Legal
Privacy Policy
This policy explains what personal information Junoleads Pty Ltd collects, why we collect it, who we share it with, and what you may ask us to do about it. It applies to our website at junoleads.io, to the Junoleads client portal, and to the outbound campaigns we run for our clients.
Who we are and what this policy covers
Junoleads is a business-to-business go-to-market agency. We plan and run outbound campaigns — cold email, LinkedIn outreach, and the systems behind them — on behalf of our clients, and we operate a client portal in which those clients review leads, manage campaigns and handle replies.
The entity responsible for personal information handled through our services is Junoleads Pty Ltd, ABN 68693511563, a company registered in New South Wales, Australia. References in this policy to "we", "us" and "Junoleads" are references to that entity.
This policy applies to three groups of people, and different parts of it are relevant to each:
- Visitors to junoleads.io.
- Clients and their users — those who sign in to the Junoleads client portal at app.junoleads.io, including anyone who connects a Google or Microsoft calendar to it. The portal is not open to the public: an account must be created for you before you are able to sign in.
- Prospects — those we contact as part of an outbound campaign. If you have received an email or a message from us and wish to know where your details came from, or how to stop hearing from us, see Prospect and contact data and Stopping outreach from us.
This policy does not extend to our clients' independent handling of information within their own systems after we have delivered it to them. Where we act on a client's instructions, our handling is additionally governed by our agreement with that client.
Information we collect
Website visitors
When you visit junoleads.io, our hosting provider records standard server-log information: your IP address, the pages requested, the site or search that referred you, and basic device and browser details. This is used to serve the site, diagnose faults and protect against abuse. We do not operate website analytics on junoleads.io, and we set no cookies of our own, as described in Cookies and tracking.
If you book a call, request a proposal or apply for a role, you provide your name, email address, company, and any other information you choose to enter in the form. Those forms and the booking calendar are hosted by third parties, as described in Who we share information with.
Client accounts and the client portal
For clients we hold account and contact details for each user, sign-in information, billing and engagement records, and the configuration of your campaigns: your ideal-customer profiles, targeting criteria, messaging angles and approved copy. We also hold the operational data your campaigns generate — which prospects were contacted, the messages sent, delivery and reply events, the replies themselves, and the drafts prepared for your review.
Calendar connections
If you connect a calendar so that Junoleads is able to offer your genuine availability in a reply and book meetings on your behalf, we access a narrow portion of your calendar account. Because this is the most sensitive category of information we handle, and because Google and Microsoft impose their own requirements on it, it is dealt with separately in Google user data and Microsoft calendar data. Connecting a calendar is optional; the portal operates without one.
Prospect and contact data
In order to run outbound campaigns we build and maintain a database of business contacts. This is personal information about people who have not provided it to us directly, so we set it out in detail below.
Where it comes from. Publicly available business sources and licensed business-to-business data providers: company websites, public professional profiles, job advertisements, business directories, and company, hiring and technology databases. Email addresses are checked against verification services to confirm that they are valid and deliverable. We do not purchase consumer data, and we do not knowingly collect sensitive or special-category information.
What we hold. Your name, business email address, job title, employer and information about that employer, your public professional profile and photograph, your professional history and stated skills, your general location, and in some cases a publicly listed business telephone number. We may also hold research and summaries that our systems generate about you in your professional capacity. If you reply to us, we hold your reply, our response, and any classification applied to the conversation.
Responsibility for this data, and its reuse. We source and maintain this database as our own rather than holding a separate list for each client, and the same contact record may therefore be used for more than one client's campaigns over time. Junoleads is the controller of that data. Where a client provides us with their own list, or directs a specific campaign, that client is the controller of what they have supplied and we act on their instructions in respect of it. The practical effect is that a single request to us covers every campaign we run, for every client, as described in Stopping outreach from us.
Our basis for holding it. Where the GDPR or UK GDPR applies, we rely on legitimate interests (Article 6(1)(f)) — direct business-to-business marketing to a person in their professional capacity, concerning services relevant to their role — having weighed that interest against your rights and freedoms. Where consent is required instead, we rely on consent. In Australia we handle personal information under the Privacy Act 1988 (Cth) and send marketing in accordance with the Spam Act 2003 (Cth); where recipients in the United States are contacted, we do so in accordance with the CAN-SPAM Act.
Google user data
If you connect a Google Account to the Junoleads client portal, we access part of your Google Calendar data through the Google Calendar API. This section describes that access in the terms required by the Google API Services User Data Policy. It applies only to those who choose to connect a Google Account; it does not apply to website visitors or to prospects.
What we request, and why
-
https://www.googleapis.com/auth/calendar.freebusyRead your free/busy availability -
https://www.googleapis.com/auth/calendar.eventsCreate and manage events on the calendar you connect
We use calendar.freebusy to determine the times at which you are genuinely
free, so that a reply we prepare for a prospect offers real availability rather than
assumed times. We use calendar.events to place a meeting on your calendar
once a prospect accepts one of those times.
We do not request access to Gmail, Google Drive, Google Contacts or
any other Google service, and we do not request the broader calendar
scope, which would grant full read and write access to every calendar on your account.
Nor do we use the narrower calendar.app.created scope, which would confine
us to a secondary calendar created by the application itself. Meetings booked onto such
a calendar would not appear in your own free/busy information, leaving your colleagues
and your other scheduling tools free to book over them. We therefore write to the
calendar you work from, since a booking that your own availability does not reflect
fails to achieve what the feature exists to do.
What we access
- Free/busy intervals — the start and end times of the periods during which you are busy. Google's free/busy endpoint returns times alone: we do not receive, and are unable to see, your event titles, descriptions, locations, attendees, guests or attachments.
- Events we create — the meetings Junoleads books on your behalf, and their status.
What we store
- The OAuth access and refresh tokens that allow the connection to continue operating without requiring you to sign in for each booking, held in encrypted storage.
- The identity of the connected account, which is sufficient for the portal to display which calendar is connected and to allow you to disconnect it.
- A record of the meetings we have booked for you.
We do not retain a copy of your calendar. Free/busy information is read at the moment a draft reply is prepared and is used to select the times that draft offers; it is not retained as a calendar record, although the times offered remain visible within the draft itself as part of that conversation.
How we use it, and what we never do with it
Google user data is used for a single purpose: providing the availability and booking feature that you have enabled. We do not use it for advertising, we do not sell it, we do not transfer it to data brokers or credit agencies, and we do not use it to develop, improve or train generalised artificial intelligence or machine-learning models. Junoleads personnel do not read Google user data except with your explicit consent, where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
Limited Use. Junoleads' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who it is shared with
The candidate meeting times derived from your free/busy information are sent to the AI provider that composes the draft reply offering those times, as described in AI and automated processing. That provider processes them as our service provider, does not train its models on them, and retains them only for a limited period. Google user data is otherwise held only within the infrastructure we use to operate the portal, and is not shared with any other party.
Revoking access and deleting your data
You may disconnect your calendar at any time within the portal, or revoke Junoleads' access directly from your Google Account at myaccount.google.com/permissions. On revocation the feature ceases to operate, and we delete the stored tokens and the connection record within 30 days. Meetings already created on your calendar remain there: they are your events, and you may delete them yourself. To have any other information removed, email privacy@junoleads.io.
Microsoft calendar data
Where you connect a Microsoft 365 or Outlook calendar rather than a Google Account, Junoleads accesses your calendar through the Microsoft Graph API, under delegated permissions that you grant. The permissions we request are:
-
Calendars.ReadRead your free/busy availability -
Calendars.ReadWriteCreate and manage events on the calendar you connect -
offline_accessKeep the connection alive without asking you to sign in again -
User.ReadRead your basic profile so we can label the connected account
We read availability in order to offer genuine times, and write events in order to book confirmed meetings. We do not request access to your mailbox, to your files, or to your organisation's directory beyond your own basic profile.
Everything stated in Google user data about what we store, how we use it, who it is shared with, how long we retain it, and what we never do with it applies equally to calendar data obtained from Microsoft. You may revoke access from your Microsoft account settings, or by disconnecting the calendar within the portal; on revocation we delete the stored tokens and the connection record within 30 days. Some organisations require an administrator to approve the connection before you are able to grant it.
How we use information
- To operate, secure and support the client portal and our services.
- To plan, run, measure and improve outbound campaigns — including building and qualifying target lists, drafting messages, sending them, and reporting on results.
- To read availability and book meetings, where a client has connected a calendar for that purpose.
- To respond to enquiries, proposals and job applications.
- To invoice, maintain business records, and meet our legal and tax obligations.
- To understand how our website is used, at an aggregate and company level, so that we are able to improve it.
Where the GDPR or UK GDPR applies, we rely on the following bases: performance of a contract, in operating the portal and delivering services to clients; legitimate interests, in business-to-business marketing, in securing and improving our services, and in business administration; consent, where we have requested it; and compliance with legal obligations. Where we rely on legitimate interests you have the right to object, as described in Your rights and choices.
AI and automated processing
We use third-party large language models to carry out parts of our campaign work. The following is sent to those providers:
- Replies you send us — the body of your reply, together with your name and email address, so that the model is able to classify what the reply indicates, such as interested, not interested, unsubscribe, or out of office, and to prepare a suggested response.
- Prospect and company research — the business information described in Prospect and contact data, so that the model is able to assess whether a contact fits a client's target profile and to draft relevant copy. Some of this content is also converted into numerical embeddings for search.
- Candidate meeting times, where a calendar is connected, as described in Google user data.
These providers act on our behalf as service providers, process the content on our instructions, and do not use it to train their models. Drafts prepared in this way are reviewed by a person before they are sent, and we do not take decisions producing legal or similarly significant effects concerning you by automated means alone.
Where information is stored
Junoleads operates from Australia, and our primary database is hosted in Australia. Some of our service providers operate in the United States, the European Union and the United Kingdom, so personal information may also be stored or processed outside the country in which you are located. Where we transfer personal information from the EEA or the United Kingdom, we rely on Standard Contractual Clauses or another lawful transfer mechanism. Where Australian Privacy Principle 8 applies, we take reasonable steps to ensure that overseas recipients handle the information consistently with the Australian Privacy Principles.
How long we keep information
- Calendar connections — until you disconnect or revoke access, after which the stored tokens and connection record are deleted within 30 days.
- Client account and campaign data — for the duration of the engagement, and subsequently for as long as we require it in order to meet Australian record-keeping, tax and legal obligations.
- Prospect data — while it remains relevant to campaigns we run, and removed or anonymised once it ceases to be relevant, or on request.
- Suppression records — retained indefinitely. If you ask us never to contact you again, we must retain the minimum record necessary to identify you and honour that request. This is the only category of information we retain following a deletion request, and it is retained solely for that purpose.
- Server logs — retained by our hosting provider for a limited period, under its own retention schedule.
Security
We protect information in transit using TLS, hold mailbox credentials and OAuth tokens in encrypted storage rather than as ordinary database fields, separate each client's data at the database level, and restrict access to the personnel who require it for their work. No method of transmission or storage is entirely secure, and we are unable to guarantee absolute security. In the event of a data breach likely to result in serious harm, we will notify the people affected and the relevant regulator as required by law.
Your rights and choices
Stopping outreach from us
Every email we send carries an unsubscribe address, and a reply asking us to stop is equally effective: such replies are detected and acted upon automatically. LinkedIn messages carry no unsubscribe link, so reply to the message itself or write to privacy@junoleads.io.
However the request reaches us, we add you to a suppression list that applies across every campaign we run, including campaigns run for clients, and you will not be contacted through us again. We act on these requests promptly and do not require you to give a reason. We do not use open or read tracking in our emails.
Access, correction and deletion
You may ask what personal information we hold about you, ask us to correct it, and ask us to delete it. Email privacy@junoleads.io and we will respond within 30 days. Prospects do not hold an account with us, so these rights are exercised by email and no account is required. We may need to verify your identity before acting, and we may retain information where the law requires it, or where we require it in order to honour a suppression request.
If you are in the EEA or the United Kingdom
You additionally have the right to object to processing based on legitimate interests, including direct marketing, which we will always honour; the right to restrict processing; the right to data portability; and the right to withdraw consent where we have relied on it. Any of these may be exercised through the same address. You may also lodge a complaint with your local supervisory authority.
If you are in California
You have the right to know what personal information we collect and how we use it, to request its deletion or correction, and not to be discriminated against for exercising those rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Children's data
Junoleads provides services to businesses. Our services are not directed to children, we do not knowingly collect personal information from anyone under 16, and if we learn that we have done so, we will delete it.
Changes to this policy
We update this policy when our practices change. The date at the top of the page reflects the last substantive change. Where a change materially affects how we handle information you have already provided to us, including anything set out in Google user data, we will take reasonable steps to notify the people affected directly rather than relying on this page alone.
Contact and complaints
For any matter arising under this policy — access, correction, deletion, opting out, or a question about how we handle your information — contact:
Junoleads Pty Ltd
ABN 68693511563
privacy@junoleads.io
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au, or, if you are in the EEA or the United Kingdom, with your local data protection supervisory authority.