Privacy Policy — B2B-Leads.biz
B2B-Leads.biz Omnexis Group LLC

Omnexis Group LLC · b2b-leads.biz

Privacy Policy

Effective date: 1 September 2026 Version: 1.0 Controller: Omnexis Group LLC (GDPR Art. 3(2))

§ 01

Scope of this Policy

This Privacy Policy explains how Omnexis Group LLC („Company”, „we”, „us”) processes personal data in connection with the website https://b2b-leads.biz („Website”) and the business data compilation services offered through it („Services”).

The Policy covers two distinct groups of people, and the rules differ for each:

  • Website visitors and Clients — people who browse the Website, submit a brief, or place an order. Their data is covered in §4.
  • Business contacts — people whose publicly published business contact details are collected into the datasets we compile for Clients. Their data is covered in §5 to §8 and §13.

If you have received a message from a company that obtained your business contact details from us, §5, §12, and §13 are the sections that concern you. You can have your details permanently suppressed at any time by writing to privacy@b2b-leads.biz.

This Policy should be read together with our Terms of Service and Cookie Policy.

§ 02

Controller & Contact

The controller of your personal data within the meaning of Article 4(7) GDPR is:

Omnexis Group LLC 5830 E 2nd St, Ste 7000 21135
Casper, Wyoming 82609
United States

EIN: 38-4340931

Data protection enquiries: privacy@b2b-leads.biz
General enquiries: office@b2b-leads.biz
Website: https://b2b-leads.biz

The Company is established outside the European Union. The GDPR nevertheless applies to our processing pursuant to Article 3(2) GDPR, because we offer services to data subjects in the Union and monitor publicly available business information relating to the Union market. We accept the obligations of a controller under the Regulation in respect of that processing.

Representative in the Union (Article 27 GDPR): [NAME AND FULL POSTAL ADDRESS OF EU REPRESENTATIVE] — [REPRESENTATIVE EMAIL]. Data subjects in the Union may address the representative on all issues related to processing, in addition to or instead of contacting us directly.

The Company has not appointed a data protection officer, as the criteria in Article 37(1) GDPR are not met. Data protection enquiries are handled by the address given above.

§ 03

Definitions

  • GDPR — Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.
  • Personal data — any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
  • Processing — any operation performed on personal data, as defined in Article 4(2) GDPR.
  • Client — a business that commissions a dataset from us.
  • Record — a single dataset entry relating to one identified business.
  • Dataset — the complete set of Records delivered to a Client in fulfilment of an order.
  • Public Sources — sources accessible to any member of the public without authentication or circumvention of technical protection measures, in particular business listings, official registers, and the websites of the businesses concerned.
  • Objection Register — our permanent suppression list of contact details that must not be included in any future Dataset, described in §13.

§ 04

Website Visitors & Clients

What we collect

  • Enquiry and brief data — name, email address, company name, and the content of your message, including the industry, area, volume, and channel you specify.
  • Order and billing data — company details, billing address, tax identifiers, payment references, invoice records, and correspondence relating to the order.
  • Technical data — IP address, browser type and version, operating system, referring page, pages viewed, and timestamps, recorded in server logs.
  • Cookie data — as described in §16 and in the Cookie Policy.

Providing enquiry data is voluntary, but without an email address we cannot respond to a brief or deliver a dataset. Billing data is required to issue a valid invoice.

Why we process it, and on what basis

PurposeLegal basisRetention
Responding to a brief, preparing an estimate and sampleArt. 6(1)(b) — steps prior to entering a contract12 months from last contact if no order follows
Performing an order and delivering a datasetArt. 6(1)(b) — performance of a contract5 years from completion of the order
Invoicing, accounting, tax recordsArt. 6(1)(c) — legal obligationAs required by applicable tax law, generally 5 years
Handling complaints and quality claimsArt. 6(1)(b) and 6(1)(f) — contract performance and defence of claimsUntil claims are time-barred
Website security, abuse prevention, server logsArt. 6(1)(f) — legitimate interest in securing our systems12 months
Analytics and improving the WebsiteArt. 6(1)(a) — consent, given through the cookie bannerPer the Cookie Policy; withdrawable at any time
Direct marketing to existing Clients about our own servicesArt. 6(1)(f) — legitimate interest, subject to your right to objectUntil you object

We do not use Client data to build datasets, and we do not include a Client’s own contact details in any dataset sold to another Client.

§ 05

Business Contact Data in Datasets

Our Service consists of compiling business contact information published by businesses themselves and delivering it to a Client who intends to contact those businesses.

Most Records relate to companies, and information about a legal person is not personal data. However, some Records identify a natural person — for example a sole trader, a partnership, or a business whose published contact address contains a personal name. In those cases the information is personal data and the GDPR applies. We treat all Records as if they were personal data and apply the safeguards in this Policy to the whole dataset, because the distinction cannot be made reliably at scale.

Categories of data

A Record contains only business-facing information published by or about the business:

  • business name and business category;
  • business street address, postal code, city, region, and country;
  • business telephone number;
  • business website address and domain;
  • the business email address published on that website or listing, and its technical verification status;
  • publicly displayed rating and review count from the listing;
  • links to publicly available business social media profiles;
  • the search phrase through which the business was found, and the timestamp of acquisition.
What we never collect We do not collect private or residential contact details, personal (non-business) email addresses or telephone numbers, dates of birth, identification numbers, financial data, or any special category data within the meaning of Article 9 GDPR. We do not collect data from behind logins, paywalls, or any technical protection measure, and we do not purchase, licence, or resell datasets obtained from third parties. We do not enrich Records with data from social profiles, breach dumps, or people-search services. We do not attempt to identify named individual employees within the businesses concerned.

Purpose and legal basis

We process this data for the purpose of compiling, verifying, and supplying business-to-business contact datasets to Clients who intend to make direct commercial approaches to the businesses concerned.

The legal basis is Article 6(1)(f) GDPR — legitimate interests. The interests pursued are our own commercial interest in providing the Service and the legitimate interest of our Clients in identifying potential business counterparties. Recital 47 GDPR expressly recognises that direct marketing may be carried out on the basis of a legitimate interest. Our assessment of that basis is summarised in §7.

Where a Record is verified against a domain, we also perform a technical check of DNS mail exchange records. This is a check of the domain’s configuration, not of any individual, and is carried out on the same legal basis.

§ 06

Sources of Data

Because we do not obtain business contact data from the data subject directly, Article 14 GDPR applies. This section, together with §5 and §12, constitutes the information required under that Article, and is published here as the practical means of making it available to a large number of businesses.

Data in a Record originates from the following categories of Public Source:

  • publicly accessible business listing and mapping services, including Google Maps business listings accessed through the Google Places API in accordance with its terms;
  • the public websites of the businesses concerned, in particular published contact and imprint pages;
  • publicly available business social media profiles, for the profile link only;
  • the public Domain Name System, for the technical verification of mail exchange records.

Every Record carries the source search phrase and the timestamp of acquisition, so that the origin of each entry can be traced. On request, we will tell any data subject which source phrase and which listing their Record was derived from.

Datasets are compiled on the date the order is placed. We do not maintain a standing master database of business contacts for resale, and we do not re-supply an expired dataset to a new Client.

§ 07

Legitimate Interest Assessment

Where processing rests on Article 6(1)(f) GDPR, the controller must balance its interests against the rights and freedoms of the data subject. Our assessment is summarised below and is available in full on request.

  • Purpose — enabling business-to-business commercial contact. The purpose is lawful, clearly articulated, and commercially ordinary.
  • Necessity — the data cannot be obtained by less intrusive means; identifying which businesses exist in a given sector and area requires collecting their published contact details. We minimise by collecting only business-facing fields and by excluding any business that has not published a contact address.
  • Nature of the data — business contact information published by the business in order to be contacted. It is not private, sensitive, or intimate, and its disclosure carries a low risk of harm.
  • Reasonable expectations — a business that publishes a telephone number and email address on its own website and on a public map listing can reasonably expect to receive business enquiries at those addresses. Recital 47 GDPR treats reasonable expectations as central to this test.
  • Impact — the principal impact is receiving unsolicited business correspondence. We mitigate this by excluding businesses on our Objection Register, by requiring our Clients contractually to identify themselves and provide a working opt-out in every message, and by acting on objections across all future datasets.
  • Safeguards — no special category data, no private contact details, no enrichment from non-public sources, permanent suppression on objection, source and timestamp recorded for every Record, and no onward resale by Clients.

On the basis of the above we consider that our legitimate interests are not overridden by the interests or fundamental rights of the data subjects concerned. That conclusion is subject to your right to object under Article 21(1) GDPR, and — where the data is used for direct marketing — to your absolute right to object under Article 21(2) GDPR. See §12 and §13.

A note on the lawfulness of the messages you receive This assessment concerns our processing: collecting business contact data and supplying it to a Client. It does not determine whether any particular message a Client sends to you is lawful. Whether a commercial email may be sent to a given recipient also depends on national law implementing Directive 2002/58/EC on privacy and electronic communications, which differs between member states and, in several of them, imposes requirements additional to the GDPR. Each Client is an independent controller and is contractually responsible for establishing its own lawful basis before sending. We make no representation that any specific campaign is compliant.

§ 08

Disclosure to Clients

A Dataset is disclosed to the Client that commissioned it, and to no one else. Each Dataset is compiled for a single Client and a single brief.

Upon delivery, the Client becomes an independent controller of the personal data in the Dataset. We are not a processor acting on the Client’s behalf, and the parties are not joint controllers. From that point, the Client determines the purposes and means of its own processing and is responsible for its own compliance, including for providing the information required under Article 14 GDPR in its own communications and for responding to requests it receives.

Our Terms of Service require every Client to:

  • establish and document its own lawful basis before sending any communication;
  • identify itself clearly and provide a functioning means of objecting in every message;
  • act promptly on any objection, opt-out, or erasure request, and cease further contact;
  • refrain from reselling, publishing, or otherwise passing the Dataset to any third party;
  • refrain from using the Dataset for credit assessment, identity verification, or any decision affecting the businesses concerned.

Where we receive an objection or erasure request concerning a Record we have already supplied, we notify the Client that received it and require suppression without undue delay. We will also, on request, tell you which Client received your Record, so that you can exercise your rights against that controller directly.

§ 09

Other Recipients

In addition to the disclosure described in §8, personal data may be made available to the following categories of recipient:

  • Hosting and infrastructure providers — for the operation of the Website and our processing environment;
  • Email and file delivery providers — for correspondence and for the transmission of datasets;
  • Payment service providers — Wise and Wise Payments Limited, for the processing of bank transfers;
  • Professional advisors — accountants and legal advisors, where required;
  • Public authorities — where disclosure is required by law binding on us.

Providers acting on our instructions do so as processors under written data processing agreements meeting the requirements of Article 28 GDPR. We do not sell personal data, and we do not disclose it to third parties for their own marketing purposes.

§ 10

International Transfers

Omnexis Group LLC is established in the United States. Processing carried out by the Company therefore involves a transfer of personal data to a third country within the meaning of Chapter V GDPR.

Where personal data of data subjects in the European Union is transferred to us or to a sub-processor outside the EEA, the transfer is made on the basis of the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, supplemented where necessary by additional technical and organisational measures identified in a transfer impact assessment.

Where a Client established outside the EEA receives a Dataset containing personal data of EU data subjects, that disclosure is likewise made subject to the Standard Contractual Clauses, incorporated into the contract between us and the Client.

A copy of the clauses relied upon, with commercially confidential terms redacted, is available on request from privacy@b2b-leads.biz.

§ 11

Retention

We retain personal data no longer than is necessary for the purposes for which it was collected.

CategoryRetention period
Working copy of a compiled DatasetDeleted 90 days after delivery, once the complaint and replacement window in the Terms of Service has closed
Order metadata (brief, phrases, area, record count, timestamps)5 years — retained without the underlying contact data, to evidence what was supplied and when
Objection Register entriesIndefinitely — retained precisely so that the objection can continue to be honoured
Client enquiries not resulting in an order12 months from last contact
Contract, invoicing, and accounting records5 years, or longer where required by applicable tax law
Server logs and security records12 months
Correspondence relating to a data subject request3 years, to evidence that the request was handled

Where data must be retained to establish, exercise, or defend legal claims, it is retained until those claims are time-barred and is restricted from all other use in the meantime.

§ 12

Your Rights

Where the GDPR applies to our processing of your personal data, you have the following rights:

  • Access (Art. 15) — to be told whether we process data about you, and to receive a copy together with information on purposes, recipients, sources, and retention.
  • Rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
  • Erasure (Art. 17) — to have your data deleted, including where you have objected and no overriding legitimate ground exists.
  • Restriction (Art. 18) — to have processing restricted while a dispute over accuracy or legitimate grounds is resolved.
  • Portability (Art. 20) — where processing is based on consent or contract and carried out by automated means, to receive your data in a structured, machine-readable format.
  • Objection (Art. 21(1)) — to object to processing based on legitimate interests. Where you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests.
  • Objection to direct marketing (Art. 21(2)) — an unconditional right. Where you object to processing for direct marketing purposes, we stop, without any balancing test. This is the right most likely to be relevant to business contact data in our datasets.
  • Withdrawal of consent (Art. 7(3)) — where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

Requests may be sent to privacy@b2b-leads.biz. We respond within one month of receipt, extendable by two further months for complex requests, in which case we will tell you within the first month. Exercising these rights is free of charge.

We may ask for information reasonably necessary to confirm that a request relates to data we actually hold — typically the email address, domain, or business name concerned. We will not ask for identity documents where the request can be verified from the contact details in the Record itself.

§ 13

Objection Register

We maintain a permanent suppression list — the Objection Register — of email addresses, domains, telephone numbers, and business identities that must never appear in a Dataset again.

To be added, write to privacy@b2b-leads.biz stating the address, domain, or business name to be suppressed. No reason is required and no account is needed.

Once an entry is on the Register:

  • the entry is excluded from every Dataset we compile from that point onward, in every industry and every country;
  • the exclusion is applied at the compilation stage, before any Client sees the data;
  • where the entry appeared in a Dataset already delivered, we notify the Client concerned and require suppression, and we will tell you which Client that was;
  • the entry is retained indefinitely, since deleting it would defeat its purpose. This retention is itself necessary for compliance with Article 21 GDPR and is the minimum required to honour the objection — the Register holds the identifier and the date of the objection, and nothing more.

We confirm suppression in writing, as a rule within 5 business days and in any event within one month.

If you have received unwanted email Being added to our Register stops us supplying your details to anyone in future, but it cannot recall a dataset already delivered. To stop messages from a company that is already contacting you, use the objection or unsubscribe mechanism in that company’s message, and contact them directly — they are the controller of that campaign. Tell us as well and we will notify them and suppress your details permanently at our end.

§ 14

Automated Decisions & Profiling

We do not carry out automated decision-making producing legal effects concerning any data subject or similarly significantly affecting them, within the meaning of Article 22 GDPR.

Dataset compilation involves automated filtering: businesses are included or excluded according to the search phrase, the geographic area, whether contact details are published, and whether the domain accepts mail. These operations determine whether a business appears in a Dataset. They do not evaluate, score, or rank any individual, and they produce no decision about a person.

§ 15

Security

We implement technical and organisational measures appropriate to the risk, as required by Article 32 GDPR, including:

  • encryption of data in transit (TLS) and encryption at rest on our processing systems;
  • access control on the principle of least privilege, with individual accounts and multi-factor authentication;
  • deletion of working dataset copies on the schedule set out in §11, rather than indefinite accumulation;
  • written processing agreements with all providers acting on our instructions;
  • logging of access to datasets, and review of that logging.

No transmission or storage system is completely secure. In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we will notify the competent supervisory authority within 72 hours in accordance with Article 33 GDPR, and will notify affected data subjects where Article 34 GDPR requires it.

§ 16

Cookies

The Website uses cookies and similar technologies. Cookies strictly necessary for the operation of the Website are set on the basis of our legitimate interest in providing a functioning service. All other cookies — including analytics — are set only after you have given consent through the cookie banner.

You may withdraw consent at any time through the cookie settings on the Website, or configure and delete cookies through your browser. Disabling certain cookies may limit functionality. The categories of cookie used, their purposes, and their lifespans are set out in the Cookie Policy.

§ 17

Changes to this Policy

We may update this Policy to reflect changes in our processing, our providers, or the applicable law. The current version, its version number, and its effective date are always published on this page.

Where a change materially affects how we process your data or the rights available to you, we will publish a notice on the Website and, where we hold your contact details as a Client, notify you by email in advance of the change taking effect.

§ 18

Complaints & Contact

If you have a question about this Policy, or wish to exercise any of the rights in §12, contact us at:

Omnexis Group LLC 5830 E 2nd St, Ste 7000 21135, Casper, Wyoming 82609, USA
EIN: 38-4340931

Data protection: privacy@b2b-leads.biz
General: office@b2b-leads.biz
Website: https://b2b-leads.biz

EU representative under Article 27 GDPR: [NAME AND FULL POSTAL ADDRESS OF EU REPRESENTATIVE] — [REPRESENTATIVE EMAIL].

If you consider that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement (Article 77 GDPR). A list of national authorities is published by the European Data Protection Board at edpb.europa.eu. You also have the right to an effective judicial remedy under Article 79 GDPR.

We would ask you to raise the matter with us first. We aim to resolve data protection complaints within 14 days.