Version 05/09/2026

Privacy & Data Security Agreement

This one document explains the privacy and security promises B2Blead makes when it handles information for a client. It also sets out what the client must do. It forms part of the client’s agreement with VIMI Co., Ltd., the company that operates B2Blead.

Review the terms before signing on behalf of your organization. B2Blead is responsible for its service safeguards and provider reviews. Your organization decides how it uses the service, including the information it collects, the optional services it allows and its retention periods.

1. Who is responsible for what

The client decides why customer information is collected and how B2Blead should use it. The client is the data controller. VIMI normally acts as the data processor for that information.

VIMI is separately responsible for account, billing, service-security and legal records that it needs to run B2Blead. The client must use B2Blead lawfully, show the right privacy notices and have a valid reason for collecting personal information.

2. What information is handled

Depending on the features the client turns on, B2Blead may handle names, business contact details, chat and form answers, uploaded files, CRM activity, email content, website information, account details and technical records such as device, source and security logs.

B2Blead is not designed to collect sensitive personal information as part of its normal service. A client must not submit sensitive information unless it is necessary, lawful and specifically approved for that use.

3. How B2Blead may use it

B2Blead may collect, store, organize, search, analyse, transmit, export, restrict, anonymize and delete information only as needed to provide the service, keep it secure, follow the client’s settings and instructions, or meet a legal duty.

B2Blead does not sell client information. B2Blead will not use client information to train a general or shared AI model unless the client gives written permission first.

4. Security protections

B2Blead uses encrypted connections, access based on a person’s role and client, private storage, protected integration credentials, separated administrator access, security and audit logs, managed secrets, software-dependency checks, backups, incident procedures and tools to reduce or delete stored information.

Security controls will change as the service changes. B2Blead will not knowingly reduce the overall level of protection in a material way without telling affected clients.

5. Outside services

B2Blead is responsible for reviewing its provider terms and applicable privacy safeguards. The client decides whether to use an optional service. That decision is an instruction to use the service, not a certification that the provider has completed its contractual, transfer, retention or no-training review.

B2Blead uses outside companies to host and operate the service. The current list, what each company does and where it may handle information are shown in the Subprocessor Register.

Core services are required to run B2Blead. Optional services receive client information only when the matching feature is allowed, connected and turned on. The client can approve, restrict or reject optional services on its Outside services page.

B2Blead will place suitable privacy and security duties on its subprocessors and remains responsible for them where the law requires. B2Blead will give reasonable notice of a material new subprocessor when practicable. A client may object within 15 days on reasonable data-protection grounds.

View the current Subprocessor Register.

6. Countries where information may be handled

B2Blead and its subprocessors may handle information outside the client’s country. The Subprocessor Register identifies the known locations. Where the law requires extra protection for an international transfer, B2Blead will use an appropriate contract or other lawful safeguard.

7. Keeping and deleting information

The client chooses retention periods for each purpose. Business sales cycles can exceed five years, and relevant CRM history may be needed throughout a continuing opportunity or customer relationship. The client should review whether records remain necessary. A long sales cycle does not by itself justify keeping rejected submissions or technical logs for as long as CRM history.

The platform currently defaults to 3,650 days (about ten years) for each configurable retention category, with CRM retention measured from the last recorded activity. Client settings may differ. These are product defaults, not a legal requirement or blanket permission to keep all information for ten years.

Automatic retention deletion is off by default. Saving a period while it is off supports review and preview but does not delete information at expiry. When the client enables automatic deletion, eligible records are deleted or identifying details removed in scheduled batches, subject to applicable safeguards. This can include deleting CRM contacts beyond their last-activity period. The client should review continuing opportunities and required records before enabling it.

Retiring a bot starts a separate 90-day period, after which its database records become eligible for deletion even if automatic retention deletion is off. External files and knowledge-base vectors require separate cleanup. The client should arrange any required export or continued retention before retiring a bot; database deletion alone does not establish that every copy has been erased.

The client can request an export or deletion through the normal support and privacy process. B2Blead may keep limited billing, security, audit or legal records where required, with continuing access controls.

8. Privacy requests

People can ask to access, correct, delete, restrict or export their information by emailing privacy@b2blead.ai. Requests are handled manually and forwarded to mike@b2blead.ai and james@b2blead.ai for review. B2Blead will help the client respond where the request concerns information the client controls.

9. Security incidents

B2Blead will investigate and contain a personal-data incident. It will tell the affected client without unnecessary delay and, where feasible, within 72 hours after becoming aware of a breach affecting that client’s information. The notice will include the facts, likely impact and response steps known at the time.

10. Proof, audits and changes

B2Blead keeps records needed to show how privacy and security controls operate. It may answer reasonable audit requests with current reports, questionnaires and security documents. If those are not enough, the client may request one reasonable audit per year, plus an audit after a material breach or regulator request.

A new version of this agreement requires a new acceptance when the change is material. A separately signed agreement takes priority if it clearly says that it replaces part of this online agreement.

11. Contact

Questions, objections and privacy requests should be sent to privacy@b2blead.ai.

Privacy & Data Security Agreement | b2blead.ai