Sub-processors Book a Demo

Data Processing Agreement

Version 1.0 — 27 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between LEAD SIGNAL AI TECHNOLOGIES LIMITED (Company No. 17361862, England & Wales) ("LeadSignal", the "Processor") and the customer that accepts the Terms (the "Customer", the "Controller"). It applies whenever LeadSignal processes personal data on the Customer's behalf and is incorporated by reference — no signature is needed. A countersigned copy is available on request from privacy@lead-signal.ai.

1. Definitions

"Data Protection Law" means the UK GDPR and the Data Protection Act 2018 and, where applicable, the EU GDPR (Regulation (EU) 2016/679). "Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Personal Data Breach" have the meanings given in Data Protection Law. "Customer Data" means Personal Data the Customer submits to, or that the Service collects for the Customer from, connected channels.

2. Roles and scope

For Customer Data, the Customer is the Controller and LeadSignal is the Processor. LeadSignal is an independent Controller only for its own account, billing and website data, as described in the Privacy Policy.

3. Details of processing

Subject matterProvision of the LeadSignal service: capturing comments and messages from the channels the Customer connects, scoring and prioritising leads, drafting and (where the Customer enables it) sending replies, follow-up email and SMS, booking, and reporting.
DurationThe term of the Customer's subscription plus the deletion period in section 10.
Nature and purposeCollection, storage, analysis by AI models, display to the Customer's users, transmission of replies to connected channels, and deletion.
Types of personal dataNames, usernames and handles, email addresses, phone numbers, message and comment content, public profile details, traffic source, AI-generated scores, summaries and drafts, booking details.
Categories of data subjectThe Customer's leads, prospects and customers who comment on or message its connected accounts, submit its forms, or are imported by it; the Customer's own users.

4. Customer instructions

LeadSignal processes Customer Data only on the Customer's documented instructions, which are: the Terms, this DPA, and the settings the Customer configures in the Service (including which channels are connected, what the AI setter may send on its own, and retention). LeadSignal will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. The Customer is responsible for having a lawful basis for the data it collects through the Service and for any consent required by the connected platforms.

5. Confidentiality

LeadSignal ensures that every person authorised to process Customer Data is bound by confidentiality obligations and accesses Customer Data only where necessary to provide, support or secure the Service.

6. Security

LeadSignal implements appropriate technical and organisational measures, described on our Security page, including encryption in transit and at rest, role-based access control, optional and enforceable two-factor authentication for Customer users, tenant isolation, webhook signature verification, logging, and seven-day point-in-time recovery. These measures may be updated but not materially reduced during the term.

7. Sub-processors

The Customer gives general authorisation for LeadSignal to engage the sub-processors listed at lead-signal.ai/subprocessors. LeadSignal will give at least 30 days' notice of any addition or replacement, will impose data-protection obligations on each sub-processor no less protective than this DPA, and remains liable for their performance. The Customer may object on reasonable grounds within the notice period; if no resolution is found, the Customer may terminate the affected part of the Service.

8. International transfers

Customer Data is hosted on Render in the United States. Where LeadSignal or a sub-processor processes Customer Data outside the UK or EEA (hosting, AI model providers and email delivery are in the United States), the transfer is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses (Module 2, controller-to-processor) as applicable, together with any supplementary measures required. The UK's adequacy decision covers transfers from the EU to LeadSignal in the UK.

8a. California and other US state privacy laws

Where the Customer is a "business" under the California Consumer Privacy Act as amended by the CPRA, or under a comparable US state privacy law, LeadSignal acts as its "service provider" or "processor". LeadSignal will not sell or share Customer Data, will not retain, use or disclose it for any purpose other than providing the Service under this DPA (or as otherwise permitted by those laws), will not combine it with personal information from other sources except as permitted, will notify the Customer if it can no longer meet these obligations, and will assist the Customer with consumer requests to know, delete, correct or opt out. The Customer may take reasonable steps to stop and remediate unauthorised use.

9. Data subject rights and assistance

LeadSignal will, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in responding to requests from Data Subjects (access, rectification, erasure, restriction, portability, objection), and in meeting the Customer's obligations on security, breach notification, data protection impact assessments and prior consultation. Requests received directly from a Data Subject are forwarded to the Customer without substantive response unless the Customer instructs otherwise.

10. Deletion and return

On termination or expiry of the subscription, LeadSignal deletes all Customer Data within 30 days, and from backups within a further 7 days, unless retention is required by law. Before that, the Customer may export its leads and conversations from the Service or request a copy. Individual leads can be deleted by the Customer at any time in the Service, and deletion requests received from connected platforms (for example Meta's data deletion callback) are honoured automatically.

11. Personal Data Breach

LeadSignal notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data, providing the information reasonably required for the Customer to meet its own notification obligations, and updates that information as it becomes available.

12. Audit

LeadSignal makes available the information necessary to demonstrate compliance with this DPA, including the Security page, this DPA, the sub-processor list and, when available, independent audit reports or certifications. Where these are insufficient to meet a specific legal requirement, the Customer may, no more than once a year and on 30 days' written notice, conduct or commission an audit at its own cost during business hours, limited to the systems processing its Customer Data and subject to reasonable confidentiality terms.

13. AI processing

Customer Data is sent to the AI model provider listed on the sub-processor page only to produce output for the Customer (scores, summaries, drafts). It is processed under API terms that prohibit use for model training. LeadSignal does not use Customer Data to train general models. The Customer decides, through the Service settings, whether AI-drafted messages are sent automatically or only after a person approves them.

14. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. This DPA is governed by the law of England and Wales.

Annex — technical and organisational measures