Compliance
Every regime we operate under asks the same five questions of a marketing email: who sent it, how do I stop it, does stopping actually stop it, is my data safe, and can I have it deleted. Those answers are the same for a recipient in Cape Town, London, or Boston, so they come first. The jurisdiction-specific reasoning follows.
Both of these come up in sales conversations, and both are easier to check than to promise, so they belong on this page rather than in an email.
LeadAtomic is a B2B account-research and outreach platform. We help businesses find and contact other businesses that genuinely fit their ideal customer profile, at a deliberately human scale, with messages a person reviews and approves. We designed the product so that doing outreach well and respecting data-protection law point in the same direction.
This page explains, in plain terms, how we align with South Africa's Protection of Personal Information Act (POPIA) and why — and how those same controls map onto comparable regimes elsewhere. It is written in good faith to describe our engineering and operational practices; it is not legal advice and does not create a warranty. Each customer remains responsible for their own lawful use of the platform.
When a customer connects a Gmail mailbox, LeadAtomic sends the outreach they approve and detects the replies to it. Nothing else. Our reply checker matches each incoming message against outreach sent through LeadAtomic before anything is stored, so unrelated mail in that inbox — personal correspondence, invoices, newsletters — is discarded in memory and never written to our systems. No LeadAtomic employee can read mailbox content, and none of it is ever used to train AI models.
LeadAtomic's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. The full detail — scopes, storage, retention, sub-processors — is in our Privacy Policy.
POPIA protects "personal information," which under South African law includes information relating to both natural persons and juristic persons (companies). We do not treat "it's just business data" as a reason to opt out of the law. Where we hold a named contact, a work email, or a phone number, we treat it as personal information and apply the protections below.
Most of the contact data in the platform is sourced from information a business has deliberately made public — its own website and public business listings. POPIA expressly permits collecting personal information from such sources, which is the lawful basis for how contact details enter the system. It does not, however, switch off the direct-marketing, openness, security, or data-subject-rights obligations, so we honour those regardless.
We also hold ourselves to a standard the law does not require. Every source we use is publicly accessible. We do not buy contact lists, trade data with anyone, or use covert techniques to obtain it — and any source we add in future has to meet the same test. Our advantage is how quickly we can read what is already public, not access to something you could not reach yourself.
POPIA requires that direct-marketing communications identify the sender and offer a way to ask them to stop. We build both into the product so they cannot be skipped:
List-Unsubscribe headers, and recipients can simply reply with "unsubscribe." Any of these works.Unsubscribe links are signed so they cannot be forged or used to guess other recipients, and the link itself contains no account login. Because email security scanners automatically open links, simply opening the page never unsubscribes anyone — the opt-out is only recorded after an explicit confirmation (or the mailbox provider's native one-click action). Recipients can also resubscribe if they change their mind.
No system can promise absolute security, and customers remain responsible for protecting their own devices, mailboxes, and credentials.
Whether you are a LeadAtomic customer or someone who received outreach through the platform, you can ask us to tell you what personal information we hold about you, correct it, or delete it. The fastest way to stop receiving outreach is the unsubscribe link in any message or replying "unsubscribe." For anything else, contact hello@leadatomic.com and we will action the request and, where the data was processed on a customer's behalf, route it to them as the responsible party while assisting as the platform operator.
We use a small set of trusted providers to operate the service — transactional email infrastructure, the mailbox providers customers connect (such as Google or Microsoft), and AI/model providers used for tasks like profile extraction, enrichment, scoring, and drafting. Some of these process data outside South Africa. We rely on these providers under terms that require them to protect the information and use it only to deliver the service, consistent with POPIA's rules on operators and cross-border transfers.
The controls above are built on principles shared across modern data-protection and anti-spam law, so the same product behaviour supports compliance beyond South Africa:
Where a customer operates under a specific regime, they should confirm their own obligations; we provide the mechanisms (identity, consent records, opt-out, suppression, security, deletion) that make meeting them practical.
We will keep this page current as the product and the law evolve. If we make a material change, we will update the effective date above.