Data Processing Addendum

Last updated: July 31, 2026

This Data Processing Addendum ("DPA") applies where LeadBridge processes personal information on your behalf as part of providing the service. It forms part of our Terms of Service. Plain-English summaries are provided alongside the operative terms.

1. Roles

You are the controller (or "business") of the personal information you bring into LeadBridge — principally your customers' names, phone numbers, service addresses, and job details. LeadBridge is the processor (or "service provider") and processes that information only on your documented instructions.

Plainly: it is your customers' data. We hold and process it for you, not for ourselves.

2. Scope of processing

3. Our commitments

4. Security measures

We maintain technical and organisational measures appropriate to the risk, currently including: encryption in transit (TLS); encryption at rest for stored third-party API credentials (AES-256-GCM); password hashing with bcrypt; role-based access control; server-side session revocation; rate limiting; a Content Security Policy and related browser protections; audit logging of privileged actions; and least-privilege runtime (non-root containers). We review these periodically and may update them, provided protection is not materially reduced.

4a. Segregation of customer data

LeadBridge is a multi-tenant service: one system serves multiple independent customers. Each customer's data is bound to their own account, and segregation is enforced at two levels.

Every request is scoped to the account of the authenticated user, resolved from our records at the time of the request rather than from any value supplied by the browser. Third-party API credentials are stored per account and are never used to retrieve data for a different account. Scheduled processing runs separately for each account.

The database additionally holds row-level security policies that restrict a connection to the rows of the account it is bound to, providing a second, independent layer where the operating configuration supports it.

Segregation is verified by an automated test that exercises the running application as two separate customers and asserts that neither can retrieve the other's data through any endpoint. This test runs on every change to the codebase.

5. Sub-processors

You authorise us to engage the sub-processors below. We remain responsible for their performance.

We will give reasonable prior notice before adding or replacing a sub-processor. If you reasonably object on data-protection grounds, you may terminate the affected service.

6. International transfers

Personal information is processed in the United States. If you are subject to laws requiring a transfer mechanism, contact us and we will put an appropriate mechanism in place.

7. Data subject requests

Where a data subject contacts us directly about data we process for you, we will refer them to you rather than respond on your behalf, unless legally required to do so. We will provide reasonable assistance in fulfilling access, correction, deletion, and portability requests.

8. Retention, return and deletion

You may clear imported lead and job data at any time from within the application. On termination, you may request an export within 30 days, after which we will delete or anonymise the personal information we hold for you, except where retention is required by law. Backups are purged on their ordinary cycle.

9. Audit

On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide information reasonably necessary to demonstrate compliance with this DPA.

10. Contact

Data protection enquiries: yourleadbridge@gmail.com.

Note

This DPA is provided as a starting point. If you have specific contractual or regulatory requirements, contact us and we can review them with you.