GDPR & CCPA
Last updated · January 29, 2026
Introduction
LaunchPal is committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA). This page explains how we comply with these frameworks for our B2B lead generation and email outreach platform.
For a comprehensive overview of our privacy practices, please see our Privacy Policy.
Our business model & data collection
LaunchPal provides a B2B lead generation service specifically for CPG/FMCG brands to connect with retailers, distributors, and buyers. Our platform:
- Collects publicly available business data from company websites, business directories, and public registries.
- Processes leads for business purposes only: CPG/FMCG suppliers reaching out to retailers and distributors.
- Sources email addresses from company websites: professional business email addresses, not personal emails.
- Includes proper sender identification: all emails include sender name, company, and contact information to comply with anti-spam laws.
We operate as a B2B platform facilitating legitimate business communications between suppliers and potential retail partners.
Cold email law compliance
LaunchPal complies with cold email regulations across multiple jurisdictions:
All emails include clear sender identification, accurate subject lines, and functional unsubscribe mechanisms. We comply with the requirement for B2B communications to include business contact information.
B2B emails to business email addresses are permitted under the business exemption. All emails include accurate sender information and opt-out mechanisms as required.
B2B cold emailing is permitted under the legitimate interest basis when contacting business email addresses for business purposes. All emails include proper identification and opt-out options.
All emails include accurate header information, clear subject lines, sender identification, physical postal address, and opt-out mechanisms honored within 10 business days.
B2B cold emails are permitted under the business relationship exemption when contacting business email addresses. All emails include clear identification and unsubscribe mechanisms.
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to all EU member states. It gives individuals control over their personal data and establishes strict requirements for organisations that process this data.
Legal basis for processing
Under GDPR Article 6, we process personal data based on the following legal grounds:
- Legitimate interests (Article 6(1)(f)): for B2B lead generation and outreach, we rely on legitimate business interests. CPG brands have a legitimate interest in contacting retailers and distributors with relevant business proposals.
- Consent (Article 6(1)(a)): when you create a LaunchPal account, you explicitly consent to our processing of your account data.
- Contract (Article 6(1)(b)): processing is necessary to fulfil our contractual obligations to provide you with lead generation and email outreach services.
- Legal obligation (Article 6(1)(c)): when we must process data to comply with legal requirements, such as tax or financial reporting obligations.
Your rights under GDPR
If you are located in the European Union or United Kingdom, you have the following rights:
Request a copy of the personal data we hold about you, including information about how we process it.
Correct any inaccurate or incomplete personal data we hold about you.
Also known as the "right to be forgotten." Request deletion of your personal data when it is no longer needed, you withdraw consent, you object to processing, or it has been unlawfully processed. Campaign leads can opt out by replying to any campaign email or contacting privacy@launchpal.io.
Limit how we use your personal data in certain situations, such as when you contest the accuracy of the data.
Receive your personal data in a structured, machine-readable format (CSV or JSON) and transmit that data to another controller.
Object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right not to be subject to decisions based solely on automated processing that significantly affect you. While we use AI for email generation, final approval always requires human review.
Data retention
We retain personal data only for as long as necessary to fulfil the purposes outlined in our Privacy Policy:
- LaunchPal user accounts: retained while account is active, deleted within 30 days of account closure.
- Campaign leads: retained for the duration of the campaign and 90 days after campaign completion, unless earlier deletion is requested.
- Email integration tokens: immediately deleted upon disconnection.
- Audit logs: retained for 2 years for compliance purposes.
- Payment records: retained for 7 years to comply with tax and financial regulations.
When data is no longer needed, we securely delete or anonymise it in accordance with GDPR requirements.
International data transfers
As LaunchPal operates globally, your data may be transferred to countries outside the EU/EEA. We ensure appropriate safeguards are in place for international transfers:
- Standard Contractual Clauses (SCCs): we use EU Commission-approved SCCs with our service providers.
- Adequacy decisions: where possible, we transfer data to countries recognised by the EU Commission as providing adequate data protection.
- Encryption: all data transfers are encrypted in transit using TLS/HTTPS.
How to exercise your rights
To exercise any of your GDPR or CCPA rights:
Manage your data directly from your account dashboard.
Reply to any campaign email with your request, or email privacy@launchpal.io.
We may ask you to verify your identity to protect your privacy and security. We will respond within 30 days (extendable by 2 months for complex requests, with notification).
There is no fee for exercising your rights. We may charge a reasonable fee if a request is clearly unfounded, repetitive, or excessive.
Data security measures
We implement appropriate technical and organisational measures to protect your personal data in accordance with GDPR Article 32:
- Encryption: data encrypted in transit (TLS/HTTPS) and at rest (AES-256).
- Access controls: role-based access control (RBAC) and row-level security (RLS).
- Authentication: multi-factor authentication available for user accounts.
- Regular audits: security assessments and penetration testing.
- Employee training: staff trained on GDPR compliance and data protection.
- Incident response: documented procedures for data breach notification.
- Data minimisation: we only collect data necessary for stated purposes.
Data breach notification
In the event of a personal data breach, we comply with GDPR Articles 33 and 34:
- Authority notification (Article 33): we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
- Individual notification (Article 34): if the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
- Breach documentation: we maintain records of all personal data breaches, including facts, effects, and remedial actions taken.
Notifications will include the nature of the breach, likely consequences, measures taken or proposed to address the breach, and contact information for our Data Protection Officer.
Children's privacy
Our Service is not directed to individuals under 16 years of age (GDPR Article 8). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without appropriate parental consent, we will delete that information immediately.
Right to lodge a complaint
Under GDPR Article 77, if you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local supervisory authority (Data Protection Authority).
European Data Protection Board, list of supervisory authorities ↗
We encourage you to contact us first at privacy@launchpal.io so we can address your concerns directly.
Updates to this page
We may update this page periodically to reflect changes in our practices or legal requirements. The "Last updated" date at the top indicates when the most recent changes were made. Material changes will be communicated to you via email or prominent notice on our platform.
Contact our DPO
If you have any questions about GDPR, CCPA, or how we handle your personal data, please contact our Data Protection Officer:
101 Pakenham Street West
Auckland 1010, New Zealand