LeadPass Privacy Policy
Version: 1.1 · Effective date: 27 July 2026
This Privacy Policy explains how we process personal data when we act as the controller — that is, when we decide why and how personal data is used. It covers the people who use or interact with LeadPass directly: Account owners and their teams, Client Users, billing contacts, visitors to our websites, business contacts we reach out to, and anyone who corresponds with us.
If you answered questions by voice on a page powered by LeadPass, you are a "Lead" and a different regime applies — please read Section 3 first. For Lead Data we act as a processor. The controller is the business that determines why the Flow is run; this may be the LeadPass Customer or, for an agency-operated Flow, that Customer's client. The exception is the small set of flows LeadPass operates for its own marketing: for those, LeadPass itself is the controller — Section 4.8 describes the ad-measurement processing, and this Policy applies to them in full.
1. Who we are
The controller of the personal data described in this Policy is:
| Legal entity | Jose Ramon Leon Rodriguez, a sole trader (jednoosobowa działalność gospodarcza) established in Poland |
| Registered address | Egipska 5/69, 03-977 Warszawa, Poland |
| Tax ID (NIP) | 8992886524 |
| EU VAT | PL8992886524 |
| REGON | 387147849 |
| Registration | Entered in the Central Registration and Information on Business (CEIDG — Centralna Ewidencja i Informacja o Działalności Gospodarczej) |
| Contact for privacy matters | legal [at] useleadpass.com |
In this Policy, "LeadPass", "we", "us" and "our" refer to the entity above. We have not appointed a Data Protection Officer. Privacy enquiries and data-subject requests should be sent to the contact email above.
We are established in Poland and process personal data under Regulation (EU) 2016/679 (the "GDPR") and applicable Polish law.
2. Scope and definitions
Capitalized terms used throughout this Policy:
| Term | Meaning |
|---|---|
| Service | The LeadPass software-as-a-service platform available at useleadpass.com, including its public flow pages, dashboards, APIs and related websites. |
| Customer | The business (typically an agency, consultancy or other company) that holds an Account and uses the Service for its own prospects or, where duly authorised, for a client. |
| Account | The Customer's billing and team entity within the Service. An Account can own one or more Workspaces. |
| Workspace | A container within an Account that holds a Customer's flows, Leads and reports. |
| Lead | A person who answers questions (by voice) on a public flow page powered by the Service. The relevant controller is the business that determines the purpose of that Flow; this may be the Customer or a Customer's client. |
| Client User | A person invited by a Customer to a Workspace with read-only access (for example, the Customer's own client following their leads and reports). |
| Lead Data | Personal data relating to Leads that we process on the Customer's behalf: contact details entered on a flow page, voice recordings, transcripts, AI evaluations and verdicts, the first use of an automatic-Pass result-screen next-step button, and related metadata. |
This Policy covers the processing for which LeadPass is the controller:
- people who register for or are invited to the Service (Account owners, team members, Client Users);
- billing contacts and billing data;
- visitors to our marketing website and public pages;
- people who answer LeadPass's own marketing flows (flows we operate for ourselves, where we determine the purpose — see Sections 3, 4.8, 8 and 9);
- business contacts we approach with our own marketing (prospecting);
- anyone who contacts us (support, privacy requests, general correspondence).
This Policy does not govern Lead Data where LeadPass acts as processor. The Customer is the controller or, for agency arrangements, must be authorised by and act for the relevant controller — see Section 3, the page-specific Lead Privacy Notice linked from each Flow, and our Data Processing Agreement. That carve-out concerns flows operated for a Customer. For the flows LeadPass operates for its own marketing, we are the controller and this Policy governs.
3. Lead Data — where LeadPass acts as processor
When a Lead answers a Flow, the relevant controller decides why the questions are asked, what is collected and what happens with the outcome. The Customer configures the Service under that controller's authority. LeadPass provides the machinery — recording, transcription, AI-assisted evaluation and reporting — on documented instructions under our Data Processing Agreement. (Flows that LeadPass operates for its own marketing are the exception: for those we are the controller — this Section's processor regime does not apply to them, and Sections 4.8, 8 and 9 do.)
What this means in practice:
- LeadPass is a processor of Lead Data. The Customer is the controller or, where it operates the Flow for its own client, an intermediary processor authorised by that client. Each Workspace can carry an owner/admin-confirmed controller profile (identity, address, privacy contact, applicable optional contacts, processing chain and supported legal basis). If no complete confirmed profile exists — including while a saved profile is incomplete — the Service does not block real responses: the page-specific Lead Privacy Notice uses the Workspace display name as controller name, the Account owner's email as privacy contact, no postal address, and Article 6(1)(f) with the localized template "Responding to and qualifying incoming business enquiries: we review each lead's answers against our published criteria to decide whether and how to follow up on their request." Billing details and the Workspace slug are not used for this fallback. These defaults are not verified legal facts or a determination that legitimate interests applies; the Customer must verify and, where necessary, replace them before processing real Leads.
- Leads should direct privacy requests (access, erasure, objection, and so on) to the controller and privacy contact identified in the Flow notice. If a Lead contacts us instead, we will route the request through the relevant Customer without undue delay and assist as our DPA requires. Contact: legal [at] useleadpass.com.
- Service email to the Lead (optional, sent on the Customer's behalf). If the Customer's flow collects the Lead's email address and the Customer enables the per-flow switch, LeadPass can send one type of Lead email through Resend: when an authorised reviewer moves the Lead from Review to Pass, the Service emails a private signed link to that Lead's Pass result screen in the flow's language. The message names the flow and the Customer's business and contains that signed bearer link, but no external next-step URL, recordings, transcripts, scores or evaluation. The screen resolves the Customer-authored Pass response and current button when opened. The Service sends Leads no other email, and the Lead's email address is not used for any other mailing.
- Webhook delivery to the Customer's own systems (optional, per Workspace). The Customer can configure one webhook URL per Workspace; every Flow in that Workspace uses it. For the Pass / Review / No pass categories the Customer selected, when an eligible verdict is decided or later changes, the Service sends that URL a cryptographically signed message containing the Lead's contact details, the verdict and the assessment (criteria bands, supporting quotes and summary). An initial Incomplete result is not a subscribable category. The destination — the Customer's own systems, or an automation or CRM platform the Customer has engaged (for example Zapier, Make or n8n) — receives Lead Data on the Customer's instruction and under the Customer's responsibility: it is a recipient engaged by the Customer, not a LeadPass sub-processor, and the Customer's own privacy notice and processor contracts govern what happens there. Delivery records (including the payload sent) are kept for 30 days for delivery assurance and support, then deleted automatically.
- Next-step button measurement (automatic-Pass result screen only). Where an automatic-Pass result shows the Customer's configured button, the Service can record the first time the Lead explicitly presses it and show that unique count in the Customer's report. Buttons for other results and manually approved Passes are not measured, including when the Lead reached the screen through its approval email. The event is stored with the Lead and contains its Flow/Workspace references, the Pass verdict and verdict revision, and the click time. It contains no IP address, user agent or destination URL, sets no analytics cookie, does not count repeated presses, and does not tell the Customer whether a booking, attendance, purchase or any other action happened after the redirect. Leads whose immutable Lead Privacy Notice predates this disclosure continue to redirect without being measured.
- We do not use Lead Data for our own purposes. In particular, we do not use Lead recordings, transcripts or evaluations to train or improve AI models, to build marketing lists, or for any purpose other than providing the Service to the Customer.
- No voice identification. Voice recordings are processed exclusively to transcribe and evaluate the content of the answers. We do not create voiceprints, do not identify or authenticate speakers by their voice, and do not analyze voice tone, pitch or other vocal characteristics. Recordings are not processed as biometric data.
- Protected characteristics are excluded from the intended scoring logic. Our evaluation instructions direct the model not to use characteristics such as age, health, disability, family status, pregnancy, ethnicity, religion, sexual orientation or union membership when scoring and not to reproduce them in evaluation output. Because free-form answers and AI outputs can be unpredictable, Customers must not design Flows to elicit such data and must review outputs before using them for any significant decision.
- Human review sits with the Customer. The Service produces an AI-generated assessment in bands with a suggested verdict; the Customer's reviewers can inspect every assessment in full, verdicts routed to manual review ("Review") can be overridden in the Service, and the Customer remains free to disregard any verdict in its own follow-up. See Section 11.
A summary of how long Lead Data is kept (recordings, transcripts, evaluations) appears in Section 8.2; the authoritative retention terms are in the DPA and the per-flow settings the Customer chooses.
4. Personal data we collect as controller
We collect only what is listed below. User profiles do not have profile-photo fields; a Customer may nevertheless upload an optional photo for the person presented on a Flow, as part of the Flow content it authors. We run no analytics or advertising trackers in your browser and do not buy data about our users. The only advertising measurement we perform is the consent-based, server-reported Meta conversion measurement described in Section 4.8.
4.1 Account owners and team members
When you register (directly or by accepting a team invitation) and use the Service:
- Identity and login: name, email address, password (stored only as a cryptographic hash — we cannot read it).
- Optional security credentials, if you enable them: two-factor authentication secret and recovery codes; passkey (WebAuthn) credentials — these are public-key credentials, not biometrics: any fingerprint or face check happens only on your own device and never reaches us.
- Session data: a session record containing your IP address, browser user agent and last-activity time, plus a "remember me" token if you tick that option at login.
- Preferences and context: interface language, Workspace timezone, and pointers to your current Account and Workspace.
- Workspace legal notice data: where an owner/admin saves a complete confirmed profile, the actual Lead-data controller's identity, address and privacy email; its selected supported legal basis and, for legitimate interests, the stated interest; optional policy URL and DPO/EEA-representative contacts where applicable; the agency name where the Workspace is managed for an agency client; and who confirmed the profile and when. Until such a profile exists, the Service derives the effective notice from data already held — Workspace display name and Account owner email — plus the legitimate-interests template described in Section 3. The synthesized values are not stored as a human-confirmed profile, but the exact effective facts shown for a real response are frozen in that response's legal snapshot.
- Invitation records: if you were invited, the email address the invitation was sent to, the role granted, who invited you, and expiry/acceptance timestamps. Invitation links contain a one-time token; we store only a hashed form of it.
- Contract evidence: when you accept the Terms at registration, we keep an append-only record of your name, email, related Account (where you create one), acceptance time, IP address and browser user agent, together with the exact version, SHA-256 fingerprint and archived text of the Terms and the Privacy Policy you acknowledged. For an invited User, the event identifies the invitation route but does not treat that User as the Customer for the existing Account.
- Paid-service access evidence: for an Account that has started a Stripe subscription or trial, we keep at most one successful authenticated-access event per User, Account and UTC day. It contains the User and Account, time, IP address and browser user agent. We do not record every page viewed or retain a session token in this ledger.
- Content you author in the Service: flow questions, criteria, briefs and settings you create, including any optional Flow-presenter name, role and photo, belong to your Account and may contain personal data you choose to include.
During registration your IP address is also used transiently for rate limiting (abuse prevention). It is not added to your editable profile; the separate contract-evidence record above retains the address used for the acceptance.
4.2 Client Users
A Client User account holds the same identity and login data as any user (name, email, hashed password, sessions), plus a Workspace membership record with the read-only "client" role and the related invitation record. Client Users have no access to billing and we hold no billing data about them.
4.3 Billing contacts and billing data
When a Customer subscribes or buys credits:
- Billing details: billing name, billing address, billing country, VAT identification number (validated and registered with our payment provider for tax purposes), plan and billing interval.
- Payment method: payment-method credentials are entered directly into Stripe's Payment Element in your browser and never touch our servers. We store the method type and, for a card, its brand and last four digits for display.
- Payment and invoice records: a ledger of purchases (product, amount, currency, tax, invoice reference, status) and subscription status records. Stripe holds payment and billing documents. Paid transactions are also mirrored to Fakturownia to create and retain the corresponding fiscal invoice and buyer record.
- Contract, payment and order evidence: append-only events for the prepared checkout, the Account owner's confirmation, verified subscription formation, Plan changes, requests to end a free trial early, Stripe-confirmed paid invoices, and subscription cancellation or resumption. User-confirmed actions are normally recorded before the corresponding Stripe mutation and provider-applied outcomes are separate events. Cancellation is never blocked if this auxiliary ledger is temporarily unavailable. These events identify the Account and time and, for user-initiated actions, the acting User. They also contain archived Terms/DPA/Privacy versions, the exact immediate-performance statement where applicable, and a frozen order snapshot (for a subscription: Plan, interval, price excluding VAT, currency, trial, limits and Stripe references; for a credit pack: pack key, credits, price excluding VAT, currency, tax, purchase source and Stripe references). Browser-initiated confirmations also contain the IP address and browser user agent when available; provider/server events do not invent them. A failed checkout or failed provider mutation remains only a prepared/confirmed attempt and is not labelled as formed or applied.
- Minimal service-delivery evidence: for each real completed qualification counted against an Account's Plan quota or credits, we retain the completion and metering times, pseudonymous Lead reference, Workspace and Flow identifiers, number of answers received and processed, number of follow-ups and analysis reference. Where the historical ledger proves which Plan and Stripe subscription preceded that delivery, those references are included; otherwise they remain empty rather than being inferred from the Account's later state. This evidence does not contain the Lead's name, email, phone, company, transcripts, audio, answer text, score or verdict. It supports billing reconciliation, fraud prevention and the establishment, exercise or defence of contractual claims.
4.4 Website visitors
When you browse our websites (marketing pages or public flow pages):
- Session record: a first-party session cookie and a corresponding database record containing your IP address, browser user agent and last activity. This applies to all visitors, signed in or not.
- Language choice: the site language you pick is remembered in your session.
- Security check: when enabled, Cloudflare Turnstile runs on public flow pages and on the registration page. It processes a challenge token and technical signals such as IP address, browser and device/network characteristics to assess whether a request is automated. For providing that check to LeadPass, Cloudflare processes on our behalf; Cloudflare states in its Turnstile Privacy Addendum that it acts separately as an independent controller when it uses Turnstile signals to improve the service. It does not run on ordinary marketing pages or the login form.
- Network delivery and security: traffic to the deployed Service passes through Cloudflare, which terminates the public TLS connection and can process request and response traffic in transit, including page content and data a visitor submits, to deliver and protect the Service.
- Rate limiting: IP addresses are used transiently in rate-limit counters on public and authentication endpoints; these counters are short-lived cache entries, not logs of your browsing.
We do not operate analytics, advertising pixels or behavioural-marketing trackers. On our own flow pages, the consent-based Meta ad-conversion measurement of Section 4.8 is reported by our servers using a hashed form of the email address the Lead typed; we do not set advertising cookies, load Meta scripts or use Meta's link parameters for it. Security and payment providers may process technical browser, device and network signals, and may use cookies or similar technologies needed for their functions, as described in Section 12 and the Cookie Policy.
4.5 Business contacts and prospect research
As a business, we may research companies and professionals who look like a good fit for the Service and contact them only through a channel for which we can document the required permission, request or existing relationship. A public work address is a research source, not consent to receive an unsolicited campaign. For this we process, as controller:
- business contact data — name, role, business email address, company name and website, and publicly stated facts about the business relevant to our pitch;
- correspondence history if you reply.
Source of this data (Article 14 GDPR): your direct enquiry or opt-in, a referral/introduction you agreed to, an existing business relationship where the channel rules permit similar-service contact, or publicly available company websites, advertising and business listings used for research. Public-source records remain quarantined from sending unless a permitted source/channel is recorded. We do not use Lead Data or any Customer's data to build these lists.
You can object to this processing at any time (Section 9) and we will stop contacting you and suppress your address.
4.6 Support and correspondence
If you write to us (email to the contact address, privacy requests, legal notices), we process your contact details and the content of the correspondence to handle the matter.
4.7 Service telemetry (no content)
For each AI operation the Service performs we record technical telemetry: the model used, token counts, cost, latency and the Workspace concerned. These records contain no prompt or response content and no Lead Data. They are cost-accounting and capacity data.
4.8 Meta ad conversion measurement (our own marketing flows)
LeadPass itself operates the qualification flows used for its own marketing — for these flows we are the controller (see Sections 2 and 3). When we advertise on Meta (Facebook/Instagram), we want to know which ads lead to completed flows.
We measure this only with your consent, which we ask for with an unticked, optional checkbox on the start screen of these flows. If you tick the box and complete the flow, our servers send Meta one conversion report so that Meta can match it against its own records of who saw or clicked our ads. If you do not tick it, no report is sent and no measurement consent, conversion report or conversion log is recorded.
The report contains, in full: the event name ("Lead"); the completion time; a deduplication identifier derived by one-way hash from our internal lead reference; the technical constant action_source = "website" (stating that the interaction happened on a website); the canonical public address of the flow page, without any query parameters; and — as the only matching key — a cryptographic SHA-256 hash of the email address you typed into the flow. That hash is a pseudonymised form of your email address, not an anonymous one: Meta can compare it with the hashes of email addresses associated with its accounts, and that comparability is precisely how the matching works. The hashed email and the hashed deduplication identifier are pseudonymous personal data; the remaining elements are event metadata. While associated with those identifiers, the report as a whole constitutes personal data. The report never contains your name, phone number, IP address, browser details, voice answers, transcripts or assessment outcome.
We do not set or read any advertising cookie, localStorage entry, pixel or Meta script for this measurement, and we do not use ad-click identifiers (such as fbclid) for it: on flows where this measurement is available, Meta's click identifiers are not stored by the application, and our web-server access logs are configured not to record URL query parameters.
Meta's roles and purposes: for matching and measurement, Meta Platforms Ireland acts as our processor. For the collection and transmission of event data used for the purposes described in Meta's Business Tools Terms — optimising the targeting and delivery of ads, personalising ads, and improving and securing Meta's products — Meta and LeadPass are joint controllers under Art. 26 GDPR pursuant to those Terms and Meta's Controller Addendum. For its subsequent processing of that data, Meta acts as an independent controller under its own privacy policy. The essence of the joint arrangement: LeadPass is responsible for the transparency and legal basis of the collection and transmission (this Section and your consent); Meta is responsible for handling data-subject rights under Articles 15–20 GDPR for the data it holds after transmission. See Section 6 for links.
Withdrawing consent is one action: untick the box before submitting, or use the withdrawal control on your result page at any time afterwards — it takes effect immediately and stops any report not yet sent. You can also write to legal [at] useleadpass.com. Withdrawal revokes the measurement; a minimal proof that consent existed (its timestamp, the withdrawal timestamp and the notice version, linked to your lead record) is kept until the lead record is deleted, on the basis of Art. 6(1)(f) GDPR, to demonstrate the lawfulness of reports already sent. A report already delivered cannot be recalled by us through Meta's interface; this does not affect your rights of access, objection and erasure against Meta for the data Meta holds. Under Meta's terms, the hashed contact key is deleted after the matching step, while the matched event data may be retained by Meta for up to two years.
5. Purposes and legal bases
| # | Purpose | Data | Legal basis (GDPR) |
|---|---|---|---|
| 1 | Providing the Service: account creation, authentication (including 2FA and passkeys), team and Workspace management, core features | 4.1, 4.2 | Art. 6(1)(b) — performance of a contract |
| 2 | Processing invitations sent by a Customer to team members and Client Users | 4.1, 4.2 | Art. 6(1)(f) — our and the Customer's legitimate interest in enabling the collaboration the Customer requested (until you accept and the contract basis applies) |
| 3 | Billing, payment processing, subscription management | 4.3 | Art. 6(1)(b) — contract |
| 4 | Issuing invoices, tax and accounting compliance (including VAT and Polish e-invoicing rules) | 4.3 | Art. 6(1)(c) — legal obligation |
| 5 | Service emails: invitations, quota notices, account-deletion and data-retention notices, password resets | 4.1–4.3 | Art. 6(1)(b) — contract; Art. 6(1)(f) — keeping you informed of events affecting your data |
| 6 | Security and abuse prevention: rate limiting, bot detection (Turnstile), honeypots, authentication of internal services, rejected-request logging | 4.1, 4.4 | Art. 6(1)(f) — legitimate interest in securing the Service and the data in it |
| 7 | Service telemetry and cost accounting for AI operations | 4.7 | Art. 6(1)(f) — legitimate interest in operating, capacity-planning and pricing the Service |
| 8 | B2B marketing to prospective customers | 4.5 | Art. 6(1)(f) — legitimate interest in marketing our Service to relevant businesses, subject to your right to object |
| 9 | Handling support requests and correspondence | 4.6 | Art. 6(1)(b) or 6(1)(f), depending on whether you are a user |
| 10 | Establishing, exercising or defending legal claims | any of the above, as needed | Art. 6(1)(f) — legitimate interest |
| 11 | Meta ad conversion measurement for our own marketing flows: reporting consented flow completions to Meta with a hashed email address as the only matching key (Section 4.8) | 4.8 | Art. 6(1)(a) — consent given on the flow's start screen and withdrawable at any time with immediate effect (Sections 4.8 and 9). The same consent is collected to satisfy, to the extent applicable, the consent requirement of Art. 5(3) of Directive 2002/58/EC (ePrivacy) and Art. 399 of the Polish Electronic Communications Law for any terminal-equipment access involved in ad attribution. |
Where the table identifies a legitimate interest, you may object as described in Section 9. We will assess the circumstances of the processing and your objection in accordance with Article 21 GDPR.
For direct marketing, a GDPR legal basis does not by itself authorise every communication channel. We also apply the electronic-marketing and communications rules applicable to the recipient and channel; the fact that business contact details are public is not treated, by itself, as consent to receive marketing.
Is providing data required? Name, email and password are required to create a user account; billing details and a supported payment method are required to subscribe. The product does not require a complete confirmed Workspace legal profile before accepting real Lead responses; it uses the Section 3 defaults until one exists. That lack of a product gate does not remove the Customer's duty to verify the real controller identity, contact and legal basis before processing real Leads. DPO and EEA-representative contacts must be supplied in a confirmed profile where they apply to the controller, while its own privacy-policy URL is optional. Other choices such as 2FA, passkeys and optional presenter details are voluntary. Without the required data we cannot provide the relevant part of the Service.
We do not intentionally request special categories of personal data (Art. 9 GDPR) about our users. A user may nevertheless include such information incidentally in support correspondence or content they author; it should not be submitted unless necessary and lawful. We do not sell personal data.
6. Recipients
We share personal data with the recipients below. The service providers among them act only on our instructions, only to the extent needed for the stated function, and under contracts binding them to confidentiality and data protection. One recipient — Meta, for the ad-conversion measurement of Section 4.8 — additionally acts in joint-controller and independent-controller roles, as its row describes. For Lead Data, the authoritative sub-processor list (with a change-notification mechanism) is in the Data Processing Agreement.
| Provider | Function | Data involved | Location |
|---|---|---|---|
| Stripe | Payment processing, subscription billing, tax calculation, invoicing, payment-form delivery and fraud prevention through Stripe.js/Elements | Billing name, address, country, VAT ID, owner email, payment-method credentials entered directly in Stripe Elements, transaction data, and technical browser/device/network signals used for payment security | EU/USA — we contract with Stripe Payments Europe, Limited (Ireland); restricted transfers are governed by the mechanisms described in Section 7 |
| Fakturownia sp. z o.o. | Creation and administration of fiscal invoices for paid LeadPass transactions | Buyer/billing name, email, address, country, VAT ID and invoice data (items, amounts, currency, tax treatment, dates and payment references); no Lead Data | Poland (EU) |
| Resend | Transactional email delivery (invitations, notices, password resets; and the optional Review → Pass Lead email described in Section 3) | Recipient name, email address and notification content; for the Lead email: the Lead's email address, flow/business name and the private signed bearer link to that Lead's Pass result screen | USA — Plus Five Five, Inc.; EU Standard Contractual Clauses incorporated into its data processing agreement (see Section 7) |
| Hetzner | Hosting of the LeadPass application and its database | Account, Workspace, application and database records described in this Policy; recordings and data held directly by the other listed providers are excluded | Germany (EU) — Hetzner Online GmbH datacenters |
| Cloudflare | TLS termination, network delivery and security in front of the Service; Turnstile bot protection on public flow and registration pages. Cloudflare also acts as an independent controller for its stated use of Turnstile signals to improve Turnstile. | Request and response traffic in transit, which can include submitted content; IP address, browser/device/network signals and Turnstile challenge data | Global network — Cloudflare, Inc. (USA); transfer mechanisms are described in Section 7 |
| OpenAI | AI evaluation of Lead answers and follow-up questions; optional personalized Lead response; AI assistance for building Flows, compiling criteria and checking question coverage; compilation of Customer offer material; generation of synthetic example Leads | Text content submitted for the applicable operation (see Section 7 for what is and is not sent) | Ireland (contracting entity); processing may also occur in the USA and other locations listed by OpenAI — see Section 7 |
| Transcription worker (operated by LeadPass) | Speech-to-text of Lead voice answers; this is a Provider-operated component rather than a separate third-party provider | Audio supplied through a time-limited signed link in the normal asynchronous path, or transmitted directly in a recovery path, plus a random job ID; no Lead name, email or phone number is included in the transcription job | Provider-operated infrastructure; network requests and callbacks are authenticated as described in the DPA |
| Wasabi | Object storage for voice recordings and optional Flow-presenter photos uploaded by Customers | Lead voice recordings; optional Customer-authored presenter photos | EU — Wasabi region eu-central-2 (Frankfurt, Germany); objects stay in that region (see Section 7 for Wasabi's limited US-side support access) |
| Meta Platforms Ireland Limited | Consent-based ad-conversion reports for LeadPass's own Meta campaigns (Section 4.8). Roles: processor for matching and measurement; joint controller with LeadPass (Art. 26 GDPR, per Meta's Business Tools Terms and Controller Addendum) for the collection and transmission of event data used for optimising ad targeting and delivery, personalising ads, and improving and securing Meta's products; independent controller for its subsequent processing under its own privacy policy. Essence of the joint arrangement: LeadPass is responsible for the transparency and legal basis of collection and transmission; Meta is responsible for data-subject rights under Arts. 15–20 GDPR for the data it holds. You can nevertheless address requests to either of us. See Meta's Business Tools Terms (facebook.com/legal/terms/businesstools), Controller Addendum (facebook.com/legal/controller_addendum) and Privacy Policy (facebook.com/privacy/policy). | SHA-256-hashed email address (pseudonymised matching key, deleted by Meta after matching under its terms), event name and time, hashed deduplication identifier, action_source constant, canonical public flow-page URL without query parameters — Section 4.8 |
Ireland — Meta Platforms Ireland Limited; onward transfers under Section 7 |
We may also disclose personal data where required by law or a binding order of a court or authority, and to professional advisers (lawyers, accountants, auditors) bound by confidentiality, to the extent necessary.
7. International transfers
The primary LeadPass application, database and configured recording-storage region are in the European Economic Area. The following providers can involve processing outside the EEA:
- OpenAI. We contract with OpenAI Ireland Limited. Processing may involve OpenAI affiliates and authorised sub-processors outside the EEA, including in the United States, under the European Commission's Standard Contractual Clauses or another valid Chapter V mechanism identified in OpenAI's Data Processing Addendum. Lead-processing requests can contain the Lead's name and company, answer transcripts and follow-up answers, together with the Flow text needed for the relevant operation. Evaluation and follow-up requests receive questions, criteria and instructions. For eligible automatic-Pass personalization, the separate composer receives the Flow name, questions and transcripts, a factual offer identity extracted from the Customer's offer material (with no fallback: without a usable identity no personalization request is made), compact units compiled from that material, and tone guidance. It does not receive the verdict, criteria, bands, outcome message, button, URL or routing instructions. It returns answer evidence for each proposed connection; the Service validates that evidence against stored answers as an internal integrity step and does not display the evidence or source-reference fields to either the Lead or Customer. Email, phone number and audio are not sent. Separate Flow-building requests can contain Customer-authored briefs, offer and next-step descriptions, questions, criteria and settings; long-form offer material pasted for compilation; and Flow details used to generate synthetic example Leads. The Service does not add existing Leads or recordings to those Flow-building requests. All requests use the provider's
store=falsesetting. OpenAI states that API data is not used to train its models by default, that abuse-monitoring retention may apply for up to 30 days unless a different approved retention control applies, and that prompt caching may temporarily retain encrypted key/value tensors in GPU-local storage until its stated 24-hour expiration. - Stripe. We contract with Stripe Payments Europe, Limited (Ireland). Stripe's global payment infrastructure may process data outside the EEA. Stripe's Data Privacy Framework certification and its Data Transfers Addendum, including Standard Contractual Clauses where applicable, provide the transfer mechanisms described in its contractual terms.
- Cloudflare. Cloudflare operates a global network and may process Service traffic, submitted content and security signals outside the EEA. Its Data Privacy Framework certification and Standard Contractual Clauses in the Cloudflare Customer DPA apply as provided in that DPA.
- Resend. Resend is operated by Plus Five Five, Inc. in the United States. Its DPA incorporates Standard Contractual Clauses for restricted transfers and also identifies its Data Privacy Framework participation.
- Wasabi. Voice recordings and optional Flow-presenter photos are stored in the configured eu-central-2 region (Frankfurt, Germany). Wasabi is a US provider and its operations may involve access from outside the EEA. Restricted transfers are governed by the Standard Contractual Clauses incorporated into Wasabi's data-processing terms; access remains subject to the provider contract and the Service's access controls.
- Meta. Conversion events under Section 4.8 are sent to Meta Platforms Ireland Limited. Meta may transfer this data onward to Meta Platforms, Inc. in the United States under its EU-U.S. Data Privacy Framework certification and, where applicable, the Standard Contractual Clauses incorporated into Meta's data-transfer terms.
You can request a copy of the applicable safeguards, or details of where they can be consulted, at legal [at] useleadpass.com.
8. Retention
We keep personal data only as long as needed for the purposes above. Concrete periods:
8.1 Data we control
| Data | Retention |
|---|---|
| Account, profile and Workspace data | For the life of the Account, then deleted as described below |
| Voluntary account deletion | When the owner requests deletion: public flow links close and paid subscriptions are cancelled immediately; a 30-day grace period follows (with a reminder around day 23) during which deletion can be undone; after it, the Service runs its permanent purge of the Account, its Workspaces, flows, Leads and the recordings still referenced by those records. A tracked recording-storage failure blocks that purge so it can be tried again. The owner's user record is deleted if it belongs to no other Account or Workspace. The Service also requests deletion of the Account's customer object (name, email, address, VAT ID) at Stripe; statutory payment and invoice records remain as described below. |
| Dormant Accounts that ever started a subscription (including a payment-method-first free trial that never converted to a paid plan) | Kept intact until the purge target at 12 months after billing access ends; we warn at month 11; then the Service repeatedly attempts to purge Lead Data while keeping the Account shell (user, flows, criteria). A tracked recording-storage failure blocks completion and is retried rather than being recorded as success. |
| Accounts that never started any subscription (entry-flow trials without a payment method) | The Lead Data purge target is 90 days after the trial ends (warning around day 76); the same storage-first, retry-until-complete rule applies. The Account shell (user profile, flows, criteria) is kept so a returning Customer finds their setup intact. |
| Users who own no Account (e.g., invited-only users who leave) | Deleted immediately on request, together with their sessions and reset tokens |
| Browser sessions | Expire after 120 minutes of inactivity; a user's session records are deleted when the user is deleted |
| Password reset tokens | Valid 60 minutes; expired entries swept daily |
| Invitation links (team and Client User) | Expire 7 days after issue |
| Contract, payment, access and minimal service-delivery evidence | Account-bound evidence is kept while the Account exists. Immediately before Account deletion, the Service detaches the live links and sets a deletion deadline to 31 December of the year in which six years have elapsed from the deletion. A registration-acceptance event for an invited User who did not create an Account is instead retained to 31 December of the year in which six years have elapsed from that acceptance. A deadline may be extended where a payment dispute, complaint, court/authority proceeding or other event interrupts, restarts or otherwise extends the applicable claims period. A daily sweep deletes detached events after the resulting deadline. Archived public legal-document versions can remain because they contain no Customer or Lead personal data. Private evidence bundles exported by the operator for a complaint or payment dispute are temporary working copies: the server copy is deleted automatically after 30 days, and any temporary operator download must be deleted manually when the task finishes and no later than the same 30-day limit. |
| Payment and invoicing records | Retained for the periods required by Polish tax, accounting and applicable e-invoicing law, including any longer period caused by suspension or interruption of a statutory limitation period. These records survive Account deletion: the purchase ledger is detached from the deleted Account, while Stripe retains payment/billing documents and Fakturownia retains the fiscal invoice and associated buyer record under their applicable retention terms. |
| AI usage telemetry (Section 4.7 — no content) | Retained after account deletion in detached, non-attributable form as financial/capacity records |
| Application logs (operational identifiers, no routine content) | 14 days |
| Prospecting contact data (Section 4.5) | Until you object or the data is no longer relevant |
| Leads of LeadPass's own marketing flows (Section 4.8) | Contact details, transcripts and assessments: kept while we pursue the enquiry and up to 24 months after the last interaction — the latest of your last answer in the flow, your last visit to your result page, or our last correspondence with you — unless you object or request erasure sooner. Recordings follow the retention promise shown in the flow (Section 8.2 mechanics). The ad-measurement consent proof (consent and withdrawal timestamps and the notice version, linked to the lead record — retained under Art. 6(1)(f) to demonstrate the lawfulness of reports already sent) and the conversion log are stored with the lead and deleted with it. On Meta's side, the hashed contact key is deleted after matching and matched event data may be retained for up to two years, as set out in Meta's Business Tools Terms — see those Terms and Meta's privacy policy. |
| Email sending history | Held by our email provider (Resend) under its own retention terms; we keep no local copy of sent mail |
Where an Account shell (the owner's user profile, flows and criteria) is retained after a Lead Data purge (dormant or trial Accounts above), it is kept until the owner deletes the Account or requests erasure (Section 9).
8.2 Lead Data (we hold it as processor — summary)
The Customer chooses the recording retention for each flow, and the promise shown to the Lead when they recorded always prevails if it is stricter:
| Item | Retention |
|---|---|
| Voice recordings — "delete after qualification" | Automatically submitted for deletion as soon as qualification completes, with a daily retry/backstop. For a new Lead, this is also the value presented and snapshotted when the Flow has no valid stored policy. A pre-feature Lead with neither a snapshot nor an explicit valid current setting remains Keep rather than receiving an invented retrospective promise. |
| Voice recordings — "keep 30 days" (new-Flow default) | Eligible for automatic deletion 30 days after completion; a tracked storage failure is retried. |
| Voice recordings — "keep" | Kept until the Customer or the account lifecycle deletes them |
| Recordings from failed/abandoned Leads | Eligible for automatic deletion after 7 days regardless of policy; tracked storage failures are retried. |
| Test-run Leads | Eligible for automatic deletion after 30 days; tracked storage failures are retried. |
| Transcripts, evaluations, verdicts and any next-step first-click event | Kept for the Customer for the life of the Account, subject to the deletion clocks in 8.1; the click event is deleted with its Lead, and the Customer can permanently delete any individual Lead (recordings, transcripts, analysis and click event) at any time |
| Webhook delivery records (Section 3 — payload sent to the Customer's configured endpoint, delivery status) | 30 days, then deleted automatically; deleting a Lead also deletes its delivery records immediately |
9. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- rectify inaccurate or incomplete data;
- erasure ("right to be forgotten") where the conditions of Art. 17 are met;
- restriction of processing in the cases of Art. 18;
- data portability for data processed by automated means on the basis of contract or consent;
- object to processing based on legitimate interests — and where you object to direct marketing (Section 4.5), we must and will stop, without exception;
- withdraw consent at any time where processing is based on consent, without affecting prior processing.
To exercise any right, email legal [at] useleadpass.com. We respond within one month (extendable by two further months for complex requests, in which case we will tell you). We may need to verify your identity first. Exercising your rights is free of charge.
If your request concerns Lead Data (you answered a business's questions on a flow page), the controller is that business — please contact them directly; if you contact us, we will forward your request to them without undue delay (see Section 3). If the flow was one of LeadPass's own marketing flows (Section 4.8), we are the controller: you can exercise every right above directly with us, including withdrawing the ad-measurement consent.
Account owners can additionally act directly in the Service: edit their profile, delete individual Leads, configure recording retention per flow, and request deletion of their entire Account.
10. Complaints
You have the right to lodge a complaint with a supervisory authority, in particular with the Polish authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stawki 2, 00-193 Warszawa, Poland https://uodo.gov.pl
You may also complain to the supervisory authority of the EU/EEA state where you live or work.
11. Automated decision-making
About you (users, billing contacts, visitors, prospects): we do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. No automated decision determines your access to the Service, your pricing or your account status.
About Leads (processor context): the Service produces AI-generated assessments of Lead answers. In plain terms: the Lead's spoken answers are transcribed, and an AI model rates them in bands against criteria the Customer defined; a suggested verdict (Pass / Review / No pass) is then derived from those bands by a fixed rule — the AI model itself does not issue the verdict. Incomplete means the available answers lacked enough required or usable evidence for a reliable overall Pass / Review / No pass recommendation; this can follow a partial response or a fully answered response that still omits a required fact, while a partial response with enough evidence may still receive one of the other three results. The available answers, criterion bands and evidence can still be shown to the Customer for an Incomplete result. The assessment is a recommendation to the Customer: the Customer's reviewers see the full report with quoted evidence; verdicts routed to manual review ("Review") can be overridden in the Service — the Service records who overrode a verdict and when, preserving the original suggestion — and the Customer remains free to disregard any verdict in its own decision about the Lead. There are four public result states — Pass, Review, No pass and Incomplete — and each uses the corresponding Customer-configured response or next action; internal result labels are not shown automatically. While a real Lead processed in manual-review mode awaits a decision, its public result is Review and its result button is disabled. After the reviewer records Pass or No pass, that outcome and any configured button become the public result. If the reviewer moves the Lead from Review to Pass and the per-flow email switch is enabled, LeadPass emails a private signed link to that Lead's Pass result screen; the screen resolves the Customer-authored Pass response and current button. No other result or transition sends a Lead email. Manual-review Leads receive no public AI personalization. Where the Flow is one of LeadPass's own marketing flows, LeadPass is both the operator and the recipient of the assessment: the human-review and contestation commitments described here apply to us as the controller. The Customer can separately enable a personalized response only for an eligible automatic Pass; Review, No pass and Incomplete are never personalized. The separate composer may use only facts the Lead stated, a factual identity extracted from the Customer's offer material (no personalization is composed when the material does not yield a usable identity), compact grounded units and tone guidance. It must propose one natural introduction and three connections between distinct Lead-stated facts and distinct real units. The Service validates the answer evidence returned for every proposed connection against the stored answers; connections that fail validation are omitted individually, and between one and three validated connections are shown. If no valid connection remains, no personalized AI block is shown. The Lead and Customer both see only the generated introduction, point titles and connection text, without transcript quotations, source cards, source titles, underlying claims or internal validation fields; the Customer can audit that exact generated copy. A configured presenter appears only with the Customer-authored outcome, not as the author of the generated introduction. The composer does not receive the verdict, criteria, bands, outcome message, button, URL or routing instructions; the outcome message and CTA remain Customer-configured and server-resolved. The AI interaction is disclosed before the Lead starts, and the per-Flow notice describes the optional AI-written response; the exact generated copy and internal validation fields are stored as part of the assessment and erased with it, while only the copy is available in the Customer audit view. Responsibility for how the assessment is used — including ensuring meaningful human review before any decision that significantly affects a Lead — rests with the relevant controller, as set out in our Data Processing Agreement and terms. Leads receive the page-specific Lead Privacy Notice from their Flow and can contest an outcome with that controller.
12. Cookies
LeadPass itself uses the following first-party cookies for sessions, security and an explicitly requested persistent login. We do not use first-party analytics or advertising cookies. The Meta ad-conversion measurement of Section 4.8 sets no cookie and loads no Meta script: consent is asked on the page itself, and the report — whose only matching key is a hashed form of the email address the Lead typed — is sent by our servers.
| Cookie | Purpose | Lifetime |
|---|---|---|
leadpass-session |
Keeps your session (login state, language choice, identifier of an in-progress flow response) | 120 minutes of inactivity |
XSRF-TOKEN |
Protects forms against cross-site request forgery | Same as the session (120 minutes) |
remember_web_* |
Keeps you signed in — set only if you tick "Remember me" at login | Long-lived |
The deployed Service configures these first-party cookies with Secure and SameSite=Lax attributes; the session cookie is also HttpOnly. Third-party security and payment components — Cloudflare/Turnstile and Stripe.js/Elements — may use cookies, local storage or comparable technical signals where needed to provide their requested security or payment function. LeadPass does not use those technologies for its own advertising or behavioural analytics. Full details are in the Cookie Policy.
13. Security
Measures we apply include:
- passwords stored only as cryptographic hashes; optional two-factor authentication and passkeys;
- encrypted connections (TLS) for user-facing traffic;
- tenant access controls based on Account/Workspace context and membership; Client Users are limited to read-only access to Leads and reports in their Workspace, with no billing visibility;
- invitation and internal-service tokens stored or verified only in hashed/signed form (invitation tokens are hashed at rest; transcription callbacks require a bearer credential and, outside local/test environments, an HMAC signature; source-IP restrictions can also be configured);
- voice recordings are not exposed through permanent public URLs: authorised playback uses short-lived links, and the normal asynchronous transcription path uses a two-hour signed link. A recovery path can transmit the audio directly to the Provider-operated transcription worker using an authenticated request;
- payment-method credentials handled exclusively by Stripe — they never transit our servers;
- automated daily deletion jobs that enforce the retention periods in Section 8;
- rate limiting and bot protection on public and authentication endpoints.
No system is perfectly secure; if a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within the statutory deadline (72 hours where required) and inform you where the risk is high. For Lead Data, we notify the affected Customer without undue delay and no later than 48 hours after becoming aware, so it can meet its own controller obligations.
14. Children
The Service is a business tool and is not directed at children: its intended purpose is the qualification of sales and business enquiries. We do not knowingly collect personal data from anyone under 16, and Customers are contractually prohibited from directing their flows at children or knowingly collecting data of persons under 16 through the Service (Terms of Service, Section 9). If you believe a child has provided personal data through the Service, contact us at legal [at] useleadpass.com. Where the data are Lead Data, we will notify and assist the relevant controller so the data can be investigated and deleted; where we are controller, we will take the action required by applicable law.
15. Changes to this Policy
We may update this Policy as the Service, our providers or the law change. For material changes we will give registered users advance notice by email or in-app message before the new version takes effect, and each version carries its date at the top. Continued use after the effective date constitutes acknowledgment of the updated Policy; where a change requires consent under applicable law, we will ask for it.
16. Contact
Questions, requests and complaints about this Policy or our data practices:
Jose Ramon Leon Rodriguez (jednoosobowa działalność gospodarcza) Egipska 5/69, 03-977 Warszawa, Poland Email: legal [at] useleadpass.com
Related documents: Terms of Service · Data Processing Agreement · Cookie Policy. Each public Flow links its own merged Lead Privacy Notice.