Skip to content
Request Samples
The MaterialMade With LeapAboutResources
Request Samples
Last updated 1 September 2026

Privacy policy

We sell material to companies, so most of what we hold is work contact details and what you told us you want to make. This page says what we collect, why, who else sees it, how long we keep it, and how to make us delete it.

The short version

Not a substitute for the detail below, but true on its own.

We are a supplier
Leap Materials sells a bio-based material to brands and manufacturers. We are not an advertising business.
We collect what you send us
Your work contact details and what you tell us about the product you want to make. Plus anonymous statistics if you allowed them, which is covered by the cookie policy.
We do not sell data
We have never sold or rented personal data and we do not share it for anyone else’s marketing.
You can end it
Ask us to delete what we hold and we do it, unless bookkeeping law requires us to keep an invoice. One email is enough.

What we collect

By where it comes from, because that is how you can check it.

When you ask for samples or a quote
Name, company, work email, phone if you give it, the application and volume you are considering, your delivery address, and what you write in the message field. We ask for the minimum that lets us send the right material and quote it.
When you subscribe to the newsletter
Your email address, and whether you opened or clicked, so we can tell whether the newsletter is worth sending at all.
When we meet at a fair or you hand us a card
Your name, company, role and work contact details, and a note of what we discussed. If you would rather we had not kept it, say so and it is gone.
When you apply for a job
Your application, CV and anything else you send. Handled by us, not fed into the CRM, and deleted when the role is filled unless you agree that we keep it on file.
When you are a supplier or partner contact
Work contact details and the correspondence needed to run the relationship, plus invoicing details.
When you visit the site
Statistics where you consented, plus technical server logs kept by our host. Detail and durations are in the cookie policy.
Company level visitor identification
Subject to your consent, a script from Apollo works out which company a visit is likely to come from, so our sales team can follow up with businesses that showed interest. It is listed in the cookie policy and you can decline it in the consent banner.
What we never ask for
Health, religion, political views, union membership, ethnicity, biometrics or anything else the GDPR calls a special category. If you send it anyway, we delete it.

Why, and on what basis

Every purpose needs a legal basis under Article 6. Here they are, one by one.

To answer you and supply material
Performance of a contract or steps leading up to one, Article 6(1)(b). Without your contact details and the application, there is no quote and no delivery.
To keep in touch about a project you started
Our legitimate interest in business to business communication, Article 6(1)(f). We weighed that against your interest in being left alone: the contact is work related, the volume is low, and one word from you ends it.
To send the newsletter
Your consent, Article 6(1)(a). Withdrawable in one click in every email, with no effect on anything else.
Statistics and marketing cookies
Your consent, Article 6(1)(a), together with the Danish Executive Order on Cookies. See the cookie policy.
To identify the company behind a visit
Your consent, Article 6(1)(a), given in the cookie banner. Withdraw it and the script stops running for you.
To keep our books
Legal obligation, Article 6(1)(c). Danish bookkeeping law requires accounting records to be kept for five years from the end of the financial year they concern.
To defend a claim
Our legitimate interest, Article 6(1)(f), in keeping the correspondence relevant to a dispute for as long as it can be raised.
Is it mandatory?
No. Nothing on this site is compulsory. If you leave the form fields empty we simply cannot quote, and you can always call instead.

Who else sees it

Short list, and it stays short.

Our own team
Only the people who need it. Sales sees enquiries, finance sees invoices, and nobody browses for curiosity.
Providers acting for us
A CRM and email marketing platform, HubSpot. A website platform, Webflow, served through Cloudflare. Email and file storage from our office software provider. Analytics and advertising measurement from Google, and company level visitor identification from Apollo, both subject to your consent. Each processes data on our instructions only. The platforms we use include data processing terms in their standard contracts, which is what the GDPR requires of us, and we do not hand personal data to a provider that offers none.
Couriers
Your delivery address goes to the carrier that brings your samples, because a parcel needs an address.
Advisers and authorities
Our accountant and auditor, and public authorities where the law requires it. Nobody else.
Not advertising networks
We do not pass your contact details to advertising platforms, and we do not upload customer lists for ad targeting.
The current list
Providers change. Ask us and we will send the list of who processes personal data for us at that moment, and what each one does with it.
No automated decisions
Nothing here is decided about you by a machine. There is no automated decision making and no profiling in the sense of Article 22, so no pricing, credit or eligibility decision is taken without a person.

Transfers outside the EU

Some of our providers are American. This is the basis for that.

Where data goes
Mainly inside the EU and the EEA. Some providers, including HubSpot and Google, are established in the United States and may process data there.
The safeguard
The EU-US Data Privacy Framework where the provider is certified under it, and the European Commission’s standard contractual clauses as a fallback, with a transfer assessment behind them.
Ask for the paperwork
You can ask which mechanism applies to a specific provider and we will tell you, including a copy of the clauses where we are allowed to share them.

How long we keep it

Deleting on time is part of the job, not a favour.

Enquiries that went nowhere
Kept while the opportunity is live and for a defined period after our last contact, then deleted. Ask us and we will tell you the current period.
Customer relationships
Kept for as long as we supply you, and afterwards only what is needed for warranty, claims and the accounts.
Accounting records
Five years from the end of the financial year the record belongs to, because Danish bookkeeping law says so. We cannot shorten this one, even at your request.
Newsletter subscription
Until you unsubscribe. After that we keep the fact that you unsubscribed, so we do not accidentally add you again.
Job applications
Deleted once the position is filled, unless you agreed that we keep your application on file for a defined period.
Cookie and analytics data
As set out in the cookie policy, which lists each cookie and its duration.

Your rights

All of them, and what it costs you. Nothing.

Access
A copy of the personal data we hold about you, and an explanation of what we do with it.
Rectification
Correction of anything wrong, and completion of anything missing.
Erasure
Deletion, unless we are required to keep the record. We will tell you if that is the case and which rule requires it.
Restriction and objection
You can ask us to pause processing, and you can object to processing based on legitimate interest. Where you object to direct marketing, we stop. There is nothing to weigh up on that one.
Portability
The data you gave us, in a machine readable file, sent to you or to another provider.
Withdrawing consent
At any time, for the newsletter and for cookies, with no effect on what was lawful before you withdrew it.
What it costs and how long
Nothing, and we answer within one month. If a request is genuinely complex we may take up to two months more, and we will tell you why inside the first month.
How to ask
Email hello@beyondleather.dk. Plain language is fine, you do not need to cite an article number. If we cannot tell that the request comes from you, we will ask for something that establishes it, and we do not keep that afterwards.
If we get it wrong
Complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, see datatilsynet.dk. If you live in another EU or EEA country you can complain to your own supervisory authority instead. We would rather you told us first.

Security

No absolute promises. Specific measures instead.

How it is protected
Access is limited to the people who need it, accounts require multi-factor authentication, data in transit is encrypted, and we use established providers rather than building storage ourselves.
Honest limit
No system is beyond reach. What we can promise is that we keep little, we keep it in few places, and we delete on schedule, which is the part that actually reduces the risk to you.
If something happens
If a breach is likely to put you at risk we notify Datatilsynet within seventy two hours and tell you directly, in plain language, including what we know and what to do about it.

Who is responsible

One company, one address, one inbox.

Data controller
Leap Materials ApS, formerly Beyond Leather Materials ApS
Smedeholm 13B, 2730 Herlev, Denmark
CVR 38698729
Data protection officer
We have not appointed one. Privacy questions go to the inbox above and are handled by us, not forwarded to an agency.

Changes to this policy

Version 2.0, 1 September 2026. It replaces all earlier privacy policies for explore-leap.com.

When we update it
When we add or drop a provider, change a purpose, or the law changes. At minimum we review it once a year.
How you find out
The date at the top always shows the version you are reading. If a change affects a purpose that rests on your consent, we ask again rather than treating the old answer as covering it.
Earlier versions
Available on request.