Global privacy policy

Privacy, in practical terms.

How ExpoLeadZ handles personal data as a global B2B service, including when LearnDo OÜ is a controller and when it processes data for a customer.

Effective and last updated: 26 August 2026

1. Who we are and how to contact us

ExpoLeadZ is operated by LearnDo OÜ, registry code 16818398, VAT ID EE103013266, an Estonian private limited company with its registered office at Kadaka tee 42b, Mustamäe linnaosa, Tallinn 12915, Harju maakond, Estonia. Contact us at contact@expoleadz.com or +49 160 2459904. Full details are in our Company Information.

2. Our data-protection roles

LearnDo OÜ is generally a controller for ExpoLeadZ account identity, workspace administration, subscriptions and billing administration, support, website operation, security, fraud and abuse prevention, audit records, service notices, and records we must retain for legal or compliance purposes. For lead, event, prospect, correspondence, meeting-note, seller-document, and customer company-knowledge data, the business customer usually decides why and how that data is used. For those activities LearnDo OÜ generally acts as the customer's processor or service provider. The exact role depends on the facts and applicable law; our Data Processing Agreement governs processor activities.

3. Data we process

  • Account and workspace data: name, business email, authentication identity, profile details, organization, role, invitations, onboarding choices, and account status.
  • Billing data: plan, subscription, seat and usage information, billing contact, and provider customer and transaction references. Payment-card details are entered with Stripe and are not stored by ExpoLeadZ.
  • Event and lead data: event details, business-card images and extracted fields, vCards, QR data, names, professional contact details, job title, company, capture context, consent or follow-up context selected by a user, and duplicate candidates.
  • Meetings and communications: notes, audio and transcripts where a user chooses to provide them, connected mailbox identity and permission state, email subject/body, provider message and thread identifiers, replies, bounces, opt-outs, classifications, and next actions.
  • Research and seller knowledge: public-company sources, extracted facts, confidence and provenance, uploaded seller documents, product and commercial information, conflicts, semantic chunks, strategy output, and processing audit records.
  • Technical and support data: IP address, browser or device information available in server/security logs, timestamps, request and workflow identifiers, error categories, security and audit events, support messages, and records needed to investigate incidents. ExpoLeadZ does not currently enable public-site advertising or behavioral analytics.

4. Where the data comes from

Data comes from users and workspace administrators; people who give a business card, vCard, QR code, follow-up request, or reply; connected Google or Microsoft mailboxes; payment and authentication providers; public company websites and public research sources; and technical operation of the service. Customers must have authority and a lawful basis for data they upload, connect, or use for outreach. Receiving or scanning a business card does not, by itself, establish consent in every jurisdiction.

5. Why we process data and our legal bases

We process account, workspace, service, support, and billing data to provide and administer the contract; authenticate users; deliver requested features; manage payment and subscription state; and respond to support. We rely on legitimate interests, where balanced against individual rights, to secure the service, prevent fraud and abuse, maintain operational and audit records, improve reliability, enforce our terms, and communicate with business users about the service. We process records where necessary to meet tax, accounting, legal, regulatory, and dispute obligations. We rely on consent only when the relevant processing genuinely requires and obtains it, such as certain device permissions or marketing choices. A customer's documented instructions are the basis for processor activities, but the customer remains responsible for its own lawful basis.

6. Business outreach and suppression

ExpoLeadZ supplies technical tools for B2B lead capture and email follow-up. Customers determine recipients, purpose, content, and timing and are responsible for applicable privacy and electronic- marketing rules. ExpoLeadZ records capture context such as requested information, agreed follow-up, card-only, or other context to help the customer preserve evidence; those labels do not turn a card into universal consent. Before eligible sends, server-side safeguards check recipient syntax, email confidence, mailbox capability, relationship state, and suppression. Opt-out and hard-bounce events close or suppress follow-up as implemented. Customers may not bypass these controls. See our Outreach Policy.

7. AI-assisted processing

ExpoLeadZ uses task-specific AI to assist with business-card extraction, transcription, research normalization, reply classification, drafting, buyer/seller matching, and next-action recommendations. Structured output, confidence signals, provenance, deterministic checks, and human confirmation are used where appropriate. AI can be incomplete or wrong. The current system does not authorize an AI model to make a legally binding decision or a solely automated decision that produces legal or similarly significant effects about a person. Users remain responsible for reviewing output and deciding whether to act.

8. Confidential seller information

Professional seller documents are private and confidential by default. They use tenant-isolated private storage, controlled server access, source provenance, and a native-parser-first path. A confidential document is never sent through an ordinary third-party web-extraction fallback. That fallback is permitted only where a verified zero-data-retention capability is available; otherwise processing fails closed for review rather than weakening the confidentiality boundary.

9. Service providers and subprocessors

We use providers for hosting, database/authentication/private storage, payment processing, mailbox connection, AI processing, public-web research, and durable workflows. They receive only the data needed for their function and act under their own terms and, where applicable, data-processing terms. We do not sell personal data or use customer content for cross-context behavioral advertising. The current provider inventory, purposes, and verified regions are published in our Subprocessor List.

10. International transfers

ExpoLeadZ is operated from Estonia and uses providers that may process data in the EEA, United Kingdom, United States, and other locations shown in their current subprocessor documentation. Where personal data leaves a jurisdiction that restricts transfers, we rely on an applicable adequacy decision or contractual safeguard, such as the European Commission Standard Contractual Clauses and, for UK restricted transfers, an appropriate UK transfer addendum or agreement, only where the relevant provider contract supports it. Provider terms, transfer mechanisms, and supplementary safeguards are reviewed before production and when material providers change.

11. Retention

We keep data only for as long as needed for the service, a customer's documented instructions, the account or subscription lifecycle, dispute and security needs, or legal obligations. Retention depends on data type, workspace instructions, relationship state, provider lifecycle, and applicable limitation, accounting, tax, and suppression obligations. Cancellation normally stops renewal at the end of the paid period; it does not automatically erase account history. Provider-side data follows the provider's contract and deletion process. We will publish more precise production retention schedules after final legal and operational review.

12. Security

Implemented safeguards include row-level tenant isolation, private object storage and canonical tenant paths, encrypted transport, encrypted mobile session and offline-queue material, restricted server operations, signed and idempotent webhooks, server-only provider credentials, role and entitlement checks, and suppression safeguards. No internet service can promise absolute security. These statements do not claim that LearnDo OÜ holds SOC 2, ISO 27001, HIPAA, or PCI certification.

13. Cookies and device storage

The public site currently sets no optional analytics, advertising, or behavioral-tracking cookies. Necessary Supabase authentication cookies are used after account or login activity to establish and refresh a session. Stripe may use necessary security, fraud, and checkout storage after a billing manager chooses to leave ExpoLeadZ for Stripe-hosted checkout. The mobile app uses encrypted local storage for sessions and pending offline captures. See the current Cookie Policy and audit inventory.

14. Your choices and privacy rights

Depending on where you live and the processing involved, you may have rights to access, correct, delete, restrict, or port personal data; object to processing, including direct marketing; withdraw consent without affecting earlier processing; and complain to a regulator. Some rights are subject to legal exceptions. Send a request to contact@expoleadz.com; no account is required. We may ask for proportionate information to verify identity and authority before disclosing or changing data. If LearnDo OÜ processes the data only for a customer, we may direct the request to that customer and assist it under the DPA. More detail is available on our Privacy Rights page.

15. Account deletion and organization records

An Individual owner may request deletion of the account and its workspace subject to safety and required retention. A Company employee can leave or delete their user identity while organization-owned records remain with the Company. A Company owner must complete the protected ownership-transfer or company closure path before deletion. We may retain limited billing, tax, security, audit, suppression, and dispute records where required or justified; we do not promise immediate deletion of every database row.

16. Children

ExpoLeadZ is a B2B professional service and is not directed to children. A person creating or administering an account must have legal capacity and authority to do so for business or professional purposes. Do not submit children's personal data to the service.

17. Regional information

EEA and Estonia

GDPR rights and legal bases described above apply. You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority where you live or work. Direct marketing requires a separate lawful assessment; a business card alone is not treated as consent.

United Kingdom

UK GDPR, the Data Protection Act 2018, and PECR may apply. Rules for corporate subscribers differ from rules for sole traders and some partnerships, while the right to object to direct marketing remains important. Whether LearnDo OÜ must appoint a UK representative is a launch decision pending final legal review; no representative has been appointed or invented in this policy.

United States

Where an applicable state privacy law covers LearnDo OÜ or a customer, relevant access, correction, deletion, portability, opt-out, and appeal rights will be supported as required. California law does not apply merely because a Californian uses ExpoLeadZ; statutory thresholds and activity must be assessed. The service is not used to sell personal information or for cross-context behavioral advertising. US commercial email remains subject to truthful sender and subject information, required identification and postal details, a working opt-out, and timely honoring of opt-outs.

Canada

PIPEDA and substantially similar provincial law may apply to commercial processing. CASL can require consent, sender identification, and unsubscribe. Express or implied consent depends on the facts. A business card or trade-show interaction may support context evidence in some circumstances but never creates automatic consent; the sender remains responsible for proof and message relevance.

Australia

The Privacy Act and Australian Privacy Principles may apply depending on turnover and statutory exceptions; no small-business exemption is assumed. Commercial electronic messages must meet applicable consent, sender-identification, and unsubscribe rules. Customers remain responsible for lawful outreach.

18. Changes to this policy

We may update this policy as the service, providers, or law changes. We will post the current version and effective date here and give additional notice where required. Material changes do not authorize incompatible processing without an appropriate legal basis.