Legal

Privacy policy

Last updated: 15 August 2026

We run outbound campaigns for other businesses, which means we handle contact details of people at companies — usually on our clients' behalf. This page explains what we collect, why, and what you can ask us to do about it.

On this page
  1. Who we are
  2. Two different roles we play
  3. What we collect
  4. Where the data comes from
  5. Why we process it, and on what basis
  6. Who we share it with
  7. International transfers
  8. How long we keep it
  9. Your rights
  10. Stopping contact from us
  11. Cookies and analytics
  12. Security
  13. Changes to this policy
  14. Contact us

1. Who we are

BalkanLead is a trading name of Balkan Bug LLC, a limited liability company registered in Texas, United States, with its registered address at 701 Tillery Street, Unit 12, Austin, TX 78702. Our operations team works from Serbia.

In this policy, "we", "us" and "our" mean Balkan Bug LLC. "You" means any individual whose personal data we handle — a visitor to this website, a person we contact as part of an outbound campaign, or a contact at one of our clients.

2. Two different roles we play

This distinction determines who is responsible for your data and who you should contact.

When we act on our own behalf (controller)

For this website, our own marketing, our own sales conversations and our internal administration, we decide why and how personal data is processed. We are the data controller, and this policy governs that processing.

When we act for a client (processor)

When we run outbound campaigns under a client's brand, that client decides who is contacted and why. The client is the data controller and we act as a processor following their instructions under a written agreement. In that case the client's own privacy notice governs the processing, and requests about your data are ultimately decided by them — though you can always contact us and we will pass your request on promptly and stop contacting you in the meantime.

3. What we collect

Website visitors

Standard technical information generated when you load a page: pages viewed, approximate location derived from IP address at country level, referring site, device type and browser. We use privacy-focused analytics that does not use cookies to track you across sites and does not build an advertising profile of you. See Cookies and analytics.

Business contacts in outbound campaigns

Business contact details in a professional capacity: full name, job title, employer, business email address, business phone number, public professional profile (such as LinkedIn), and notes about our interaction — for example whether a call took place, what was discussed, and whether you asked not to be contacted again. Calls may be recorded for quality and training purposes where the applicable law permits it and, where required, only after notice is given at the start of the call.

Clients and prospective clients

Name, business contact details, the content of our correspondence, contract and billing information, and records of the services we provided.

We do not deliberately collect special category data (such as health, political opinions, religious beliefs, trade union membership or biometric data) and we ask that you do not send it to us.

4. Where the data comes from

5. Why we process it, and on what basis

Where the GDPR or UK GDPR applies, our legal bases are:

For recipients in the United States, our email outreach is conducted in line with the CAN-SPAM Act: messages identify the sender, include a valid postal address and a working way to opt out, and we honour opt-outs promptly. Telephone outreach is screened against applicable do-not-call requirements.

6. Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. If you are a California resident, this means we have no "sale" or "sharing" for you to opt out of under the CCPA/CPRA — but your other rights below still apply.

7. International transfers

We are a US company with an operations team in Serbia, and we serve clients in the United States, United Kingdom, Canada and Australia. Personal data will therefore be transferred outside the European Economic Area and the United Kingdom.

Where we transfer personal data from the EEA or UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), together with additional safeguards where appropriate. You can request a copy of the relevant safeguards using the contact details below.

8. How long we keep it

9. Your rights

Depending on where you live, you may have the right to:

To exercise any of these, email us at the address below. We will respond within one month (GDPR) or 45 days (CCPA/CPRA), and will tell you if we need longer. We may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

If we handled your data as a processor for a client, we will forward your request to that client and confirm to you that we have done so.

If you are in the EEA or UK and are unhappy with how we handled your request, you can complain to your local data protection authority. We would appreciate the chance to address it first.

10. Stopping contact from us

You can stop hearing from us at any time, and you do not need to give a reason:

We add the details to a permanent suppression list. Requests are actioned within 10 business days, and usually much sooner. If a campaign was run under a client's brand, tell us which brand contacted you so we can suppress you there as well.

11. Cookies and analytics

This website does not use advertising or tracking cookies, and it does not run third-party advertising pixels.

We use Vercel Web Analytics to count page views and understand which pages are read. It is designed to be privacy-friendly: it does not set tracking cookies, does not store an identifier on your device that follows you across websites, and does not create a profile of you. Where it processes an IP address, it is used transiently to derive coarse information such as country and is not retained in a form that identifies you.

Our site loads fonts from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address as part of that request. If you would prefer to avoid this, browser extensions that block third-party requests will prevent it, and the site remains fully readable.

Our hosting provider, Vercel, keeps short-lived server logs for security and reliability.

12. Security

We use access controls, encryption in transit, multi-factor authentication on business systems, and limit access to personal data to staff who need it for their work. Our SDRs are trained on data handling and are bound by confidentiality obligations. No system is perfectly secure, but if a breach affects your personal data and poses a risk to you, we will notify you and the relevant regulator as the law requires.

13. Changes to this policy

We will update this page when our practices change. The "last updated" date at the top always reflects the current version. Material changes affecting people we hold data about will be reflected here before they take effect.

14. Contact us

For anything in this policy — access requests, deletion, opt-outs, or a question about a call you received — contact us and a person will read it.

Data protection contact

Balkan Bug LLC (trading as BalkanLead)

701 Tillery Street, Unit 12, Austin, TX 78702, United States

Email: info@balkanbug.com

Phone: +381 63 200212 · Mon–Fri, 09:00–19:00 CET