Compliance

Privacy Policy

Last updated: 11 June 2026

IntentBridge (“IntentBridge”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and safeguard personal data when you visit https://intentbridge.co/ (the “Website”), engage our lead generation and client acquisition services (the “Services”), or submit information through a lead capture page that we operate. It also describes your rights in relation to your personal data.

1.Who we are

The Website and Services are operated by Purple Labs AB (Reg. No. 559100-6506), Stockholm, Sweden, trading as IntentBridge. Purple Labs AB is the controller responsible for the personal data described in this Policy, except where we process personal data on behalf of, and under the instructions of, a client (in which case that client is the controller). If you have any questions about this Policy or how we handle your data, you can contact us at [email protected].

2.Who this Policy applies to

This Policy applies to two main groups:

  • Business visitors and clients — people who visit the Website, request a quote, or use the Services as a business or on behalf of a business.
  • Lead prospects — individuals who submit their information through an advertisement, form, quiz, or landing page that we operate as part of generating leads for our clients.

3.Personal data we collect

Depending on how you interact with us, we may collect the following categories of personal data:

  • Information you provide directly — your name, business name, email address, phone number, the content of any message or enquiry, and any information you submit when requesting a quote or contacting us.
  • Lead information — when you respond to one of our campaigns or forms, we may collect your name, email address, phone number, general location, your answers to qualifying questions, and details relating to your enquiry, together with a record of the consent you provided and the date and time it was given.
  • Verification data — information used to verify contact details, such as one-time-password (OTP) confirmation of a phone number.
  • Technical and usage data — your IP address, device and browser type, pages viewed, referring pages, and similar information collected automatically through cookies and similar technologies.
  • Information from third parties — data we receive from advertising and analytics platforms (such as Meta and Google) in connection with the campaigns we run.

4.How we collect personal data

We collect personal data directly from you when you submit a form, complete a quiz, request a quote, or otherwise contact us; automatically through cookies and similar technologies when you use the Website or our landing pages; and from third-party advertising and analytics platforms that help us deliver and measure our campaigns.

5.How we use personal data and our legal bases

We use personal data for the purposes set out below. Where the General Data Protection Regulation (GDPR) applies, we rely on the legal bases indicated:

  • To provide and deliver the Services — including generating, qualifying, and delivering leads to our clients (performance of a contract and our legitimate interests in operating our business).
  • To verify and screen leads — including OTP verification and quality checks (our legitimate interests and, where required, consent).
  • To communicate with you — to respond to enquiries, provide quotes, and manage our relationship with you (performance of a contract and our legitimate interests).
  • For marketing — to send information about our Services where you have requested it or where we are otherwise permitted to do so (consent and/or our legitimate interests).
  • To operate, analyze, and improve the Website and Services — including analytics and security (our legitimate interests).
  • To comply with legal obligations — including record-keeping, accounting, and responding to lawful requests (compliance with a legal obligation).

Where we rely on consent, you may withdraw it at any time as described in Section 10.

6.How we share personal data

We may share personal data with:

  • Our clients — where you submit your information as a lead prospect, that information is provided to the client who has requested leads matching your enquiry. Once a lead has been delivered, that client acts as an independent controller of your personal data and processes it under its own privacy policy. From that point, IntentBridge no longer controls how the client uses or processes your personal data. You should review that client’s privacy policy and contact it directly regarding its handling of your data.
  • Service providers and processors — including providers of website and landing-page hosting and customer relationship management (such as GoHighLevel), communication and verification services (such as Twilio for SMS and OTP), email delivery, and analytics (such as Google Analytics). These providers process personal data on our behalf and under our instructions.
  • Advertising and analytics platforms — such as Meta (including the Meta Pixel and the Meta Conversions API) and Google, in connection with running, measuring, and optimizing our campaigns.
  • Legal and compliance recipients — where we are required to share data to comply with the law, enforce our terms, or protect our rights, property, or safety, or those of others.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, in which case personal data may be transferred as part of that transaction.

Other than sharing lead information with the relevant client as part of providing the Services, we do not sell your personal data.

7.Cookies and similar technologies

We use cookies and similar technologies on the Website and our landing pages for the following purposes:

  • Strictly necessary cookies — required for the site to function (for example, security and form submission). These are typically session cookies or stored for up to 12 months.
  • Analytics cookies — help us understand how visitors use the site so we can improve it. We use tools such as Google Analytics. These are typically stored for up to 24 months.
  • Advertising and conversion technologies — used to deliver, measure, and optimize our advertising. We use tools such as the Meta Pixel, the Meta Conversions API, and Google advertising tags. Browser-based advertising cookies are typically stored for up to 12 months (for example, the Meta _fbp cookie is generally stored for around 90 days).

For visitors in the European Economic Area (EEA) and the United Kingdom, we set non-essential cookies and similar technologies (such as analytics and advertising technologies) only after you have given consent through our cookie banner, and you can withdraw or change your choices at any time. You can also control cookies through your browser settings. Some tracking technologies, such as the Meta Conversions API, operate server-side; where these process the personal data of EEA visitors, we rely on consent as described above.

8.Do Not Track

Some browsers offer a “Do Not Track” (DNT) setting. The Website does not currently respond to browser-based Do Not Track signals.

9.International transfers

We are based in Sweden and operate within the European Union. Because we serve clients and use service providers located in other countries, your personal data may be transferred to, and processed in, countries outside the EEA, including the United States. Where we make such transfers, we take steps to ensure your data is protected by appropriate safeguards, such as standard contractual clauses, where required by applicable law.

10.Your rights

Depending on your location and applicable law, you may have the following rights in relation to your personal data:

  • to access the personal data we hold about you;
  • to request correction of inaccurate or incomplete data;
  • to request erasure of your data;
  • to restrict or object to our processing of your data;
  • to request a copy of your data in a portable format;
  • to withdraw consent at any time where we rely on consent; and
  • to lodge a complaint with a supervisory authority.

If you are in the EEA, you may contact your local data protection authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). To exercise any of these rights, please email us at [email protected]. Where your information has already been shared with a client as a lead, you may also need to contact that client directly to exercise your rights against them.

11.California privacy rights

If you are a California resident, you may have additional rights under applicable California privacy laws. These may include the right to know what personal information we collect and how we use and disclose it, the right to request deletion or correction of your personal information, and the right not to be discriminated against for exercising your rights. To exercise any such rights, please contact us at [email protected].

12.Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected and to meet our legal obligations. Our general retention periods are:

  • Marketing and general enquiries: up to 24 months from your last contact with us.
  • Lead records: up to 36 months from the date the lead was generated.
  • Accounting and transaction records: 7 years, as required by Swedish bookkeeping law.

When personal data is no longer required, we delete or anonymize it. Specific retention periods may vary where a longer or shorter period is required by law or by a particular client engagement.

13.Data Processing Agreement

Where required by applicable data protection law, a Data Processing Agreement (DPA) is available to our clients upon request. Please contact us at [email protected].

14.Security

We maintain appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration. These measures include encryption of data in transit, access controls that limit who can access personal data, and authentication measures for our systems. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

15.Children

The Website and Services are intended for businesses and adults. We do not knowingly collect personal data from children under 18 years of age. If you believe a child under 18 has provided us with personal data, please contact us so that we can take appropriate action.

16.Third-party links

The Website and our landing pages may contain links to third-party websites or services that we do not operate. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.

17.Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will take effect when posted on the Website, and your continued use of the Website or Services after that point constitutes acceptance of the updated Policy.

18.Contact

If you have any questions or requests regarding this Privacy Policy or your personal data, please contact:

Purple Labs AB (trading as IntentBridge) Email: [email protected]