Security and GDPR

Login, encryption, EU data storage, sub-processors under SCCs and the data processing agreement.

How Leo handles security, data and GDPR.

Login

One-time code via email, no passwords that can leak. The session logs out automatically after 24 hours.

Encryption

API keys and mailbox passwords are encrypted with AES-256-GCM and deleted when you disconnect the respective integration.

Where the data lives

Your data is stored and hosted within the EU. Some sub-processors outside the EEA, such as our AI provider, process data in the United States under EU-approved Standard Contractual Clauses (SCCs). The full list is in the privacy policy.

Data processing agreement

You accept the data processing agreement (DPA) in the platform before Leo processes leads on your behalf. Your data is used only on your behalf, never to train models for other customers.

Outbound B2B contact relies on legitimate interest (article 6.1f), the same legal basis as traditional sales prospecting. Opt-outs are always respected, permanently, see suppression.

What Leo never does

  • Changes or deletes anything in your CRM, he reads, and writes notes only if you turned that on
  • Sends bulk email, every message is personal and sent one at a time
  • Shares your data with other customers

Questions

Security questions are answered via support or adam@revexa.io.