Last updated: December 17, 2025 | Effective: December 17, 2025
Introduction
LeadToWork ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our multi-brand customer relationship management (CRM) platform for trade services.
This policy applies to all users of our services, including business customers (brands), their team members, service providers, and end customers whose information may be processed through our platform. We comply with the General Data Protection Regulation (GDPR), Hungarian data protection laws (GDPR implementation Act CXII of 2011), and other applicable data protection regulations.
Data Controller Information
Data Controller: LeadToWork Contact Email: privacy@leadtowork.com Data Protection Officer: Available upon request
For brands using our platform, LeadToWork acts as a data processor on their behalf. Each brand is the data controller for their customers' and leads' personal data processed through our platform.
Information We Collect
Account Information
Full name
Email address
Phone number (optional)
Profile photo (optional)
Password (stored in encrypted/hashed form)
OAuth provider identifiers (Google, Facebook)
Business Information (For Brands)
Brand name and description
Logo and branding assets
Custom domain configuration
Business settings and preferences
Team member roles and permissions
Lead and Customer Data
Customer names and contact information
Project descriptions and requirements
Quote requests and specifications
Communication history
Lead source information (Facebook Lead Ads, web forms)
Technical and Usage Data
IP address and device information
Browser type and version
Pages visited and features used
Login timestamps and session data
Error logs and performance data
Third-Party Integration Data
Facebook Lead Ads webhook data
Google OAuth profile information
PPC conversion tracking events
Legal Basis for Processing
We process your personal data under the following legal bases as defined by GDPR Article 6:
Contractual necessity (Art. 6(1)(b)): Processing necessary to provide our services, manage your account, and fulfill our contractual obligations.
Legitimate interests (Art. 6(1)(f)): Processing for fraud prevention, security, service improvement, and analytics, where such interests are not overridden by your data protection rights.
Consent (Art. 6(1)(a)): Where you have given explicit consent, such as for marketing communications or optional features.
Legal obligation (Art. 6(1)(c)): Processing required to comply with applicable laws and regulations.
How We Use Your Information
To provide, maintain, and improve our CRM platform services
To process leads, quotes, and customer communications
To authenticate users and manage account access
To provide AI-powered project estimation and insights
To facilitate team collaboration and workflow management
To send service-related notifications and updates
To respond to support requests and inquiries
To detect, prevent, and address security issues and fraud
To comply with legal obligations and enforce our terms
To analyze usage patterns and improve user experience
Data Sharing and Disclosure
We do not sell your personal data. We may share information with:
Service Providers: Third-party vendors who assist in operating our platform (hosting, authentication, analytics) under strict data processing agreements.
Within Your Organization: Team members with appropriate permissions within your brand/organization.
Business Partners: Service providers assigned to projects, with only necessary information shared.
Legal Requirements: When required by law, court order, or to protect our rights and safety.
Business Transfers: In connection with mergers, acquisitions, or asset sales, with appropriate notice provided.
Third-Party Services We Use
Supabase: Database hosting and authentication (EU region available)
Google: OAuth authentication services
Facebook/Meta: OAuth authentication and Lead Ads integration
Vercel: Application hosting and deployment
International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When such transfers occur, we ensure appropriate safeguards are in place, including:
Standard Contractual Clauses (SCCs) approved by the European Commission
EU-US Data Privacy Framework certification (where applicable)
Adequacy decisions by the European Commission
Binding Corporate Rules for intra-group transfers
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
Account Data: Retained while your account is active, plus 30 days after deletion request for recovery purposes.
Lead and Customer Data: Retained according to brand settings, typically 3 years for business records, unless earlier deletion is requested.
Transaction Records: Retained for 7 years to comply with tax and accounting requirements.
Technical Logs: Retained for 90 days for security and debugging purposes.
Backup Data: Purged within 30 days of source data deletion.
Your Data Protection Rights
Under GDPR and applicable data protection laws, you have the following rights:
Right of Access (Art. 15): Request a copy of your personal data we hold.
Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
Right to Restriction (Art. 18): Request limitation of processing in certain circumstances.
Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
Right to Lodge a Complaint: File a complaint with your local data protection authority.
Hungarian Data Protection Authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) Address: 1055 Budapest, Falk Miksa utca 9-11. Website: www.naih.hu
To exercise any of these rights, please contact us at privacy@leadtowork.com. We will respond within 30 days as required by law.
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
Encryption of data in transit (TLS/HTTPS) and at rest
Secure password hashing using industry-standard algorithms
Role-based access controls and multi-tenant data isolation
Row-level security policies for database access
Regular security assessments and monitoring
Secure OAuth 2.0 authentication flows
Automated backup and disaster recovery procedures
Cookies and Similar Technologies
We use cookies and similar technologies to enhance your experience:
Essential Cookies: Required for authentication, security, and basic functionality. Cannot be disabled.
Preference Cookies: Store your settings such as language and interface preferences (e.g., sidebar state).
Analytics Cookies: Help us understand how users interact with our platform to improve the service.
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect platform functionality.
Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately, and we will take steps to delete such information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:
Posting the updated policy on our platform with a new effective date
Sending email notification for significant changes
Displaying a prominent notice upon login after updates
We encourage you to review this policy periodically. Continued use of our services after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email:privacy@leadtowork.com Subject Line: Privacy Policy Inquiry Response Time: Within 30 days