Data Processing Addendum

Version 1.0 (Beta) · Last updated 2026-07-13

This page summarizes our Data Processing Addendum ("DPA"). The full DPA forms part of our Terms of Service where it applies, and the complete executed text is available to business customers on request at support@leadgenai.studio.

The DPA governs how LeadGen AI processes Customer Personal Data — the personal data you submit, import, scrape, enrich, or otherwise process through the Service about your own leads, recipients, affiliates, and customers. For that data, you are the controller and we act as your processor / service provider, acting on your documented instructions. (For our own operations — billing, security, fraud prevention, product analytics — we act as a controller, as described in the Privacy Policy.)

Key commitments

  • Processing on instructions only. We process Customer Personal Data only to provide the Service and as you instruct; we do not sell it or "share" it for cross-context behavioral advertising.
  • No AI training. We do not use Customer Personal Data to train our own or third parties' generative AI models; our model providers process it under API terms that do not train their models on it.
  • Confidentiality & security. Personnel are bound by confidentiality, and we maintain technical and organizational measures including encryption in transit, access controls, short-lived signed URLs for media, and secret management.
  • Subprocessors. We use subprocessors under written terms to provide the Service (see "Subprocessors" below), and will give notice of changes and an opportunity to object as described in the DPA.
  • Data-subject requests. We assist you in responding to access, deletion, correction, portability, and similar requests, taking into account the nature of the processing.
  • Personal-data breaches. We notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with information reasonably available to us.
  • International transfers. We operate in the United States; where required for EEA/UK/Swiss data, we rely on the EU/UK Standard Contractual Clauses (Module Two controller-to-processor and Module Three processor-to-processor) and supplementary measures.
  • Deletion & return. On termination, Customer Personal Data is deleted or returned following the 30-day recovery window, except records we must retain by law.

Subprocessors

We engage third-party subprocessors to provide the Service, in categories including cloud hosting and storage, AI model providers, email delivery, payment processing, and notifications. We require each subprocessor to protect personal data consistent with applicable law and this DPA.

A current list of named subprocessors is available to customers on request at support@leadgenai.studio. We provide notice of new or replacement subprocessors and an opportunity to object as described in this DPA.

Requesting the full DPA

Business customers who need the complete, executable DPA (including the Standard Contractual Clauses and the security and data-flow annexes) can request it at support@leadgenai.studio.

© LeadGen AI LLC · Data Processing Addendum (summary) · Version 1.0 (Beta) · Last updated 2026-07-13