Free100Leads
Privacy
Last updated 19 August 2026
Who this covers
Two different groups of people, with different rights, and this notice speaks to both. Visitors are people using the site to find leads. Listed people are the professionals whose business details appear in our database. If you arrived here after finding yourself in a search result, the section you want is If you are listed.
Who controls the data
Free100Leads decides what is collected, from where, and how long it is kept, which makes us the controller. Raise anything on this page through the contact form, which logs your request and gives you a reference.
Where the data comes from
Our business contact records are gathered from sources that are publicly available on the internet, together with data licensed from third party providers. This is the same category of sourcing used across the B2B contact data industry, by companies such as Apollo, ZoomInfo, Lusha and Cognism.
Public sources include:
- Professional and business networking profiles that are visible without logging in
- Company websites, team pages, staff directories and press releases
- Public business registries, filings and licence records
- Conference speaker lists, published bios and public professional directories
We do not buy consumer data, we do not scrape private or logged in areas of any site, and we do not attempt to gather special category data such as health, religion, political opinion, or trade union membership. If you believe a record came from somewhere it should not have, tell us and we will trace it.
What we hold about a listed person
Business identity in a business context, and nothing beyond it:
- Name
- Job title and employer
- Business email address
- Business phone number
- City, region and country
- Employer industry and rough employee count
No home addresses, no personal email accounts we can identify as personal, no dates of birth, no financial details, no browsing history, no inferred characteristics.
Why we are allowed to hold it
Our lawful basis under Article 6(1)(f) of the UK and EU GDPR is legitimate interests: the interest of businesses in reaching other businesses, balanced against the rights of the people listed. We keep a written assessment of that balance and will share it on request.
Because we did not collect this data from you directly, Article 14 requires us to tell you that we hold it and where it came from. This page is that notice, and it is linked from every page of the site rather than buried. It is also why removal is a form and not an email thread.
If you are listed
You can exercise any of these at any time, free, and we will not ask you why:
- Erasure. Use the removal form on the contact page, under My data. Your record is deleted immediately, and a one way hash of your email address is added to a suppression list so that a future data refresh cannot bring you back. The suppression list holds the hash only. We keep no readable copy of your address.
- Objection. Tell us to stop processing your data and we will, which in practice means the same deletion.
- Access. Ask what we hold and we will send you the record itself.
- Rectification. Tell us what is wrong and we will correct it, or delete the record if you prefer.
- Restriction and portability. Available on request.
- Complaint. You can complain to the data protection authority for your country. We would rather you gave us the chance to fix it first.
The removal form is instant. Everything else goes through the message form on the same page, which records the request with a reference so it cannot be lost in a mailbox. You get an answer within 30 days.
If you are a visitor
To give you 100 leads a day without an account, we need to recognise you tomorrow:
- A cookie holding a random identifier, signed so it cannot be forged, and a copy of it in your browser storage. It expires after a year.
- A hash derived from your browser configuration, used only to make the daily limit harder to bypass.
- A shortened form of your IP address. We cut it to the network block before it is stored: the last part of an IPv4 address is discarded, and most of an IPv6 address is. For visitors without an account, the full address is never written down.
- Counts: how many leads you took today, which filters you used, which prizes you won.
This exists to ration a free product and to stop bulk scraping. It is not used to build a profile of you, and it is not shared with advertisers. Details of each cookie are in the cookie notice.
If you have an account
An account is optional. The hundred a day works without one; an account is what keeps the leads you claimed, which otherwise disappear when you close the tab. If you create one we hold:
- Your email address, and your name if you gave one.
- A scrypt hash of your password. Never the password, and we cannot recover it for you.
- Session records so you stay signed in: a hashed identifier, when it was created, and the network block it was used from.
- Which leads you claimed and on which day, which is the point of the account.
- If you subscribe: your plan, its status and dates, and Stripe's identifiers for you. No card number, expiry or security code ever reaches us. Those go from your browser to Stripe directly.
- A record of how many records you took in each billing period, which is what invoices are based on.
- An account activity record: sign-ins, API key use and file downloads, each with the time, the network it came from, the country, and the browser. From 20 September 2026 this includes the full IP address; until then only the shortened network block is kept. It exists for fraud prevention and to answer payment disputes: when a bank asks whether a subscription was really used, this is the evidence. It is kept for 24 months, then deleted. Legitimate interest is the legal basis; it is not used for advertising or profiling.
Delete your account and all of it goes, apart from what we must keep for accounting. Ask through the contact form.
Who else sees any of this
Our servers are in Germany, run by Hetzner. Cloudflare sits in front of the site for protection against bots and denial of service attacks. Stripe handles payments if you subscribe, and SMTP2GO sends the handful of emails an account needs: confirmation, password resets and receipts. That is the entire list. We do not sell visitor data, we do not run advertising networks, and no analytics company receives your behaviour on this site.
Where data reaches a country without an adequacy decision, the transfer runs on Standard Contractual Clauses.
How long we keep things
- Contact records: until the source stops supporting them, or you ask us to delete.
- Suppression hashes: permanently, because that is what makes a deletion stick.
- Daily counters: 48 hours.
- Visitor cookie: one year, or until you clear it.
- Records of which batches were served: 12 months, for abuse investigation.
- Sign-in records: 12 months. Account activity records: 24 months.
- Account details: until you delete the account. Saved leads on a free account are cleared nightly and only today's are kept; on a paid account they stay while the subscription does, then thirty days more.
- Billing and usage records: seven years, because tax law says so.
Children
The site is for business use and is not directed at anyone under 18. We do not knowingly hold data about children. If you find any, report it and we will remove it that day.
Changes
When this notice changes materially we update the date at the top and describe the change here, dated, at least 30 days before it takes effect. We do not make quiet edits.
Posted 21 August 2026, effective 20 September 2026: account activity records for signed-in users will include the full IP address, as described in the account section above. Until that date only the shortened network block is stored.