This Data Processing Addendum ("DPA") applies where LeadBridge processes personal information on your behalf as part of providing the service. It forms part of our Terms of Service. Plain-English summaries are provided alongside the operative terms.
1. Roles
You are the controller (or "business") of the personal information you bring into LeadBridge — principally your customers' names, phone numbers, service addresses, and job details. LeadBridge is the processor (or "service provider") and processes that information only on your documented instructions.
Plainly: it is your customers' data. We hold and process it for you, not for ourselves.
2. Scope of processing
- Subject matter: providing lead-to-revenue analytics.
- Duration: for as long as your account is active, plus any retention period described below.
- Categories of data subject: your customers and prospective customers; your authorised users.
- Categories of personal information: names, phone numbers, service address/city and postal code, job type, job amount and completion date; the timing of calls and messages between the data subject and you, including call duration; for your users, name, email, and login credentials.
- Purpose: matching advertising leads to completed jobs, computing attributed revenue, measuring response times, and generating dashboards and reports.
3. Our commitments
- Process personal information only on your instructions and as needed to provide the service.
- Not sell or share personal information, and not retain, use, or disclose it for any purpose other than providing the service.
- Not use your data, or your customers' data, to train AI models.
- Keep personnel with access bound by confidentiality.
- Assist you, so far as reasonably practicable, in responding to data subject requests and in meeting your own security and breach obligations.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data.
4. Security measures
We maintain technical and organisational measures appropriate to the risk, currently including: encryption in transit (TLS); encryption at rest for stored third-party API credentials (AES-256-GCM); password hashing with bcrypt; role-based access control; server-side session revocation; rate limiting; a Content Security Policy and related browser protections; audit logging of privileged actions; and least-privilege runtime (non-root containers). We review these periodically and may update them, provided protection is not materially reduced.
4a. Segregation of customer data
LeadBridge is a multi-tenant service: one system serves multiple independent customers. Each customer's data is bound to their own account, and segregation is enforced at two levels.
Every request is scoped to the account of the authenticated user, resolved from our records at the time of the request rather than from any value supplied by the browser. Third-party API credentials are stored per account and are never used to retrieve data for a different account. Scheduled processing runs separately for each account.
The database additionally holds row-level security policies that restrict a connection to the rows of the account it is bound to, providing a second, independent layer where the operating configuration supports it.
Segregation is verified by an automated test that exercises the running application as two separate customers and asserts that neither can retrieve the other's data through any endpoint. This test runs on every change to the codebase.
5. Sub-processors
You authorise us to engage the sub-processors below. We remain responsible for their performance.
- Railway — application hosting and managed database (United States).
- Cloudflare — DNS and network delivery.
- SendGrid (Twilio) — delivery of report emails you enable.
- FormSubmit — delivery of website contact-form submissions only (does not receive your customers' data).
We will give reasonable prior notice before adding or replacing a sub-processor. If you reasonably object on data-protection grounds, you may terminate the affected service.
6. International transfers
Personal information is processed in the United States. If you are subject to laws requiring a transfer mechanism, contact us and we will put an appropriate mechanism in place.
7. Data subject requests
Where a data subject contacts us directly about data we process for you, we will refer them to you rather than respond on your behalf, unless legally required to do so. We will provide reasonable assistance in fulfilling access, correction, deletion, and portability requests.
8. Retention, return and deletion
You may clear imported lead and job data at any time from within the application. On termination, you may request an export within 30 days, after which we will delete or anonymise the personal information we hold for you, except where retention is required by law. Backups are purged on their ordinary cycle.
9. Audit
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide information reasonably necessary to demonstrate compliance with this DPA.
10. Contact
Data protection enquiries: yourleadbridge@gmail.com.
Note
This DPA is provided as a starting point. If you have specific contractual or regulatory requirements, contact us and we can review them with you.