§Legal · GDPR & CCPA

GDPR & CCPA

Last updated · January 29, 2026

Section 01

Introduction

LaunchPal is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA). This page explains how we comply with these frameworks for our B2B lead generation and email outreach platform.

For a comprehensive overview of our privacy practices, please see our Privacy Policy.

02

Our business model & data collection

LaunchPal provides a B2B lead generation service specifically for CPG/FMCG brands to connect with retailers, distributors, and buyers. Our platform:

  • Collects publicly available business data from company websites, business directories, and public registries.
  • Processes leads for business purposes only: CPG/FMCG suppliers reaching out to retailers and distributors.
  • Sources email addresses from company websites: professional business email addresses, not personal emails.
  • Includes proper sender identification: all emails include sender name, company, and contact information to comply with anti-spam laws.

We operate as a B2B platform facilitating legitimate business communications between suppliers and potential retail partners.

Section 03

Cold email law compliance

LaunchPal complies with cold email regulations across multiple jurisdictions:

NZ
New Zealand
Unsolicited Electronic Messages Act 2007

All emails include clear sender identification, accurate subject lines, and functional unsubscribe mechanisms. We comply with the requirement for B2B communications to include business contact information.

AU
Australia
Spam Act 2003

B2B emails to business email addresses are permitted under the business exemption. All emails include accurate sender information and opt-out mechanisms as required.

EU
European Union
GDPR & ePrivacy Directive

B2B cold emailing is permitted under the legitimate interest basis when contacting business email addresses for business purposes. All emails include proper identification and opt-out options.

US
United States
CAN-SPAM Act

All emails include accurate header information, clear subject lines, sender identification, physical postal address, and opt-out mechanisms honored within 10 business days.

CA
Canada
CASL (Canadian Anti-Spam Legislation)

B2B cold emails are permitted under the business relationship exemption when contacting business email addresses. All emails include clear identification and unsubscribe mechanisms.

Section 04

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to all EU member states. It gives individuals control over their personal data and establishes strict requirements for organisations that process this data.

Section 05

Legal basis for processing

Under GDPR Article 6, we process personal data based on the following legal grounds:

  • Legitimate interests (Article 6(1)(f)): for B2B lead generation and outreach, we rely on legitimate business interests. CPG brands have a legitimate interest in contacting retailers and distributors with relevant business proposals.
  • Consent (Article 6(1)(a)): when you create a LaunchPal account, you explicitly consent to our processing of your account data.
  • Contract (Article 6(1)(b)): processing is necessary to fulfil our contractual obligations to provide you with lead generation and email outreach services.
  • Legal obligation (Article 6(1)(c)): when we must process data to comply with legal requirements, such as tax or financial reporting obligations.
06 · Critical

Your rights under GDPR

If you are located in the European Union or United Kingdom, you have the following rights:

01
Article 15
Right to access

Request a copy of the personal data we hold about you, including information about how we process it.

02
Article 16
Right to rectification

Correct any inaccurate or incomplete personal data we hold about you.

03
Article 17
Right to erasure

Also known as the "right to be forgotten." Request deletion of your personal data when it is no longer needed, you withdraw consent, you object to processing, or it has been unlawfully processed. Campaign leads can opt out by replying to any campaign email or contacting privacy@launchpal.io.

04
Article 18
Right to restrict processing

Limit how we use your personal data in certain situations, such as when you contest the accuracy of the data.

05
Article 20
Right to data portability

Receive your personal data in a structured, machine-readable format (CSV or JSON) and transmit that data to another controller.

06
Article 21
Right to object

Object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.

07
Article 22
Automated decision-making

Right not to be subject to decisions based solely on automated processing that significantly affect you. While we use AI for email generation, final approval always requires human review.

Section 07

Data retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in our Privacy Policy:

  • LaunchPal user accounts: retained while account is active, deleted within 30 days of account closure.
  • Campaign leads: retained for the duration of the campaign and 90 days after campaign completion, unless earlier deletion is requested.
  • Email integration tokens: immediately deleted upon disconnection.
  • Audit logs: retained for 2 years for compliance purposes.
  • Payment records: retained for 7 years to comply with tax and financial regulations.

When data is no longer needed, we securely delete or anonymise it in accordance with GDPR requirements.

Section 08

International data transfers

As LaunchPal operates globally, your data may be transferred to countries outside the EU/EEA. We ensure appropriate safeguards are in place for international transfers:

  • Standard Contractual Clauses (SCCs): we use EU Commission-approved SCCs with our service providers.
  • Adequacy decisions: where possible, we transfer data to countries recognised by the EU Commission as providing adequate data protection.
  • Encryption: all data transfers are encrypted in transit using TLS/HTTPS.
09

How to exercise your rights

To exercise any of your GDPR or CCPA rights:

LaunchPal users

Manage your data directly from your account dashboard.

Campaign leads

Reply to any campaign email with your request, or email privacy@launchpal.io.

We may ask you to verify your identity to protect your privacy and security. We will respond within 30 days (extendable by 2 months for complex requests, with notification).

There is no fee for exercising your rights. We may charge a reasonable fee if a request is clearly unfounded, repetitive, or excessive.

Section 10

Data security measures

We implement appropriate technical and organisational measures to protect your personal data in accordance with GDPR Article 32:

  • Encryption: data encrypted in transit (TLS/HTTPS) and at rest (AES-256).
  • Access controls: role-based access control (RBAC) and row-level security (RLS).
  • Authentication: multi-factor authentication available for user accounts.
  • Regular audits: security assessments and penetration testing.
  • Employee training: staff trained on GDPR compliance and data protection.
  • Incident response: documented procedures for data breach notification.
  • Data minimisation: we only collect data necessary for stated purposes.
Section 11

Data breach notification

In the event of a personal data breach, we comply with GDPR Articles 33 and 34:

  • Authority notification (Article 33): we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
  • Individual notification (Article 34): if the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
  • Breach documentation: we maintain records of all personal data breaches, including facts, effects, and remedial actions taken.

Notifications will include the nature of the breach, likely consequences, measures taken or proposed to address the breach, and contact information for our Data Protection Officer.

Section 12

Children's privacy

Our Service is not directed to individuals under 16 years of age (GDPR Article 8). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without appropriate parental consent, we will delete that information immediately.

Section 13

Right to lodge a complaint

Under GDPR Article 77, if you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local supervisory authority (Data Protection Authority).

European Data Protection Board, list of supervisory authorities ↗

We encourage you to contact us first at privacy@launchpal.io so we can address your concerns directly.

Section 14

Updates to this page

We may update this page periodically to reflect changes in our practices or legal requirements. The "Last updated" date at the top indicates when the most recent changes were made. Material changes will be communicated to you via email or prominent notice on our platform.

Section 15

Contact our DPO

If you have any questions about GDPR, CCPA, or how we handle your personal data, please contact our Data Protection Officer:

Data Protection Officer
General supportsupport@launchpal.io
AddressLaunchPal
101 Pakenham Street West
Auckland 1010, New Zealand