Skip to content
ContactSecurityAbout
Leadbuild LogoLeadbuild
How It Works
Pricing
Book a WalkthroughTry the Demo
  1. Home
  2. legal
  3. DPA

Legal

Data Processing Addendum

This Data Processing Addendum (DPA) describes the terms under which Leadbuild processes personal data on your behalf, acting as a data processor. This addendum is incorporated by reference into our Terms of Service or master service agreements and ensures compliance with global privacy regulations, including the GDPR and CCPA/CPRA.

Leadbuild policy
Data Processing Addendum

Current version

Last updated · July 2026
Last updatedJuly 2026

Questions about this document?

legal@leadbuild.pro

This Data Processing Addendum (DPA) describes the terms under which Leadbuild processes personal data on your behalf, acting as a data processor. This addendum is incorporated by reference into our Terms of Service or master service agreements and ensures compliance with global privacy regulations, including the GDPR and CCPA/CPRA.

Roles and scope of processing

You act as the Data Controller (or Service Provider client) determining the purposes and means of processing personal data. Leadbuild acts as the Data Processor (or Service Provider) processing personal data solely on your documented instructions. The personal data processed includes customer names, contact emails, voice transcripts, survey inputs, and feedback quotes uploaded to the platform. Processing operations consist of text analysis, semantic indexing, citation mapping, and brief generation in order to deliver the service.

Technical and organizational security measures (TOMs)

Leadbuild implements and maintains industry-standard technical and organizational measures designed to protect controller personal data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access. These measures include: (a) logical database isolation per tenant; (b) encryption of data at rest using AES-256 and data in transit using TLS 1.3; (c) regular vulnerability scanning and penetration testing; (d) strict access controls restricted to authorized personnel on a need-to-know basis; and (e) secure log audit trails for all data accesses and system operations.

Sub-processors and routing options

Leadbuild engages third-party infrastructure hosts and LLM API providers as sub-processors to perform data storage and text processing tasks. A list of active sub-processors can be requested from our privacy team. We ensure all sub-processors are bound by contract to data protection obligations no less restrictive than those in this DPA. You can configure model routing to keep high-sensitivity data inside local model instances running within your secure virtual network, which completely bypasses external LLM API sub-processors.

Data subject rights and breach notifications

We will assist you, as Data Controller, in fulfilling your obligations to respond to data subjects exercising their rights under applicable privacy laws (such as access, rectification, and erasure). In the event of a confirmed security incident affecting controller personal data stored on our platform, Leadbuild will notify your tenant administrator within 72 hours of confirmation, providing detailed info regarding the scope of the incident and our remediation steps. See our security overview for additional architectural details.

Contact & Execution of DPA

To execute a custom signed copy of this Data Processing Addendum, or to obtain our Standard Contractual Clauses (SCCs), please email our legal compliance team at legal@leadbuild.pro.

For security architecture, isolation, and erasure details, visit our security overview.

Leadbuild LogoLeadbuild

Lead generation with receipts.

AI proposes. Humans decide.
© 2026 Leadbuild.PrivacyTermsDPA

Product

Knowledge IngestionCitation-Verified InsightsBrand BriefsReview WorkbenchChannels

Solutions

For AgenciesFor In-house TeamsHow It WorksPricing

Company

AboutContactSecurityChangelog

Resources

BlogResource hubDocsPrivacyTerms