1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between LeadRadar AI ("Processor") and you ("Controller") when you use the Service to process personal data.
This DPA reflects the parties' agreement with regard to the processing of personal data in accordance with the General Data Protection Regulation (GDPR), India's Personal Data Protection Bill (PDPB), and other applicable data protection laws.
2. Roles and Responsibilities
You (Data Controller)
- • Determine purposes for processing lead data
- • Ensure lawful basis for processing exists
- • Respond to data subject requests
- • Ensure your use complies with applicable laws
LeadRadar AI (Data Processor)
- • Process data only as instructed
- • Maintain appropriate security measures
- • Assist with data subject requests
- • Notify of breaches within 72 hours
3. Data We Process on Your Behalf
When you use LeadRadar, we process the following categories of data as your processor:
- Lead Data: Business names, addresses, phone numbers, websites, email addresses that you discover and store via the platform
- CRM Data: Pipeline stages, notes, and status updates you record for each lead
- Outreach Data: AI-generated messages and outreach history you create
- Team Data: Names and emails of team members you invite to your workspace
4. Processing Purposes and Legal Basis
We process personal data only to provide the services described in the Terms of Service. The legal basis for processing is performance of contract (Article 6(1)(b) GDPR) — you need us to process data to receive the service.
We do not process personal data for our own commercial purposes, profiling, or marketing without your explicit instruction.
5. Security Measures
We implement the following technical and organisational security measures:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Row-level security (RLS) ensuring data isolation between tenants
- Role-based access controls within the platform
- Regular automated backups with point-in-time recovery
- Periodic security assessments and penetration testing
- Audit logging of all administrative actions
- Multi-factor authentication available for all accounts
6. Sub-processors
We use the following approved sub-processors to deliver the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | AWS / Global |
| Vercel | Application hosting and CDN | Global |
| PayU India | Payment processing | India |
| Groq | AI text generation (prompts only) | USA |
| Sentry | Error monitoring | USA |
We will notify you of any new sub-processors before they are engaged. All sub-processors are bound by data processing agreements with equivalent protections.
7. Data Subject Requests
If your leads submit data subject requests (access, deletion, correction), you are responsible as the Controller for responding. We will assist you by providing the data we hold within 5 business days of your written request.
8. Breach Notification
In the event of a personal data breach affecting your data, we will notify you within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, categories of data affected, and steps taken to address it.
9. Data Retention and Deletion
We retain your processed data for the duration of your subscription. Upon account termination:
- Data is retained for 30 days to allow reactivation
- After 30 days, all personal data is permanently and irreversibly deleted
- Anonymised aggregate statistics may be retained indefinitely
- Legal records (billing) are retained as required by law (typically 7 years)
10. Contact
For data processing queries, contact our Data Protection team at: rahulkarthik1998@gmail.com