Skip to content

Legal

Privacy Policy

How we collect, use, store and protect your data when you visit our website, use our platform, or interact with us.

Version 1.3 · Last updated 13 September 2026

At LeadJourney we value your privacy and are committed to protecting your personal information. This policy explains how we collect, use, store and protect your data when you visit our website, use our platform, or interact with us in any way.

It applies to (a) visitors to our website at leadjourney.io, (b) LeadJourney customers and subscribers, and (c) end users of our customers whose data is processed through the LeadJourney platform.

Our two roles: controller and processor

The GDPR distinguishes between the entity that decides why and how personal data is processed (the controller) and the entity that processes data on another party's instructions (the processor). LeadJourney acts in both roles depending on the context:

  • We are the controller when you visit our website, fill in a form, sign up for an account, or hold a LeadJourney subscription. We decide how that data is handled, as described in this policy.
  • We are your processor when you use LeadJourney to track your own visitors, leads and customers. In that case you, the customer, are the controller: you decide what is collected and why, and we process it only on your documented instructions under our Data Processing Agreement (DPA).

If you are an end user of a LeadJourney customer

Questions about how your data is handled within that customer's service belong with them, not with us. Review that customer's own privacy policy or contact them directly. If you contact us instead, we will forward your request to them as the controller.

Responsible party and contact

The controller responsible for this website and the LeadJourney platform is:

Company
LeadJourney Ltd.Registration HE485008 (Cyprus)
Address
Artemidos 6 str., Office 24Joanna Court6030 LarnacaCyprus
Data Protection Officer
Jonas Strambach[email protected]

Your responsibilities

  • Read this policy and our other legal documents, collected at leadjourney.io/legal.
  • If you are a customer, review the Data Processing Agreement (DPA), available on request at [email protected].
  • When submitting data to the LeadJourney platform, ensure any personal data was obtained lawfully, through consent or another valid legal basis under the GDPR.
  • Do not submit special categories of personal data (Art. 9 GDPR) or data relating to minors under the age of 16 through the platform.
  • You may refuse our request for information, although this may limit the services we can provide.

Data we collect

Website visitors. When you visit our website we automatically collect standard browser data. This may include your IP address, browser type, device type, pages visited, time of visit, URL clickstreams and referring source.

Personal information. We collect personal information when you interact with our services, for example when you sign up for an account, request a demo, contact support or subscribe to our newsletter. This may include:

  • Name, email address, phone number and company name
  • Billing and payment information, processed by Stripe
  • Messages and enquiry content you send to us
  • Marketing attribution parameters tied to your visit (UTM parameters, click IDs)
  • The IP address the enquiry was sent from, and the approximate location our CDN derives from it (country, and where available city, region and time zone). We use it to tell a real enquiry from an automated one and to route it to the right team. No IP address is sent to a location lookup service: the value is read from a header our CDN has already attached.

Platform and business data. We collect business data generated through your use of the LeadJourney platform, including account configuration, usage analytics, integration settings and activity logs.

Advertising and retargeting data. When you visit our website, advertising pixels and tags from the platforms listed in section 8 may collect data about your visit for measuring ad performance, retargeting and conversion optimisation. This may include your IP address, browser identifiers, cookie IDs, pages visited and actions taken on our website, such as clicking a button or completing a form.

That processing is based on our legitimate interest in measuring and optimising our advertising (Art. 6(1)(f) GDPR). The pixels load on every visit, whatever you chose in the cookie banner. You can object at any time (see your rights) and opt out with each provider, see our cookie policy.

Customer end user data. Our customers may integrate LeadJourney into their websites, landing pages or other digital properties to track their own visitors, leads and customers. Our customers, not LeadJourney, decide what data is collected and for what purpose. We process this data only on the customer's instructions and solely to provide the tracking, attribution and reporting features they have configured. We do not sell this data, use it for our own marketing, or share it except with the sub-processors listed in section 8.

How we collect information

Directly from you
When you fill in a form, sign up for an account, book a demo, contact support or subscribe to communications.
Automatically
When you visit our website. See our cookie policy for the detail.
Via advertising pixels
When you interact with our ads on Meta, Google, LinkedIn, Microsoft, X or Reddit, those platforms may share event data with us under their respective data policies.
From your use of the platform
Usage data, integration activity and configuration data generated as you use the service.
From third party sources
We may receive limited business contact information from trusted data providers who have obtained an appropriate legal basis for sharing it.

How we use your data

We use your personal data for the purposes below, each with a legal basis under Art. 6 GDPR.

We may use anonymised or aggregated data to improve our services and produce usage reports or benchmarks. Customer data submitted to the platform is never used to train models or to improve the service for other customers.

How long we keep data

  • Website analytics: up to 14 months.
  • Advertising pixel data: governed by the respective ad platform's retention policy. Conversion data we receive back from those platforms is retained for up to 24 months.
  • Leads and demo requests that do not convert: up to 24 months, then deleted or anonymised.
  • Customer account data: for the duration of the contract, then deleted, except records required for tax and accounting purposes, typically up to 10 years under applicable law.
  • Customer end user data (processor role): kept according to the customer's configuration, and deleted on request or at contract end, within 60 days.

If you request deletion of your personal data, or if your data is no longer necessary for the purpose it was collected for, we erase it from our systems within a reasonable timeframe.

Third party processors and sub-processors

LeadJourney works with a carefully selected set of providers to deliver the service and run our marketing. The table below lists every provider that may process personal data on our behalf.

These providers may only access personal data to the extent necessary to perform their specific function on our behalf. We do not sell personal data. Advertising pixels load on every visit; our cookie policy lists them and how to opt out.

When you connect your own advertising accounts (Meta, Google, LinkedIn, Microsoft) to LeadJourney, data is also exchanged with those platforms under your own agreements with them and on your instruction.

International data transfers

All production data is hosted within the European Economic Area, on DigitalOcean infrastructure in Frankfurt, Germany. No personal data is transferred outside the EEA by default.

Some sub-processors listed in section 8 are headquartered outside the EEA, for example in the United States. Where personal data is transferred to them, we ensure an adequate level of protection through Standard Contractual Clauses adopted by the European Commission pursuant to Art. 46 GDPR, or another applicable lawful transfer mechanism.

Security

  • AES-256 encryption of data at rest, TLS 1.2 or higher for all data in transit
  • Role based access controls on a least privilege basis
  • Two-factor authentication for platform access
  • Audited access to production systems
  • Regular backups and infrastructure redundancy
  • Signed webhooks with HMAC, to prevent unauthorised data injection
  • Regular review of our security measures and of the requirements imposed on sub-processors

The full detail is on our security page. While we apply industry standard protections, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute data security.

Your rights

Right of access (Art. 15)
Receive confirmation of whether we process your data, and obtain a copy of it.
Right to rectification (Art. 16)
Have inaccurate or incomplete data corrected.
Right to erasure (Art. 17)
Request deletion of your data where no overriding legal basis exists.
Right to restriction (Art. 18)
Request that we limit processing in certain circumstances.
Right to data portability (Art. 20)
Receive your data in a structured, machine readable format.
Right to object (Art. 21)
Object to processing based on legitimate interests, or to direct marketing.
Right to withdraw consent
Where processing is based on consent, withdraw it at any time, without affecting processing carried out beforehand.

To exercise any of these rights, email [email protected]. We respond within one calendar month. The procedure behind each request is set out in our data subject rights policy.

If your data reached us through a LeadJourney customer's account, where we act as processor, we forward your request to that customer, who is the controller.

Right to lodge a complaint

If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with a supervisory authority. As a Cyprus registered company, our lead supervisory authority is:

Supervisory authority
Office of the Commissioner for Personal Data Protection (Cyprus)www.dataprotection.gov.cy[email protected]

You may also contact the supervisory authority in your own country of residence.

Cookies

Our website uses cookies and similar technologies. Our cookie policy lists every cookie and tool we use, states that they load on every visit, and explains how to switch them off in your browser or with each provider. Blocking certain cookies may limit some features of the service.

Data Processing Agreement

If you process personal data through the LeadJourney platform, we make a Data Processing Agreement available that meets the requirements of Art. 28 GDPR. It covers our role as your processor, the sub-processors listed in section 8, the security measures we apply, and how we assist you with data subject requests. To request one, email [email protected].

Limits of this policy

This policy covers only LeadJourney's own collection and handling of personal data. We work only with partners and sub-processors whose privacy and security standards align with ours, but we cannot accept responsibility for their independent privacy practices.

Our website contains links to external sites we do not operate. We have no control over their content or policies and cannot accept responsibility for their privacy practices.

Changes to this policy

We may update this policy to reflect changes in our practices, our sub-processors or applicable law. The date at the top always reflects the current version. For significant changes affecting customers or their data subjects, we give reasonable prior notice.

LeadJourney Ltd. · HE485008 · Artemidos 6 str., Office 24, Joanna Court, 6030 Larnaca, Cyprus · [email protected] · Version 1.3