Terms Book a Demo

Privacy Policy

Last updated: 27 August 2026

This Privacy Policy explains how personal data is collected, used and protected in connection with the LeadSignal platform ("LeadSignal", the "Service"), operated by LEAD SIGNAL AI TECHNOLOGIES LIMITED, a company registered in England & Wales, Company No. 17361862 ("LeadSignal", "we", "us"). It covers both visitors to our website and people whose data is processed through LeadSignal on behalf of our clients.

1. Who we are

LeadSignal is operated by LEAD SIGNAL AI TECHNOLOGIES LIMITED, a company registered in England & Wales, Company No. 17361862, with its HQ at Imperial Place, 4 Maxwell Rd, Borehamwood, Herts, WD6 1JN. For personal data processed through the Service on behalf of a client, that client is the data controller and we act as a data processor. For our own website and business contacts, we are the controller. You can reach us at our support assistant.

2. Data we process

CategoryExamples
Lead & conversation dataComments and direct messages from the Instagram, Facebook, LinkedIn, WhatsApp, SMS, website-chat and YouTube channels you connect, with names, usernames, email addresses, phone numbers, traffic source and attribution details.
Meta Platform data (optional)Where you connect a Facebook Page and Instagram Professional account: comments on your own posts, commenter usernames, and post/media identifiers; your Page list during connection; where messaging is enabled, direct messages sent to your connected account, the sender's public profile name and username, and message delivery/read status; and, where publishing is enabled, the posts you schedule through LeadSignal. See section 8.
LinkedIn data (optional)Where you connect LinkedIn: your profile identity for the connection; posts you publish through LeadSignal; where the Company Page comment funnel is enabled: public comments on your page’s posts, the commenter’s name, public profile and comment text, and the replies your page publishes; and, where you authorise your ad account: campaign performance data, Lead Gen Form submissions, and member verification status. See section 9.
WhatsApp data (optional)Where you take a WhatsApp business number through LeadSignal: the phone number of anyone who messages it, their WhatsApp profile name, the content of the messages exchanged, and delivery and read status. Handled as Meta Platform Data. See section 10.
YouTube data (optional)Where you connect a YouTube channel: public comment text and comment IDs, commenter display names, and video and channel identifiers and titles. See section 7.
Booking, form & import dataBookings made through your booking pages or connected calendar, submissions to your website forms, and leads you import from a file.
Derived dataAI-generated lead scores, tiers, summaries and suggested replies.
Account & usage dataUser names, email logins, authentication data, and technical logs needed to run and secure the Service.

3. How we use data

4. Legal bases

Where we act as controller, we rely on legitimate interests (operating and improving our business and website), performance of a contract, consent (where required, e.g. certain communications), and compliance with legal obligations. Where we act as processor, we process data under our client's instructions and their agreement with us. In practice that means: for the leads and conversations inside a customer’s workspace — including people who comment on a connected Company Page or channel, message a connected number, or submit a form — the customer is the controller and decides why that data is held; LeadSignal is the processor acting on their instructions. Customers are responsible for having a lawful basis (commonly legitimate interests for business contact data, or consent where they collect it), for telling those people how their data is used, and for honouring objections. The Service provides the controls to do that: exclusion lists and a “never message” state that stop all outbound contact including public replies, unsubscribe handling on email, and deletion of a lead and its history on request. The data-processing terms that govern this are in our Terms.

5. AI processing

Lead scoring, summaries and reply drafts are produced using AI models provided by OpenAI through its API. Conversation content, lead names and handles, and the client's own training answers are sent to the provider solely to generate this output for the relevant client, under API terms that prohibit use for model training. We do not use client conversation data to train general models, and one client's data is never used for another. Each client decides in its settings whether AI-drafted messages are sent automatically or only after a person approves them, and the AI never denies being an AI when a lead asks.

6. Sharing and sub-processors

We share data only as needed to run the Service. Our sub-processors, with what each one does and where it processes data, are published at lead-signal.ai/subprocessors; in summary:

Every sub-processor is bound by a data processing agreement no less protective than our own Data Processing Agreement, and we give clients 30 days' notice before adding one.

7. Google user data (Gmail, Calendar and YouTube)

LeadSignal offers several optional connections to your Google account — a Gmail or Google Workspace mailbox, your Google Calendar, and a YouTube comment funnel. Each is connected by signing in with Google and granting access through Google's own consent screen, each is entirely optional, and you can decline or disconnect any of them at any time without affecting LeadSignal's core lead scoring.

Gmail / Google Workspace mailbox. If you connect a mailbox, LeadSignal requests the gmail.send and gmail.readonly scopes so that it can:

We store the metadata and content of messages that relate to your leads and contacts (sender, recipient, subject, timestamp and body) so they can be shown on the contact's timeline. We do not read, store or index mail unrelated to your CRM activity, and we do not access your Google contacts, Drive or any Google data beyond the scopes you approve.

Google Calendar. If you connect a calendar, LeadSignal requests the calendar.events scope so it can read your availability — so a lead booking a call never double-books you — and write a confirmed booking onto the calendar you actually keep. We do not read the content of unrelated calendar events beyond the busy/free times needed to offer accurate availability.

YouTube comment funnel. When the YouTube funnel is enabled, LeadSignal uses the YouTube API Services to:

We store the comment text, the commenter's public YouTube display name and comment ID, and the associated video and channel identifiers. We do not access your private videos, your subscriber list, your analytics, or any Google data beyond the scopes you approve.

Limited Use. LeadSignal's use and transfer of information received from Google APIs — including Gmail message content, Google Calendar data and YouTube data — adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use this data solely to provide and improve the user-facing features you have enabled. We do not sell Google user data, we do not use it for advertising, and we do not use it to train generalised or machine-learning models. We do not allow humans to read your Gmail or other Google user data except: with your explicit consent for a specific message; where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and anonymised. Where we send content to our AI provider — for example to draft a reply or summarise a conversation for your own account, as described in section 5 — it is processed only to deliver that feature to you and is not used to train the provider's models.

By using the YouTube funnel you are also agreeing to the YouTube Terms of Service, and Google's own handling of your data is governed by the Google Privacy Policy.

You can disconnect any Google connection — mailbox, calendar or YouTube channel — at any time from the Integrations settings inside LeadSignal. Disconnecting immediately deletes the stored Google refresh token and stops all further access. You can also revoke LeadSignal's access directly at Google's security settings page. Records already created in your CRM — leads from YouTube comments, or email logged onto a contact — remain in your own pipeline so your reporting stays intact; they are retained under section 9 and are deleted on request to our support assistant or when your account is closed.

8. Meta Platform data (Facebook & Instagram)

LeadSignal offers an optional connection to Meta Platforms via Facebook Login for Business. You connect your own Facebook Page and its linked Instagram Professional account through Meta's consent dialog; connecting is entirely optional and you can disconnect at any time from the Integrations settings.

Comment capture. When enabled, LeadSignal reads comments on the connected account's own posts (via the permissions instagram_basic, instagram_manage_comments, pages_show_list, pages_read_engagement and business_management) so that commenters become scored leads in the connected business's own pipeline. We store the comment text, the commenter's public username, and the post identifier for attribution. We only read comments — we do not reply to, hide or delete them — and we only access the account you connected.

Messaging. Where messaging permissions are enabled (instagram_manage_messages, pages_messaging), LeadSignal receives the direct messages sent to your connected Instagram account or Facebook Page and sends replies on your behalf — replies you send yourself, and AI-assisted replies under the controls you configure (including a drafts-only mode where nothing sends without a person's approval). For each conversation we store the message content, the sender's channel identifier, and — where Meta makes it available — the sender's public profile name and username, together with delivery and read status so your team can see whether a message was seen. Replies respect Meta's messaging window rules; where a human team member replies after the standard window, the message is sent under Meta's Human Agent provision and only ever as a human-initiated reply. The permission pages_manage_metadata is used solely to subscribe your connected Page to these message and comment events — it is what lets Meta deliver them to us.

Publishing. Where publishing permissions are enabled (instagram_content_publish, pages_manage_posts), LeadSignal publishes only the posts you compose and approve in the platform, to the Page and Instagram account you connected. We never post without your action or schedule.

Deletion. Disconnecting stops all further access immediately. We honour Meta's data deletion requests via our registered Data Deletion callback: if you remove LeadSignal from your Meta account settings, we delete the associated platform data. Records already created in the connected business's CRM (leads and their comment text) belong to that business and are deleted on request or when the account closes. Meta's own handling of your data is governed by the Meta Privacy Policy.

9. LinkedIn data

LeadSignal offers optional LinkedIn connections, each authorised through LinkedIn's own OAuth consent screen and disconnectable at any time:

LinkedIn data is used solely to provide these features to the account that connected it, is never shared across customers or resold, and is not used to train AI models. LinkedIn's own handling of your data is governed by the LinkedIn Privacy Policy.

10. WhatsApp data

Where you take a WhatsApp business number through LeadSignal, that number is registered to your business on the WhatsApp Business Platform and used only for your account. When someone messages it we process their phone number, their WhatsApp profile name, the content of the messages exchanged, and delivery and read status, so the conversation can be scored, answered and recorded on the lead’s timeline like any other channel.

11. International transfers

Client data is hosted on Render in the United States, and some sub-processors — the AI model provider, email delivery and parts of the connected platforms — also process data there. Those transfers are made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with any supplementary measures required. Transfers from the EU to LeadSignal in the UK are covered by the European Commission's adequacy decision for the United Kingdom.

12. Retention

13. Security

We use technical and organisational measures including encryption in transit and at rest, TLS-only database access, role-based access control, two-factor authentication (enforceable account-wide by a client's admin), tenant isolation, signature verification on inbound webhooks, and seven-day point-in-time recovery. They are described in full on our Security page. No system is perfectly secure, but we work to protect data against unauthorised access, loss or misuse, and we notify affected clients of a personal data breach within 72 hours of becoming aware of it.

14. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. Where LeadSignal processes your data on behalf of a client, please direct requests to that client; we will assist them in responding. Otherwise, contact our support assistant.

15. Cookies

Our website uses cookies needed to operate it, including an authentication cookie used to keep you signed in to the dashboard. We do not sell data, and the lead data we process for clients is never used for advertising.

Our public marketing pages also use Google Analytics to measure how the site is used — which pages are visited, how visitors arrive, and which content leads to a demo. This sets analytics cookies and sends Google a pseudonymous identifier along with page and device information. It is not used on the signed-in dashboard, and it is never used to track individual leads or the conversation data we process for clients. Where we show a cookie banner, these analytics cookies are not set until you accept, and declining keeps them off. You can also opt out with the Google Analytics opt-out browser add-on, or by blocking cookies in your browser. Google's own handling of this data is governed by the Google Privacy Policy.

Our public marketing pages also use the Meta pixel to measure the performance of our own advertising — for example, whether a Meta ad led to a demo booking. This sets advertising cookies and shares page-visit information with Meta, governed by the Meta Privacy Policy. Like our analytics cookies, it runs only on the public marketing pages — never on the signed-in dashboard and never against client lead data — and where we show a cookie banner it is not set unless you accept.

16. Children

The Service is not directed at children and is intended for business use. We do not knowingly collect data from children.

17. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email, and the "last updated" date above will change.

18. Contact

Privacy questions or requests: privacy@lead-signal.ai. Security reports: security@lead-signal.ai. Anything else: our support assistant. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.