LR Hub Privacy Policy

Effective date: 4 September 2026 · Version 2.0 · Terms of Service

LR Hub is the internal sales-operations platform of LR partners ApS, a Danish B2B sales agency. This policy explains what personal data LR Hub processes, why, who it is shared with, how long it is kept, and what rights you have. It applies to LR Partners staff, to the client companies we work for and their users, to people whose calendars are connected to LR Hub, and to the prospects we contact on our clients' behalf.

1. Who we are

The data controller for LR Hub is LR partners ApS, CVR 44489791, Titangade 13A, 1., 2200 København N, Denmark.

Privacy questions and requests: ads@lr-partners.dk. General enquiries: info@lr-partners.dk. We have not appointed a formal Data Protection Officer; the privacy contact above handles all requests.

2. Our role: controller or processor

We are the controller for data about our own staff, for the accounts of client users, and for the prospect records we build and use to book meetings on our clients' behalf.

We are a processor for personal data that a client entrusts to us and that we process only on the client's instructions. This includes data in a client's connected calendar, contact lists a client supplies to us, and meeting details entered by client users. For this processing, the client is the controller and our handling is governed by our agreement with that client.

3. Whose data we process

  • LR Partners staff (sales development representatives, team leads, administrators) who sign in to LR Hub.
  • Client users: employees of the companies we work for who sign in to see their pipeline, team and statistics.
  • Calendar owners: client employees who choose to connect their Google or Microsoft 365 calendar so meetings can be booked directly into it.
  • Prospects: business contacts at companies our clients want to meet. These are people acting in their professional capacity. Their data is imported by our staff or supplied by the client, and enriched from business data sources.
  • Meeting participants: the client contact and the prospect who attend a booked meeting.

4. What data we collect

Account data. Name, email address, role, job title, profile photo (optional), sign-in timestamps and security events.

Staff work data. Clock-in and clock-out times, adjusted hours, activity counts, meeting outcomes, performance statistics, compensation arrangements and payroll calculations.

Prospect data. Name, job title, company, work email, work phone number, LinkedIn profile URL, notes from calls, and the outcome and status of each contact attempt.

Meeting data. Participants, date and time, duration, meeting link, notes, status history and, where a client enables it, call recordings and transcripts linked to a meeting.

Call data. For calls placed through the built-in dialer: the number called, the number called from, start and end time, outcome, an audio recording of the call and a machine-generated transcript.

Calendar data. For connected calendars: the connected account's identity, busy/free times, and the events LR Hub itself created. See section 6.

Technical data. IP address, browser type, and request logs used for security, rate limiting and troubleshooting.

We do not collect special categories of personal data (health, political opinions, religion, and similar) and we ask users not to enter such data in notes.

5. Why we process it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Running LR Hub for staff: sign-in, assignments, time tracking, payrollEmployment contract (6(1)(b)) and legal obligations (6(1)(c))
Providing the client portal and reports to client usersContract with the client (6(1)(b))
Contacting prospects and booking B2B sales meetingsLegitimate interest of LR Partners and its clients in B2B outreach (6(1)(f))
Connecting to a Google or Microsoft calendarConsent of the calendar owner (6(1)(a)), withdrawable at any time
Recording and transcribing calls for quality and trainingLegitimate interest (6(1)(f)); the called party is informed and may object
Security, abuse prevention, backupsLegitimate interest (6(1)(f))
Bookkeeping and record keepingLegal obligation (6(1)(c))

Where we rely on legitimate interest, the data concerned is professional contact data used for B2B outreach, and you can object at any time (section 13).

6. Google and Microsoft calendar data

Connecting a calendar is always optional and always an explicit choice made by the calendar's owner in Google's or Microsoft's own sign-in flow. We request only delegated permissions on that one calendar. We never request organisation-wide or application-level access, and we never request access to email, contacts or files.

If you connect a calendar, we access it only to:

  • create, update and cancel meeting events that were booked through LR Hub;
  • read your availability (busy times) so meetings are only booked in free slots. We read only start, end and busy status, never the subject, description, attendees or location of your own events;
  • read the status of events LR Hub created (accepted, declined, moved or cancelled) to keep both sides in sync.

We do not read, store or process calendar events that were not created by LR Hub, beyond the busy/free times needed for availability. Change notifications from Microsoft or Google carry only event identifiers, never event content.

Google. LR Hub's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the scheduling features described above, is never used for advertising, is never sold, and is never transferred to third parties except as necessary to provide the service or as required by law. No human reads Google user data except with your consent, for security purposes, or to comply with the law.

Microsoft. The same commitments apply to data obtained through Microsoft Graph. Our Microsoft Entra application requests only the delegated permissions openid, profile, email, offline_access, User.Read and Calendars.ReadWrite, and only for the account that consented.

You can revoke a connection at any time inside LR Hub, from your Google account permissions, or from your Microsoft account or your organisation's Entra ID admin centre. When a connection is revoked, its stored access and refresh tokens are deleted immediately.

7. Call recording and transcription

Calls placed through LR Hub's built-in dialer may be recorded and transcribed. Recordings are used to check meeting quality, resolve disputes about what was agreed, and train our staff. They are available only to the staff member who made the call, their team lead and administrators, and, where a client has enabled it, to that client for meetings booked for them.

Recordings are copied from our telephony provider into LR Hub's own encrypted storage, where only the people listed above can play them, and are transcribed through a speech-to-text API that does not use the audio to train its models. If you were called by LR Partners you can object to the recording being kept (section 13).

8. Browser extension

LR Partners staff may use an optional Chrome extension that reads the LinkedIn profile page currently open in the browser and looks it up in LR Hub. It only runs on the active tab when the staff member opens it, sends data only to LR Hub, and stores only the staff member's own API token locally. It does not track browsing and is not offered to clients or prospects.

9. Sub-processors

We use the following categories of service providers to run LR Hub. Each processes data under data processing terms and only for the purpose listed.

ProviderPurpose
SupabaseDatabase, authentication and file storage
VercelApplication hosting and server-side code
BackblazeEncrypted off-site database backups
ResendTransactional email (invites, password resets, reports, alerts)
TelnyxOutbound telephony and call recording for the dialer
OpenAITranscription of recorded calls (API, no training on your data)
AnthropicAI-assisted drafting and staff training features
SurfeProspect contact enrichment (phone and email lookup)
GoogleGoogle Calendar integration, only for connected accounts
MicrosoftMicrosoft 365 calendar integration, only for connected accounts
HubSpot and AdversusCRM and dialer synchronisation, only where a client uses them

This list is updated when a provider is added or replaced.

10. International transfers

Our primary database and application servers are hosted in the EU. Some of the providers listed above are established in the United States. Where personal data is transferred outside the EU/EEA, the transfer is covered by the EU-U.S. Data Privacy Framework where the provider is certified under it, and otherwise by the European Commission's Standard Contractual Clauses.

11. How long we keep data

We keep personal data for as long as it is needed for the purpose it was collected for, and afterwards only as long as we are required to by law, for example bookkeeping and employment record-keeping rules, or as needed to establish, exercise or defend legal claims. Prospect records are removed or anonymised when they are no longer relevant to an active client engagement, and at once if the person objects. Calendar access tokens are deleted when the connection is revoked.

Deleted records are first archived (hidden from normal use) and then permanently removed. Deleted data may persist in encrypted backups for a short period before the backup cycle overwrites it.

12. How data is protected

  • All traffic is encrypted in transit (TLS). Data is encrypted at rest by our hosting providers.
  • Calendar access tokens are additionally encrypted at the application layer with a key that is never stored in the database, and are only ever used by LR Hub's servers. They are never exposed to browsers or to other users.
  • Access inside LR Hub is role based and enforced in the database: users only see the clients and meetings they are assigned to, and client users see only their own company's data.
  • Sign-in uses individual accounts with password reset by email. Sessions expire and are refreshed server-side.
  • Every request is rate limited, security headers are enforced, and server-to-server calls are authenticated with signed tokens.
  • Changes to sensitive records are written to an audit log. Calls to calendar providers are logged without any request content or credentials.
  • Encrypted database backups are taken regularly and stored off-site on a rolling cycle.

In the event of a personal data breach we notify the Danish Data Protection Agency, affected clients and affected individuals as required by the GDPR.

13. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data, where we have no overriding legal obligation to keep it;
  • restrict processing while a request is being handled;
  • portability: receive data you provided in a machine-readable format;
  • object to processing based on legitimate interest, including B2B outreach. If you are a prospect and do not want to be contacted, tell us and we will mark your record as do-not-contact and stop;
  • withdraw consent at any time, for example by disconnecting a calendar.

Send requests to ads@lr-partners.dk. We respond within the time limits set by the GDPR. If your data was entrusted to us by one of our clients, we may forward your request to that client, who is the controller.

You may also complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk.

14. Cookies

LR Hub uses only the strictly necessary cookies required to keep you signed in and to protect against cross-site request forgery. There are no advertising, analytics or third-party tracking cookies, so no cookie consent banner is shown.

15. Automated decision-making

LR Hub does not make decisions with legal or similarly significant effects on you by automated means. AI features are used to draft text and generate transcripts for staff to review; they do not decide who is contacted or how staff are paid.

16. Changes to this policy

If this policy changes materially, the effective date and version above are updated and signed-in users are informed inside LR Hub.