← Back to Home

GDPR Compliance

Last updated: 8/12/2026

1. Our Commitment

SoLEAD is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy of individuals in the European Union (EU) and European Economic Area (EEA). This page summarizes our approach to GDPR compliance. For full details, see our Privacy Policy.

2. Legal Basis for Processing

We process personal data only when we have a valid legal basis, including:

  • Contract: Processing necessary to provide the Service you requested
  • Legitimate interests: Improving the Service, security, fraud prevention
  • Consent: Where you have given clear consent (e.g., marketing communications)
  • Legal obligation: Compliance with applicable laws

3. Your Rights Under GDPR

If you are in the EU/EEA, you have the following rights:

  • Right of access: Request a copy of your personal data
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure: Request deletion of your data ("right to be forgotten")
  • Right to restrict processing: Request limitation of processing in certain circumstances
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent
  • Right to lodge a complaint: File a complaint with a supervisory authority in your country

To exercise these rights, contact us at info@solead.ai. We will respond within 30 days.

4. Data Protection Officer

For privacy-related inquiries, including GDPR requests, you may contact our data protection contact at info@solead.ai.

5. International Transfers

Your data may be transferred to and processed in countries outside the EU/EEA. When we do so, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where the recipient country is recognized as providing adequate protection
  • Other mechanisms permitted under GDPR

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in our Privacy Policy, or as required by law. When data is no longer needed, we securely delete or anonymize it.

7. Security Measures

We implement technical and organizational measures to protect personal data, including encryption, access controls, regular security assessments, and staff training. In the event of a data breach affecting your data, we will notify the relevant supervisory authority and, where required, affected individuals.

8. Processor Obligations

Where we act as a processor on behalf of our customers (e.g., when processing contact data in campaigns), we enter into Data Processing Agreements (DPAs) that comply with GDPR Article 28 and process personal data only according to our customers' documented instructions.

9. Contact

For GDPR-related questions or to exercise your rights, contact us at info@solead.ai.