Client Login
Book a Call Request a Proposal

Legal

Privacy Policy

Last updated 18 September 2026

This policy explains what personal information Junoleads Pty Ltd collects, why we collect it, who we share it with, and what you may ask us to do about it. It applies to our website at junoleads.io, to the Junoleads client portal, and to the outbound campaigns we run for our clients.

Contents

  1. Who we are and what this policy covers
  2. Information we collect
  3. Google user data
  4. Microsoft calendar data
  5. How we use information
  6. AI and automated processing
  7. Who we share information with
  8. Where information is stored
  9. How long we keep information
  10. Security
  11. Your rights and choices
  12. Cookies and tracking
  13. Children's data
  14. Changes to this policy
  15. Contact and complaints

Who we are and what this policy covers

Junoleads is a business-to-business go-to-market agency. We plan and run outbound campaigns — cold email, LinkedIn outreach, and the systems behind them — on behalf of our clients, and we operate a client portal in which those clients review leads, manage campaigns and handle replies.

The entity responsible for personal information handled through our services is Junoleads Pty Ltd, ABN 68693511563, a company registered in New South Wales, Australia. References in this policy to "we", "us" and "Junoleads" are references to that entity.

This policy applies to three groups of people, and different parts of it are relevant to each:

  • Visitors to junoleads.io.
  • Clients and their users — those who sign in to the Junoleads client portal at app.junoleads.io, including anyone who connects a Google or Microsoft calendar to it. The portal is not open to the public: an account must be created for you before you are able to sign in.
  • Prospects — those we contact as part of an outbound campaign. If you have received an email or a message from us and wish to know where your details came from, or how to stop hearing from us, see Prospect and contact data and Stopping outreach from us.

This policy does not extend to our clients' independent handling of information within their own systems after we have delivered it to them. Where we act on a client's instructions, our handling is additionally governed by our agreement with that client.

Information we collect

Website visitors

When you visit junoleads.io, our hosting provider records standard server-log information: your IP address, the pages requested, the site or search that referred you, and basic device and browser details. This is used to serve the site, diagnose faults and protect against abuse. We do not operate website analytics on junoleads.io, and we set no cookies of our own, as described in Cookies and tracking.

If you book a call, request a proposal or apply for a role, you provide your name, email address, company, and any other information you choose to enter in the form. Those forms and the booking calendar are hosted by third parties, as described in Who we share information with.

Client accounts and the client portal

For clients we hold account and contact details for each user, sign-in information, billing and engagement records, and the configuration of your campaigns: your ideal-customer profiles, targeting criteria, messaging angles and approved copy. We also hold the operational data your campaigns generate — which prospects were contacted, the messages sent, delivery and reply events, the replies themselves, and the drafts prepared for your review.

Calendar connections

If you connect a calendar so that Junoleads is able to offer your genuine availability in a reply and book meetings on your behalf, we access a narrow portion of your calendar account. Because this is the most sensitive category of information we handle, and because Google and Microsoft impose their own requirements on it, it is dealt with separately in Google user data and Microsoft calendar data. Connecting a calendar is optional; the portal operates without one.

Prospect and contact data

In order to run outbound campaigns we build and maintain a database of business contacts. This is personal information about people who have not provided it to us directly, so we set it out in detail below.

Where it comes from. Publicly available business sources and licensed business-to-business data providers: company websites, public professional profiles, job advertisements, business directories, and company, hiring and technology databases. Email addresses are checked against verification services to confirm that they are valid and deliverable. We do not purchase consumer data, and we do not knowingly collect sensitive or special-category information.

What we hold. Your name, business email address, job title, employer and information about that employer, your public professional profile and photograph, your professional history and stated skills, your general location, and in some cases a publicly listed business telephone number. We may also hold research and summaries that our systems generate about you in your professional capacity. If you reply to us, we hold your reply, our response, and any classification applied to the conversation.

Responsibility for this data, and its reuse. We source and maintain this database as our own rather than holding a separate list for each client, and the same contact record may therefore be used for more than one client's campaigns over time. Junoleads is the controller of that data. Where a client provides us with their own list, or directs a specific campaign, that client is the controller of what they have supplied and we act on their instructions in respect of it. The practical effect is that a single request to us covers every campaign we run, for every client, as described in Stopping outreach from us.

Our basis for holding it. Where the GDPR or UK GDPR applies, we rely on legitimate interests (Article 6(1)(f)) — direct business-to-business marketing to a person in their professional capacity, concerning services relevant to their role — having weighed that interest against your rights and freedoms. Where consent is required instead, we rely on consent. In Australia we handle personal information under the Privacy Act 1988 (Cth) and send marketing in accordance with the Spam Act 2003 (Cth); where recipients in the United States are contacted, we do so in accordance with the CAN-SPAM Act.

Google user data

If you connect a Google Account to the Junoleads client portal, we access part of your Google Calendar data through the Google Calendar API. This section describes that access in the terms required by the Google API Services User Data Policy. It applies only to those who choose to connect a Google Account; it does not apply to website visitors or to prospects.

What we request, and why

  • https://www.googleapis.com/auth/calendar.freebusy Read your free/busy availability
  • https://www.googleapis.com/auth/calendar.events Create and manage events on the calendar you connect

We use calendar.freebusy to determine the times at which you are genuinely free, so that a reply we prepare for a prospect offers real availability rather than assumed times. We use calendar.events to place a meeting on your calendar once a prospect accepts one of those times.

We do not request access to Gmail, Google Drive, Google Contacts or any other Google service, and we do not request the broader calendar scope, which would grant full read and write access to every calendar on your account.

Nor do we use the narrower calendar.app.created scope, which would confine us to a secondary calendar created by the application itself. Meetings booked onto such a calendar would not appear in your own free/busy information, leaving your colleagues and your other scheduling tools free to book over them. We therefore write to the calendar you work from, since a booking that your own availability does not reflect fails to achieve what the feature exists to do.

What we access

  • Free/busy intervals — the start and end times of the periods during which you are busy. Google's free/busy endpoint returns times alone: we do not receive, and are unable to see, your event titles, descriptions, locations, attendees, guests or attachments.
  • Events we create — the meetings Junoleads books on your behalf, and their status.

What we store

  • The OAuth access and refresh tokens that allow the connection to continue operating without requiring you to sign in for each booking, held in encrypted storage.
  • The identity of the connected account, which is sufficient for the portal to display which calendar is connected and to allow you to disconnect it.
  • A record of the meetings we have booked for you.

We do not retain a copy of your calendar. Free/busy information is read at the moment a draft reply is prepared and is used to select the times that draft offers; it is not retained as a calendar record, although the times offered remain visible within the draft itself as part of that conversation.

How we use it, and what we never do with it

Google user data is used for a single purpose: providing the availability and booking feature that you have enabled. We do not use it for advertising, we do not sell it, we do not transfer it to data brokers or credit agencies, and we do not use it to develop, improve or train generalised artificial intelligence or machine-learning models. Junoleads personnel do not read Google user data except with your explicit consent, where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.

Limited Use. Junoleads' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Who it is shared with

The candidate meeting times derived from your free/busy information are sent to the AI provider that composes the draft reply offering those times, as described in AI and automated processing. That provider processes them as our service provider, does not train its models on them, and retains them only for a limited period. Google user data is otherwise held only within the infrastructure we use to operate the portal, and is not shared with any other party.

Revoking access and deleting your data

You may disconnect your calendar at any time within the portal, or revoke Junoleads' access directly from your Google Account at myaccount.google.com/permissions. On revocation the feature ceases to operate, and we delete the stored tokens and the connection record within 30 days. Meetings already created on your calendar remain there: they are your events, and you may delete them yourself. To have any other information removed, email privacy@junoleads.io.

Microsoft calendar data

Where you connect a Microsoft 365 or Outlook calendar rather than a Google Account, Junoleads accesses your calendar through the Microsoft Graph API, under delegated permissions that you grant. The permissions we request are:

  • Calendars.Read Read your free/busy availability
  • Calendars.ReadWrite Create and manage events on the calendar you connect
  • offline_access Keep the connection alive without asking you to sign in again
  • User.Read Read your basic profile so we can label the connected account

We read availability in order to offer genuine times, and write events in order to book confirmed meetings. We do not request access to your mailbox, to your files, or to your organisation's directory beyond your own basic profile.

Everything stated in Google user data about what we store, how we use it, who it is shared with, how long we retain it, and what we never do with it applies equally to calendar data obtained from Microsoft. You may revoke access from your Microsoft account settings, or by disconnecting the calendar within the portal; on revocation we delete the stored tokens and the connection record within 30 days. Some organisations require an administrator to approve the connection before you are able to grant it.

How we use information

  • To operate, secure and support the client portal and our services.
  • To plan, run, measure and improve outbound campaigns — including building and qualifying target lists, drafting messages, sending them, and reporting on results.
  • To read availability and book meetings, where a client has connected a calendar for that purpose.
  • To respond to enquiries, proposals and job applications.
  • To invoice, maintain business records, and meet our legal and tax obligations.
  • To understand how our website is used, at an aggregate and company level, so that we are able to improve it.

Where the GDPR or UK GDPR applies, we rely on the following bases: performance of a contract, in operating the portal and delivering services to clients; legitimate interests, in business-to-business marketing, in securing and improving our services, and in business administration; consent, where we have requested it; and compliance with legal obligations. Where we rely on legitimate interests you have the right to object, as described in Your rights and choices.

AI and automated processing

We use third-party large language models to carry out parts of our campaign work. The following is sent to those providers:

  • Replies you send us — the body of your reply, together with your name and email address, so that the model is able to classify what the reply indicates, such as interested, not interested, unsubscribe, or out of office, and to prepare a suggested response.
  • Prospect and company research — the business information described in Prospect and contact data, so that the model is able to assess whether a contact fits a client's target profile and to draft relevant copy. Some of this content is also converted into numerical embeddings for search.
  • Candidate meeting times, where a calendar is connected, as described in Google user data.

These providers act on our behalf as service providers, process the content on our instructions, and do not use it to train their models. Drafts prepared in this way are reviewed by a person before they are sent, and we do not take decisions producing legal or similarly significant effects concerning you by automated means alone.

Who we share information with

We do not sell personal information. We share it in the following four circumstances.

  • With our clients. The prospects contacted for a campaign, the replies received and the leads generated are visible to the client for whom that campaign was run, including through shared review channels in that client's own messaging tools.
  • With service providers that process information on our behalf, under contract and only for the purposes we set. These fall into the following categories: cloud hosting and application infrastructure; database and file storage; email sending, mailbox and deliverability platforms; LinkedIn outreach tooling; business-to-business data, enrichment and email-verification providers; AI model and embedding providers; workflow automation; scheduling and form tools; internal CRM and team messaging; domain registration; and payment, invoicing and accounting providers.
  • In a business transfer — if Junoleads is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction.
  • Where the law requires it — in order to comply with a legal obligation, or to establish, exercise or defend legal claims.

A current list of the service providers we use is available on request. Data obtained from a connected calendar is subject to the narrower restrictions set out in Google user data.

Where information is stored

Junoleads operates from Australia, and our primary database is hosted in Australia. Some of our service providers operate in the United States, the European Union and the United Kingdom, so personal information may also be stored or processed outside the country in which you are located. Where we transfer personal information from the EEA or the United Kingdom, we rely on Standard Contractual Clauses or another lawful transfer mechanism. Where Australian Privacy Principle 8 applies, we take reasonable steps to ensure that overseas recipients handle the information consistently with the Australian Privacy Principles.

How long we keep information

  • Calendar connections — until you disconnect or revoke access, after which the stored tokens and connection record are deleted within 30 days.
  • Client account and campaign data — for the duration of the engagement, and subsequently for as long as we require it in order to meet Australian record-keeping, tax and legal obligations.
  • Prospect data — while it remains relevant to campaigns we run, and removed or anonymised once it ceases to be relevant, or on request.
  • Suppression records — retained indefinitely. If you ask us never to contact you again, we must retain the minimum record necessary to identify you and honour that request. This is the only category of information we retain following a deletion request, and it is retained solely for that purpose.
  • Server logs — retained by our hosting provider for a limited period, under its own retention schedule.

Security

We protect information in transit using TLS, hold mailbox credentials and OAuth tokens in encrypted storage rather than as ordinary database fields, separate each client's data at the database level, and restrict access to the personnel who require it for their work. No method of transmission or storage is entirely secure, and we are unable to guarantee absolute security. In the event of a data breach likely to result in serious harm, we will notify the people affected and the relevant regulator as required by law.

Your rights and choices

Stopping outreach from us

Every email we send carries an unsubscribe address, and a reply asking us to stop is equally effective: such replies are detected and acted upon automatically. LinkedIn messages carry no unsubscribe link, so reply to the message itself or write to privacy@junoleads.io.

However the request reaches us, we add you to a suppression list that applies across every campaign we run, including campaigns run for clients, and you will not be contacted through us again. We act on these requests promptly and do not require you to give a reason. We do not use open or read tracking in our emails.

Access, correction and deletion

You may ask what personal information we hold about you, ask us to correct it, and ask us to delete it. Email privacy@junoleads.io and we will respond within 30 days. Prospects do not hold an account with us, so these rights are exercised by email and no account is required. We may need to verify your identity before acting, and we may retain information where the law requires it, or where we require it in order to honour a suppression request.

If you are in the EEA or the United Kingdom

You additionally have the right to object to processing based on legitimate interests, including direct marketing, which we will always honour; the right to restrict processing; the right to data portability; and the right to withdraw consent where we have relied on it. Any of these may be exercised through the same address. You may also lodge a complaint with your local supervisory authority.

If you are in California

You have the right to know what personal information we collect and how we use it, to request its deletion or correction, and not to be discriminated against for exercising those rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Cookies and tracking

Junoleads does not operate website analytics on junoleads.io. We set no cookies of our own, and we use no advertising cookies, tracking pixels or visitor-identification tools.

Our homepage embeds the Cal.com booking widget, so that a call may be booked without leaving the site. That widget is loaded from Cal.com and may set its own cookies; what it collects is governed by Cal.com's privacy policy. The proposal and careers forms are hosted by Tally and are governed by Tally's privacy policy; those are ordinary links, so nothing is loaded from Tally unless you follow one.

Our hosting provider, Cloudflare, processes request information including your IP address in order to serve and protect the site, and retains it in server logs for a limited period.

You may block or delete cookies in your browser settings, and most browsers allow you to refuse third-party cookies without impairing this site. Should we adopt an analytics or visitor-identification tool in future, this section and the date at the top of this page will be updated before that tool is deployed.

Children's data

Junoleads provides services to businesses. Our services are not directed to children, we do not knowingly collect personal information from anyone under 16, and if we learn that we have done so, we will delete it.

Changes to this policy

We update this policy when our practices change. The date at the top of the page reflects the last substantive change. Where a change materially affects how we handle information you have already provided to us, including anything set out in Google user data, we will take reasonable steps to notify the people affected directly rather than relying on this page alone.

Contact and complaints

For any matter arising under this policy — access, correction, deletion, opting out, or a question about how we handle your information — contact:

Junoleads Pty Ltd
ABN 68693511563
privacy@junoleads.io

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au, or, if you are in the EEA or the United Kingdom, with your local data protection supervisory authority.

© 2026 Junoleads PTY LTD All rights reserved

Privacy Careers