LeadPass

LeadPass Data Processing Agreement

(Umowa powierzenia przetwarzania danych osobowych — Article 28 GDPR)

Effective date: 20 July 2026 Version: 1.0


1. Parties, incorporation and precedence

1.1. This Data Processing Agreement (the "DPA") is concluded between:

Jose Ramon Leon Rodriguez, a sole trader (jednoosobowa działalność gospodarcza) established in Poland Registered address: Egipska 5/69, 03-977 Warszawa, Poland NIP (tax ID): 8992886524 · EU VAT: PL8992886524 · REGON: 387147849 Registration: entered in CEIDG (Centralna Ewidencja i Informacja o Działalności Gospodarczej) Contact: legal [at] useleadpass.com

(the "Provider", "LeadPass", "we", "us") — acting as processor or sub-processor, as applicable,

and the Customer — acting as controller of Lead Data or as an intermediary processor authorised by its client controller, as described in Section 3.5.

1.2. This DPA is incorporated by reference into, and forms an integral part of, the LeadPass Terms of Service (the "Terms"). It is concluded electronically when the Account owner confirms the subscription checkout action beside the link to this DPA; the Service records that acceptance for the Account. No separate signature is required. Article 28(9) GDPR permits this electronic form.

1.3. This DPA governs the Provider's processing of Lead Data on the Customer's behalf. In case of conflict between this DPA and the Terms regarding the processing of Lead Data, this DPA prevails. For all other matters the Terms prevail.

1.4. This DPA is drafted to satisfy Article 28(3) GDPR. If mandatory law applicable to the Customer requires the parties to execute the European Commission's standard contractual clauses for Article 28 contracts (Commission Implementing Decision (EU) 2021/915), the parties will do so on the Customer's written request; those clauses will then be read consistently with the commercial terms of this DPA.


2. Definitions

Capitalised terms not defined here have the meaning given in the Terms — in particular "Account", "Workspace", "Flow", "Public Flow Page", "Lead", "Lead Data", "AI Outputs", "User", "Team Member", "Client User", "Plan" and the "Service".


3. Roles and scope

3.1. Roles. For Lead Data, the Customer is the controller (or, where the Customer itself acts for another controller, a processor — see Section 3.5) and the Provider is the Customer's processor. The Customer determines the purposes of processing Lead Data (which prospects to qualify, what to ask, which criteria apply, what happens with the outcome); the Provider processes Lead Data only to provide the Service, on Documented Instructions.

3.2. Outside this DPA. This DPA does not cover personal data for which the Provider is the controller — in particular registration and profile data of the Customer and its Users (including Team Members and Client Users), billing and payment data, support correspondence, and marketing-site visitor data. That processing is described in the LeadPass Privacy Policy.

3.3. No own purposes (Article 28(10) GDPR). The Provider processes Lead Data solely to provide the Service and on Documented Instructions. The Provider does not:

a) use Lead Data (including voice recordings, transcripts or AI Outputs) to train, fine-tune or improve AI models — its own or any third party's; b) sell Lead Data or use it for advertising, benchmarking, prospecting or any other purpose of its own; c) create voiceprints or use recordings to identify or authenticate speakers (Section 16).

3.4. Content-free telemetry. The Customer acknowledges and instructs that the Provider records, per AI operation, purely technical usage telemetry (model name, token counts, cost, latency and internal references) which contains no Lead content and no Lead contact data. This telemetry is financial/operational bookkeeping of the Provider; it is retained detached from any tenant after deletion and is not "Lead Data".

3.5. Customer as intermediary processor. Where the Customer runs a Workspace on behalf of its own client (e.g., an agency operating Flows for that client), the Customer warrants that it is authorised by the relevant controller to engage the Provider on the terms of this DPA, and references to the "controller's" rights and obligations apply to that arrangement accordingly.


4. Details of the processing

The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.


5. Documented Instructions

5.1. The Customer's complete and final Documented Instructions to the Provider are:

a) this DPA and the Terms; b) the Customer's configuration and use of the Service through its documented features and settings — including, without limitation: which contact fields each Flow requests, the questions and qualification criteria of each Flow, the Flow language, each Flow's audio-retention policy, the Workspace's outbound webhook endpoint (one destination used by all of its Flows, with the Pass / Review / No pass categories the Customer selects), opening/closing of Public Flow Pages, use of the review queue and manual verdict overrides, invitation of Users, and deletion of individual Leads or of the Account; and c) any further written instructions agreed by the parties, where the Provider can reasonably implement them within the Service.

5.2. Technical latitude. The Provider may select and update the non-essential technical means of the processing — including transcription and evaluation models, infrastructure, and internal processing mechanics — provided the changes do not diminish the level of protection of Lead Data and comply with Sections 8 (Sub-processors) and 9 (Transfers). Such updates are not a change of Documented Instructions.

5.3. Unlawful instructions. The Provider will immediately inform the Customer if, in the Provider's opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. The Provider may suspend execution of the instruction concerned until it is confirmed or modified.

5.4. Transfers on instruction. The Provider transfers Lead Data to a third country only as described in Section 9 and Annex III, which the Customer authorises as part of its Documented Instructions, or where required by Union or Member State law applicable to the Provider — in which case the Provider will inform the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.

5.5. Outbound webhooks. Where the Customer configures a Workspace webhook, the Provider uses that one endpoint for the Workspace's Flows and, for the Pass / Review / No pass verdict categories the Customer selected, transmits to the chosen URL — signed so the recipient can authenticate the Provider — the qualified Lead's contact details, verdict, assessment and eligible later verdict changes. An initial Incomplete result is not a subscribable webhook category. This transmission is a disclosure to the Customer, or to a recipient acting on the Customer's behalf (for example the Customer's CRM or an automation platform the Customer has engaged), made on Documented Instructions. Such recipients are engaged by the Customer, act under the Customer's responsibility as its own processors or recipients, and are not sub-processors of the Provider; the Customer is responsible for the lawfulness of the destination it configures. The Provider keeps delivery records (including the transmitted payload) for 30 days for delivery assurance and support, after which they are deleted automatically; deleting a Lead deletes its delivery records immediately.


6. Confidentiality

6.1. The Provider ensures that every person authorised to process Lead Data (employees, contractors) is bound by a contractual confidentiality obligation or an appropriate statutory obligation of confidentiality, and processes Lead Data only on Documented Instructions and to the extent needed for their role.

6.2. Access to Lead Data within the Provider's organisation is restricted to persons who need it to operate, support or secure the Service.


7. Security (Article 32 GDPR)

7.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to data subjects, the Provider implements and maintains the technical and organisational measures described in Annex II. Annex II describes the controls implemented in the Service; it does not represent a third-party certification or guarantee that a security incident can never occur. The Provider reviews the measures as the Service, deployment and risk profile change.

7.2. The Provider ensures that any natural person acting under its authority who has access to Lead Data does not process it except on Documented Instructions (Article 32(4) GDPR).

7.3. The Provider may update the TOMs from time to time, provided that updates do not materially diminish the overall level of protection of Lead Data. The current version of Annex II is available at https://useleadpass.com/legal/dpa.


8. Sub-processors

8.1. General authorisation. The Customer grants the Provider general written authorisation to engage the Sub-processors listed in Annex III, and to add or replace Sub-processors in accordance with this Section.

8.2. Current list. The current list of Sub-processors — including for each: name, function, the Lead Data concerned, processing location and transfer safeguard — is set out in Annex III and maintained at https://useleadpass.com/legal/dpa (Annex III).

8.3. Changes. The Provider will inform the Customer of any intended addition or replacement of a Sub-processor at least 14 days before the new Sub-processor processes Lead Data, by email to the Account owner. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected subscription and stop using the Service; Section 13 (Deletion and return) then applies. Continued use of the Service after the notice period constitutes acceptance of the change. This period reflects the shortest advance notice currently committed by a listed Sub-processor; the Provider will give longer notice where reasonably available.

8.4. Flow-down. The Provider imposes on each Sub-processor, by contract, data protection obligations providing materially the same level of protection as this DPA — in particular concerning security, confidentiality, sub-processing and international transfers.

8.5. Liability. Where a Sub-processor fails to fulfil its data protection obligations, the Provider remains fully liable to the Customer for the performance of that Sub-processor's obligations.

8.6. Boundary for billing, email and Provider-operated transcription. Stripe (payments and billing) and Fakturownia (fiscal invoicing) process data for which the Provider is controller and do not process Lead Data. They are therefore outside this DPA and are described in the Privacy Policy. Resend processes data for which the Provider is controller when delivering email to the Customer and its Users, and additionally acts as a Sub-processor of Lead Data for one narrow function: where a Flow collects the Lead's email address and the Customer enables the per-Flow switch, Resend delivers a private signed link to the Lead's Pass result screen when an authorised reviewer moves the Lead from Review to Pass. The message names the Flow and the Customer's business and contains that signed bearer link, but no external next-step URL, recordings, transcripts, scores or evaluation. The result screen resolves the Customer-authored Pass response and current button when opened. The Service sends Leads no other email. The speech-to-text transcription worker is operated by the Provider and is a component of the Service, not a separate third-party Sub-processor.


9. International transfers

9.1. The primary hosting and object-storage locations are listed in Annex III; the Provider-operated transcription worker is described in Annex III's notes. Third-country processing of Lead Data can occur through: OpenAI, for the text evaluation described in Annex I; Cloudflare, whose global network terminates public TLS and can process Lead Data transmitted through the Service; Resend, where a Flow's Review → Pass email is enabled; and Wasabi, to the extent its global support or administrative operations involve restricted access. Cloudflare's separate independent-controller use of IP, browser and Turnstile security signals to improve Turnstile is not processing on the Customer's instructions and is described in the Privacy Policy. A webhook destination selected by the Customer is not a Provider Sub-processor: any transfer caused by that destination is made on the Customer's instruction and is the Customer's responsibility under Section 5.5.

9.2. For restricted OpenAI transfers, the Provider relies on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 — Module Two and/or Module Three as applicable), an adequacy decision, or another valid Chapter V mechanism identified in OpenAI's data processing addendum. The Provider contracts with OpenAI Ireland Limited. OpenAI states that API data is not used to train its models by default; abuse-monitoring retention may apply for up to 30 days unless a different approved retention control applies, and prompt caching may temporarily retain encrypted key/value tensors in GPU-local storage until its stated 24-hour expiration.

9.3. What is transferred is limited by design: the Lead's name and company, the transcripts of the Lead's answers (including follow-up answers), and the Flow text needed for the relevant operation. Evaluation and follow-up operations receive the Flow's questions, criteria and instructions. For eligible automatic-Pass personalization, the separate composer instead receives the Flow name, questions and transcripts together with a factual identity extracted from the Customer's offer material (with no fallback: if the material does not yield a usable identity, no personalization request is made), compact offer units compiled from that material, and tone guidance. The composer does not receive the verdict, criteria, bands, outcome message, button, URL or routing instructions. It returns answer evidence for each proposed connection; the Service validates that evidence against stored answers as an internal integrity step and does not show the evidence or source-reference fields to either the Lead or Customer. The Lead's email address and phone number collected in the contact fields are never sent to OpenAI, and voice recordings are never sent to OpenAI — transcription runs on the Provider's own infrastructure. Transcripts are transmitted as spoken: contact details a Lead volunteers aloud in an answer reach OpenAI as part of the transcript text. The Provider's OpenAI configuration uses store=false; this does not remove OpenAI's separately described abuse-monitoring or temporary prompt-cache processing in Section 9.2.

9.4. Any other Sub-processor whose operations may involve a third country (including Cloudflare, Resend and Wasabi) is engaged subject to a valid Chapter V transfer mechanism, as recorded per Sub-processor in the "Transfer safeguard" column of Annex III.

9.5. On the Customer's written request, the Provider will make available documentation reasonably available to it and necessary to demonstrate the transfer safeguards relied on, subject to third-party confidentiality and security restrictions.


10. Assistance with data subject rights

10.1. Taking into account the nature of the processing, the Provider assists the Customer, by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subjects' requests under Articles 12–23 GDPR (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making).

10.2. In-product tools. The Service itself provides the primary assistance:

a) Access / explanation — the Customer can view, per Lead: contact fields, transcripts, per-criterion band scores with verbatim evidence quotes, the overall band, summary, analyzer proposal, published verdict, and the exact questions and criteria the Lead was assessed against (frozen per Lead). Where the Customer has decided or overridden a verdict, the proposal and the decision/override audit (who, when) are preserved. This supports answering requests for meaningful information about the logic of the assessment (Article 15(1)(h) GDPR). b) Erasure — the Customer can permanently delete an individual Lead (recordings, transcripts and analysis) from the Leads screen at any time; recordings are deleted from storage before the database records. Client Users cannot delete Leads. c) Rectification — the Provider executes requests to rectify a Lead's contact fields through support within a reasonable time.

10.3. Routing. If the Provider receives a request from a Lead directly, it will not respond on the merits (beyond acknowledging receipt and directing the Lead to the Customer as controller) and will forward the request to the Customer without undue delay, unless legally required to respond itself.

10.4. Assistance beyond the in-product tools that requires disproportionate manual effort may be charged at reasonable, documented cost, except where the need for assistance results from the Provider's breach of this DPA.


11. Assistance with Articles 32–36 GDPR

11.1. Taking into account the nature of the processing and the information available to it, the Provider assists the Customer in ensuring compliance with the Customer's obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation).

11.2. This includes, on written request: making available the current Annex II (TOMs), the description of the processing in Annex I, the Sub-processor list, and reasonable additional information about the Service's data flows needed for the Customer's own DPIA of its use of the Service.


12. Personal Data Breach notification

12.1. The Provider will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Lead Data, and in any event no later than 48 hours after becoming aware.

12.2. The notification will, to the extent then known (and supplemented in phases as information becomes available):

a) describe the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; b) name a contact point at the Provider; c) describe the likely consequences of the breach; and d) describe the measures taken or proposed to address the breach and mitigate its possible adverse effects.

12.3. The Provider will take reasonable steps to contain and remediate the breach and will cooperate with the Customer's reasonable requests for information needed for the Customer's notifications to supervisory authorities (Article 33 GDPR) and to data subjects (Article 34 GDPR).

12.4. The Provider does not notify supervisory authorities or Leads on the Customer's behalf, unless the parties agree otherwise in writing or the Provider is legally required to do so. The Customer is solely responsible for deciding whether and how to notify.

12.5. Notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability. Breaches affecting only data for which the Provider is controller are handled under the Privacy Policy, not this Section.


13. Deletion and return of Lead Data

13.1. During the Agreement, deletion runs continuously per the Customer's Documented Instructions:

a) Per-Flow audio-retention policy — each Flow deletes voice recordings under the policy the Customer selected: delete after qualification, keep 30 days (the new-Flow default), or keep. For every new Lead, a missing or invalid stored Flow value is presented and snapshotted as delete-after-qualification. A pre-retention-feature Lead that has no policy snapshot is different: if its Flow still has no explicit valid setting, completed audio remains kept rather than inventing a promise after the event; an explicit current setting applies. Where a snapshot exists, the stricter of the policy shown at recording and the current setting always wins, so a later change can never extend retention beyond what was shown. Delete-after runs when qualification completes (with the daily sweep as a retry/backstop); keep-30 becomes eligible for deletion after 30 days; keep remains until the Lead or Account lifecycle deletes it. Failed-Lead audio becomes eligible for deletion after 7 days regardless of policy, and test Leads after 30 days. A tracked storage refusal blocks a destructive database step and is retried rather than falsely recording completion. b) Per-Lead deletion — Section 10.2(b). c) Account deletion — when the Customer requests deletion of its Account, all Public Flow Pages close and the subscription is cancelled on day 0; after a 30-day grace period (during which the Customer can undo the request) the Account is permanently purged: recordings are deleted from storage first, then Workspaces, Flows, Leads (including transcripts and AI Outputs) and memberships are deleted.

13.2. Dormancy deletion (standing instruction). The Customer instructs the Provider to start and repeatedly attempt the permanent purge of all Lead Data of an Account when the applicable target is reached: (a) 12 months after the Account's billing access ended, where the Account ever started a subscription — including a payment-method-first free trial that never converted to a paid plan (warning email at approximately 11 months, never less than 14 days before the first purge attempt); or (b) 90 days after the trial ends, where the Account never started any subscription — an entry-flow trial without a payment method (warning at approximately day 76). Recordings are removed before their database pointers and Leads. A tracked storage failure blocks completion and the scheduler retries; it is not silently treated as a completed purge. Once complete, the Account shell (Users, Flows, criteria) is retained so the Customer can return; Lead Data is not.

13.3. At the end of the provision of services, at the choice of the Customer, the Provider will delete or return all Lead Data and delete existing copies, unless Union or Member State law requires storage of the personal data. Absent a different written instruction, the Customer's choice is deletion under the mechanics in Sections 13.1(c) and 13.2.

13.4. Surviving records. Deletion does not extend to: (a) records the Provider must retain under applicable law (in particular invoicing, payment and tax records — which concern the Customer, not Leads); and (b) the content-free technical telemetry described in Section 3.4. Log copies, where they exist, are deleted or overwritten in the ordinary rotation cycle described in Annex II and are not restored except for lawful recovery purposes.

13.5. On written request, the Provider will confirm in writing (email suffices) that deletion under this Section has been completed.


14. Audits and information

14.1. The Provider makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, as set out below.

14.2. Information first. The Provider satisfies audit requests in the first instance by providing: this DPA and its Annexes, the current TOMs, the Sub-processor list, relevant extracts of its records of processing (Section 18), transfer documentation (Section 9.5), and written answers to reasonable security questionnaires.

14.3. Inspections. Where the information under Section 14.2 is not reasonably sufficient, or where a supervisory authority requires it, the Customer (or a mandated auditor that is not a competitor of the Provider and is bound by confidentiality) may audit the Provider's relevant processing operations, subject to: at least 30 days' written notice; scope limited to Lead Data processing under this DPA; during business hours; no more than once in any 12-month period (except after a Personal Data Breach affecting the Customer's Lead Data or where required by a supervisory authority); no access to other customers' data or to the Provider's confidential information unrelated to the audit; and the Customer bearing its own costs and the Provider's reasonable, documented costs of supporting the audit.

14.4. Audit results are confidential information of both parties. The Customer will share findings relevant to the Provider's compliance so they can be remediated.


15. Customer obligations

15.1. The Customer is responsible for the lawfulness of the Lead Data processing within its role — as controller, or as an intermediary processor acting on its client controller's documented instructions — and in particular warrants that it:

a) has a valid legal basis (Article 6 GDPR) for the qualification of its Leads via the Service, and documents it. The Workspace profile supports legitimate interests under Article 6(1)(f) and necessary pre-contractual steps requested by the Lead under Article 6(1)(b). Until a complete confirmed profile exists, the Service presents Article 6(1)(f) with the localized template "Responding to and qualifying incoming business enquiries: we review each lead's answers against our published criteria to decide whether and how to follow up on their request." That product default is not a legitimate-interests assessment or a representation by the Provider that Article 6(1)(f) applies. Before processing real Leads, the Customer must determine the basis that actually applies; where it relies on legitimate interests it must verify the concrete interest and retain its assessment, and where the default is inaccurate it must save the correct supported basis in the Workspace profile; b) ensures that Leads receive the transparency information required by Articles 13/14 GDPR — including the actual controller's identity and contact details, purposes, legal basis, recipients (the Provider and the Sub-processors in Annex III, including the OpenAI transfer), retention, data-subject rights and the existence of automated assessment. A missing or incomplete confirmed profile does not by itself block new real Leads. Until a complete confirmed profile exists, the per-Flow notice uses the Workspace display name as the controller name, the Account owner's email as privacy contact, no postal address, and the legitimate-interests default in Section 15.1(a). The Customer acknowledges that the Provider does not verify that those synthesized values identify the actual controller or satisfy the Customer's transparency duties. The Customer must verify them before processing real Leads and save an accurate profile — including any postal address, representative or DPO details and agency processing chain that apply — wherever the fallback is not accurate and complete. The effective facts and basis actually shown, whether confirmed or synthesized, are frozen with the Lead for accountability; that snapshot evidences what was displayed, not that the Customer's choice was lawful; c) configures Flows lawfully — including honest questions, appropriate contact fields, and an audio-retention policy consistent with the promises it makes to Leads; d) does not design Flows to elicit special categories of personal data (Article 9 GDPR — e.g., health, religion, sexual orientation, trade-union membership) or data relating to criminal convictions (Article 10 GDPR). If such data may nevertheless arise incidentally in the Customer's context, the Customer is responsible for identifying and documenting an applicable Article 9(2) condition and for assessing, on the facts and risks of that processing, whether a DPIA is required; neither explicit consent nor a DPIA is represented here as universally sufficient or universally required; e) uses the Service only within the acceptable-use and AI use restrictions of the Terms — including the prohibitions on recruitment/employment screening, creditworthiness assessment and other restricted uses, and the rule that only the responding Lead may be recorded; f) does not use verdicts or AI Outputs as the sole basis for decisions producing legal or similarly significant effects on a Lead without the safeguards required by Article 22 GDPR — meaningful human review by a person with the authority and competence to change the decision, the possibility for the Lead to express their point of view, and to contest the decision. The Service supports these safeguards as follows: verdicts routed to the manual review queue can be overridden in-app (with the analyzer proposal preserved), and for every Lead the full assessment — transcripts, per-criterion bands with evidence quotes, and the frozen questions/criteria snapshots — is preserved so the Customer can re-decide (Section 17). For verdicts not routed to the review queue, the Customer must operate its own process for human review and for receiving and acting on a Lead's expression of views or contest of the decision; g) responds to data subjects' requests concerning Lead Data (the Provider assists per Section 10); and h) keeps its Account contact details current so that the Provider's notices under this DPA (Sub-processor changes, breach notifications, deletion warnings) reach it.

15.2. The Customer acknowledges that the Provider relies on the Customer's configuration as Documented Instructions and has no obligation to review Flow content for lawfulness (without prejudice to the Provider's moderation rights under the Terms).


16. No voice identification; nature of voice processing

16.1. Voice recordings of Leads are processed exclusively to transcribe what was said and to evaluate the content of the answers against the Customer's criteria. The Provider does not create voiceprints, does not perform speaker identification, verification or diarization for identity purposes, and does not analyse voice characteristics (tone, pitch, prosody) to infer emotions or anything else. Processing by the Service does not use specific technical means to uniquely identify a natural person from their voice; the recordings are therefore not processed as biometric data within the meaning of Articles 4(14) and 9(1) GDPR.

16.2. The AI evaluation instructions direct the model not to use protected characteristics (such as age, health, disability, family or marital status, pregnancy, ethnicity, religion, sexual orientation or trade-union membership) in scoring and not to reproduce them in evaluation output. Because free-form input and model output can be unpredictable, this control does not replace the Customer's obligation to avoid collecting such data and to review outputs before using them for significant decisions.

16.3. Any future feature that analyses vocal characteristics or performs speaker identification would require a reassessment of roles, legal basis, transparency, security and this DPA before it is made available for Lead Data.


17. Automated assessment; human review support

17.1. The Service produces AI-generated assessments of Leads (per-criterion bands and summary), then deterministically derives an analyzer proposal from the bands according to a fixed mapping defined by the Service. In automatic mode that proposal is published as the verdict; in per-Flow manual-review mode an authorised Customer team member publishes the verdict. Published verdicts can be overridden in-app; the Service preserves the analyzer proposal and records who decided or overrode the published verdict and when. There are four public result states — Pass, Review, No pass and Incomplete — and each uses the corresponding Customer-configured response or next action. While a real Lead processed under per-Flow manual-review mode awaits a decision, its public state is Review and its Review button is disabled. Once the Customer records Pass or No pass, that outcome and any configured button become the public result. If Review becomes Pass and the per-Flow email switch is enabled, the Service emails a private signed link to that Lead's Pass result screen; the screen resolves the Customer-authored Pass response and current button, and no other result or transition sends a Lead email. Manual-review runs receive no public AI personalization. The Service preserves the full assessment (transcripts, per-criterion bands with evidence quotes, and the frozen questions/criteria snapshots — Section 10.2(a)) so the Customer can re-decide outside the verdict field.

17.2. The Provider supports the Customer's Article 22 and transparency obligations by making available, per Lead, the criteria applied, the band per criterion with verbatim evidence quotes, and the frozen questions/criteria snapshots (Section 10.2(a)). The Provider does not itself take any decision concerning a Lead.

17.3. Responsibility for ensuring that any decision with legal or similarly significant effects on a Lead involves meaningful human review lies with the Customer (Section 15.1(f)).


18. Records; demonstration of compliance

18.1. The Provider will maintain the records of categories of processing activities required by Article 30(2) GDPR and will make the relevant record available to the Customer or a supervisory authority on request. Operational launch requires that record to be completed and kept current; this clause is not a statement that a separate certification or external audit exists.

18.2. Each party will cooperate, on request, with supervisory authorities in the performance of their tasks, within the scope of its role.


19. Liability

19.1. The liability of each party under or in connection with this DPA is subject to the exclusions and limitations set out in Section 18 of the Terms, which apply to this DPA as if set out in full here.

19.2. Nothing in this DPA or the Terms limits or excludes: (a) a data subject's rights against either party under Article 82 GDPR; or (b) either party's liability toward supervisory authorities. As between the parties, each is liable for administrative fines and Article 82 compensation to the extent attributable to its own breach of the GDPR or of this DPA, consistent with the allocation of responsibility in Articles 82(2)–(5) GDPR.


20. Term, termination and final provisions

20.1. This DPA takes effect when the Agreement is concluded and remains in force for as long as the Provider processes Lead Data on the Customer's behalf — including the retention and deletion windows described in Section 13, which survive termination of the subscription.

20.2. Termination of the Agreement terminates this DPA once deletion or return under Section 13 is complete. Sections that by their nature survive (in particular 3.3, 12, 13, 14, 19) survive.

20.3. Changes. The Provider may update this DPA under the change mechanism of the Terms (advance notice on a durable medium, effective date, right to terminate before the change takes effect), provided that changes never diminish the protection of Lead Data below what Article 28 GDPR requires. Sub-processor changes follow Section 8.3, not this Section.

20.4. Governing law and jurisdiction. This DPA is governed by Polish law, and disputes are resolved as set out in the Terms — without prejudice to the direct applicability of the GDPR and to the competence of supervisory authorities and courts under it.

20.5. If any provision of this DPA is held invalid, the remainder stays in force, and the invalid provision is replaced by a valid one that comes closest to the parties' intent and to the requirements of Article 28 GDPR.


Annex I — Description of the processing

1. Subject-matter

Provision of the LeadPass Service: AI-assisted voice qualification of the Customer's Leads — collection of a Lead's contact details and voice answers at a Public Flow Page, automated transcription, AI evaluation against the Customer's criteria, presentation of results (bands, summary, verdict) to the Customer — and, where the Customer separately enables personalization for a specific automatic-Pass response, display to an eligible Pass Lead of a short response containing between one and three validated connections between facts the Lead stated and distinct units grounded in the Customer's offer material — plus first-use measurement of a Customer-configured next-step button shown on an automatic-Pass result screen, and related storage, reporting and deletion.

2. Duration

The term of the Agreement, plus the deletion windows described in Section 13 of the DPA (per-Flow audio retention; 30-day account-deletion grace; 12-month / 90-day dormancy clocks), until deletion or return is complete.

3. Nature of the processing

Collection (via Public Flow Pages), recording, storage, organisation, transcription (speech-to-text on Provider-operated infrastructure), automated evaluation (transmission of transcripts to the AI Sub-processor and receipt of assessments), transmission of the optional Review → Pass email to the Lead's email address (Section 8.6), consultation and display to the Customer's authorised Users, optional generation and display of the personalized result-screen response described in Section 6 of this Annex, recording the first explicit use of a Customer-configured next-step button on an automatic-Pass result screen (without observing the external destination), transmission to a webhook destination selected by the Customer where configured, disclosure per Documented Instructions, restriction, erasure and destruction.

4. Purpose

Qualification of the Customer's Leads before the Customer's next step (call, proposal, booking), against criteria configured by the Customer, and reporting whether an automatic-Pass Lead used the next-step button shown by the Service. The event is not a booking, attendance, purchase or destination-tracking event. No other purpose (Section 3.3 of the DPA).

5. Categories of data subjects

Leads: natural persons (the Customer's prospects or enquirers, including natural-person representatives of prospect businesses) who answer a Flow at a Public Flow Page.

6. Categories of personal data

Note. The Lead's browser session (IP address, user agent — held in server-side session storage with a 120-minute idle lifetime) and IP-based security processing (rate limiting, anti-bot verification) are carried out by the Provider as controller for site security, as described in its Privacy Policy, and are not Lead Data under this DPA. No IP address or user agent is stored on the Lead record.

7. Special categories of data

None are intended or requested by the Service, and the Customer is prohibited from designing Flows to elicit them (Section 15.1(d)). Leads may incidentally volunteer such information in free-form voice answers; the Customer is responsible for that risk as controller. The AI evaluation is instructed to disregard protected characteristics (Section 16.2). Voice recordings are not processed as biometric data (Section 16.1).

8. Frequency

Continuous, for as long as the Customer operates Flows.

9. Retention summary (as instructed through the Service)

Data Retention
Voice recordings Per-Flow policy for new Leads: eligible on qualification / after 30 days (new-Flow default) / kept until deletion; a missing/invalid Flow setting is presented and snapshotted as delete-on-qualification for a new Lead. A pre-feature row with neither a snapshot nor an explicit valid current setting remains Keep. Strictest of a valid policy-at-recording vs current policy wins. Failed audio becomes eligible after 7 days and test recordings after 30 days; tracked storage failures block completion and are retried.
Transcripts, contact fields, AI Outputs and any next-step first-click event Life of the Lead — until per-Lead deletion, Account deletion (30-day grace, then purge) or the dormancy purge target (12 months after billing access ends for Accounts that ever started a subscription, including unconverted payment-method-first trials / 90 days after the trial ends for Accounts that never started one). The click event cascades with its Lead. A storage-blocked purge is retried until completion.
Content-free AI telemetry (Section 3.4) Retained detached; contains no Lead content or contact data

Browser session records (120-minute idle lifetime) are processed by the Provider as controller — see the note in Section 6 of this Annex — and are therefore not listed here.


Annex II — Technical and organisational measures (TOMs)

1. Encryption and transport security

2. Pseudonymisation and data minimisation

3. Access control and tenant isolation

4. Lead Data lifecycle controls

5. Availability and resilience

6. Anti-abuse measures on Public Flow Pages

7. Organisational measures


Annex III — Authorised Sub-processors (Lead Data)

Current as of: 16 July 2026. Maintained at: https://useleadpass.com/legal/dpa (this Annex). Changes follow Section 8.3.

# Sub-processor Function Lead Data processed Location Transfer safeguard
1 OpenAI — contracting entity for the EEA: OpenAI Ireland Limited AI evaluation of answers; generation of follow-up questions; optional generation of the personalized response shown to eligible automatic-Pass Leads Lead name, company, answer transcripts and follow-up answers; the Flow text needed for the operation (questions, criteria and instructions for evaluation/follow-ups; Flow name, questions, factual offer identity extracted from Customer material — no personalization request occurs without it — compiled offer units and tone guidance for personalization). The personalization request does not include the verdict, criteria, bands, outcome message, button, URL or routing instructions. It returns answer evidence which the Service validates against stored answers as an internal integrity step and does not display to either the Lead or Customer. Never Lead email, phone number or audio. Ireland (contracting entity); OpenAI affiliates and authorised sub-processors may process in other locations listed by OpenAI, including the USA EU Standard Contractual Clauses (Decision (EU) 2021/914, Modules Two and Three as applicable), adequacy decisions or another valid Chapter V mechanism identified in OpenAI's DPA; requests use store=false; OpenAI states that API data is not used for training by default, abuse-monitoring retention may apply for up to 30 days, and temporary prompt-cache state may remain for up to 24 hours
2 Hetzner Online GmbH Hosting of the application and database and infrastructure used for Provider-operated processing Lead Data held in the application/database and processed on that infrastructure; recordings stored by Wasabi and data sent to the other listed Sub-processors are excluded Germany (EU datacenters) None required for processing in Germany; Hetzner Online GmbH is engaged under its Article 28 data processing terms
3 Wasabi Technologies LLC Object storage for voice recordings Voice recordings and object metadata Storage configured in EU region eu-central-2 (Frankfurt, Germany); Wasabi's global support and administrative operations may involve access from other locations EU Standard Contractual Clauses incorporated into Wasabi's data-processing terms for restricted transfers; storage-region and access controls configured for the Service
4 Cloudflare, Inc. TLS termination, network security and delivery in front of the Service; Turnstile bot protection. Cloudflare's stated independent-controller use of Turnstile signals to improve Turnstile is disclosed in the Privacy Policy and is not sub-processing on the Customer's instructions. Request and response traffic in transit, which can include contact fields, audio uploads and other Lead Data; IP, browser/device/network signals and Turnstile challenge data Global network / USA EU–U.S. Data Privacy Framework where applicable and EU Standard Contractual Clauses incorporated into the Cloudflare Customer DPA for other restricted transfers
5 Resend (legal entity: Plus Five Five, Inc.) Transactional email — delivery of the optional Review → Pass Lead email described in Section 8.6 Lead email address; Flow name; Customer business name; private signed bearer link to that Lead's Pass result screen — no Customer external next-step URL, recordings, transcripts or AI Outputs in the email body USA EU–U.S. Data Privacy Framework (Plus Five Five, Inc. — record #8907; certified to the EU–U.S. DPF and the UK Extension per Resend's DPA Section 11.1) and, in any event, EU Standard Contractual Clauses deemed entered into under Resend's DPA (Sections 6.2–6.3)

Notes.

  1. The speech-to-text transcription worker is operated by the Provider itself and is not a third-party Sub-processor. The application supplies audio by expiring signed URL in the normal asynchronous path or by authenticated direct upload in a recovery path, together with a random job identifier; the job does not include the Lead's name, email or phone number. Any temporary working data exists only to complete transcription and is not the system of record.
  2. Stripe (payments, billing and tax) and Fakturownia (fiscal invoicing) do not process Lead Data and are outside this DPA. Resend processes data for which the Provider is controller when delivering transactional email to the Customer and its Users, and acts as Sub-processor #5 for the optional Review → Pass email described in Section 8.6. These providers are also described in the Privacy Policy.
  3. Sub-processors added or replaced after the date above will be notified under Section 8.3 before they process Lead Data.