Privacy notice
LAST UPDATED 18 JULY 2026We sell a data service, so we will be direct about our own data handling. This notice explains what happens on this website, what happens with the contact details we deliver to our clients, and what your rights are.
1. Who is responsible
Kukuri Gogiashvili I Lane 8, Apt 44, 3rd floor
0177 Tbilisi, Georgia
Tax number 305845128
Email: privacy@vegaleads.ai
Georgia is not a member of the European Union and is not covered by an EU adequacy decision. Where we process personal data of people in the EU or EEA, we do so on the basis of the appropriate safeguards described in section 7.
2. This website sets no cookies
This site uses no cookies, no local storage, no analytics, no tracking pixels and no advertising tools. It loads no fonts, scripts or images from third-party servers — everything is served from our own domain. That is why you will not see a cookie banner here: there is nothing to consent to.
If we ever add analytics, we will add a consent mechanism first and update this notice before doing so.
Server log files
Our hosting provider automatically records technical data when a page is requested: IP address, date and time, the page requested, referrer, browser and operating system. This is necessary to deliver and secure the website (Art. 6(1)(f) GDPR — our legitimate interest in a functioning, secure site). These logs are deleted or anonymised after a short retention period by the provider and are not merged with other data.
Hosting is provided by Vercel Inc. as a processor on our behalf.
3. Contact form, email and phone
When you submit the contact form, we process the details you enter: agency name, your name, email address, phone number, what you sell, and your message. We use them for one purpose — to answer you and, if it fits, to prepare a possible engagement.
- Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract) and Art. 6(1)(f) GDPR (our legitimate interest in responding to business enquiries).
- Providing the data: voluntary. Without contact details we cannot reply.
- Retention: we keep enquiries for up to 24 months so we can follow up on conversations, then delete them. If you tell us you are not interested, we delete your enquiry within 30 days, apart from what we must keep for tax or accounting purposes.
- Recipients: only our own team. We do not sell enquiry data and do not pass it to third parties for their own purposes.
The same applies if you contact us by email or phone instead.
4. Booking a demo
If you book a demo slot, the scheduling is handled by our booking provider, which processes your name, email address and chosen time in order to create the appointment. This happens on the provider's own page, not on this site.
5. The lead data we deliver to clients
This is the part that matters most in our line of work, so we set it out plainly.
What we collect
For our clients we research publicly accessible business information: company websites, legal and imprint pages, and public business directories. This can include the company name, address, business phone number, business email address, website, and the publicly named managing director or owner. Where such details identify a person, they are personal data and this section applies.
Why we may do this
We process this data as a processor on behalf of our client, who is the controller and decides how the contact details are used. The processing rests on the client's legitimate interest in direct business-to-business communication (Art. 6(1)(f) GDPR), balanced against the interests of the people concerned. We do not collect special categories of data, we do not scrape private social media profiles, and we do not buy address lists.
Information and objection
Where personal data is not collected from the person directly, Art. 14 GDPR requires that they be informed. Our clients are contractually responsible for meeting that obligation in their outreach, and for handling objections. If you believe your data has been processed by us on behalf of a client and you want it removed, write to privacy@vegaleads.ai — we will suppress the record on our side and pass the request to the client without delay.
Separation between clients
Each client has their own separate database. Lead data is never pooled, never resold, and never shared between clients.
6. When you are our client
To run your cockpit we process your account data (name, business email, hashed password), your configuration, and the data you enter about your own leads. We act as your processor for that data and sign a data processing agreement with you before delivery starts. You can export your data at any time. If our agreement ends, you receive a full export and we delete your database within 30 days, or immediately on request.
Passwords are stored only as a cryptographic hash. We cannot read them.
7. International transfers
We are established in Georgia, and some of our processors are established in the United States. Where personal data from the EU or EEA is transferred to us or to those processors, the transfer is based on the European Commission's Standard Contractual Clauses together with additional technical measures, in particular encryption in transit and separation of client databases. You can request a copy of the relevant safeguards from us.
8. Processors we use
- Vercel Inc. (USA) — website hosting and log files
- Turso / libSQL (EU region) — client databases
- Firecrawl — retrieval of publicly accessible website content
- Email and scheduling providers — communication and appointments
Each of these acts on our documented instructions under a data processing agreement.
9. Your rights
You have the right to request access to your personal data, to have inaccurate data corrected, to have data erased, to have processing restricted, to receive your data in a portable format, and to object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time with effect for the future.
To exercise any of these, write to privacy@vegaleads.ai. We answer within 30 days.
You also have the right to lodge a complaint with a data protection supervisory authority, in the EU normally the authority of your habitual residence or place of work.
10. Security
Traffic is encrypted in transit (TLS). Access to client cockpits requires authentication, sessions expire, and each client's data lives in its own database rather than in a shared table. Passwords are hashed. Access to production data is limited to the people who need it to run the service.
11. Changes
We update this notice when our processing changes. The date at the top always shows the current version.