure, and send transactional email you need — confirming your address, resetting your password and important service notices. We do not sell customer data, and we do not send marketing email you have not asked for.
We log request metadata (time, endpoint, key, status, latency) for security, billing and debugging, and we keep responses briefly in cache to avoid charging you twice for the same lookup. We do not use your queries to build profiles of you or to train models.
This website sets no advertising or analytics cookies. The application stores a session token in your browser so you stay signed in, and remembers small preferences locally. That is all.
Transport is HTTPS everywhere. Passwords are hashed, API key secrets are encrypted at rest, and access to production is limited. If a breach affects you we will tell you and the relevant authority within the deadlines the law sets.
We keep account and billing records while your account is open and for as long afterwards as tax and accounting law requires. Ask us to close your account and we delete the rest within 30 days.
Privacy questions and rights requests: privacy@leadocean.io. Everything else: support@leadocean.io.