Legal
Data Processing Addendum
This Data Processing Addendum (DPA) describes the terms under which Leadbuild processes personal data on your behalf, acting as a data processor. This addendum is incorporated by reference into our Terms of Service or master service agreements and ensures compliance with global privacy regulations, including the GDPR and CCPA/CPRA.
Current version
Last updated · July 2026This Data Processing Addendum (DPA) describes the terms under which Leadbuild processes personal data on your behalf, acting as a data processor. This addendum is incorporated by reference into our Terms of Service or master service agreements and ensures compliance with global privacy regulations, including the GDPR and CCPA/CPRA.
Roles and scope of processing
You act as the Data Controller (or Service Provider client) determining the purposes and means of processing personal data. Leadbuild acts as the Data Processor (or Service Provider) processing personal data solely on your documented instructions. The personal data processed includes customer names, contact emails, voice transcripts, survey inputs, and feedback quotes uploaded to the platform. Processing operations consist of text analysis, semantic indexing, citation mapping, and brief generation in order to deliver the service.
Technical and organizational security measures (TOMs)
Leadbuild implements and maintains industry-standard technical and organizational measures designed to protect controller personal data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access. These measures include: (a) logical database isolation per tenant; (b) encryption of data at rest using AES-256 and data in transit using TLS 1.3; (c) regular vulnerability scanning and penetration testing; (d) strict access controls restricted to authorized personnel on a need-to-know basis; and (e) secure log audit trails for all data accesses and system operations.
Sub-processors and routing options
Leadbuild engages third-party infrastructure hosts and LLM API providers as sub-processors to perform data storage and text processing tasks. A list of active sub-processors can be requested from our privacy team. We ensure all sub-processors are bound by contract to data protection obligations no less restrictive than those in this DPA. You can configure model routing to keep high-sensitivity data inside local model instances running within your secure virtual network, which completely bypasses external LLM API sub-processors.
Data subject rights and breach notifications
We will assist you, as Data Controller, in fulfilling your obligations to respond to data subjects exercising their rights under applicable privacy laws (such as access, rectification, and erasure). In the event of a confirmed security incident affecting controller personal data stored on our platform, Leadbuild will notify your tenant administrator within 72 hours of confirmation, providing detailed info regarding the scope of the incident and our remediation steps. See our security overview for additional architectural details.
Contact & Execution of DPA
To execute a custom signed copy of this Data Processing Addendum, or to obtain our Standard Contractual Clauses (SCCs), please email our legal compliance team at legal@leadbuild.pro.
For security architecture, isolation, and erasure details, visit our security overview.