Legal
Privacy Policy
Last updated: August 27, 2026
Nead, LLC ("SalesDeveloper," "we," "our," or "us") operates the SalesDeveloper.ai platform and this website. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and what rights you have over your data.
1. Who We Are
Nead, LLC is a Delaware limited liability company and the data controller responsible for personal data processed through the SalesDeveloper.ai platform and website (collectively, the "Service"). Our principal place of business is in the United States. Where this Policy refers to personal data processed on behalf of our customers (particularly prospect contact data), SalesDeveloper acts as a data processor and the customer is the data controller, as described in Section 6.
Questions, concerns, and formal data subject requests can be directed to our privacy team at [email protected].
2. Scope of This Policy
This Privacy Policy applies to:
- Visitors to the SalesDeveloper.ai website and any subdomains we operate (collectively, the "Site").
- Registered users of the SalesDeveloper.ai platform, including administrators, team members, and any personnel with access to a subscribed account (collectively, "Users").
- Individuals whose contact information is processed by the Service as part of a User's outbound prospecting campaigns ("Prospects").
This Policy does not apply to the data practices of third-party services, CRM platforms, or applications that Users connect to SalesDeveloper via our integrations. Those services have their own privacy policies, and we encourage you to review them.
3. Data We Collect
We collect different categories of personal data depending on your relationship with SalesDeveloper.
3.1 Account and Registration Data
When you create an account, we collect your name, business email address, company name, job title, and the password you create (stored as a salted cryptographic hash — we never store plaintext passwords). If you register via a supported Single Sign-On provider (e.g., Google Workspace), we receive your name and email from that provider.
3.2 Billing and Payment Data
We use Stripe, Inc. ("Stripe") as our payment processor. When you subscribe to a paid plan, Stripe collects your payment card details directly. SalesDeveloper receives only a tokenized reference to your payment method, the last four digits of your card, the card brand, and your billing address for invoicing purposes. We never store raw card numbers, CVV codes, or full card data on our servers. Stripe's privacy practices are governed by the Stripe Privacy Policy.
3.3 Ideal Customer Profile (ICP) Configuration Data
When you configure the AI SDR agent, you provide details describing your target customer — including industry verticals, company size ranges, job titles, geographies, technology stacks, and other firmographic or technographic criteria. This ICP configuration is treated as confidential customer data and is used exclusively to direct the AI agent's prospecting activity on your behalf.
3.4 Prospect Contact Data
As part of using the Service, the AI SDR agent identifies and processes contact information for third-party business professionals ("Prospects") who match your ICP. This data includes business email addresses, first and last names, job titles, company names, LinkedIn profile URLs, and professional signals derived from publicly available sources or licensed data providers. See Section 6 for a detailed description of how Prospect data is handled.
3.5 Usage and Platform Data
We collect data about how you interact with the Service, including: pages visited, features accessed, campaign configurations created or modified, sequences triggered or paused, reply events handled, meetings booked through the agent, filters applied in the prospect discovery interface, CRM sync events, and API calls made if you use our developer API. This usage data is used to provide the Service, generate your analytics dashboard, and improve the platform.
3.6 Device and Technical Data
When you visit the Site or use the platform, our servers and analytics tools automatically collect: IP address, browser type and version, operating system, referring URL, pages viewed and time spent, and approximate geographic location derived from IP address (country and region-level only). This data is used for security monitoring, fraud prevention, debugging, and aggregate analytics.
3.7 Communications Data
When you contact us by email, submit a form on the Site, or communicate with our support team, we retain the contents of those communications and your contact details in order to respond to you and, where applicable, to maintain a record of our support interactions.
3.8 LinkedIn Data
Where our platform connects to LinkedIn (e.g., through our LinkedIn automation module), we process data obtained via LinkedIn's APIs in accordance with LinkedIn's Platform Terms. This may include public profile information of Prospects (name, title, employer, and publicly listed contact details) and connection status with Users who have linked their LinkedIn accounts. We do not scrape LinkedIn in violation of their terms, and Users are responsible for ensuring their use of the LinkedIn automation feature complies with LinkedIn's User Agreement.
4. How We Collect Data
We collect data through the following means:
- Directly from you: Registration forms, onboarding questionnaires, ICP configuration interfaces, support ticket submissions, demo request forms, and contact form submissions on the Site.
- Automatically through technology: Browser cookies, server log files, analytics tags (see Section 9), and session recording tools used in aggregate to understand platform usage patterns.
- From third-party data providers:Licensed B2B contact databases and intent signal providers that supply verified business contact information used to populate prospect discovery results in accordance with those providers' licensing terms.
- From integrated third-party services: When you connect a CRM, calendar, or email service, we receive data from those services as authorized by the OAuth scopes you approve during integration setup.
- From LinkedIn:Via LinkedIn's official API integrations, where authorized by you and compliant with LinkedIn's Platform Terms.
5. Why We Process Data
We process personal data under the following legal bases (applicable where GDPR or equivalent frameworks apply):
5.1 Performance of a Contract (GDPR Art. 6(1)(b))
We process your account data, ICP configuration, and usage data because it is necessary to deliver the Service you have contracted for. This includes operating the AI SDR agent, generating your analytics dashboard, syncing data to your CRM, processing your subscription payments through Stripe, and providing customer support.
5.2 Legitimate Interests (GDPR Art. 6(1)(f))
We process certain data where we have a legitimate interest that is not overridden by your fundamental rights and freedoms. These legitimate interests include:
- Preventing fraud, abuse, and unauthorized access to the Service.
- Maintaining the security and integrity of our systems.
- Improving the platform through aggregate, anonymized analysis of usage patterns.
- Communicating with Users about product updates, new features, maintenance windows, and security notices relevant to their accounts.
- Enforcing our Terms of Service and Acceptable Use Policy.
5.3 Compliance with Legal Obligations (GDPR Art. 6(1)(c))
We process and retain certain data where required to do so by applicable law, including financial recordkeeping obligations under US tax law, compliance with valid law enforcement requests, and compliance with applicable data protection regulations.
5.4 Consent (GDPR Art. 6(1)(a))
Where we rely on consent — for example, for non-essential cookies or for sending you marketing communications about our products — we will obtain your consent before processing. You may withdraw consent at any time by adjusting your communication preferences in your account settings or by using our cookie preference manager, without affecting the lawfulness of processing that occurred before withdrawal.
5.5 Purposes Summary
Specifically, we use your data to:
- Create and manage your account and authenticate your identity.
- Operate the AI SDR agent and execute outbound campaigns on your behalf.
- Process subscription payments and maintain billing records.
- Sync campaign activity to your connected CRM systems.
- Generate analytics, performance dashboards, and A/B test results.
- Send transactional emails (receipts, alerts, meeting confirmations).
- Send product update communications, where you have not opted out.
- Respond to support inquiries and resolve technical issues.
- Detect and prevent fraudulent or abusive use of the Service.
- Monitor and improve the reliability, performance, and security of the platform.
- Comply with legal obligations, respond to lawful government requests, and exercise or defend legal claims.
6. Prospect Contact Data
This section addresses the personal data of third-party Prospects that is processed by the Service as part of your outbound campaigns. Understanding this distinction is important.
6.1 Controller vs. Processor
With respect to Prospect data, you (the User) are the data controller, and SalesDeveloper is the data processor. This means you determine the purposes and means of processing (i.e., who to contact and why), and SalesDeveloper carries out that processing on your instructions. SalesDeveloper does not sell or transfer Prospect data to other customers or third parties for their own purposes.
6.2 Your Responsibilities
As the data controller for Prospect data, you are responsible for:
- Ensuring you have a lawful basis under applicable data protection law (e.g., legitimate interests under GDPR, or compliance with CAN-SPAM, CASL, or equivalent laws) for conducting outbound email and LinkedIn outreach to each Prospect.
- Honoring opt-out and unsubscribe requests promptly. SalesDeveloper maintains a suppression list system that automatically prevents further contact to opted-out Prospects; you may not override or circumvent this system.
- Responding to data subject rights requests made by Prospects in relation to your outreach campaigns (e.g., requests to access, correct, or erase their data from your own systems).
- Complying with applicable anti-spam, commercial email, and data protection laws in all jurisdictions you target.
6.3 What SalesDeveloper Does with Prospect Data
SalesDeveloper processes Prospect data only as necessary to operate the Service on your behalf: discovering Prospects matching your ICP, generating personalized outreach messages, executing email and LinkedIn sequences, handling replies, booking meetings, and logging activity to your CRM. We do not use Prospect data to train AI models shared across customers, and we do not sell or broker Prospect data.
6.4 Data Handling Agreement
Where required by applicable law (e.g., for Users processing personal data of EU data subjects), SalesDeveloper offers a Data Processing Agreement (DPA) that governs the processing of Prospect data. Contact [email protected] to request a DPA.
7. How We Share Data
We do not sell your personal data. We do not share personal data with third parties for their own marketing purposes. We share data only in the following circumstances:
- With authorized service providers (processors): We engage third-party companies who process data on our behalf to operate the Service. These are listed in Section 8.
- CRM and calendar integrations you authorize: When you connect a CRM (e.g., Salesforce, HubSpot, Pipedrive) or calendar (e.g., Google Calendar) through our integration settings, we sync relevant campaign and meeting data to that service as you have directed.
- Business transfers: In the event of a merger, acquisition, reorganization, or sale of substantially all of our assets, your data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Site at least 30 days before any such transfer becomes effective and before your data becomes subject to a materially different privacy policy.
- Legal requirements: We may disclose data if required to do so by a valid subpoena, court order, or government agency request; to comply with applicable law; or to protect the rights, property, or safety of SalesDeveloper, our Users, or the public. Where permissible, we will notify the affected User before complying with any such compelled disclosure.
- With your consent: We may share data in other circumstances where you have given explicit consent for us to do so.
8. Third-Party Processors
We engage the following categories of sub-processors to help operate the Service. All sub-processors are contractually bound to process data only on our instructions and to implement appropriate technical and organizational security measures.
- Stripe, Inc. — Payment processing and subscription management. Data processed: billing information, payment method tokens, invoices. Stripe is PCI DSS Level 1 certified.
- SendGrid (Twilio Inc.) — Transactional email delivery for platform notifications, receipts, and system alerts. Data processed: recipient email addresses, email content, delivery metadata.
- Vercel Inc. — Hosting and content delivery for the SalesDeveloper.ai website and application infrastructure. Data processed: request logs, IP addresses, page content.
- Analytics providers — We use privacy-respecting web analytics to understand aggregate usage patterns on the Site. Where applicable, these tools are configured to anonymize IP addresses and process only aggregate data without identifying individual visitors.
- Cloud infrastructure providers — Our platform runs on cloud infrastructure in the United States. Infrastructure providers may have incidental access to data stored on their systems as part of operating that infrastructure, subject to their own data processing terms and our contractual requirements.
- LinkedIn Corporation— Where you use our LinkedIn automation features, data is exchanged with LinkedIn via their official API under LinkedIn's Platform Terms.
- B2B data providers — Licensed third-party databases that supply verified business contact data used in our prospect discovery engine. All providers are contractually required to warrant that they have lawfully obtained the data they license to us.
We maintain an up-to-date list of active sub-processors. Customers may request the current sub-processor list by emailing [email protected].
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on the Site and platform. You can manage your cookie preferences through our cookie consent banner, which appears on your first visit, and through your browser settings.
9.1 Types of Cookies We Use
Strictly Necessary Cookies: These cookies are required for the Site and platform to function. They include session management cookies that keep you logged in, CSRF protection tokens, and load balancing cookies. These cookies cannot be disabled without breaking core functionality.
Analytics Cookies: We use analytics cookies to understand aggregate traffic patterns, the most visited pages, and how Users navigate the platform. This helps us identify where the experience can be improved. Analytics cookies may be set by our analytics provider or by us directly. IP addresses are anonymized before storage.
Preference Cookies: These cookies remember your settings choices, such as your selected theme (light or dark mode) and notification preferences, so you do not have to reconfigure them on each visit.
Marketing Cookies:We do not currently serve personalized advertising on our own Site. Where we use third-party advertising or remarketing on external platforms (e.g., LinkedIn Ads), we rely on those platforms' own cookie and pixel mechanisms, subject to your opt-out choices on those platforms.
9.2 Managing Cookies
You may refuse non-essential cookies at any time via our cookie preference center, accessible from the banner on your first visit or via the "Cookie Settings" link in the footer. You may also configure your browser to block all cookies; however, doing so may impair the functionality of the platform. Note that cookie opt-outs are stored as cookies themselves, so clearing your browser cookies may reset your preferences.
10. Data Retention
We retain personal data for as long as necessary to fulfill the purposes described in this Policy, subject to the following guidelines:
- Active account data: Retained for the duration of your subscription and for 90 days following account termination or cancellation. During this 90-day window, you may export your data or request deletion.
- Campaign and analytics data: Retained for the duration of the subscription plus 90 days. Aggregate, de-identified analytics (which do not constitute personal data) may be retained indefinitely for product improvement purposes.
- Billing records: Retained for seven (7) years from the date of the transaction, as required by US federal and state tax laws.
- Support communications: Retained for two (2) years from the date of the last communication in a thread, after which they are deleted or anonymized.
- Prospect contact data: Processed for the duration of the campaign and retained in your account data for 90 days after account termination, consistent with active account data above. Suppression list entries (opted-out Prospects) are retained indefinitely to prevent further contact.
- Server logs: Retained for 90 days for security monitoring and debugging, then automatically purged.
Upon expiration of retention periods, data is either securely deleted or anonymized such that it can no longer be attributed to an identifiable individual.
11. Security
We implement technical, organizational, and administrative safeguards designed to protect your data against unauthorized access, disclosure, alteration, and destruction. Our security measures include:
- Encryption at rest: All customer data stored in our databases is encrypted using AES-256 encryption.
- Encryption in transit: All communications between your browser and our servers are protected using TLS 1.2 or TLS 1.3. We enforce HTTPS-only access and use HSTS headers.
- Access controls: Access to production systems and customer data is restricted to authorized personnel on a need-to-know basis, enforced through role-based access control (RBAC) and multi-factor authentication (MFA) requirements for all internal accounts with production access.
- Vulnerability management: We conduct periodic penetration tests and vulnerability assessments. Critical vulnerabilities are remediated on an expedited schedule.
- Incident response: We maintain a written incident response plan and will notify affected Users and, where required by law, applicable supervisory authorities, in the event of a personal data breach, within the timeframes required by applicable law (72 hours under GDPR Article 33, where applicable).
- SOC 2 Type I: We are currently pursuing SOC 2 Type I certification. Progress on this certification can be confirmed by contacting [email protected].
While we implement these measures, no system is entirely immune to attack. We encourage you to use a strong, unique password, enable multi-factor authentication on your account, and report any suspected security incidents to [email protected] immediately.
12. International Data Transfers
SalesDeveloper is based in the United States. If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with data transfer restrictions, your personal data will be transferred to and processed in the United States.
We rely on the following transfer mechanisms to ensure that such transfers comply with applicable data protection law:
- EU-US Data Privacy Framework (DPF): Where we or our sub-processors participate in the EU-US DPF (and UK Extension to the DPF), this provides a valid transfer mechanism for EEA and UK personal data.
- Standard Contractual Clauses (SCCs):Where DPF participation does not apply, we use the European Commission's approved Standard Contractual Clauses as the lawful transfer mechanism. Customers requiring SCCs or a Data Processing Agreement may request them from [email protected].
13. Your Privacy Rights
Depending on where you are located, you may have the following rights with respect to your personal data:
13.1 Rights Under GDPR and UK GDPR
If you are located in the EEA or the United Kingdom, you have the following rights under Regulation (EU) 2016/679 (GDPR) or the UK GDPR:
- Right of Access (Art. 15): You have the right to obtain confirmation of whether we process personal data about you, and to receive a copy of that data together with information about how it is processed.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate personal data and completion of incomplete data.
- Right to Erasure / "Right to Be Forgotten" (Art. 17): You have the right to request deletion of your personal data where: (a) the data is no longer necessary for the purposes for which it was collected; (b) you withdraw consent on which processing was based; (c) you object to processing based on legitimate interests and there are no overriding legitimate grounds; (d) the data has been unlawfully processed; or (e) deletion is required to comply with a legal obligation. We will fulfill erasure requests within 30 days, subject to any legal retention obligations that require us to retain certain data (e.g., billing records under tax law).
- Right to Restriction of Processing (Art. 18): You may request that we restrict processing of your data in certain circumstances, such as while the accuracy of data is being contested.
- Right to Data Portability (Art. 20): You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have that data transmitted to another controller where technically feasible. From your account dashboard, you can export your account data, ICP configurations, and campaign history at any time.
- Right to Object (Art. 21): You have the right to object to processing based on legitimate interests at any time. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.
- Rights Related to Automated Decision-Making (Art. 22): The Service does not make decisions with legal or similarly significant effects based solely on automated processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your applicable supervisory authority if you believe we have processed your personal data in violation of applicable law. In the EEA, this is typically the data protection authority in the EU Member State of your habitual residence.
13.2 Exercising Your Rights
To exercise any of the above rights, please submit a written request to [email protected]. We will respond to verifiable requests within 30 days. We may ask you to verify your identity before processing the request. There is no fee for reasonable requests; however, we may charge a reasonable administrative fee for manifestly unfounded, excessive, or repetitive requests.
14. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (together, "CCPA") provides you with specific rights regarding your personal information.
14.1 Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information (as defined by the CCPA) from California residents who are Users of the Service: identifiers (name, email address, company name); commercial information (subscription history, billing records); internet or other electronic network activity information (usage logs, page views, feature interactions); and geolocation data (approximate location derived from IP address, country/region level only).
14.2 No Sale of Personal Information
SalesDeveloper does not sell personal information, as "sell" is defined under the CCPA. We do not exchange personal information with third parties for monetary or other valuable consideration for their own use.
14.3 No Sharing for Cross-Context Behavioral Advertising
SalesDeveloper does not share personal information for cross-context behavioral advertising purposes, as defined under the CPRA.
14.4 Your CCPA Rights
California residents have the right to: (a) know what personal information is collected about them; (b) delete personal information subject to certain exceptions; (c) correct inaccurate personal information; (d) opt out of sale or sharing (not applicable here, as we do not sell or share); (e) non-discrimination for exercising their rights. To exercise these rights, contact [email protected]. We will respond within 45 days of receiving a verifiable consumer request.
15. Children
The Service is designed for and directed exclusively to businesses and business professionals. We do not knowingly collect personal data from individuals under the age of 16. If you become aware that a child under 16 has provided us with personal data, please notify us immediately at [email protected] and we will take steps to delete the relevant information. The Site is not directed at children, and we do not have actual knowledge that we have collected personal information from any child under 16.
16. Third-Party Links and Services
The Site may contain links to third-party websites, and the platform supports integrations with third-party services such as CRMs, calendar applications, and LinkedIn. This Privacy Policy does not cover the data practices of those third parties. We encourage you to review the privacy policies of any third-party service before connecting it to SalesDeveloper or providing personal data to it.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, new legal requirements, or improvements to our transparency. When we make material changes, we will:
- Post the updated Policy on this page with a new "Last updated" date.
- Send registered Users an email notification at the address associated with their account at least 30 days before material changes take effect (or as required by applicable law, whichever is longer).
- Display a prominent banner on the platform notifying Users of the pending change.
Your continued use of the Service after the effective date of the revised Policy constitutes your acknowledgment of the update. If you disagree with the changes, you may terminate your account before the effective date.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: [email protected]
- Legal entity: Nead, LLC
- Website: https://salesdeveloper.ai
We aim to respond to all privacy inquiries within 10 business days. For formal GDPR or CCPA rights requests, please include "Data Subject Request" in your subject line to ensure timely routing to our privacy team.