GDPR and data protection
How data protection law applies when you use QuickExtract to collect B2B leads, who is responsible for what, and how people can exercise their rights.
1. Overview
QuickExtract is operated by Quickprosp Pvt Ltd, based in Ahmedabad, Gujarat, India (“Quickprosp”, “we”, “us”). QuickExtract helps you collect business leads, such as names, job titles, companies, websites and emails, from sources you choose. Much of that is personal data under laws like the EU General Data Protection Regulation (GDPR), the UK GDPR and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
This page explains how we see the roles and duties involved. It should be read with our Privacy Policy and Terms of Service.
General information, not legal advice. Data protection rules depend on where you and the people you contact are, and on how you use their data. Ask a qualified lawyer about your own situation.
2. Who is responsible
Leads you collect: you are the controller
You decide which searches to run, which leads to keep, and whether and how to contact them. For that lead data, you (or the organisation you work for) act as the controller: you decide the purposes and means of processing, and you are responsible for having a lawful basis and meeting your obligations to the people in your lists.
Lead data in your account: we act as processor
We store and process the leads in your account on your behalf, to provide the Service: showing them in your dashboard, finding company emails, finding and verifying person emails you request, and exporting or sending them where you choose. For that data we act as a processor. We don't use your leads to build lists for other customers, and we don't sell them.
Account data: we are the controller
For your own account data, such as your name, email address, hashed password, payment records, settings and support messages, Quickprosp is the controller. Our Privacy Policy explains how we use it.
3. Lawful basis for B2B outreach
Under the GDPR, you need a lawful basis to collect and use personal data. For B2B prospecting, many businesses rely on legitimate interests. Whether that basis fits your use depends on the facts, and some countries have extra rules for marketing emails.
The balancing test
Legitimate interests is commonly assessed in three steps:
- Purpose: is there a genuine business interest, such as offering a relevant product or service to a company?
- Necessity: is the data you collect needed for that purpose, and no more than needed?
- Balance: would the person reasonably expect to be contacted in their professional role, and does your interest outweigh any impact on their rights?
Writing this assessment down helps you show your reasoning later.
Relevance and data minimisation
Contact people about matters linked to their job and their company. Collect the fields you'll actually use, and remove leads you no longer need.
Transparency
When you collect personal data from sources other than the person, the GDPR generally requires you to tell them who you are, why you have their data, where it came from and what their rights are, within a reasonable time and at the latest when you first contact them. A short notice in your first email, with a link to your own privacy notice, is a common approach.
Opt-out
People have the right to object to direct marketing at any time. Give a simple way to opt out in every message, stop contacting people who object, and keep a suppression list so they aren't added again in a later run.
Email marketing rules
Separate e-privacy and anti-spam rules apply to marketing emails, such as the EU ePrivacy rules as implemented in each country, the UK PECR, the US CAN-SPAM Act and India's Information Technology Act, 2000. Some countries require prior consent for marketing emails even to business addresses. Check the rules for the countries your recipients are in. Our guide Is web scraping legal? covers this in more detail.
4. Your responsibilities
As controller of the leads you collect, you are responsible for:
- having a lawful basis for collecting and using each lead;
- telling people how you use their data, and where you got it;
- honouring opt-outs, objections and deletion requests promptly, including in your exports and other tools;
- following the terms of the sites you collect from, using your own accounts;
- keeping exported files secure and deleting data you no longer need;
- following anti-spam laws when you send messages.
Our Terms of Service set out the acceptable use rules for the Service.
5. Data subject rights
Depending on the law that applies, people can ask to:
- access their personal data and learn how it is used;
- correct inaccurate data;
- delete their data;
- restrict processing in some cases;
- object to processing, including direct marketing at any time;
- receive their data in a portable format, in some cases;
- withdraw consent, where processing is based on consent;
- complain to a data protection authority.
6. How to send a request
If you are a QuickExtract user
You can change your name and password on the Profile page, and delete leads and groups from your dashboard at any time. For a copy of your account data, or to delete your account, email us from the address on your account.
If your details are in a user's list
The user who collected your details controls that data, so the quickest route is usually to reply to their message or contact them directly. You can also email us. Tell us your name, the email address or profile involved, and what you'd like done. We will help, including by passing your request to the user concerned. We may ask for information to confirm your identity before acting on a request.
If you receive a request as a user
Delete or update the person's row in your dashboard, remove them from any exported files and other tools, and add them to your suppression list. Email us if you need help finding their data in your account.
We respond to requests sent to us within 30 days.
7. India's DPDP Act, 2023
Quickprosp is based in India, and the Digital Personal Data Protection Act, 2023 sets rules for processing digital personal data in India and, in some cases, outside it. It uses the terms data fiduciary (broadly similar to a controller) and data processor, and gives individuals (data principals) rights such as access, correction, erasure and grievance redressal.
The Act contains provisions on personal data that a person has made publicly available. How these and other provisions apply depends on the rules made under the Act and on the facts, so take advice if you rely on them. Grievances about our own processing can be sent to the contact address below.
8. Retention and deletion
- We keep your account data and leads while your account is open.
- You can delete leads and groups from your dashboard at any time.
- When you ask us to delete your account, we delete your account data within 30 days, except records we must keep by law, such as payment records.
As controller of your leads, set your own retention period and delete leads you no longer need, both in QuickExtract and in any files or tools you exported them to.
9. International transfers
We are based in India, and our service providers may process data in other countries. If you or the people in your lists are in the EU, the UK or elsewhere, using QuickExtract involves transferring personal data to India and possibly to other countries. When data moves across borders, we take steps to protect it as our Privacy Policy describes. Consider how these transfers fit your own obligations.
10. Service providers
We use service providers to run QuickExtract. They process data only to provide their service to us, under contracts that limit how they can use it:
- Hosting and infrastructure: to store your account and leads and run our servers.
- Email verification: to check whether person emails you request are valid.
- Payment processing: to take payments for credits. We don't store your full card details.
If you need more detail about our providers for your own records, email us.
11. Security
We protect data with safeguards appropriate to the risk, including:
- passwords stored only as a one-way hash, never in plain text;
- signed sign-in tokens that expire after 7 days;
- access controls that keep each account's data separate from every other account;
- an extension that reads web pages only when you use one of its features, and never reads LinkedIn pages through autosave.
No system is perfectly secure. Use a strong, unique password, and protect files you export from QuickExtract.
12. Changes
We may update this page as the law or the Service changes. We will change the date at the top of the page.
13. Contact
For data protection questions, requests or grievances, contact us:
Need help with a data request?
Email us and we'll help you find, update or delete the data involved.