Legal · GDPR
GDPR posture.
CogniLead runs cold-adjacent email outbound on leads you supply, so GDPR shows up on both sides of the relationship: as your data processor for the outbound campaigns you run through us, and as a data controller for our own account and billing data. This page explains, factually, how each of those roles works — it is not legal advice (see the disclaimer above), and does not replace review by your own counsel or Data Protection Officer.
1. Overview
CogniLead is a compliance-first cold-email deliverability engine: you supply leads (via the dashboard or the /api/v1/leads API) and CogniLead runs the send — warmed sender-domain pools, a reputation circuit-breaker, jurisdiction-aware routing, suppression, and RFC 8058 one-click unsubscribe. It is not a lead database and does not source or sell contact data, and it does not run consumer or newsletter email — only B2B cold outbound on data you already hold.
2. Controller vs processor
- For the leads and campaign recipients you supply: you are the controller — you decide who to contact and why — and CogniLead acts as your processor, running the send and enforcing outbound hygiene on your instructions. This relationship is what the Data Processing Agreement template covers.
- For your own account and billing data: CogniLead is the controller, as described in the Privacy Policy.
3. Lawful basis for cold outbound
Cold B2B outreach typically relies on legitimate interest (Article 6(1)(f)) as its lawful basis, not consent — reaching a business contact at a work address, about something genuinely relevant to their role, is a recognized use of that basis. It is not unconditional: the outreach still has to be relevant, the controller (you) still has to balance the interest against the recipient's rights, and every recipient still has to be able to object easily. CogniLead does not evaluate whether your specific use of legitimate interest is well-founded — that judgment sits with you as the controller — but it enforces the mechanical side of the obligation on every send: suppression and one-click unsubscribe, described in section 5. A fuller, general walkthrough is in our blog post on GDPR and cold email.
4. Data subject rights
Recipients of campaigns you run through CogniLead may have the following rights over their data, depending on where they are located:
- Access — a request for what data is held about them.
- Erasure — a request to delete their data.
- Objection — a request to stop being contacted, which must be honored immediately and permanently.
As the controller for your recipients' data, you are responsible for responding to these requests. CogniLead supports you as processor: erasure and access requests against campaign data run through your dashboard or a support ticket, and objection is handled automatically by the suppression mechanism below — it does not require a manual data-protection response for every unsubscribe.
5. Suppression as objection-handling
The practical tool that turns "the right to object" into something that actually happens on every send is CogniLead's suppression list. Every outbound message carries a working RFC 8058 one-click unsubscribe; a recipient who uses it (or who is added to suppression manually, or who hard-bounces) is checked against on every subsequent send, permanently, across every campaign in the tenant. This mechanism cannot be disabled. See the suppression feature page for the mechanics.
6. Data residency
Primary tenant data — accounts, leads, campaigns, and generated content — is hosted in the EU (Supabase, eu-west-1), consistent with the posture documented in Security §8. LLM inference for outbound personalization is performed by phi-cloud; CogniLead does not send it patient or health data and does not use phi-cloud's HIPAA/PHI tier. Re-region of an existing tenant is a controlled operation requiring a service ticket, with in-flight sends paused during the migration window.
7. Sub-processors
We use the following sub-processors to run the service:
- Supabase — authentication and the primary multi-tenant Postgres database (Row Level Security enforced per tenant).
- Amazon SES — outbound and transactional email delivery, and bounce/complaint notifications.
- Cloudflare — application hosting and edge network.
- Stripe — billing.
- phi-cloud — LLM inference for outbound personalization and content scaffolding.
The full, current list — kept consistent with the Privacy Policy — is also mirrored in the DPA.
8. International transfers
Where personal data crosses a border to reach a sub-processor above, we rely on appropriate safeguards such as Standard Contractual Clauses, consistent with the Privacy Policy's international transfers section.
9. Breach notification
A confirmed personal-data breach is communicated to affected customers within 48 hours of discovery, via email to the address on the account and a banner in the dashboard — the same commitment documented in Security §12.
10. Data Processing Agreement
For the contractual detail of CogniLead's role as processor — processing scope, sub-processor list, deletion on termination, and breach-notification terms — see the DPA template. Like every document in /legal, it is a template for review, not a signable contract, until CogniLead GmbH completes incorporation.