Compliance

Data protection & POPIA compliance

How LeadAtomic is built to respect the rights of both our customers and the people they reach — and the legal reasoning behind it.

1. The controls, wherever you are

Every regime we operate under asks the same five questions of a marketing email: who sent it, how do I stop it, does stopping actually stop it, is my data safe, and can I have it deleted. Those answers are the same for a recipient in Cape Town, London, or Boston, so they come first. The jurisdiction-specific reasoning follows.

  • Identity on every message. The sender's name, role, and the business they represent are composed by the system at send time, not left to a template or to the person writing.
  • Opt-out on every message, honoured permanently. A signed unsubscribe link, standard one-click headers, or simply replying "unsubscribe" — any of them works, and the result is recorded against the address rather than against a campaign.
  • Suppression that survives rediscovery. An opt-out is checked on every send, under every sender identity and mailbox that workspace owns, and it holds even if the same company is discovered again months later.
  • The system refuses to send what it cannot make compliant. If a sender identity and a working unsubscribe link cannot be attached, the send fails. It does not go out without them.
  • Security and deletion. Mailbox credentials are encrypted at rest, no employee reads mailbox content, and a deletion request stops processing immediately and removes the data on a stated schedule.

2. Two commitments worth stating plainly

Both of these come up in sales conversations, and both are easier to check than to promise, so they belong on this page rather than in an email.

  • You choose the domain you send from, and it stays yours. Outreach only ever sends from a mailbox you connect — Google, Microsoft, or your own SMTP server. LeadAtomic does not own, share, or provision a sending domain, and does not send on a pooled one. If you would rather build reputation on a separate domain from your main one, that is a matter of connecting a mailbox on it. The reputation you build is on infrastructure you control, and it leaves with you.
  • We do not sell, license, or share your workspace's data. Not to advertisers, not to data brokers, not to other customers. There is no export path out of the product and no resale path through it. Your research, your contacts, your drafts and your replies exist to be used by you.
    Stated precisely, because the distinction matters: this is a commitment about not selling data. It is not a claim that a company we surface for you will never be surfaced to anyone else. Public information about a company is public, and two customers working the same market can reach the same company independently — as they could without us. What stays private is everything specific to your workspace: your ICP, your scores and their reasoning, your contacts, your messages, and your outcomes.

3. Our approach

LeadAtomic is a B2B account-research and outreach platform. We help businesses find and contact other businesses that genuinely fit their ideal customer profile, at a deliberately human scale, with messages a person reviews and approves. We designed the product so that doing outreach well and respecting data-protection law point in the same direction.

This page explains, in plain terms, how we align with South Africa's Protection of Personal Information Act (POPIA) and why — and how those same controls map onto comparable regimes elsewhere. It is written in good faith to describe our engineering and operational practices; it is not legal advice and does not create a warranty. Each customer remains responsible for their own lawful use of the platform.

4. Connected mailboxes and Google API data

When a customer connects a Gmail mailbox, LeadAtomic sends the outreach they approve and detects the replies to it. Nothing else. Our reply checker matches each incoming message against outreach sent through LeadAtomic before anything is stored, so unrelated mail in that inbox — personal correspondence, invoices, newsletters — is discarded in memory and never written to our systems. No LeadAtomic employee can read mailbox content, and none of it is ever used to train AI models.

LeadAtomic's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. The full detail — scopes, storage, retention, sub-processors — is in our Privacy Policy.

5. Why POPIA applies to us — and how we treat it

POPIA protects "personal information," which under South African law includes information relating to both natural persons and juristic persons (companies). We do not treat "it's just business data" as a reason to opt out of the law. Where we hold a named contact, a work email, or a phone number, we treat it as personal information and apply the protections below.

Most of the contact data in the platform is sourced from information a business has deliberately made public — its own website and public business listings. POPIA expressly permits collecting personal information from such sources, which is the lawful basis for how contact details enter the system. It does not, however, switch off the direct-marketing, openness, security, or data-subject-rights obligations, so we honour those regardless.

We also hold ourselves to a standard the law does not require. Every source we use is publicly accessible. We do not buy contact lists, trade data with anyone, or use covert techniques to obtain it — and any source we add in future has to meet the same test. Our advantage is how quickly we can read what is already public, not access to something you could not reach yourself.

6. POPIA's eight conditions, and what we do about each

  • Accountability. Data-protection responsibilities are owned internally, and customer-facing requests route to hello@leadatomic.com.
  • Processing limitation. We collect business-contact data from public sources, in proportion to a legitimate outreach purpose, and keep volumes at a human, non-spam scale.
  • Purpose specification. Data is used to qualify and contact prospects that fit a customer's stated ideal customer profile — not resold or repurposed.
  • Further-processing limitation. Enrichment and scoring serve that same outreach purpose and nothing incompatible with it.
  • Information quality. Records are deduplicated and kept current; bounced or invalid addresses are detected and suppressed automatically.
  • Openness. This page and our Privacy Policy explain what we process and why, including a dedicated section for people who receive outreach.
  • Security safeguards. See section 6 below.
  • Data-subject participation. Anyone can ask what we hold, correct it, or have it deleted — see section 7.

7. Direct marketing: identity & opt-out (POPIA s69)

POPIA requires that direct-marketing communications identify the sender and offer a way to ask them to stop. We build both into the product so they cannot be skipped:

  • Every email identifies who is writing. Each message carries a sender identity — the person's name, role, and the business they represent — added by the system at send time rather than left to chance.
  • Every email offers a one-click opt-out. Messages include a personal unsubscribe link and standard one-click List-Unsubscribe headers, and recipients can simply reply with "unsubscribe." Any of these works.
  • Opt-outs are honoured permanently and immediately. An opt-out is recorded against that recipient for that customer and permanently ends all marketing to them — every campaign, sequence and follow-up, under every sender and mailbox the customer uses — even if the same company is rediscovered later. Nothing automated can email that address again.
  • The single exception is a reply the recipient asked for. If someone who has opted out writes to the customer afterwards, a person may answer that message by hand. Correspondence a recipient themselves started is not marketing, and the system enforces the distinction rather than trusting it: the exception applies only to a human-written message, only to the address that wrote in, and only while that address's own last message is no older than its opt-out. Every such send is logged against the reply that authorised it.
  • We fail safe. If a compliant sender identity and working unsubscribe link cannot be attached to a message, the system refuses to send it rather than send a non-compliant email.
  • Human scale and human approval. Outreach is low-volume and reviewed by a person, not bulk blasting — consistent with proportionate, legitimate business communication.

8. Unsubscribe links are safe by design

Unsubscribe links are signed so they cannot be forged or used to guess other recipients, and the link itself contains no account login. Because email security scanners automatically open links, simply opening the page never unsubscribes anyone — the opt-out is only recorded after an explicit confirmation (or the mailbox provider's native one-click action). Recipients can also resubscribe if they change their mind.

9. Security safeguards

  • Account passwords are hashed, never stored in plain text.
  • Connected-mailbox credentials and OAuth tokens are encrypted at rest.
  • Authentication and sensitive public endpoints are rate-limited and abuse-resistant.
  • Operational and audit records support investigation and accountability.
  • Access to customer data is limited to what operating the service requires.

No system can promise absolute security, and customers remain responsible for protecting their own devices, mailboxes, and credentials.

10. Your rights and how to exercise them

Whether you are a LeadAtomic customer or someone who received outreach through the platform, you can ask us to tell you what personal information we hold about you, correct it, or delete it. The fastest way to stop receiving outreach is the unsubscribe link in any message or replying "unsubscribe." For anything else, contact hello@leadatomic.com and we will action the request and, where the data was processed on a customer's behalf, route it to them as the responsible party while assisting as the platform operator.

11. Service providers & cross-border processing

We use a small set of trusted providers to operate the service — transactional email infrastructure, the mailbox providers customers connect (such as Google or Microsoft), and AI/model providers used for tasks like profile extraction, enrichment, scoring, and drafting. Some of these process data outside South Africa. We rely on these providers under terms that require them to protect the information and use it only to deliver the service, consistent with POPIA's rules on operators and cross-border transfers.

12. Alignment with comparable regimes

The controls above are built on principles shared across modern data-protection and anti-spam law, so the same product behaviour supports compliance beyond South Africa:

  • GDPR / UK GDPR (EU & UK). Lawful-basis thinking, transparency, data-subject access and erasure, security of processing, and an objection/opt-out route.
  • PECR & similar e-marketing rules. Clear sender identification and a simple, free, always-available way to opt out of electronic marketing.
  • CAN-SPAM (US). Accurate sender identity, honest subject lines, a working unsubscribe mechanism honoured promptly, and (optionally) a postal identifier on the sender identity.

Where a customer operates under a specific regime, they should confirm their own obligations; we provide the mechanisms (identity, consent records, opt-out, suppression, security, deletion) that make meeting them practical.

13. Changes to this page

We will keep this page current as the product and the law evolve. If we make a material change, we will update the effective date above.