Skip to content
NextCog
SolutionsHow it worksSecurityAboutContact
Try Lead Research Agent→
SolutionsHow it worksSecurityAboutContactTry Lead Research Agent →
Home/Lead Research Agent/LeadResearchAgent Privacy

LeadResearchAgent legal

LeadResearchAgent Privacy Notice

This Notice explains how personal data is handled for LeadResearchAgent accounts, imported professional Contacts, requested public-source Research, and generated outreach Drafts.

Service
LeadResearchAgent
Version
1.0
Effective and last updated
27 July 2026

Contents

  1. Who is responsible
  2. People covered
  3. Data about account Users
  4. Imported Contact data
  5. Publicly researched data
  6. Sources of personal data
  7. Purposes and legal bases
  8. Professional prospecting responsibilities
  9. Automated analysis and human review
  10. AI and search providers
  11. Service providers and subprocessors
  12. International transfers
  13. Retention
  14. Security
  15. Cookies and local storage
  16. Data-subject rights
  17. Imported or researched Contacts
  18. Children
  19. Changes to this Notice
  20. Contact and complaints
At a glance. Customers decide which professional Contacts to add and whether to request Research or generate a Draft. LeadResearchAgent produces material for a User to review; it does not decide that outreach is lawful or send a message on the Customer’s behalf. NextCog handles account, service, support, and security data and processes Customer-provided Contact data to deliver the service. The detailed allocation of privacy responsibilities depends on the activity and applicable agreement.

1. Who is responsible for processing

LeadResearchAgent is operated by NEXTCOG, a Société par actions simplifiée (SAS) with its registered office at 73 Boulevard de Strasbourg, 34000 Montpellier, France (“NextCog,” “we,” or “us”).

Registration
888 436 672 RCS Montpellier
SIREN / SIRET
888 436 672 / 888 436 672 00024
Privacy contact
NextCog contact page or the registered office above

The privacy role depends on why and how the data is processed:

  • NextCog as controller. NextCog determines the purposes and essential means for account creation, authentication administration, subscription or entitlement administration, service security, abuse prevention, support, legal compliance, and core product operations. NextCog may also act as controller where it independently determines a purpose for service analytics, reliability improvement, or legal claims.
  • The Customer Organization as controller. The Customer generally decides which Contacts to create or import, what Campaign objectives to pursue, what Research to request, who to contact, the communication channel, and whether to use a Draft.
  • NextCog as processor or service provider. Where NextCog handles Customer-provided Contact data solely to provide the configured service on the Customer’s documented instructions, NextCog acts for the Customer. The applicable contract or data processing agreement may describe those instructions and duties in more detail.

A label does not override the parties’ actual decisions and obligations under applicable law. For an activity in which both parties independently determine purposes or essential means, each may have its own controller responsibilities.

2. People covered by this Notice

This Notice covers personal data relating to:

  • account holders and Organization administrators;
  • Users invited to an Organization workspace;
  • people who contact support or make a privacy request;
  • visitors to the LeadResearchAgent application;
  • professional Contacts whose records a Customer creates or imports; and
  • people whose public professional information a User asks the service to research.

Sections about accounts, authentication, usage, billing, and support primarily concern Users. Sections about imports, public Research, prospecting, and indirect collection primarily concern imported or researched Contacts. A person may fall into more than one category.

3. Data about account Users

Depending on the features a User chooses and the account configuration, LeadResearchAgent may process:

  • name, email address, profile image, and an identifier or claims supplied by a configured authentication provider;
  • professional role, sender profile, Organization details, and workspace membership;
  • Campaign objectives, message preferences, instructions, and saved settings;
  • files the User imports and the resulting Contact records;
  • Research requests and results, Drafts, edits, review actions, corrections, and feedback;
  • plan entitlement, quotas, usage counts, and subscription or billing status where applicable;
  • support correspondence and privacy or account requests; and
  • IP address, date and time, device and browser information, session events, requested actions, error records, and security or audit events.

Exact fields depend on what the User supplies, the identity provider returns, and the features enabled for the Customer.

4. Imported Contact data

A Customer may create or upload professional Contact information such as a name, professional role, Organization, professional profile URL, professional email address, professional telephone number, company website, work location, import source or date, notes, and Campaign assignment. The exact fields depend on the file or record the Customer supplies.

LeadResearchAgent does not require special-category or other highly sensitive personal data for its ordinary purpose. Customers should not upload information about health, biometrics, religion, political opinions, union membership, sexual life or orientation, racial or ethnic origin, criminal allegations, government identifiers, financial accounts, passwords, or similarly sensitive matters unless a documented lawful purpose and an applicable agreement expressly justify it.

A User-provided LinkedIn export is treated as an imported file. Importing it is not LinkedIn authentication. LeadResearchAgent is not LinkedIn and is not affiliated with, endorsed by, or sponsored by LinkedIn. LinkedIn names and trademarks belong to their respective owners.

5. Publicly researched data

When a User requests Research, the service may collect relevant professional or Organization information from lawfully accessible public sources such as corporate websites, public business announcements, public professional profiles, articles, publications, public conference material, search results, and registries or directories where appropriate.

Research results may contain:

  • source-backed professional or Organization facts and links to their sources;
  • generated summaries of public material;
  • inferences about possible relevance, context, or business signals;
  • confidence indicators or uncertainty notes; and
  • suggested message angles or other preparation material.

An inference, summary, confidence indicator, or suggested angle is generated analysis, not necessarily a confirmed fact. Public information and generated results can be inaccurate, incomplete, or outdated. Users are required by the LeadResearchAgent Terms to verify material claims before use.

6. Sources of personal data

Personal data may come from:

  • an account User directly;
  • the Customer Organization, including imported files and instructions from its Users;
  • a configured authentication provider’s identity claims;
  • Organization websites and public professional or corporate sources;
  • configured search providers and the results they return for a User-requested operation;
  • service-generated usage, quota, audit, error, and security records; and
  • User feedback, corrections, support messages, and account requests.

7. Purposes and legal bases

The table describes NextCog’s intended processing. “Contract” includes steps requested before a User or Customer enters a contract. “Legitimate interests” are used only after considering the purpose, necessity, and effect on the people concerned. Where NextCog acts solely as processor, the Customer determines its own lawful basis.

Processing purposeData categoriesAffected peopleLegal basisRetention approach
Create and manage accounts and workspacesIdentity, contact, role, Organization, membership, settingsUsers and administratorsContract; legitimate interests in Organization administrationWhile the account is active, then closure and legal-record criteria below
Authenticate UsersProvider identifier and claims, session, IP, device, security eventsUsersContract; legitimate interests in secure accessSession lifetime plus proportionate security-log periods
Provide the requested SaaSCustomer Data, instructions, profiles, Campaigns, usageUsers and ContactsContract for User data; Customer instructions where NextCog is processor; Customer’s legal basis for Contact dataActive service period and deletion/return terms
Import, organize, and de-duplicate ContactsImported files, professional Contact fields, import metadataImported Contacts and UsersCustomer instructions; contract for the requested operationUntil Customer deletion or account closure, subject to backups and legal holds
Perform requested Research and generate DraftsContact and Organization data, public sources, profiles, objectives, prompts, outputsContacts and UsersCustomer instructions; contract for the requested operation; any independent NextCog purpose requires its own lawful basisWith the related Contact or Campaign until deleted or the account closes
Apply entitlements, quotas, and billingPlan, usage, transaction status, invoice and Organization detailsCustomers, administrators, and UsersContract; legal obligations for accounting and tax recordsOperational period plus applicable statutory accounting periods
Support and service communicationsContact details, correspondence, diagnostics, account eventsUsers and requestersContract; legitimate interests in support and service administrationWhile needed to resolve the issue and for proportionate claim records
Prevent fraud, abuse, and security incidentsIP, device, session, audit, error, access, and investigation dataUsers, visitors, and affected ContactsLegitimate interests; legal obligations where applicableRisk-based log period; longer only for an incident, claim, or legal duty
Maintain and improve reliability and usabilityFeature events, performance, errors, feedback, preferably minimized or aggregatedUsersLegitimate interests, subject to balancing and user expectationsOnly while useful for defined improvement and validation work
Meet legal duties and manage claimsRelevant account, acceptance, billing, security, request, and dispute recordsUsers, Customers, Contacts, and requestersLegal obligation; legitimate interests in establishing or defending rightsApplicable legal period or until the claim is resolved
Optional NextCog marketing, if offeredContact details, preferences, and engagement where lawfully collectedUsers who separately receive itConsent where required; otherwise a validated legitimate interest and right to objectUntil withdrawal, objection, or the defined inactivity period

Optional marketing is separate from necessary account and security messages. Refusing or withdrawing optional marketing consent does not prevent use of the contracted service.

8. Professional prospecting responsibilities

LeadResearchAgent generates Drafts but does not determine that outreach is lawful. The Customer controls which Contacts it selects, the purpose and audience of each Campaign, the communication channel, whether a Draft is used, and whether a message is sent.

The Customer is responsible for the privacy notices, lawful basis, electronic-marketing rules, platform requirements, and opt-out mechanism applicable to each Campaign. It must respect objections and suppression requests and must not use the service to evade a person’s choice, a platform restriction, or applicable law. A professional context does not make every B2B message automatically lawful.

9. Automated analysis and human review

LeadResearchAgent analyzes professional and Organization information. It may organize sources, assess apparent relevance, identify possible business signals, produce inferences or confidence indicators, and generate suggested Drafts. This analysis may constitute profiling depending on the Customer’s configuration and use.

Outputs require User review. The service is not intended to make a solely automated decision that produces legal or similarly significant effects on a Contact. Customers must not use an output as the sole basis for an employment, credit, insurance, healthcare, housing, education, legal, or other high-impact decision. A User should correct or disregard an unsupported inference.

10. AI and search providers

When a User initiates Research or Draft generation, LeadResearchAgent may send the data needed for that operation to configured search or language-model providers. Depending on the task, this can include a professional Contact’s name, role, Organization, public profile URL, relevant public-source text, sender and Organization profiles, Campaign objectives, User instructions, and a generated prompt. Users control whether to initiate the relevant operation and what optional context they provide.

Providers process data to return search results, analyze supplied context, or generate the requested output. Their exact retention, region, and model-improvement treatment depend on the provider, account type, contract, and settings configured by NextCog. This Notice does not claim that every provider offers zero retention, excludes all model training, or processes only in the European Economic Area. Current provider information and applicable settings may be requested through the contact page.

Users should minimize personal data in instructions and must not submit passwords, credentials, or unnecessary sensitive personal data to a Research or generation operation.

11. Service providers and subprocessors

Depending on the configured service and Customer plan, personal data may be handled by providers supporting:

  • application hosting, storage, databases, and backups;
  • authentication and account security;
  • transactional email and service communications;
  • public-source search and retrieval;
  • language-model analysis and Draft generation;
  • payments and subscription administration, if paid access is enabled;
  • monitoring, logging, rate limiting, and security; and
  • customer support and incident response.

Providers are authorized only for the service they supply and are subject to applicable contractual and legal duties. A provider is a subprocessor only for processing in which NextCog acts as processor; it may instead be NextCog’s processor where NextCog acts as controller. NextCog will identify exact providers through applicable service documentation, contractual information, or on request once the Customer’s configuration is known.

Data may also be disclosed to professional advisers, courts, regulators, public authorities, or another party where required by law or reasonably necessary to protect legal rights.

12. International transfers

A configured provider may process personal data outside the European Economic Area, depending on its service region and support arrangements. Before relying on a restricted transfer, NextCog must identify the destination and role, assess the transfer, and use an applicable mechanism where required, such as an adequacy decision or approved contractual safeguards, together with supplementary measures where appropriate.

This Notice does not assert that a particular transfer mechanism covers a provider until that provider and configuration have been verified. Customers may request information about the safeguards relevant to their account through the contact page.

13. Retention

NextCog keeps personal data only while needed for the purpose described, the Customer’s documented instructions, or a legal requirement. The applicable criterion depends on the record:

  • Active accounts and profiles: while the account is active and needed to provide the service.
  • Closed accounts: removed or de-identified after a reasonable closure period, except for records needed for law, security, billing, suppression, or disputes.
  • Imported Contacts, Research, and Drafts: until a permitted User deletes them, the Customer’s agreed retention setting applies, or the account closes, subject to limited backups and legal holds.
  • Uploaded source files: only while needed to complete, validate, or troubleshoot the import, unless the Customer intentionally retains the file as part of its workspace.
  • Security and audit logs: for a proportionate risk-based period, extended only where an event is relevant to an investigation, legal duty, or claim.
  • Billing records: for the period required by applicable accounting and tax law.
  • Support correspondence: while needed to resolve and document the request, then for a proportionate claim or compliance period.
  • Backups: until overwritten under the backup rotation, with access restricted and restoration subject to the same protections.
  • Suppression records: the minimum data needed to ensure a valid objection is not defeated by a later import, for as long as reasonably necessary for that purpose.
  • Legal acceptance records: while needed to demonstrate the applicable Terms or Notice and for the relevant limitation period.

Deletion from an active system may not immediately remove a protected backup copy. If a Customer instructs NextCog as processor to delete data, the applicable agreement and lawful exceptions govern completion of that instruction.

14. Security

NextCog uses technical and organizational measures intended to protect personal data in light of the nature of the service and risk. Controls are selected as appropriate to the deployed architecture and risk from measures such as HTTPS encryption in transit, access controls, separation between Customer workspaces, restricted administrative access, logging, backups, dependency and vulnerability management, rate limiting, and incident-response procedures.

Users must protect their credentials and devices, assign workspace access carefully, and report suspected unauthorized access promptly. No internet service or storage system can be guaranteed completely secure.

15. Cookies and local storage

LeadResearchAgent uses browser storage where necessary to establish or maintain an authenticated session, protect requests, and remember a User-requested preference. A configured authentication provider may set its own strictly necessary security or session cookies during sign-in. Users can inspect current cookies and local-storage entries through their browser.

Non-essential analytics, advertising, or marketing storage must not be activated without updating this Notice and obtaining consent where required. The cookie and storage configuration of the public nextcog.ai website is described separately in thegeneral NextCog Privacy Policy.

16. Data-subject rights

Subject to applicable conditions and exceptions, a person may request access to, correction of, or deletion of personal data; restriction of processing; portability of data they provided; or object to processing based on legitimate interests. A person may withdraw consent for consent-based processing at any time without affecting earlier processing. A person also has rights concerning solely automated decisions with legal or similarly significant effects where such processing applies.

The appropriate recipient depends on the processing role. A Contact should normally contact the Customer Organization responsible for the Campaign first. NextCog will assist the Customer where it acts as processor and will respond directly for processing for which NextCog is controller. A request may be submitted through the NextCog contact page or by post. Please identify the relevant email address, profile URL, Organization, or other limited detail needed to find the record. We may request proportionate identity verification if there is reasonable doubt about the requester.

A right may depend on the legal basis and circumstances. A valid deletion request does not require immediate deletion of a record that must be kept for a legal obligation, security, suppression, or the establishment, exercise, or defense of a legal claim.

17. Information for imported or researched Contacts

You may appear in LeadResearchAgent without creating an account if a Customer imports your professional details or asks the service to research relevant public professional or Organization information. Typical data includes your name, role, employer, professional contact details or profile URL, work location, public business context, source links, and generated Research or suggested outreach material.

The Customer uses this information to organize professional prospect Research, assess possible relevance to a Campaign, and prepare a Draft for human review. The Customer generally decides whether to contact you and is responsible for the outreach purpose and legal basis. NextCog provides the software and may act as the Customer’s processor for that activity, while remaining controller for its own security, support, and legal-compliance processing.

You may ask for access, correction, deletion, restriction, or objection as described above. If you contact NextCog, provide enough information to locate the possible record but do not send an identity document unless requested. Where possible, NextCog will identify or route the request to the relevant Customer without revealing unrelated Customers, Campaigns, or Contacts.

A valid objection or request not to be contacted should be recorded using only the information needed to prevent the same Customer from reactivating the Contact through a later import. Suppression information must not be reused for a new purpose.

18. Children

LeadResearchAgent is designed for professional and business use and is not intended for children. Customers must not create Contact records for the purpose of targeting children or invite children to use the service.

19. Changes to this Notice

NextCog may update this Notice when the service, provider configuration, law, or processing practices change. The version and dates at the top identify the current text. For a material change, NextCog will provide an appropriate notice in the application, by account email, or through another suitable channel where practicable.

A material change to processing may require an updated Customer instruction, contract, or application notice rather than reliance only on this webpage. Historical versions and records of the version presented or accepted should be retained where needed.

20. Contact and complaints

Privacy questions and requests may be sent through the NextCog contact page or by post to:

NEXTCOG
73 Boulevard de Strasbourg, 34000 Montpellier, France
888 436 672 RCS Montpellier

Please state that your request concerns LeadResearchAgent and provide only the information reasonably needed to locate the relevant account or Contact record.

You may complain to the French data-protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), throughwww.cnil.fr or by post at 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France. You may also have a right to contact another competent supervisory authority.

Related pages

  • LeadResearchAgent Terms of Service
  • General NextCog Privacy Policy
  • General NextCog Website Terms
  • Lead Research Agent product page
  • Contact NextCog
  • Open LeadResearchAgent (opens an external site)
NextCog

NextCog builds focused AI-powered software for practical business problems.

Product

Lead Research AgentHow it worksOpen application

Company

AboutContactSecurity

Legal

GeneralPrivacy policyWebsite termsProduct-specificLeadResearchAgent privacyLeadResearchAgent terms

© 2026 NEXTCOG · Société par actions simplifiée (SAS) · 888 436 672 RCS Montpellier

Public website · No analytics enabled