Legal

GDPR Notice

This notice explains how LeadRealPro supports the General Data Protection Regulation (EU) 2016/679 and the UK GDPR for customers and the individuals whose data they process on our platform.

Last updated: August 20, 2026

1. Controller and processor roles

We are the controller of account and usage data relating to our customers. We are a processor of the lead and contact data our customers store in their workspace; the customer is the controller and determines the purposes and means of that processing.

2. Data processing agreement

Our Data Processing Addendum forms part of the customer agreement and includes Article 28 processor obligations: processing only on documented instructions, confidentiality commitments, security measures, subprocessor terms, assistance with data subject requests, deletion or return at termination, and audit support. Request an executed copy at privacy@leadrealpro.com.

3. Lawful bases

  • Contract — to deliver the platform and its features to account holders.
  • Legitimate interests — security, abuse prevention, service analytics, and product improvement.
  • Consent — optional marketing communications and non-essential cookies.
  • Legal obligation — tax, accounting, and lawful requests from authorities.

4. Data subject rights

Individuals in the EEA, UK, and Switzerland may exercise the following rights:

  • Access — obtain a copy of personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion where no overriding basis to retain applies.
  • Restriction — limit processing while a dispute is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or to direct marketing.
  • Withdraw consent — at any time, without affecting prior lawful processing.

5. Making a request

Send requests to privacy@leadrealpro.com with enough detail to locate your records. We respond within one month and may extend by two further months for complex requests, telling you why. If your data sits in a customer's workspace, we will forward your request to that customer as controller and assist them.

6. International transfers

Where personal data leaves the EEA or UK, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), supported by encryption in transit and access controls.

7. Subprocessors

We use vetted subprocessors for hosting and database, transactional email, analytics, DNS and TLS certificate issuance, payment processing, and AI inference. A current list is available on request, and we provide notice of material additions so customers can object.

8. Security measures

  • Row-level security enforcing per-workspace data isolation.
  • Encryption in transit and at rest with managed key rotation.
  • Role-based access with least privilege and audit logging of administrative actions.
  • Environment separation and secret management outside application code.

9. Personal data breaches

We maintain an incident response process and will notify affected customers without undue delay, and in any case within 72 hours of becoming aware of a reportable breach, with the information needed for their own regulatory notifications.

10. Retention and deletion

Customer Data is retained for the life of the workspace. On termination we delete or return data on request and remove it from active systems, with backups aging out on a rolling schedule.

11. Complaints

You may lodge a complaint with your local supervisory authority. We ask that you contact us first at privacy@leadrealpro.com so we can try to resolve the issue directly.

This document is provided as a general template and does not constitute legal advice. Have counsel review and adapt it to your jurisdiction and business practices before relying on it.