Privacy Policy

Effective Date: June 18, 2026  ·  Last Updated: June 18, 2026

1. Introduction & Definitions

This Privacy Policy describes how Wako Digital Hub Ltd ("we," "us," "our," or "iLeadX") collects, uses, stores, shares, and protects your information when you use our lead generation platform (the "Platform"). By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

Definitions

2. Data We Collect

2.1 Information You Provide Directly

CategoryExamples
Account InformationFull name, email address, company name, service description, password (hashed)
Profile InformationProfile picture (via Google OAuth), service context, notification preferences
Payment InformationBilling cycle, plan selection, transaction records (card numbers are NOT stored — card payments processed by Paystack and Stripe; crypto payments processed by NowPayments)
CommunicationsEmails sent to [email protected], feedback, feature requests

2.2 Information Collected Automatically

CategoryExamples
Usage DataPages visited, searches performed, leads viewed, features used
Device InformationBrowser type, operating system, device type, screen resolution
Session DataIP address (masked for display), login timestamps, session tokens, user agent string
Search HistorySearch queries, search results, enrichment operations

2.3 Lead Data

CategoryExamplesSource
Business IdentityCompany name, industry, description, logoGoogle Maps, company websites
Contact InformationBusiness email addresses, business phone numbers, website URLs, physical addressesCompany websites, public directories
Social MediaLinkedIn, Facebook, Twitter, Instagram, YouTube, TikTok, Pinterest profilesCompany websites, social platforms
Reviews & RatingsGoogle Maps ratings, review counts, review sentiment, top complaintsGoogle Maps
Technology StackCMS, analytics tools, e-commerce platforms, hosting providersWebsite analysis
AI-Generated DataLead scores (1-100), urgency assessments, pain point analysis, personalized pitch angles, revenue leakage estimatesAI models (locally processed)

2.4 Third-Party Authentication Data

When you sign in via Google OAuth, we receive your email address, full name, profile picture URL, and Google account identifier. We do NOT receive your Google password or access to your Google account beyond basic profile information.

2.5 No Sensitive Data

iLeadX does not intentionally collect or process any special categories of Personal Data, including health information, biometric identifiers, political opinions, religious beliefs, sexual orientation, or any other sensitive data as defined under GDPR and similar global regulations. If such data is discovered in public sources, it is ignored and not processed.

3. How We Use Data

3.1 Core Platform Functionality

PurposeData Used
Lead discovery and searchSearch queries, Google Maps data
Contact enrichmentBusiness websites, public directories
AI scoring and analysisLead Data processed through local AI models
Export and integrationsLead Data exported to CSV, Google Sheets, HubSpot, Zapier, Slack, Mailchimp, Notion
Dashboard analyticsAggregated search and lead statistics

3.2 Account Management

PurposeData Used
User authenticationEmail, hashed password, OAuth tokens
Session managementSession tokens, device information, IP address
Billing and subscriptionsPlan selection, payment records, usage tracking
Support and communicationEmail correspondence, account information

3.3 Platform Improvement & Security

PurposeData Used
Analytics and usage monitoringAggregated usage patterns, feature adoption
Fraud prevention and securityIP addresses, login patterns, session data
Debugging and error resolutionError logs, search diagnostics, system health data
Legal complianceAll data as required by applicable law

3.4 Marketing & Communications

We send the following communications to Users only: account verification emails, password reset emails, payment confirmations and receipts, plan expiry reminders, onboarding guides, and product updates (with opt-out available). We do NOT send marketing emails to Lead Subjects. The Platform generates pitch angles for Users to use in their own outreach — iLeadX does not send communications to Leads on behalf of Users.

4. Legal Basis for Processing (GDPR)

For Users located in the European Economic Area (EEA) or the United Kingdom, our legal bases for processing Personal Data are:

Processing ActivityLegal Basis
Account creation and authenticationContractual necessity — required to provide the Service
Lead generation and enrichmentLegitimate interest — core functionality of the Platform
AI scoring and analysisLegitimate interest — value-added feature of the Service
Payment processingContractual necessity — required to process subscriptions
Usage analyticsLegitimate interest — improving and securing the Platform
Marketing emails to UsersConsent — Users may opt out at any time via notification preferences
Google OAuth authenticationConsent — granted at the point of OAuth authorization

Where we rely on legitimate interest, we have conducted a Legitimate Interest Assessment (LIA) balancing our interests against the rights and freedoms of data subjects.

5. How Lead Data Is Obtained & Processed

5.1 Sources of Lead Data

iLeadX collects Lead Data from the following public and legally accessible sources:

  1. Google Maps — Business names, addresses, phone numbers, websites, ratings, review counts, categories, and hours of operation.
  2. Company Websites — Publicly accessible web pages are visited to extract contact information, social media links, technology stacks, and business descriptions. We only access pages that are publicly available without login or authentication requirements.
  3. Public Business Directories — Supplementary business information from publicly indexed sources.
  4. Social Media Platforms — Public business profiles on LinkedIn, Facebook, Twitter, Instagram, YouTube, TikTok, and Pinterest.

5.2 Data Controller vs. Data Processor

iLeadX acts as a Data Controller for User account information, billing data, and platform usage analytics. For Lead Data discovered and enriched through the Platform, iLeadX acts as a Data Processor on behalf of Users, who determine the purpose and scope of their lead generation activities.

5.3 Technical Access Restrictions

iLeadX does not bypass authentication barriers, CAPTCHA systems, paywalls, or other technical access restrictions when collecting publicly available business information. We do not access non-public, password-protected, or restricted content.

5.4 Compliance with Anti-Spam Laws

iLeadX does NOT initiate contact with Lead Subjects. The Platform provides enriched data to Users, who are solely responsible for their own outreach compliance. Users are responsible for complying with CAN-SPAM, GDPR, CCPA, and other applicable laws when contacting leads. We do not provide, sell, or distribute email lists for bulk marketing purposes.

5.3 Data Accuracy

While we strive to provide accurate and up-to-date information, Lead Data is sourced from public information and AI analysis. We do not guarantee the accuracy, completeness, or currency of Lead Data. Users should independently verify Lead Data before use.

6. Data Sharing & Third Parties

6.1 Service Providers & Sub-Processors

ProviderPurposeData Shared
PaystackPayment processingTransaction amounts, plan details, email
StripePayment processing (alternative)Transaction amounts, plan details, email
Google OAuthUser authenticationEmail, name, profile picture
Google Sheets APILead export (user-initiated)Lead Data selected for export
NowPaymentsCrypto payment processing (USDT TRC20)Transaction amounts, wallet addresses, plan details
Ollama (Local)AI scoring and enrichmentLead Data for analysis
NowPaymentsCryptocurrency payment processingTransaction amounts, wallet addresses, plan details
SMTP Email ServiceTransactional emailsEmail address, email content

6.2 Integrations (User-Initiated)

Users may choose to connect iLeadX to third-party services including HubSpot, Salesforce, Slack, Zapier, Mailchimp, Notion, and webhooks. When a User enables an integration, data is transmitted directly to the third-party service at the User's direction. iLeadX is not responsible for the privacy practices of integrated services.

Users are solely responsible for ensuring that their use of third-party integrations complies with the terms and privacy policies of those services, including but not limited to Google Maps, HubSpot, Salesforce, Slack, Zapier, and any other connected platforms.

6.3 Legal Disclosures

We may disclose Personal Data if required to do so by law, court order, or governmental regulation, or if we believe in good faith that such disclosure is necessary to comply with legal obligations, protect our rights or property, prevent or investigate possible wrongdoing, or protect the personal safety of Users or the public.

7. Data Retention Policy

7.1 User Account Data

7.2 Lead Data

7.3 Data Residency Requests

Users may request data residency accommodations for enterprise deployments, subject to technical feasibility and contractual agreement.

7.4 Payment Records

Transaction records are retained for 7 years to comply with tax and accounting regulations. Payment card numbers are never stored on our servers.

8. User Rights

8.1 Rights Under GDPR (EEA/UK Users)

RightDescription
Right of AccessRequest a copy of your Personal Data
Right to RectificationCorrect inaccurate or incomplete data
Right to ErasureRequest deletion of your Personal Data
Right to Restrict ProcessingLimit how we use your data
Right to Data PortabilityReceive your data in a structured, machine-readable format
Right to ObjectObject to processing based on legitimate interest
Rights Related to Automated Decision-MakingRequest human review of AI-generated scores or decisions

8.2 Rights Under CCPA (California Users)

RightDescription
Right to KnowKnow what Personal Data is collected, used, shared, or sold
Right to DeleteRequest deletion of Personal Data
Right to Opt-OutOpt out of the sale of Personal Data (iLeadX does not sell Personal Data)
Right to Non-DiscriminationNot be discriminated against for exercising CCPA rights

8.3 Global Rights

Users outside the EU, UK, and California may have additional rights under their local data protection laws, including the LGPD (Brazil), PIPEDA (Canada), the Privacy Act (Australia), and the NDPR (Nigeria). iLeadX will honor all valid requests to the extent required by applicable law.

8.4 How to Exercise Your Rights

Submit requests via email to [email protected] with the subject line "Data Privacy Request." We will respond within 30 days. We may require identity verification before processing requests.

9. Security Measures

MeasureImplementation
Encryption in TransitAll data transmitted via HTTPS/TLS 1.3
Password SecurityArgon2 hashing with salting
AuthenticationJWT-based access tokens with refresh token rotation, session management with device fingerprinting
Two-Factor AuthenticationTOTP-based 2FA available for all Users, mandatory for admin accounts
Access ControlsRole-based access (user, admin, super_admin) with privilege hierarchy
Audit LoggingAll administrative actions logged with timestamp, admin identity, target, and change details
Session SecurityPer-device session tracking, session revocation capability, IP logging with masking

While we implement industry-standard security measures, no method of transmission or storage is completely secure. Users acknowledge that they use the Platform at their own risk and that iLeadX cannot guarantee absolute security.

9.1 Breach Notification

In the event of a data breach affecting Personal Data, we will notify affected Users within 72 hours of discovery, as required by GDPR. Notifications will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed to address the breach.

10. International Data Transfers

iLeadX servers are currently Hetzner Cloud (Germany, EU). Data is stored and processed on Hetzner Cloud servers located in Germany (European Union). Data may also be processed in Nigeria or the United States where we or our service providers operate. For Users in the EEA or UK, we implement appropriate safeguards for international data transfers, including EU-approved Standard Contractual Clauses (SCCs).

11. Children's Privacy

iLeadX is a B2B lead generation platform intended for business professionals. The Platform is not directed to individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that a child under 18 has provided us with Personal Data, we will delete such information immediately.

12. Cookies & Tracking Technologies

Cookie/StoragePurposeDuration
access_tokenUser authenticationSession (browser memory)
refresh_tokenToken renewalPersistent (7-30 days)
themeDark/light mode preferencePersistent (localStorage)
user_emailLogin conveniencePersistent (localStorage)
Session tokensServer-side session trackingSession

Most browsers allow you to control cookies through settings. Disabling essential cookies may prevent the Platform from functioning properly.

13. AI-Generated Content & Automated Decision-Making

iLeadX uses artificial intelligence models to score leads, generate urgency assessments and pain point analyses, create personalized pitch angles, and analyze review sentiment. AI-generated scores, assessments, and pitch angles are advisory in nature and intended to assist Users in prioritizing and personalizing their sales outreach. They do not constitute legally binding decisions about any individual or business, credit decisions, employment decisions, or guarantees of lead quality or conversion likelihood.

AI outputs are probabilistic and may contain inaccuracies, omissions, or biases. Users must independently verify AI-generated insights before relying on them for business decisions. iLeadX makes no warranty regarding the accuracy, completeness, or suitability of AI-generated content for any particular purpose.

Users may request human review of any AI-generated output by contacting [email protected]. Lead Subjects may request information about AI-generated data associated with their business by contacting us. AI models may produce inaccurate, incomplete, or biased outputs. Users should independently verify AI-generated content before relying on it. iLeadX disclaims liability for decisions made based on AI-generated content.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email notification to the address associated with your account and prominent notice on the Platform at least 30 days before changes take effect. Continued use of the Platform after changes take effect constitutes acceptance of the updated Privacy Policy.

15. Contact Information

Data Controller: iLeadX — a subsidiary of Wako Digital Hub Ltd
Email: [email protected]
Subject Line: "Data Privacy Request"

For GDPR-related inquiries or questions about this Privacy Policy, contact [email protected]. We aim to respond within 5 business days. If you are located in the EEA or UK and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

16. Disclaimer of Liability

No Warranty on Lead Data. iLeadX provides Lead Data "as is" and "as available" without warranty of any kind, express or implied. We do not warrant the accuracy, completeness, currency, or reliability of any Lead Data.

User Responsibility. Users are solely responsible for verifying Lead Data before use, complying with all applicable laws regarding outreach, obtaining necessary consents before contacting individuals, and using AI-generated content appropriately and ethically.

Limitation of Liability. To the maximum extent permitted by law, Wako Digital Hub and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from use of the Platform, Lead Data, or AI-generated content.

Indemnification. Users agree to indemnify and hold harmless Wako Digital Hub from any claims, damages, or expenses arising from their use of Lead Data, violation of applicable laws, or non-compliance with third-party platform terms.

Outreach Responsibility. Users are solely responsible for ensuring that their outreach to Lead Subjects complies with all applicable laws, including anti-spam, privacy, and marketing regulations in their jurisdiction. iLeadX provides Lead Data for informational purposes only and does not authorize, endorse, or facilitate any particular use of such data by Users.

© 2026 iLeadX — a subsidiary of Wako Digital Hub Ltd. All rights reserved.

← Back to iLeadX