1. Who we are and scope
Leads8x is a done-for-you B2B outbound service operated by FP GLOBAL PTE. LTD., a company registered in Singapore.
- Legal entity
- FP GLOBAL PTE. LTD.
- Trading name
- Leads8x
- Singapore UEN
- 201908912M
- Registered office
- 79 Anson Road, #21-23, Singapore 079906
- Contact
- hello@leads8x.com
Our data protection contact can be reached at hello@leads8x.com. Privacy enquiries and rights requests sent to that address are routed to the people responsible for data protection at FP Global.
This notice covers:
- this website, including enquiry forms, calls and meeting bookings;
- our relationships with prospective clients, existing clients and suppliers;
- sourcing, enrichment and verification of business-contact data for campaigns;
- campaign delivery by email, and LinkedIn outreach where that channel is used;
- campaign replies, meeting bookings and handing results over to a client's CRM.
2. Our roles
Our role depends on the activity. We are not always only a controller, and not always only a processor.
- Controller. For our own website, enquiries, client and supplier relationships, security, vendor management, suppression and objection records, and general business operations, FP Global decides why and how personal data is used.
- Processor. For client campaigns, the client generally determines the product or service being sold, the purpose of the campaign, the ideal customer profile and the target markets. Where we follow a client’s documented instructions, we act as a processor on that client’s behalf.
- Independent controller. For processing where we determine our own purposes or the essential means, including maintaining suppression records, and certain sourcing, data quality, security and compliance activities, we act as an independent controller.
Where a client Data Processing Agreement applies, that agreement governs the client-instructed processing.
3. Categories of data
Depending on the context, we may process:
- name, employer, business email address and business phone number where that channel is used;
- job title, seniority and department;
- LinkedIn or other public professional profile URL;
- country or region;
- company details such as domain, industry, size and technology in use;
- professional and company signals such as hiring activity, role changes, funding, growth, technology changes and engagement or intent indicators;
- verification status of a contact record;
- campaign messages, replies, meeting status and CRM notes;
- website enquiry and booking details, and other communications with us;
- device, IP and security-related data where our website or systems actually generate it.
We do not intentionally seek sensitive or special-category personal data, or data about children, for ordinary B2B campaigns. Clients should not provide such data to us.
4. Where data comes from
- directly from you, for example when you email us, complete a form or book a call;
- from our clients and their CRM systems;
- from public company websites;
- from publicly available professional sources, including LinkedIn profiles;
- from licensed and vetted B2B data and enrichment providers.
Providers currently used include Clay, AI Ark, BetterContact, BetterEnrich and Signaliz, alongside other vetted providers selected for a particular campaign. Clay may orchestrate or combine data from several underlying providers, so Clay is not necessarily the original source of a given record.
Using a publicly accessible source does not remove privacy obligations. We still treat that data as personal data and apply this notice to it. Nothing here implies that LinkedIn endorses, partners with or is affiliated with Leads8x.
5. Purposes and lawful bases
Where the law requires a lawful basis, we rely on the bases below, as applicable in the relevant jurisdiction.
| Purpose | Lawful basis (as applicable) |
|---|---|
| Responding to enquiries and arranging calls | Steps prior to entering a contract; legitimate interests |
| Client service delivery and campaign operation | Contract; client instructions; legitimate interests |
| Relevant B2B prospecting and outreach | Legitimate interests, or another lawful basis where one is required |
| Data enrichment, verification and quality control | Legitimate interests; client instructions |
| Suppression and opt-out records | Legal obligations; legitimate interests in respecting objections |
| Security, fraud detection and prevention | Legitimate interests; legal obligation |
| Accounting, record-keeping and legal claims | Legal obligation; legitimate interests |
| Non-essential cookies or analytics, only if enabled | Consent |
Legitimate interests are assessed rather than assumed: we weigh the business relevance of the contact against the individual’s rights and expectations, and we only send communications where the applicable electronic marketing laws permit them.
6. AI-assisted processing
We use AI-assisted tooling to support research, identify company and role signals, verify and prioritise records, draft message variants and run quality checks. Campaign targeting and messaging are reviewed by people before they go out, and a person remains accountable for what is sent.
We do not intend to make decisions about individuals that produce legal or similarly significant effects solely by automated means.
Some of this tooling is provided by third parties, which means limited business-contact data may be processed by those providers under contract for the purposes described in this notice.
7. Who we share data with
- the client whose product or service is represented in a campaign;
- service providers for enrichment, email sequencing and delivery, CRM, cloud and hosting, scheduling, security and collaboration;
- professional advisers, and regulators or authorities where we are legally required to disclose.
We do not sell personal data for money. Business-contact data is, however, disclosed to the relevant client as necessary to deliver a contracted campaign, and some laws define “sale” or “sharing” broadly enough to capture disclosures of this kind. If you would rather we did not process or disclose your details, contact us and we will act on your objection.
We do not reuse one client’s confidential campaign data for another client.
8. Service providers we use
| Provider | Role |
|---|---|
| Clay | Data orchestration and enrichment |
| AI Ark | B2B company and contact intelligence and enrichment |
| BetterContact | Business contact enrichment and verification |
| BetterEnrich | Business contact enrichment and verification |
| Signaliz | Go-to-market data governance and routing |
| Instantly | Campaign sequencing and email delivery |
| Calendly | Meeting scheduling |
| Public professional source and outreach channel where used |
Other providers may be used depending on a client’s systems and target market. This list is updated when there is a material change. These providers are suppliers to us; naming them does not indicate a partnership, endorsement or affiliation.
9. International transfers
We are based in Singapore and work with clients and vendors globally, so personal data may be processed in countries other than your own. Where legally required, we put contractual and organisational safeguards in place, which may include EU Standard Contractual Clauses, the UK IDTA or Addendum, transfer risk assessments, and the comparable-protection requirements under Singapore’s PDPA. We cannot guarantee that all data stays within a single region.
10. Retention
We keep personal data only as long as we reasonably need it. The periods below are normal practice and may vary with client instructions, contracts and legal requirements.
| Data | Normal retention |
|---|---|
| Website enquiries and unconverted sales contacts | Up to 24 months from the last meaningful interaction |
| Active client and project records | The engagement plus a reasonable transition or deletion period, normally up to 90 days after completion, unless the client instructs otherwise or law or contract requires longer |
| Campaign prospect data and correspondence | For the campaign, and normally up to 12 months after last activity, subject to client instructions and applicable law |
| Suppression and objection records | The minimum identifying data, kept as long as reasonably necessary to prevent re-contact and demonstrate compliance; reviewed periodically |
| Security and technical logs | Normally up to 12 months |
| Contracts, invoices and legal records | The statutory retention or legal claims period |
| Backups | Removed through normal secure backup rotation |
When data is no longer needed, we delete it or anonymise it so it can no longer be linked to you.
11. Your rights
Depending on where you live, you may have the right to access your data, ask for it to be corrected or deleted, ask us to restrict processing, object to processing, withdraw consent where we rely on it, request portability where applicable, and complain to your local data protection authority.
You can always object to direct marketing.
This right is absolute. Tell us and we will stop, no reason needed. Email hello@leads8x.com.
Send requests to hello@leads8x.com. We may ask for proportionate information to verify your identity before we act, and we will not ask for more than we need. Rights and time limits vary by jurisdiction, so the exact outcome depends on the law that applies to you.
12. Outreach transparency and opt-out
- our first communication should identify the client or business being represented, explain why we believe the message is relevant to your role, link to this notice and include a free and easy opt-out where one is required;
- you can reply "no" or "unsubscribe" to any message, or email hello@leads8x.com;
- objections are added to a suppression record and honoured across campaigns wherever reasonably possible;
- where prospect data is sourced indirectly rather than from you, we provide privacy information within the timelines that apply under the relevant law.
13. Security, cookies, breaches, updates and complaints
Security. We apply reasonable technical and organisational controls, including access restrictions, vendor review and secure handling of campaign data. No system is perfectly secure, and we do not claim certifications we do not hold.
Cookies and tracking. This website does not currently run advertising trackers, and we do not use open-tracking pixels in client email campaigns because they harm deliverability. Essential technical operation and hosting may still generate logs. If we introduce non-essential analytics or cookies in future, we will disclose them here and obtain consent where required.
Breaches. If we become aware of a personal data breach we assess it and notify affected people, clients and regulators where the law requires.
Updates. We may update this notice. Material changes will be reflected in the effective date at the top of the page.
Complaints. Please contact us first so we can put things right. You can also complain to Singapore’s Personal Data Protection Commission (PDPC) or to another competent supervisory authority in your country.