Privacy, explained

B2B data privacy essentials for sales teams.

Prospecting data is business data about people, and B2B teams often treat it as a grey area it is not. This is a plain, vendor-neutral guide to what GDPR actually requires for B2B outreach, the legal basis that makes cold email legitimate, and why where your data physically lives is part of the compliance picture, not an afterthought.

Where the data lives

Data residency is part of privacy, not a side issue

Legal basis is only half the picture. The other half is where the data physically sits once you have collected it, who else can access it, and what happens to it if you stop paying.

�A8C7; What "in the cloud" actually means

The default for most sales tools
  • Your lead lists live on the vendor's servers, often in a different legal jurisdiction than your company
  • Enrichment history and outreach logs are stored and processed by a third party
  • A Data Processing Agreement becomes necessary because personal data is being processed on your behalf
  • Cancellation usually means asking a vendor to delete data you no longer control

🔒 What runs entirely locally changes

The alternative, less common shape
  • Lead lists and enrichment stay on your own machine, never transmitted to a vendor's server
  • No third-party processor for that data flow, which simplifies the DPA question for it specifically
  • Deletion is immediate and entirely in your control, not a support ticket
  • The tool's own telemetry if any, is a separate thing worth checking independently
The honest comparison

Cloud-first vs local-first, what actually changes

Cloud-first prospecting tool

  • Data leaves your machine and is processed on shared infrastructure.
  • A DPA with the vendor is required, and worth actually reading.
  • Cross-border transfer rules apply if the vendor is outside your region.
  • You depend on the vendor's own security practices and breach history.

Local-first prospecting tool

  • Lead data stays on your machine for that data flow.
  • No third-party processor for the prospecting data itself.
  • No cross-border transfer question for that data, since it never moves.
  • Security of the data is now your own machine's security, not delegated.

Neither shape is automatically "more compliant" in every respect, a well-run cloud vendor with a solid DPA and EU hosting can be entirely appropriate. The point is that data residency is a real variable to evaluate deliberately, not a detail to skip because a vendor's homepage says "GDPR compliant." See desktop vs cloud lead generation tools for the fuller trade-off beyond privacy alone.

Use it for

Questions this guide answers

  • Is it legal to cold email a business contact under GDPR?
  • What is the difference between legitimate interest and consent?
  • Do I need a Data Processing Agreement for my sales tools?
  • Where does my prospecting data actually live when I use a cloud platform?
  • What changes about compliance when a tool runs locally instead of in the cloud?
How AtlasForgeX fits

How AtlasForgeX handles this in practice

A Windows desktop app, data stays on your machine

AtlasForgeX runs the discovery, enrichment and email-generation locally on your own computer. Company data read from official registers and public sources is processed on your machine, not uploaded to and stored on a shared server for AtlasForgeX to hold on your behalf. There are no API keys to manage and no per-contact credits, and canceling does not require asking anyone to delete anything from a server, because nothing left your machine in the first place.

Runs: locally on Windows, no cloud processing of your lead data Sourced from: official public registers across 92 countries

This does not remove the need to think about the legal basis for your own outreach, that responsibility stays with whoever sends the message. What it removes is the additional layer of trusting a third-party server with the list itself. See the full privacy policy for the exact detail.

Questions

FAQ

Is cold emailing B2B contacts legal under GDPR?+
In most EU markets, yes, under the legitimate interest basis, provided the email relates to the recipient's professional role, you identify yourself clearly, and you offer an easy opt-out. This differs from B2C marketing, which generally needs consent. Rules vary slightly by country, so check local implementation for direct marketing specifically.
What is the difference between legitimate interest and consent under GDPR?+
Consent means the person actively opted in before you process their data. Legitimate interest means you can process it without prior opt-in if your interest is real, the processing is necessary, and it does not override the individual's rights, which is the usual basis for B2B outreach to a person's work contact in their professional capacity.
Where does prospecting data actually go when I use a sales tool?+
With most cloud platforms, your lead lists, enrichment results and outreach history live on the vendor's servers, often outside the country or even the legal region where your company operates. With a locally-run tool, the equivalent data stays on your own machine, which changes both the compliance surface and what happens to your data if you cancel.
Do I need a Data Processing Agreement for a lead generation tool?+
If a vendor processes personal data on your behalf in the cloud, yes, a DPA is standard practice and often a legal requirement under GDPR Article 28. A tool that runs entirely on your own machine and never sends prospecting data to a third-party server removes this requirement for that specific data flow, though the tool's own telemetry, if any, is a separate question worth checking.

See prospecting data that never leaves your machine

Run AtlasForgeX on your market and see discovery, enrichment and outreach happen locally, with nothing uploaded to a third-party server.

Download for Windows, free 1-day trial Book a live demo