LeadPass Data Processing Agreement
(Umowa powierzenia przetwarzania danych osobowych — Article 28 GDPR)
Effective date: 20 July 2026 Version: 1.0
1. Parties, incorporation and precedence
1.1. This Data Processing Agreement (the "DPA") is concluded between:
Jose Ramon Leon Rodriguez, a sole trader (jednoosobowa działalność gospodarcza) established in Poland Registered address: Egipska 5/69, 03-977 Warszawa, Poland NIP (tax ID): 8992886524 · EU VAT: PL8992886524 · REGON: 387147849 Registration: entered in CEIDG (Centralna Ewidencja i Informacja o Działalności Gospodarczej) Contact: legal [at] useleadpass.com
(the "Provider", "LeadPass", "we", "us") — acting as processor or sub-processor, as applicable,
and the Customer — acting as controller of Lead Data or as an intermediary processor authorised by its client controller, as described in Section 3.5.
1.2. This DPA is incorporated by reference into, and forms an integral part of, the LeadPass Terms of Service (the "Terms"). It is concluded electronically when the Account owner confirms the subscription checkout action beside the link to this DPA; the Service records that acceptance for the Account. No separate signature is required. Article 28(9) GDPR permits this electronic form.
1.3. This DPA governs the Provider's processing of Lead Data on the Customer's behalf. In case of conflict between this DPA and the Terms regarding the processing of Lead Data, this DPA prevails. For all other matters the Terms prevail.
1.4. This DPA is drafted to satisfy Article 28(3) GDPR. If mandatory law applicable to the Customer requires the parties to execute the European Commission's standard contractual clauses for Article 28 contracts (Commission Implementing Decision (EU) 2021/915), the parties will do so on the Customer's written request; those clauses will then be read consistently with the commercial terms of this DPA.
2. Definitions
Capitalised terms not defined here have the meaning given in the Terms — in particular "Account", "Workspace", "Flow", "Public Flow Page", "Lead", "Lead Data", "AI Outputs", "User", "Team Member", "Client User", "Plan" and the "Service".
- "GDPR" — Regulation (EU) 2016/679.
- "Personal Data Breach", "processing", "controller", "processor", "data subject", "supervisory authority" — as defined in the GDPR.
- "Documented Instructions" — the instructions described in Section 5.
- "Sub-processor" — a third party engaged by the Provider to process Lead Data on the Customer's behalf, as listed in Annex III.
- "TOMs" — the technical and organisational measures described in Annex II.
3. Roles and scope
3.1. Roles. For Lead Data, the Customer is the controller (or, where the Customer itself acts for another controller, a processor — see Section 3.5) and the Provider is the Customer's processor. The Customer determines the purposes of processing Lead Data (which prospects to qualify, what to ask, which criteria apply, what happens with the outcome); the Provider processes Lead Data only to provide the Service, on Documented Instructions.
3.2. Outside this DPA. This DPA does not cover personal data for which the Provider is the controller — in particular registration and profile data of the Customer and its Users (including Team Members and Client Users), billing and payment data, support correspondence, and marketing-site visitor data. That processing is described in the LeadPass Privacy Policy.
3.3. No own purposes (Article 28(10) GDPR). The Provider processes Lead Data solely to provide the Service and on Documented Instructions. The Provider does not:
a) use Lead Data (including voice recordings, transcripts or AI Outputs) to train, fine-tune or improve AI models — its own or any third party's; b) sell Lead Data or use it for advertising, benchmarking, prospecting or any other purpose of its own; c) create voiceprints or use recordings to identify or authenticate speakers (Section 16).
3.4. Content-free telemetry. The Customer acknowledges and instructs that the Provider records, per AI operation, purely technical usage telemetry (model name, token counts, cost, latency and internal references) which contains no Lead content and no Lead contact data. This telemetry is financial/operational bookkeeping of the Provider; it is retained detached from any tenant after deletion and is not "Lead Data".
3.5. Customer as intermediary processor. Where the Customer runs a Workspace on behalf of its own client (e.g., an agency operating Flows for that client), the Customer warrants that it is authorised by the relevant controller to engage the Provider on the terms of this DPA, and references to the "controller's" rights and obligations apply to that arrangement accordingly.
4. Details of the processing
The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.
5. Documented Instructions
5.1. The Customer's complete and final Documented Instructions to the Provider are:
a) this DPA and the Terms; b) the Customer's configuration and use of the Service through its documented features and settings — including, without limitation: which contact fields each Flow requests, the questions and qualification criteria of each Flow, the Flow language, each Flow's audio-retention policy, the Workspace's outbound webhook endpoint (one destination used by all of its Flows, with the Pass / Review / No pass categories the Customer selects), opening/closing of Public Flow Pages, use of the review queue and manual verdict overrides, invitation of Users, and deletion of individual Leads or of the Account; and c) any further written instructions agreed by the parties, where the Provider can reasonably implement them within the Service.
5.2. Technical latitude. The Provider may select and update the non-essential technical means of the processing — including transcription and evaluation models, infrastructure, and internal processing mechanics — provided the changes do not diminish the level of protection of Lead Data and comply with Sections 8 (Sub-processors) and 9 (Transfers). Such updates are not a change of Documented Instructions.
5.3. Unlawful instructions. The Provider will immediately inform the Customer if, in the Provider's opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. The Provider may suspend execution of the instruction concerned until it is confirmed or modified.
5.4. Transfers on instruction. The Provider transfers Lead Data to a third country only as described in Section 9 and Annex III, which the Customer authorises as part of its Documented Instructions, or where required by Union or Member State law applicable to the Provider — in which case the Provider will inform the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.
5.5. Outbound webhooks. Where the Customer configures a Workspace webhook, the Provider uses that one endpoint for the Workspace's Flows and, for the Pass / Review / No pass verdict categories the Customer selected, transmits to the chosen URL — signed so the recipient can authenticate the Provider — the qualified Lead's contact details, verdict, assessment and eligible later verdict changes. An initial Incomplete result is not a subscribable webhook category. This transmission is a disclosure to the Customer, or to a recipient acting on the Customer's behalf (for example the Customer's CRM or an automation platform the Customer has engaged), made on Documented Instructions. Such recipients are engaged by the Customer, act under the Customer's responsibility as its own processors or recipients, and are not sub-processors of the Provider; the Customer is responsible for the lawfulness of the destination it configures. The Provider keeps delivery records (including the transmitted payload) for 30 days for delivery assurance and support, after which they are deleted automatically; deleting a Lead deletes its delivery records immediately.
6. Confidentiality
6.1. The Provider ensures that every person authorised to process Lead Data (employees, contractors) is bound by a contractual confidentiality obligation or an appropriate statutory obligation of confidentiality, and processes Lead Data only on Documented Instructions and to the extent needed for their role.
6.2. Access to Lead Data within the Provider's organisation is restricted to persons who need it to operate, support or secure the Service.
7. Security (Article 32 GDPR)
7.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to data subjects, the Provider implements and maintains the technical and organisational measures described in Annex II. Annex II describes the controls implemented in the Service; it does not represent a third-party certification or guarantee that a security incident can never occur. The Provider reviews the measures as the Service, deployment and risk profile change.
7.2. The Provider ensures that any natural person acting under its authority who has access to Lead Data does not process it except on Documented Instructions (Article 32(4) GDPR).
7.3. The Provider may update the TOMs from time to time, provided that updates do not materially diminish the overall level of protection of Lead Data. The current version of Annex II is available at https://useleadpass.com/legal/dpa.
8. Sub-processors
8.1. General authorisation. The Customer grants the Provider general written authorisation to engage the Sub-processors listed in Annex III, and to add or replace Sub-processors in accordance with this Section.
8.2. Current list. The current list of Sub-processors — including for each: name, function, the Lead Data concerned, processing location and transfer safeguard — is set out in Annex III and maintained at https://useleadpass.com/legal/dpa (Annex III).
8.3. Changes. The Provider will inform the Customer of any intended addition or replacement of a Sub-processor at least 14 days before the new Sub-processor processes Lead Data, by email to the Account owner. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected subscription and stop using the Service; Section 13 (Deletion and return) then applies. Continued use of the Service after the notice period constitutes acceptance of the change. This period reflects the shortest advance notice currently committed by a listed Sub-processor; the Provider will give longer notice where reasonably available.
8.4. Flow-down. The Provider imposes on each Sub-processor, by contract, data protection obligations providing materially the same level of protection as this DPA — in particular concerning security, confidentiality, sub-processing and international transfers.
8.5. Liability. Where a Sub-processor fails to fulfil its data protection obligations, the Provider remains fully liable to the Customer for the performance of that Sub-processor's obligations.
8.6. Boundary for billing, email and Provider-operated transcription. Stripe (payments and billing) and Fakturownia (fiscal invoicing) process data for which the Provider is controller and do not process Lead Data. They are therefore outside this DPA and are described in the Privacy Policy. Resend processes data for which the Provider is controller when delivering email to the Customer and its Users, and additionally acts as a Sub-processor of Lead Data for one narrow function: where a Flow collects the Lead's email address and the Customer enables the per-Flow switch, Resend delivers a private signed link to the Lead's Pass result screen when an authorised reviewer moves the Lead from Review to Pass. The message names the Flow and the Customer's business and contains that signed bearer link, but no external next-step URL, recordings, transcripts, scores or evaluation. The result screen resolves the Customer-authored Pass response and current button when opened. The Service sends Leads no other email. The speech-to-text transcription worker is operated by the Provider and is a component of the Service, not a separate third-party Sub-processor.
9. International transfers
9.1. The primary hosting and object-storage locations are listed in Annex III; the Provider-operated transcription worker is described in Annex III's notes. Third-country processing of Lead Data can occur through: OpenAI, for the text evaluation described in Annex I; Cloudflare, whose global network terminates public TLS and can process Lead Data transmitted through the Service; Resend, where a Flow's Review → Pass email is enabled; and Wasabi, to the extent its global support or administrative operations involve restricted access. Cloudflare's separate independent-controller use of IP, browser and Turnstile security signals to improve Turnstile is not processing on the Customer's instructions and is described in the Privacy Policy. A webhook destination selected by the Customer is not a Provider Sub-processor: any transfer caused by that destination is made on the Customer's instruction and is the Customer's responsibility under Section 5.5.
9.2. For restricted OpenAI transfers, the Provider relies on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 — Module Two and/or Module Three as applicable), an adequacy decision, or another valid Chapter V mechanism identified in OpenAI's data processing addendum. The Provider contracts with OpenAI Ireland Limited. OpenAI states that API data is not used to train its models by default; abuse-monitoring retention may apply for up to 30 days unless a different approved retention control applies, and prompt caching may temporarily retain encrypted key/value tensors in GPU-local storage until its stated 24-hour expiration.
9.3. What is transferred is limited by design: the Lead's name and company, the transcripts of the Lead's answers (including follow-up answers), and the Flow text needed for the relevant operation. Evaluation and follow-up operations receive the Flow's questions, criteria and instructions. For eligible automatic-Pass personalization, the separate composer instead receives the Flow name, questions and transcripts together with a factual identity extracted from the Customer's offer material (with no fallback: if the material does not yield a usable identity, no personalization request is made), compact offer units compiled from that material, and tone guidance. The composer does not receive the verdict, criteria, bands, outcome message, button, URL or routing instructions. It returns answer evidence for each proposed connection; the Service validates that evidence against stored answers as an internal integrity step and does not show the evidence or source-reference fields to either the Lead or Customer. The Lead's email address and phone number collected in the contact fields are never sent to OpenAI, and voice recordings are never sent to OpenAI — transcription runs on the Provider's own infrastructure. Transcripts are transmitted as spoken: contact details a Lead volunteers aloud in an answer reach OpenAI as part of the transcript text. The Provider's OpenAI configuration uses store=false; this does not remove OpenAI's separately described abuse-monitoring or temporary prompt-cache processing in Section 9.2.
9.4. Any other Sub-processor whose operations may involve a third country (including Cloudflare, Resend and Wasabi) is engaged subject to a valid Chapter V transfer mechanism, as recorded per Sub-processor in the "Transfer safeguard" column of Annex III.
9.5. On the Customer's written request, the Provider will make available documentation reasonably available to it and necessary to demonstrate the transfer safeguards relied on, subject to third-party confidentiality and security restrictions.
10. Assistance with data subject rights
10.1. Taking into account the nature of the processing, the Provider assists the Customer, by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subjects' requests under Articles 12–23 GDPR (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making).
10.2. In-product tools. The Service itself provides the primary assistance:
a) Access / explanation — the Customer can view, per Lead: contact fields, transcripts, per-criterion band scores with verbatim evidence quotes, the overall band, summary, analyzer proposal, published verdict, and the exact questions and criteria the Lead was assessed against (frozen per Lead). Where the Customer has decided or overridden a verdict, the proposal and the decision/override audit (who, when) are preserved. This supports answering requests for meaningful information about the logic of the assessment (Article 15(1)(h) GDPR). b) Erasure — the Customer can permanently delete an individual Lead (recordings, transcripts and analysis) from the Leads screen at any time; recordings are deleted from storage before the database records. Client Users cannot delete Leads. c) Rectification — the Provider executes requests to rectify a Lead's contact fields through support within a reasonable time.
10.3. Routing. If the Provider receives a request from a Lead directly, it will not respond on the merits (beyond acknowledging receipt and directing the Lead to the Customer as controller) and will forward the request to the Customer without undue delay, unless legally required to respond itself.
10.4. Assistance beyond the in-product tools that requires disproportionate manual effort may be charged at reasonable, documented cost, except where the need for assistance results from the Provider's breach of this DPA.
11. Assistance with Articles 32–36 GDPR
11.1. Taking into account the nature of the processing and the information available to it, the Provider assists the Customer in ensuring compliance with the Customer's obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation).
11.2. This includes, on written request: making available the current Annex II (TOMs), the description of the processing in Annex I, the Sub-processor list, and reasonable additional information about the Service's data flows needed for the Customer's own DPIA of its use of the Service.
12. Personal Data Breach notification
12.1. The Provider will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Lead Data, and in any event no later than 48 hours after becoming aware.
12.2. The notification will, to the extent then known (and supplemented in phases as information becomes available):
a) describe the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; b) name a contact point at the Provider; c) describe the likely consequences of the breach; and d) describe the measures taken or proposed to address the breach and mitigate its possible adverse effects.
12.3. The Provider will take reasonable steps to contain and remediate the breach and will cooperate with the Customer's reasonable requests for information needed for the Customer's notifications to supervisory authorities (Article 33 GDPR) and to data subjects (Article 34 GDPR).
12.4. The Provider does not notify supervisory authorities or Leads on the Customer's behalf, unless the parties agree otherwise in writing or the Provider is legally required to do so. The Customer is solely responsible for deciding whether and how to notify.
12.5. Notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability. Breaches affecting only data for which the Provider is controller are handled under the Privacy Policy, not this Section.
13. Deletion and return of Lead Data
13.1. During the Agreement, deletion runs continuously per the Customer's Documented Instructions:
a) Per-Flow audio-retention policy — each Flow deletes voice recordings under the policy the Customer selected: delete after qualification, keep 30 days (the new-Flow default), or keep. For every new Lead, a missing or invalid stored Flow value is presented and snapshotted as delete-after-qualification. A pre-retention-feature Lead that has no policy snapshot is different: if its Flow still has no explicit valid setting, completed audio remains kept rather than inventing a promise after the event; an explicit current setting applies. Where a snapshot exists, the stricter of the policy shown at recording and the current setting always wins, so a later change can never extend retention beyond what was shown. Delete-after runs when qualification completes (with the daily sweep as a retry/backstop); keep-30 becomes eligible for deletion after 30 days; keep remains until the Lead or Account lifecycle deletes it. Failed-Lead audio becomes eligible for deletion after 7 days regardless of policy, and test Leads after 30 days. A tracked storage refusal blocks a destructive database step and is retried rather than falsely recording completion. b) Per-Lead deletion — Section 10.2(b). c) Account deletion — when the Customer requests deletion of its Account, all Public Flow Pages close and the subscription is cancelled on day 0; after a 30-day grace period (during which the Customer can undo the request) the Account is permanently purged: recordings are deleted from storage first, then Workspaces, Flows, Leads (including transcripts and AI Outputs) and memberships are deleted.
13.2. Dormancy deletion (standing instruction). The Customer instructs the Provider to start and repeatedly attempt the permanent purge of all Lead Data of an Account when the applicable target is reached: (a) 12 months after the Account's billing access ended, where the Account ever started a subscription — including a payment-method-first free trial that never converted to a paid plan (warning email at approximately 11 months, never less than 14 days before the first purge attempt); or (b) 90 days after the trial ends, where the Account never started any subscription — an entry-flow trial without a payment method (warning at approximately day 76). Recordings are removed before their database pointers and Leads. A tracked storage failure blocks completion and the scheduler retries; it is not silently treated as a completed purge. Once complete, the Account shell (Users, Flows, criteria) is retained so the Customer can return; Lead Data is not.
13.3. At the end of the provision of services, at the choice of the Customer, the Provider will delete or return all Lead Data and delete existing copies, unless Union or Member State law requires storage of the personal data. Absent a different written instruction, the Customer's choice is deletion under the mechanics in Sections 13.1(c) and 13.2.
13.4. Surviving records. Deletion does not extend to: (a) records the Provider must retain under applicable law (in particular invoicing, payment and tax records — which concern the Customer, not Leads); and (b) the content-free technical telemetry described in Section 3.4. Log copies, where they exist, are deleted or overwritten in the ordinary rotation cycle described in Annex II and are not restored except for lawful recovery purposes.
13.5. On written request, the Provider will confirm in writing (email suffices) that deletion under this Section has been completed.
14. Audits and information
14.1. The Provider makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, as set out below.
14.2. Information first. The Provider satisfies audit requests in the first instance by providing: this DPA and its Annexes, the current TOMs, the Sub-processor list, relevant extracts of its records of processing (Section 18), transfer documentation (Section 9.5), and written answers to reasonable security questionnaires.
14.3. Inspections. Where the information under Section 14.2 is not reasonably sufficient, or where a supervisory authority requires it, the Customer (or a mandated auditor that is not a competitor of the Provider and is bound by confidentiality) may audit the Provider's relevant processing operations, subject to: at least 30 days' written notice; scope limited to Lead Data processing under this DPA; during business hours; no more than once in any 12-month period (except after a Personal Data Breach affecting the Customer's Lead Data or where required by a supervisory authority); no access to other customers' data or to the Provider's confidential information unrelated to the audit; and the Customer bearing its own costs and the Provider's reasonable, documented costs of supporting the audit.
14.4. Audit results are confidential information of both parties. The Customer will share findings relevant to the Provider's compliance so they can be remediated.
15. Customer obligations
15.1. The Customer is responsible for the lawfulness of the Lead Data processing within its role — as controller, or as an intermediary processor acting on its client controller's documented instructions — and in particular warrants that it:
a) has a valid legal basis (Article 6 GDPR) for the qualification of its Leads via the Service, and documents it. The Workspace profile supports legitimate interests under Article 6(1)(f) and necessary pre-contractual steps requested by the Lead under Article 6(1)(b). Until a complete confirmed profile exists, the Service presents Article 6(1)(f) with the localized template "Responding to and qualifying incoming business enquiries: we review each lead's answers against our published criteria to decide whether and how to follow up on their request." That product default is not a legitimate-interests assessment or a representation by the Provider that Article 6(1)(f) applies. Before processing real Leads, the Customer must determine the basis that actually applies; where it relies on legitimate interests it must verify the concrete interest and retain its assessment, and where the default is inaccurate it must save the correct supported basis in the Workspace profile; b) ensures that Leads receive the transparency information required by Articles 13/14 GDPR — including the actual controller's identity and contact details, purposes, legal basis, recipients (the Provider and the Sub-processors in Annex III, including the OpenAI transfer), retention, data-subject rights and the existence of automated assessment. A missing or incomplete confirmed profile does not by itself block new real Leads. Until a complete confirmed profile exists, the per-Flow notice uses the Workspace display name as the controller name, the Account owner's email as privacy contact, no postal address, and the legitimate-interests default in Section 15.1(a). The Customer acknowledges that the Provider does not verify that those synthesized values identify the actual controller or satisfy the Customer's transparency duties. The Customer must verify them before processing real Leads and save an accurate profile — including any postal address, representative or DPO details and agency processing chain that apply — wherever the fallback is not accurate and complete. The effective facts and basis actually shown, whether confirmed or synthesized, are frozen with the Lead for accountability; that snapshot evidences what was displayed, not that the Customer's choice was lawful; c) configures Flows lawfully — including honest questions, appropriate contact fields, and an audio-retention policy consistent with the promises it makes to Leads; d) does not design Flows to elicit special categories of personal data (Article 9 GDPR — e.g., health, religion, sexual orientation, trade-union membership) or data relating to criminal convictions (Article 10 GDPR). If such data may nevertheless arise incidentally in the Customer's context, the Customer is responsible for identifying and documenting an applicable Article 9(2) condition and for assessing, on the facts and risks of that processing, whether a DPIA is required; neither explicit consent nor a DPIA is represented here as universally sufficient or universally required; e) uses the Service only within the acceptable-use and AI use restrictions of the Terms — including the prohibitions on recruitment/employment screening, creditworthiness assessment and other restricted uses, and the rule that only the responding Lead may be recorded; f) does not use verdicts or AI Outputs as the sole basis for decisions producing legal or similarly significant effects on a Lead without the safeguards required by Article 22 GDPR — meaningful human review by a person with the authority and competence to change the decision, the possibility for the Lead to express their point of view, and to contest the decision. The Service supports these safeguards as follows: verdicts routed to the manual review queue can be overridden in-app (with the analyzer proposal preserved), and for every Lead the full assessment — transcripts, per-criterion bands with evidence quotes, and the frozen questions/criteria snapshots — is preserved so the Customer can re-decide (Section 17). For verdicts not routed to the review queue, the Customer must operate its own process for human review and for receiving and acting on a Lead's expression of views or contest of the decision; g) responds to data subjects' requests concerning Lead Data (the Provider assists per Section 10); and h) keeps its Account contact details current so that the Provider's notices under this DPA (Sub-processor changes, breach notifications, deletion warnings) reach it.
15.2. The Customer acknowledges that the Provider relies on the Customer's configuration as Documented Instructions and has no obligation to review Flow content for lawfulness (without prejudice to the Provider's moderation rights under the Terms).
16. No voice identification; nature of voice processing
16.1. Voice recordings of Leads are processed exclusively to transcribe what was said and to evaluate the content of the answers against the Customer's criteria. The Provider does not create voiceprints, does not perform speaker identification, verification or diarization for identity purposes, and does not analyse voice characteristics (tone, pitch, prosody) to infer emotions or anything else. Processing by the Service does not use specific technical means to uniquely identify a natural person from their voice; the recordings are therefore not processed as biometric data within the meaning of Articles 4(14) and 9(1) GDPR.
16.2. The AI evaluation instructions direct the model not to use protected characteristics (such as age, health, disability, family or marital status, pregnancy, ethnicity, religion, sexual orientation or trade-union membership) in scoring and not to reproduce them in evaluation output. Because free-form input and model output can be unpredictable, this control does not replace the Customer's obligation to avoid collecting such data and to review outputs before using them for significant decisions.
16.3. Any future feature that analyses vocal characteristics or performs speaker identification would require a reassessment of roles, legal basis, transparency, security and this DPA before it is made available for Lead Data.
17. Automated assessment; human review support
17.1. The Service produces AI-generated assessments of Leads (per-criterion bands and summary), then deterministically derives an analyzer proposal from the bands according to a fixed mapping defined by the Service. In automatic mode that proposal is published as the verdict; in per-Flow manual-review mode an authorised Customer team member publishes the verdict. Published verdicts can be overridden in-app; the Service preserves the analyzer proposal and records who decided or overrode the published verdict and when. There are four public result states — Pass, Review, No pass and Incomplete — and each uses the corresponding Customer-configured response or next action. While a real Lead processed under per-Flow manual-review mode awaits a decision, its public state is Review and its Review button is disabled. Once the Customer records Pass or No pass, that outcome and any configured button become the public result. If Review becomes Pass and the per-Flow email switch is enabled, the Service emails a private signed link to that Lead's Pass result screen; the screen resolves the Customer-authored Pass response and current button, and no other result or transition sends a Lead email. Manual-review runs receive no public AI personalization. The Service preserves the full assessment (transcripts, per-criterion bands with evidence quotes, and the frozen questions/criteria snapshots — Section 10.2(a)) so the Customer can re-decide outside the verdict field.
17.2. The Provider supports the Customer's Article 22 and transparency obligations by making available, per Lead, the criteria applied, the band per criterion with verbatim evidence quotes, and the frozen questions/criteria snapshots (Section 10.2(a)). The Provider does not itself take any decision concerning a Lead.
17.3. Responsibility for ensuring that any decision with legal or similarly significant effects on a Lead involves meaningful human review lies with the Customer (Section 15.1(f)).
18. Records; demonstration of compliance
18.1. The Provider will maintain the records of categories of processing activities required by Article 30(2) GDPR and will make the relevant record available to the Customer or a supervisory authority on request. Operational launch requires that record to be completed and kept current; this clause is not a statement that a separate certification or external audit exists.
18.2. Each party will cooperate, on request, with supervisory authorities in the performance of their tasks, within the scope of its role.
19. Liability
19.1. The liability of each party under or in connection with this DPA is subject to the exclusions and limitations set out in Section 18 of the Terms, which apply to this DPA as if set out in full here.
19.2. Nothing in this DPA or the Terms limits or excludes: (a) a data subject's rights against either party under Article 82 GDPR; or (b) either party's liability toward supervisory authorities. As between the parties, each is liable for administrative fines and Article 82 compensation to the extent attributable to its own breach of the GDPR or of this DPA, consistent with the allocation of responsibility in Articles 82(2)–(5) GDPR.
20. Term, termination and final provisions
20.1. This DPA takes effect when the Agreement is concluded and remains in force for as long as the Provider processes Lead Data on the Customer's behalf — including the retention and deletion windows described in Section 13, which survive termination of the subscription.
20.2. Termination of the Agreement terminates this DPA once deletion or return under Section 13 is complete. Sections that by their nature survive (in particular 3.3, 12, 13, 14, 19) survive.
20.3. Changes. The Provider may update this DPA under the change mechanism of the Terms (advance notice on a durable medium, effective date, right to terminate before the change takes effect), provided that changes never diminish the protection of Lead Data below what Article 28 GDPR requires. Sub-processor changes follow Section 8.3, not this Section.
20.4. Governing law and jurisdiction. This DPA is governed by Polish law, and disputes are resolved as set out in the Terms — without prejudice to the direct applicability of the GDPR and to the competence of supervisory authorities and courts under it.
20.5. If any provision of this DPA is held invalid, the remainder stays in force, and the invalid provision is replaced by a valid one that comes closest to the parties' intent and to the requirements of Article 28 GDPR.
Annex I — Description of the processing
1. Subject-matter
Provision of the LeadPass Service: AI-assisted voice qualification of the Customer's Leads — collection of a Lead's contact details and voice answers at a Public Flow Page, automated transcription, AI evaluation against the Customer's criteria, presentation of results (bands, summary, verdict) to the Customer — and, where the Customer separately enables personalization for a specific automatic-Pass response, display to an eligible Pass Lead of a short response containing between one and three validated connections between facts the Lead stated and distinct units grounded in the Customer's offer material — plus first-use measurement of a Customer-configured next-step button shown on an automatic-Pass result screen, and related storage, reporting and deletion.
2. Duration
The term of the Agreement, plus the deletion windows described in Section 13 of the DPA (per-Flow audio retention; 30-day account-deletion grace; 12-month / 90-day dormancy clocks), until deletion or return is complete.
3. Nature of the processing
Collection (via Public Flow Pages), recording, storage, organisation, transcription (speech-to-text on Provider-operated infrastructure), automated evaluation (transmission of transcripts to the AI Sub-processor and receipt of assessments), transmission of the optional Review → Pass email to the Lead's email address (Section 8.6), consultation and display to the Customer's authorised Users, optional generation and display of the personalized result-screen response described in Section 6 of this Annex, recording the first explicit use of a Customer-configured next-step button on an automatic-Pass result screen (without observing the external destination), transmission to a webhook destination selected by the Customer where configured, disclosure per Documented Instructions, restriction, erasure and destruction.
4. Purpose
Qualification of the Customer's Leads before the Customer's next step (call, proposal, booking), against criteria configured by the Customer, and reporting whether an automatic-Pass Lead used the next-step button shown by the Service. The event is not a booking, attendance, purchase or destination-tracking event. No other purpose (Section 3.3 of the DPA).
5. Categories of data subjects
Leads: natural persons (the Customer's prospects or enquirers, including natural-person representatives of prospect businesses) who answer a Flow at a Public Flow Page.
6. Categories of personal data
- Contact fields, as configured per Flow: name, email address, company, phone number. Each field can be off, optional or required, but at least email or phone is required; the default is name and email required, company and phone optional.
- Marketing attribution: a whitelist of campaign parameters attached to the Lead's visit (utm_source, utm_medium, utm_campaign, utm_content, utm_term, and Google/Meta click identifiers gclid/fbclid).
- Voice recordings of the Lead's answers (3 seconds to 10 minutes per answer).
- Transcripts of those answers, with technical segment metadata (detected language, timing, transcription model reference).
- AI-generated follow-up questions and the Lead's answers to them.
- AI Outputs about the Lead: per-criterion band scores with verbatim quotes of the Lead's words as evidence, overall band, summary, and the analyzer's proposal plus the published verdict — Pass / Review / No pass, or Incomplete where the available answers lack enough required or usable evidence for a reliable overall proposal. Incomplete may follow a partial response or a fully answered response that still omits a required fact; the available answers, bands and evidence remain visible to the Customer. A partial response with enough evidence may instead produce Pass, Review or No pass. Outputs also include manual-decision and override records (published verdict, analyzer proposal, who decided or overrode, and when) and, where the Customer enables personalization for an eligible automatic Pass, the personalized response generated for that Pass result. Each of the four public results uses the corresponding Customer-configured response or next action; internal result labels are not shown automatically. While a real manual-review Lead awaits a decision, its public result is Review without an active result button; after the Customer records Pass or No pass, that result and any configured button are shown. If Review becomes Pass and the per-Flow email switch is enabled, the Service emails a private signed link to that Lead's Pass result screen; the screen resolves the Customer-authored Pass response and current button, and no other result or transition sends a Lead email. Manual-review runs, Review, No pass and Incomplete receive no public personalization. The separate composer may use only facts stated in the Lead's answers, a factual offer identity extracted from the Customer's offer material (no personalization is composed when the material does not yield a usable identity), compact grounded units and tone guidance. It must return one natural introduction and three proposed connections, each joining a distinct Lead-stated fact to a distinct unit. The Service validates the answer evidence returned for each connection against the stored answers, resolves the source title and underlying claim, and omits individually any connection that fails validation; between one and three validated connections are shown. If no valid connection remains, no personalized AI block is shown. The Lead and Customer both see only the generated introduction, point titles and connection text, not transcript quotations, source cards, source titles, underlying claims or the internal validation fields. The Customer can audit that exact generated copy. The composer does not receive the verdict, criteria, bands, outcome message, button, URL or routing instructions. The Customer-configured outcome message and CTA are separately resolved by the Service. Optional presenter identity and image are resolved by the Service and appear only with the Customer-authored outcome, not as attribution for generated prose. The AI interaction is disclosed before the Lead starts and the per-Flow privacy notice describes the optional AI-written response. The exact generated copy and internal validation fields are stored within the assessment and deleted with it; the Customer can audit the copy, while the record does not establish that the Lead opened or viewed the result.
- Next-step first-click event: whether and when an automatic-Pass Lead first pressed the Customer-configured button on the result screen, the Pass verdict and verdict revision that issued it, and the Lead/Flow/Workspace references needed for the Customer's report. Buttons for other results and manually approved Passes are not measured, including when the Lead reached the screen through its approval email. No IP address, user agent, destination URL, repeated-click count, booking, attendance, purchase or destination activity is stored in this event.
- Snapshots of the exact questions asked and criteria applied to that Lead.
Note. The Lead's browser session (IP address, user agent — held in server-side session storage with a 120-minute idle lifetime) and IP-based security processing (rate limiting, anti-bot verification) are carried out by the Provider as controller for site security, as described in its Privacy Policy, and are not Lead Data under this DPA. No IP address or user agent is stored on the Lead record.
7. Special categories of data
None are intended or requested by the Service, and the Customer is prohibited from designing Flows to elicit them (Section 15.1(d)). Leads may incidentally volunteer such information in free-form voice answers; the Customer is responsible for that risk as controller. The AI evaluation is instructed to disregard protected characteristics (Section 16.2). Voice recordings are not processed as biometric data (Section 16.1).
8. Frequency
Continuous, for as long as the Customer operates Flows.
9. Retention summary (as instructed through the Service)
| Data | Retention |
|---|---|
| Voice recordings | Per-Flow policy for new Leads: eligible on qualification / after 30 days (new-Flow default) / kept until deletion; a missing/invalid Flow setting is presented and snapshotted as delete-on-qualification for a new Lead. A pre-feature row with neither a snapshot nor an explicit valid current setting remains Keep. Strictest of a valid policy-at-recording vs current policy wins. Failed audio becomes eligible after 7 days and test recordings after 30 days; tracked storage failures block completion and are retried. |
| Transcripts, contact fields, AI Outputs and any next-step first-click event | Life of the Lead — until per-Lead deletion, Account deletion (30-day grace, then purge) or the dormancy purge target (12 months after billing access ends for Accounts that ever started a subscription, including unconverted payment-method-first trials / 90 days after the trial ends for Accounts that never started one). The click event cascades with its Lead. A storage-blocked purge is retried until completion. |
| Content-free AI telemetry (Section 3.4) | Retained detached; contains no Lead content or contact data |
Browser session records (120-minute idle lifetime) are processed by the Provider as controller — see the note in Section 6 of this Annex — and are therefore not listed here.
Annex II — Technical and organisational measures (TOMs)
1. Encryption and transport security
- All web traffic to the Service (application, Public Flow Pages) is served over HTTPS/TLS.
- The deployed Service configures session cookies as HttpOnly, Secure and SameSite=Lax and encrypts server-side session data.
- Authorised playback uses 30-minute signed URLs. The normal asynchronous transcription path uses a two-hour signed URL; a recovery path may instead transmit audio directly to the Provider-operated worker in an authenticated request.
- Transcription callbacks require a bearer credential and, outside local/test environments, an HMAC-SHA-256 signature. A source-IP allowlist can also be configured. Payment webhooks are signature-verified.
- Public traffic terminates TLS at Cloudflare in front of the Service. Cloudflare can therefore process request and response traffic in transit, including Lead Data submitted through a Public Flow Page. Communication between the application and the transcription worker uses a Provider-configured endpoint authenticated with a bearer credential.
2. Pseudonymisation and data minimisation
- The transcription worker receives audio through a signed temporary URL in the normal path or as a direct upload in a recovery path, plus a random job identifier — no Lead name, email or phone number is included in the transcription request.
- OpenAI receives the minimized text described in Section 9.3 for evaluation, follow-ups or the optional personalized response — never the Lead's email, phone number or audio — and requests use
store=false. - No IP address or user agent is stored on Lead records; Lead IPs are used only ephemerally (rate limiting, anti-bot verification).
- Routine application logging is designed around internal record/job identifiers rather than transcript content. The application log channel is configured with a 14-day rotation; access to operational logs is restricted.
3. Access control and tenant isolation
- Multi-tenant access is enforced through Workspace-context middleware, membership checks and explicit Workspace scoping in tenant-data queries; Users are authorised only for Workspaces to which they belong.
- Role-based access: Account owner; Team Members (admin/member); Client Users limited to read-only access to Leads and reports in their Workspace, with no billing access and no ability to delete Leads.
- Authentication: passwords stored only as cryptographic hashes; TOTP two-factor authentication and WebAuthn passkeys available to all Users; re-authentication (password confirmation) required before sensitive operations; "remember me" only on explicit opt-in.
- Sessions are stored server-side with a 120-minute idle lifetime and are destroyed when the user is deleted.
- Invitations (Team Members, Client Users) use single-use tokens stored only as SHA-256 hashes, expiring after 7 days.
4. Lead Data lifecycle controls
- Upload validation for recordings (allowed formats, 20 MB size cap, 3 s – 10 min duration), stored under a dedicated, isolated storage prefix.
- Automated retention enforcement: purge of recordings on qualification (per policy), daily retention sweeps (30-day policy, 7-day failed-audio cleanup, 30-day test-data cleanup), per-Lead policy snapshots with strictest-wins semantics.
- A central audio-deletion service validates that an object is within the recordings storage prefix. Scheduled pruning records storage failures so a later run can retry them.
- Where a deletion still has a database pointer, the Service attempts to delete the stored recording before removing its record; a storage failure blocks that record deletion. When answer re-recording replaces an audio pointer, or a Failed Lead is restarted and replaced, the old recording paths are committed to a durable deletion outbox in the same database transaction as that change. The scheduled outbox worker retries blocked storage deletions with bounded exponential backoff until storage confirms that the object is gone; these paths are not left to a one-shot best-effort cleanup.
- Account-lifecycle jobs execute grace-period purges, dormancy warnings and dormancy purges, with state re-checks before a purge is applied.
5. Availability and resilience
- Queued, retry-safe background processing for transcription and evaluation; stuck or abandoned Leads are automatically recovered and finalised.
- Scheduled jobs run with overlap protection; failed deletion runs are retried daily.
6. Anti-abuse measures on Public Flow Pages
- Per-IP rate limiting on flow start, audio upload and restart; honeypot field; Cloudflare Turnstile human-verification challenge.
- Where a Flow collects an email address, deduplication prevents more than one non-test Lead with the same email address to that Flow.
7. Organisational measures
- Personnel access to Lead Data restricted to operational need; personnel process Lead Data only on Documented Instructions and are bound by confidentiality (Section 6).
- Changes to the Service are developed against an automated test suite and reviewed before deployment.
- The AI evaluation prompt instructs the model not to use protected characteristics in scoring or reproduce them in output; Customers remain responsible for avoiding sensitive questions and reviewing outputs (Section 16.2).
Annex III — Authorised Sub-processors (Lead Data)
Current as of: 16 July 2026. Maintained at: https://useleadpass.com/legal/dpa (this Annex). Changes follow Section 8.3.
| # | Sub-processor | Function | Lead Data processed | Location | Transfer safeguard |
|---|---|---|---|---|---|
| 1 | OpenAI — contracting entity for the EEA: OpenAI Ireland Limited | AI evaluation of answers; generation of follow-up questions; optional generation of the personalized response shown to eligible automatic-Pass Leads | Lead name, company, answer transcripts and follow-up answers; the Flow text needed for the operation (questions, criteria and instructions for evaluation/follow-ups; Flow name, questions, factual offer identity extracted from Customer material — no personalization request occurs without it — compiled offer units and tone guidance for personalization). The personalization request does not include the verdict, criteria, bands, outcome message, button, URL or routing instructions. It returns answer evidence which the Service validates against stored answers as an internal integrity step and does not display to either the Lead or Customer. Never Lead email, phone number or audio. | Ireland (contracting entity); OpenAI affiliates and authorised sub-processors may process in other locations listed by OpenAI, including the USA | EU Standard Contractual Clauses (Decision (EU) 2021/914, Modules Two and Three as applicable), adequacy decisions or another valid Chapter V mechanism identified in OpenAI's DPA; requests use store=false; OpenAI states that API data is not used for training by default, abuse-monitoring retention may apply for up to 30 days, and temporary prompt-cache state may remain for up to 24 hours |
| 2 | Hetzner Online GmbH | Hosting of the application and database and infrastructure used for Provider-operated processing | Lead Data held in the application/database and processed on that infrastructure; recordings stored by Wasabi and data sent to the other listed Sub-processors are excluded | Germany (EU datacenters) | None required for processing in Germany; Hetzner Online GmbH is engaged under its Article 28 data processing terms |
| 3 | Wasabi Technologies LLC | Object storage for voice recordings | Voice recordings and object metadata | Storage configured in EU region eu-central-2 (Frankfurt, Germany); Wasabi's global support and administrative operations may involve access from other locations | EU Standard Contractual Clauses incorporated into Wasabi's data-processing terms for restricted transfers; storage-region and access controls configured for the Service |
| 4 | Cloudflare, Inc. | TLS termination, network security and delivery in front of the Service; Turnstile bot protection. Cloudflare's stated independent-controller use of Turnstile signals to improve Turnstile is disclosed in the Privacy Policy and is not sub-processing on the Customer's instructions. | Request and response traffic in transit, which can include contact fields, audio uploads and other Lead Data; IP, browser/device/network signals and Turnstile challenge data | Global network / USA | EU–U.S. Data Privacy Framework where applicable and EU Standard Contractual Clauses incorporated into the Cloudflare Customer DPA for other restricted transfers |
| 5 | Resend (legal entity: Plus Five Five, Inc.) | Transactional email — delivery of the optional Review → Pass Lead email described in Section 8.6 | Lead email address; Flow name; Customer business name; private signed bearer link to that Lead's Pass result screen — no Customer external next-step URL, recordings, transcripts or AI Outputs in the email body | USA | EU–U.S. Data Privacy Framework (Plus Five Five, Inc. — record #8907; certified to the EU–U.S. DPF and the UK Extension per Resend's DPA Section 11.1) and, in any event, EU Standard Contractual Clauses deemed entered into under Resend's DPA (Sections 6.2–6.3) |
Notes.
- The speech-to-text transcription worker is operated by the Provider itself and is not a third-party Sub-processor. The application supplies audio by expiring signed URL in the normal asynchronous path or by authenticated direct upload in a recovery path, together with a random job identifier; the job does not include the Lead's name, email or phone number. Any temporary working data exists only to complete transcription and is not the system of record.
- Stripe (payments, billing and tax) and Fakturownia (fiscal invoicing) do not process Lead Data and are outside this DPA. Resend processes data for which the Provider is controller when delivering transactional email to the Customer and its Users, and acts as Sub-processor #5 for the optional Review → Pass email described in Section 8.6. These providers are also described in the Privacy Policy.
- Sub-processors added or replaced after the date above will be notified under Section 8.3 before they process Lead Data.