Legal
Privacy policy
We run outbound campaigns for other businesses, which means we handle contact details of people at companies — usually on our clients' behalf. This page explains what we collect, why, and what you can ask us to do about it.
1. Who we are
BalkanLead is a trading name of Balkan Bug LLC, a limited liability company registered in Texas, United States, with its registered address at 701 Tillery Street, Unit 12, Austin, TX 78702. Our operations team works from Serbia.
In this policy, "we", "us" and "our" mean Balkan Bug LLC. "You" means any individual whose personal data we handle — a visitor to this website, a person we contact as part of an outbound campaign, or a contact at one of our clients.
2. Two different roles we play
This distinction determines who is responsible for your data and who you should contact.
When we act on our own behalf (controller)
For this website, our own marketing, our own sales conversations and our internal administration, we decide why and how personal data is processed. We are the data controller, and this policy governs that processing.
When we act for a client (processor)
When we run outbound campaigns under a client's brand, that client decides who is contacted and why. The client is the data controller and we act as a processor following their instructions under a written agreement. In that case the client's own privacy notice governs the processing, and requests about your data are ultimately decided by them — though you can always contact us and we will pass your request on promptly and stop contacting you in the meantime.
3. What we collect
Website visitors
Standard technical information generated when you load a page: pages viewed, approximate location derived from IP address at country level, referring site, device type and browser. We use privacy-focused analytics that does not use cookies to track you across sites and does not build an advertising profile of you. See Cookies and analytics.
Business contacts in outbound campaigns
Business contact details in a professional capacity: full name, job title, employer, business email address, business phone number, public professional profile (such as LinkedIn), and notes about our interaction — for example whether a call took place, what was discussed, and whether you asked not to be contacted again. Calls may be recorded for quality and training purposes where the applicable law permits it and, where required, only after notice is given at the start of the call.
Clients and prospective clients
Name, business contact details, the content of our correspondence, contract and billing information, and records of the services we provided.
We do not deliberately collect special category data (such as health, political opinions, religious beliefs, trade union membership or biometric data) and we ask that you do not send it to us.
4. Where the data comes from
- Directly from you — when you call us, email us, or speak with one of our SDRs.
- Publicly available business sources — company websites, public professional networking profiles, company registries, published directories and industry listings.
- Licensed B2B data providers — who represent to us that they collected the data lawfully and that individuals were given the required notice.
- Our clients — where a client supplies a target list or their own customer base for renewals, upsell or win-back campaigns. The client is responsible for having a lawful basis for sharing that data with us.
5. Why we process it, and on what basis
Where the GDPR or UK GDPR applies, our legal bases are:
- Legitimate interests (Article 6(1)(f)) — for business-to-business outreach to individuals in their professional capacity, for running and improving our own business, for website analytics, and for keeping records of who has asked not to be contacted. We have weighed our interest in marketing our clients' and our own services against your interests, rights and freedoms; we contact people only in a professional capacity, about products relevant to their role, and we stop as soon as we are asked to.
- Performance of a contract (Article 6(1)(b)) — to deliver services to clients and administer that relationship.
- Consent (Article 6(1)(a)) — where the law requires consent for a particular channel or jurisdiction, for example certain electronic marketing or call recording. Where we rely on consent you may withdraw it at any time.
- Legal obligation (Article 6(1)(c)) — for tax, accounting and responding to lawful requests.
For recipients in the United States, our email outreach is conducted in line with the CAN-SPAM Act: messages identify the sender, include a valid postal address and a working way to opt out, and we honour opt-outs promptly. Telephone outreach is screened against applicable do-not-call requirements.
6. Who we share it with
- Our clients — campaign results, meeting notes and contact records for campaigns run on their behalf.
- Service providers who process data on our instructions under contract: CRM and sales engagement platforms, email delivery and deliverability tools, telephony and call recording providers, cloud hosting and storage, and analytics. We require them to protect the data and to use it only for the service they provide to us.
- Professional advisers — accountants and lawyers, where necessary.
- Authorities — where we are legally required to disclose, or to establish or defend legal claims.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. If you are a California resident, this means we have no "sale" or "sharing" for you to opt out of under the CCPA/CPRA — but your other rights below still apply.
7. International transfers
We are a US company with an operations team in Serbia, and we serve clients in the United States, United Kingdom, Canada and Australia. Personal data will therefore be transferred outside the European Economic Area and the United Kingdom.
Where we transfer personal data from the EEA or UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), together with additional safeguards where appropriate. You can request a copy of the relevant safeguards using the contact details below.
8. How long we keep it
- Prospect records — for as long as the contact remains commercially relevant, and reviewed at least every 24 months. Records that are stale or that we no longer have a basis to hold are deleted.
- Do-not-contact records — indefinitely. We keep the minimum necessary (typically an email address, phone number or domain) precisely so we do not contact you again. This is in your interest and we will not delete it on request unless you insist, in which case we can no longer guarantee you will not be contacted.
- Call recordings — no longer than 12 months unless a specific matter requires otherwise.
- Client records — for the duration of the engagement and for as long afterwards as required for tax, accounting and limitation periods.
- Data processed for a client — deleted or returned at the end of the engagement, per our agreement with that client.
9. Your rights
Depending on where you live, you may have the right to:
- know what personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to processing — including an absolute right to object to direct marketing, which we will always honour;
- receive data you gave us in a portable format;
- withdraw consent, where we relied on it;
- not be discriminated against for exercising these rights.
To exercise any of these, email us at the address below. We will respond within one month (GDPR) or 45 days (CCPA/CPRA), and will tell you if we need longer. We may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
If we handled your data as a processor for a client, we will forward your request to that client and confirm to you that we have done so.
If you are in the EEA or UK and are unhappy with how we handled your request, you can complain to your local data protection authority. We would appreciate the chance to address it first.
10. Stopping contact from us
You can stop hearing from us at any time, and you do not need to give a reason:
- tell the SDR during a call — it is recorded on the spot;
- reply to any email asking to be removed, or use the unsubscribe link;
- email us directly using the details below, including the email address, phone number or company domain you want suppressed.
We add the details to a permanent suppression list. Requests are actioned within 10 business days, and usually much sooner. If a campaign was run under a client's brand, tell us which brand contacted you so we can suppress you there as well.
11. Cookies and analytics
This website does not use advertising or tracking cookies, and it does not run third-party advertising pixels.
We use Vercel Web Analytics to count page views and understand which pages are read. It is designed to be privacy-friendly: it does not set tracking cookies, does not store an identifier on your device that follows you across websites, and does not create a profile of you. Where it processes an IP address, it is used transiently to derive coarse information such as country and is not retained in a form that identifies you.
Our site loads fonts from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address as part of that request. If you would prefer to avoid this, browser extensions that block third-party requests will prevent it, and the site remains fully readable.
Our hosting provider, Vercel, keeps short-lived server logs for security and reliability.
12. Security
We use access controls, encryption in transit, multi-factor authentication on business systems, and limit access to personal data to staff who need it for their work. Our SDRs are trained on data handling and are bound by confidentiality obligations. No system is perfectly secure, but if a breach affects your personal data and poses a risk to you, we will notify you and the relevant regulator as the law requires.
13. Changes to this policy
We will update this page when our practices change. The "last updated" date at the top always reflects the current version. Material changes affecting people we hold data about will be reflected here before they take effect.
14. Contact us
For anything in this policy — access requests, deletion, opt-outs, or a question about a call you received — contact us and a person will read it.
Balkan Bug LLC (trading as BalkanLead)
701 Tillery Street, Unit 12, Austin, TX 78702, United States
Email: info@balkanbug.com
Phone: +381 63 200212 · Mon–Fri, 09:00–19:00 CET