Skip to content

Template — needs review by a lawyer before launch. This text is a starting point, not legal advice.

Privacy policy

Last updated September 28, 2026

OmniLead is built on public, verifiable data, and we hold ourselves to the same standard: we say where data comes from, why we use it, and how you can remove it.

1. Who we are

OmniLead is operated by CloudGens. For account data and for the OmniLead database of public professional information, we are the controller. For data our customers upload or create in their workspaces, we are a processor acting on their instructions. Contact our privacy team at privacy@omni.cloudgens.net.

2. If you use OmniLead

What we collectWhyLawful basis
Name, email, password hash, workspace and roleCreate and secure your accountContract
Billing details (card payments are handled by Stripe; we never see or store card numbers)Charge for plans and credit packs, calculate taxContract, legal obligation
Mailbox connection details (SMTP/IMAP credentials, encrypted with AES-256-GCM)Send your sequences and detect repliesContract
Usage events such as searches, reveals and exports, and the audit logEnforce plan limits, prevent abuse, keep an audit trail, improve the productLegitimate interest
Product analytics (only with your consent)Understand which pages and features helpConsent
Onboarding and billing emailsHelp you get started and tell you about your accountContract, legitimate interest (you can opt out of non-essential emails)

3. If you're in our database

OmniLead helps businesses, founders and researchers find professional contacts. To do that we compile public, professional information about people in their work roles, for example a fund partner named in an SEC filing, a company's head of operations listed on its team page, or an academic's published affiliation.

Where it comes from

  • Public registries and filings: SEC EDGAR (including Form D), OpenCorporates.
  • Public research and funding records: OpenAlex, ORCID, Crossref, NIH RePORTER, NSF Awards, Grants.gov.
  • Public business web pages (team, about, contact and impressum pages) read by our crawler, which respects robots.txt and identifies itself. We don't scrape LinkedIn or sites whose terms forbid it, and we don't log in to any third-party site.
  • Google Places business listings, where a customer has enabled that provider.

What we hold

Name, job title, organisation, work email and phone where published, professional profile links, and, for researchers, publications and affiliations. Every field is stored with the URL it came from and the date we found it. We never collect special-category data (such as health, religion, ethnicity or political opinions) and don't allow targeting people by personal traits.

Why, and on what basis

We rely on legitimate interests: our customers' interest in contacting relevant professionals about business matters, and ours in providing that service. We've balanced these against your interests, limit data to professional information, show its source, and make removal easy. You can object at any time.

Remove or suppress your data

Use our opt-out portal. After verifying your email you can remove your data from OmniLead or ask us to suppress it so no OmniLead customer can email you. Either applies across every workspace.

4. Data customers upload

Customers may import contacts, write notes and send emails through OmniLead. We process that data on their behalf under our Data processing addendum. If you've been contacted by an OmniLead customer, you can reply to them directly or use the unsubscribe link in their email, which takes effect immediately.

5. Sharing and sub-processors

We don't sell personal data. We share it with service providers that help us run OmniLead, listed on our sub-processors page, with customers who reveal a contact in the database, and when the law requires.

6. International transfers

Our primary database is hosted in the European Union. Some sub-processors operate in the United States. Where data leaves the EEA or UK we rely on adequacy decisions, the EU–US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses.

7. Retention

  • Account data: while your account is open, then deleted within 30 days of closure, except billing records we must keep for tax purposes.
  • Database records: refreshed from their sources, and removed when a source no longer publishes them or you ask us to remove them.
  • Suppression records: kept for as long as needed to honour your request, storing only what's needed to recognise your address.
  • Audit logs: 12 months.

8. Your rights

Depending on where you live, you can ask to access, correct, delete or export your data, object to or restrict processing, and withdraw consent. We respond within 30 days. Email privacy@omni.cloudgens.net or use the opt-out portal. You can also complain to your local data protection authority.

9. California residents

Under the CCPA as amended by the CPRA you have the right to know, delete, correct, and opt out of the sale or sharing of your personal information, and not to be discriminated against for exercising these rights. We don't sell personal information for money. Because customers can access database records, some may consider this a “sale” or “sharing”; you can opt out at Do Not Sell or Share My Personal Information. We honour Global Privacy Control signals as an opt-out of sharing for analytics.

10. Cookies and analytics

We use essential cookies to keep you signed in, remember your theme and store your cookie choice (the omni_consent cookie). Product analytics (PostHog) loads only after you allow it in the cookie banner. You can change your choice at any time with “Cookie settings” in the site footer.

11. Security

We use row-level security to isolate workspaces, encrypt secrets with AES-256-GCM, encrypt data in transit with TLS, and log sensitive actions. Read more on our security page.

12. Contact

CloudGens · privacy@omni.cloudgens.net. We'll post changes to this policy here and tell customers by email about material changes.