How Leo handles security, data and GDPR.
Login
One-time code via email, no passwords that can leak. The session logs out automatically after 24 hours.
Encryption
API keys and mailbox passwords are encrypted with AES-256-GCM and deleted when you disconnect the respective integration.
Where the data lives
Your data is stored and hosted within the EU. Some sub-processors outside the EEA, such as our AI provider, process data in the United States under EU-approved Standard Contractual Clauses (SCCs). The full list is in the privacy policy.
Data processing agreement
You accept the data processing agreement (DPA) in the platform before Leo processes leads on your behalf. Your data is used only on your behalf, never to train models for other customers.
Legal basis for outreach
Outbound B2B contact relies on legitimate interest (article 6.1f), the same legal basis as traditional sales prospecting. Opt-outs are always respected, permanently, see suppression.
What Leo never does
- Changes or deletes anything in your CRM, he reads, and writes notes only if you turned that on
- Sends bulk email, every message is personal and sent one at a time
- Shares your data with other customers
Questions
Security questions are answered via support or adam@revexa.io.