Legal · Last updated 10 August 2026
Privacy Policy
How OpenLeadGraph collects, uses, stores and protects personal data — for website visitors, platform users and candidate data processed on behalf of client agencies.
1. Who we are
OpenLeadGraph is a private lead generation and recruitment platform for staffing agencies, provided as a hosted, monthly-rented service. The platform is operated and hosted by DK Engineering Lab (https://www.dkenglab.com) on DK Engineering Lab server infrastructure.
For the purposes of the EU General Data Protection Regulation (GDPR) and applicable data-protection laws, the operator of this website and the provider of the platform acts as: (a) the data controller for data collected through this website and for account and billing data of client users; and (b) the data processor for candidate, client-contact and vacancy data that client agencies store in the platform, which is governed by our Data Processing Agreement.
You can reach us at any time at hello@openleadgraph.com.
2. Scope of this policy
This policy covers three categories of data subjects:
- Website visitors — people browsing openleadgraph.com or contacting us about the platform.
- Platform users — employees of client agencies who receive accounts in a configured workspace (owners, recruiters, sales staff, administrators).
- Candidates and business contacts — individuals whose professional data is stored in a client's workspace by that client, or appears in publicly available job-market sources aggregated by the platform.
3. Data we collect
Depending on how you interact with us, we process:
- Contact and request data — name, company, work email and the content of messages you send us through forms or email.
- Account data — name, work email, role and access permissions of each user in a client workspace.
- Usage and technical data — log records, IP addresses, browser type, timestamps and feature-usage events required for security, debugging and product improvement.
- Client content — data that client agencies upload or create in their workspace: candidate profiles, CVs, client contacts, vacancies, notes, housing records, invoices and payment tracking information.
- Publicly sourced market data — job postings and company information collected from public job platforms for lead-discovery purposes.
We do not intentionally collect special categories of personal data (health, biometric, racial or political data). If a client places such data into their workspace, the client is responsible for the lawfulness of doing so.
4. Legal bases for processing (GDPR)
We rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — providing the platform, onboarding, support and billing to client agencies.
- Legitimate interest (Art. 6(1)(f)) — securing the service, preventing abuse, improving the product and responding to business inquiries.
- Consent (Art. 6(1)(a)) — where we explicitly ask for it, for example for optional marketing communication; consent can be withdrawn at any time.
- Legal obligation (Art. 6(1)(c)) — accounting, tax and record-keeping duties.
5. How we use data
- To configure, host and operate each client's private workspace.
- To provide lead discovery, CRM, AI matching, housing and finance modules the client has enabled.
- To communicate with you: demo scheduling, onboarding, support and service notices.
- To secure the platform: authentication, access control, abuse prevention and audit logging.
- To invoice, account and comply with tax obligations.
- To improve the product using aggregated, non-identifying usage patterns.
We do not sell personal data, do not share it with advertisers, and do not use client workspace content to train models for other clients.
6. Lead data from public sources
The lead-discovery module aggregates job postings and related company information that businesses have made publicly available on job platforms. This data concerns business entities and their hiring needs, not private individuals.
Where candidate data appears in a workspace, it is placed there by the client agency or comes from sources the client has connected. The client agency is the data controller for that data and is responsible for having a lawful basis and for informing data subjects as required by GDPR.
7. Hosting, storage and tenant isolation
All platform infrastructure runs on servers operated by DK Engineering Lab. Each client receives an isolated workspace: data is logically separated per tenant, and no client can access another client's data.
Data is stored on DK Engineering Lab infrastructure with encrypted connections (TLS) for all traffic, encryption of stored data, daily backups and 24/7 infrastructure monitoring. Workspace access is governed by per-user roles configured for each client.
9. International transfers
Data is primarily stored and processed on DK Engineering Lab infrastructure. If processing ever involves a transfer outside the European Economic Area, it will be covered by an adequacy decision or Standard Contractual Clauses, and clients will be informed in advance through an update of our Data Processing Agreement.
10. Retention
- Website inquiries — kept for up to 24 months after the last contact, then deleted.
- Client workspace data — kept for the duration of the subscription. After termination, data is available for export for 30 days, then permanently deleted from production systems and from backups within the backup rotation cycle.
- Account and billing records — kept for the period required by applicable accounting and tax law.
- Security and audit logs — kept for up to 12 months.
11. Security measures
We apply technical and organizational measures appropriate to the risk, including:
- Multi-tenant architecture with strict per-client data isolation.
- Encryption in transit (TLS) for all connections and encryption of stored data.
- Role-based access control inside each workspace; least-privilege access for our staff.
- Daily backups with tested restore procedures.
- 24/7 infrastructure monitoring and alerting on DK Engineering Lab servers.
- Access and audit logging of administrative actions.
- Confidentiality obligations for everyone with access to production systems.
12. Your rights
Under GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability and the right to withdraw consent at any time. You also have the right to lodge a complaint with your national data-protection authority.
To exercise any right, email hello@openleadgraph.com. For data stored in a client's workspace (candidate or contact data), please contact the relevant agency first — as the controller they instruct us, and we assist them in fulfilling your request.
14. Changes to this policy
If we change this policy, the updated version will be published on this page with a new revision date. Material changes affecting client data will additionally be communicated to client administrators by email before taking effect.
15. Contact
OpenLeadGraph — operated and hosted by DK Engineering Lab (https://www.dkenglab.com). Privacy questions, requests and complaints: hello@openleadgraph.com.