Legal

Privacy Policy

Information about data protection and the processing of personal data.

Status

May 2026

1. General information

This privacy policy explains the type, scope and purpose of the processing of personal data when using our website and the SaaS platform LeadTS. Personal data means all information relating to an identified or identifiable natural person. Processing is carried out in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection laws.

2. Controller

LeadTS (sole proprietorship) Owner: Rotinda Getiren Gruenhainer Str. 8 08340 Schwarzenberg Germany Phone: 017641567624 Email: support@leadts.com Website: https://leadts.com

3. Processing roles

LeadTS processes personal data depending on the specific processing context. As controller For the following processing activities, we act as an independent controller: * website and visitor data * contract and billing data * customer data * user account data * support and communication data * marketing and analytics data (where used) As processor Where customers process personal data of third parties (e.g. leads, contacts, prospects) within LeadTS, we act as a processor pursuant to Art. 28 GDPR. In such cases, processing is carried out exclusively on the customer's instructions.

4. Data processing when visiting the website

When our website is accessed, technical access data is processed automatically: * IP address * date and time of access * browser type and browser version * operating system * referrer URL * hostname of the accessing device * pages/files accessed Processing is carried out for: * technical provision of the website * ensuring stability and security * error analysis * detection of misuse and attacks Legal basis: Art. 6(1)(f) GDPR

5. Registration and user account

When creating and using a user account, we process in particular: * email address * password (stored only in hashed form) * display name / name * profile information * language settings * optional avatar/profile image data Legal basis: Art. 6(1)(b) GDPR

6. Use of the LeadTS platform / processing of CRM and lead data

Within use of the platform, and depending on customer usage, the following data may be processed in particular: * names of leads / contacts * email addresses * phone numbers * company data * lead sources / campaign mappings * funnel/pipeline data * status and activity histories * revenue/deal/conversion data * custom additional fields Data may be introduced in particular via: * API/webhook integrations * third-party interfaces * CSV/file imports * manual input Legal basis: Art. 6(1)(b) GDPR / Art. 6(1)(f) GDPR

7. Processing on behalf

Where our customers process personal data of third parties within the platform, this takes place as processing on behalf pursuant to Art. 28 GDPR. A corresponding data processing agreement (DPA) is provided.

8. Payment processing / contract administration

For payment processing and subscription management, we use Stripe Payments Europe Ltd. In particular, we process: * billing and contract data * customer data * Stripe customer IDs * plan and subscription data * payment status Complete payment data is processed exclusively by Stripe. Legal basis: Art. 6(1)(b) GDPR Further information: https://stripe.com/privacy

9. Support and communication

If you contact us, we process your details to handle your request. This includes in particular: * name * email address * communication content * support/ticket information Legal basis: Art. 6(1)(b) GDPR / Art. 6(1)(f) GDPR

10. Service providers / recipients used

To provide our services, we use the following service providers: * Supabase – database, authentication, backend infrastructure * Vercel – hosting / frontend infrastructure * Stripe – payment processing * Resend – delivery of transactional emails * Nango – OAuth/integration management * Google – OAuth/Google integrations / Search Console * Meta Platforms – Meta/Facebook integrations * Cookiebot (Usercentrics A/S) – consent management Disclosure is limited to what is necessary.

11. Hosting and storage location

Primary processing of platform data takes place in data centers within the European Union, in particular Frankfurt am Main.

12. Third-country transfers

Where personal data is transferred to recipients outside the European Union or the European Economic Area, this takes place only in compliance with the legal requirements under Art. 44 et seq. GDPR. In particular based on: * adequacy decisions * EU standard contractual clauses * other permissible safeguards

13. Security measures

We take appropriate technical and organizational measures to protect personal data, including in particular: * TLS/HTTPS encryption * access restrictions * role and authorization concepts * authentication and session management * security monitoring / logging * protection against unauthorized API/webhook access * regular security updates

14. Cookies and consent management

We use cookies and comparable technologies. Technically necessary cookies These are required for operation, security and functionality of the website/platform. Optional cookies / tracking Non-essential technologies are used only based on your consent. To manage consent, we use Cookiebot by Usercentrics A/S.

15. Analytics and performance tools

Vercel Analytics / Speed Insights We use analytics and performance services from Vercel to evaluate technical usage and performance data of our website. This may include in particular: * technical usage data * browser and device information * page views * load times / performance metrics * referrer information Processing is based on our legitimate interest in technical optimization and stability of our website pursuant to Art. 6(1)(f) GDPR, where consent is not required. Google Search Console We use Google Search Console for technical analysis, SEO and monitoring the discoverability of our website in search engines. Aggregated search and performance data is processed. We do not perform direct personal profiling in this context. Legal basis: Art. 6(1)(f) GDPR

16. Retention period

We store personal data only as long as necessary for the respective processing purposes or as required by statutory retention obligations. Data is then deleted or anonymized.

17. Obligation to provide data

Providing certain personal data is required for conclusion and performance of the contractual relationship. Without this data, use of the platform may be impossible in whole or in part.

18. Automated decision-making / profiling

Automated decision-making or profiling within the meaning of Art. 22 GDPR does not take place, unless explicitly stated otherwise.

19. Data subject rights

Data subjects have the following rights: * access pursuant to Art. 15 GDPR * rectification pursuant to Art. 16 GDPR * erasure pursuant to Art. 17 GDPR * restriction of processing pursuant to Art. 18 GDPR * data portability pursuant to Art. 20 GDPR * objection pursuant to Art. 21 GDPR * withdrawal of consent pursuant to Art. 7(3) GDPR Requests to: support@leadts.com

20. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority.

21. Google user data (Google APIs and OAuth)

This section supplements the disclosures above and is intended to meet the transparency requirements of the Google API Services User Data Policy and the Google APIs Terms of Service for customers who connect a Google account to LeadTS. When this applies If you optionally connect Google to LeadTS (for example via OAuth through our integration provider Nango), LeadTS accesses limited Google user data as described below. Connecting Google is voluntary and used to ingest lead data from spreadsheets you select. LeadTS does not use Google Sign-In for website or app authentication. Data accessed (categories) * OAuth authorization data: When you authorize the integration, Google provides authorization artifacts needed to call Google APIs on your behalf (handled through Nango). * Google Drive (metadata): To help you pick a spreadsheet, we may list Google Drive items such as folders and spreadsheet files. We process identifiers and descriptive metadata returned by Google (for example file IDs, names, parent folder references, and web view links where provided by Google). * Google Sheets (content and structure for the selected spreadsheet only): We read spreadsheet metadata needed for setup (for example worksheet/tab titles) and cell values from the specific spreadsheet and range you configure in LeadTS. * What we do not access: LeadTS does not access, collect, or use Gmail messages, Google Calendar, Google Contacts, Google Photos, YouTube, or other Google services beyond the Drive/Sheets functionality described here. How we use Google user data (purposes and processing) * Google Sheets lead source: We use the data solely to (1) establish and maintain the connection you requested, (2) display selectable spreadsheets/folders in the product UI, and (3) read the configured sheet range to import rows as leads into your LeadTS workspace. * Secure operation: We use OAuth tokens/credentials only as required to perform these API calls. Token storage and refresh are handled by Nango as our OAuth/integration infrastructure. * No unrelated purposes: We do not sell Google user data. We do not use Google user data for advertising. We do not use Google user data to train generalized artificial intelligence or machine learning models. * Automated decisions: Importing rows does not constitute automated decision-making about individuals within the meaning of Art. 22 GDPR. Storage, sharing, and subprocessors * Our systems: Imported sheet rows are stored in LeadTS like other lead records you choose to process in the product, subject to this privacy policy and (where applicable) our DPA. * Nango: OAuth connection management and API proxying may involve processing by Nango (USA/EU). Disclosure is limited to what is necessary to provide the integration. * Google: API requests are processed by Google as the provider of Google Drive/Google Sheets. Retention and revocation You can disconnect the Google integration in LeadTS and/or revoke LeadTS access in your Google Account security settings. After disconnection, we stop initiating new data access via that connection (subject to reasonable technical propagation delays). Legal bases (GDPR) Where you connect Google as a LeadTS customer user, processing is typically based on Art. 6(1)(b) GDPR (performance of the contract) and/or Art. 6(1)(f) GDPR (legitimate interest in providing the integration you requested), depending on the processing context. If you have questions about this integration, contact: support@leadts.com

22. Changes to this privacy policy

We reserve the right to amend this privacy policy if this becomes necessary due to legal, technical or business changes.