HercuLeads – Privacy Policy
Effective Date: 29 May 2024
Your Privacy Matters to Us
At HercuLeads, we’re committed to protecting your personal data with the highest standards of security and transparency. As a UK-based lead generation specialist, we adhere strictly to the General Data Protection Regulation (GDPR-UK) and ensure all data processing is fair, lawful, and designed with your rights in mind.
This policy explains how we collect, use, and safeguard your data—whether you’re a visitor to our website, a lead, or a business client.
For privacy-related inquiries, contact our Data Protection Officer (DPO):
📧 Email: dpo@herculeads.co.uk
Key Principles
- Consent-Driven: We rely on your explicit “opt-in” for marketing, data sharing, or non-essential tracking.
- Purpose-Limited: Data is only used for the reasons you’ve approved (e.g., generating quotes or delivering leads).
- Secure by Design: Encryption, access controls, and regular audits protect your information.
- Transparent: Clear explanations of what we collect and why.
What We Collect & Why
Data Type | Purpose | Legal Basis |
---|---|---|
Contact details (email, phone) | Deliver requested quotes/services | Consent / Contract |
Website usage data | Improve site performance (anonymized where possible). | Legitimate Interest |
Lead preferences | Match you with relevant home improvement/solar providers. | Consent |
We never:
- Sell your data to third parties.
- Use “pre-ticked” boxes for consent.
- Process sensitive data (e.g., health, financial details) without explicit permission.
Your Rights
Under GDPR, you can:
- Access your data or request a copy.
- Correct inaccurate information.
- Delete your data (where applicable).
- Withdraw consent at any time (e.g., unsubscribe from emails).
- Object to processing based on legitimate interests.
To exercise these rights, email: dpo@herculeads.co.uk.
Data Sharing & International Transfers
- Partners: Your data is shared with home improvement/solar businesses only with your explicit opt-in.
- Service Providers: We use GDPR-compliant vendors (e.g., cloud hosting) under strict contracts.
- International Transfers: Data stays within the UK/EEA unless safeguards (e.g., Standard Contractual Clauses) are in place.
Security & Retention
- Encryption: Data is secured in transit and at rest.
- Retention Periods: Kept only as long as necessary (e.g., 2 years for lead inquiries unless deleted sooner).
- Breach Protocol: Immediate action and notification to the ICO if risks arise.
Cookies & Tracking
- Essential Cookies: Required for site functionality (no consent needed).
- Analytics/Marketing Cookies: Only activated with your opt-in via our cookie banner.
Policy Updates
We’ll notify you of significant changes via email or website notices.
Last Updated: 2 June 2025