Privacy Policy

    Last updated: December 17, 2025 | Effective: December 17, 2025

    Introduction

    LeadToWork ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our multi-brand customer relationship management (CRM) platform for trade services.

    This policy applies to all users of our services, including business customers (brands), their team members, service providers, and end customers whose information may be processed through our platform. We comply with the General Data Protection Regulation (GDPR), Hungarian data protection laws (GDPR implementation Act CXII of 2011), and other applicable data protection regulations.

    Data Controller Information

    Data Controller: LeadToWork
    Contact Email: privacy@leadtowork.com
    Data Protection Officer: Available upon request

    For brands using our platform, LeadToWork acts as a data processor on their behalf. Each brand is the data controller for their customers' and leads' personal data processed through our platform.

    Information We Collect

    Account Information

    • Full name
    • Email address
    • Phone number (optional)
    • Profile photo (optional)
    • Password (stored in encrypted/hashed form)
    • OAuth provider identifiers (Google, Facebook)

    Business Information (For Brands)

    • Brand name and description
    • Logo and branding assets
    • Custom domain configuration
    • Business settings and preferences
    • Team member roles and permissions

    Lead and Customer Data

    • Customer names and contact information
    • Project descriptions and requirements
    • Quote requests and specifications
    • Communication history
    • Lead source information (Facebook Lead Ads, web forms)

    Technical and Usage Data

    • IP address and device information
    • Browser type and version
    • Pages visited and features used
    • Login timestamps and session data
    • Error logs and performance data

    Third-Party Integration Data

    • Facebook Lead Ads webhook data
    • Google OAuth profile information
    • PPC conversion tracking events

    Legal Basis for Processing

    We process your personal data under the following legal bases as defined by GDPR Article 6:

    • Contractual necessity (Art. 6(1)(b)): Processing necessary to provide our services, manage your account, and fulfill our contractual obligations.
    • Legitimate interests (Art. 6(1)(f)): Processing for fraud prevention, security, service improvement, and analytics, where such interests are not overridden by your data protection rights.
    • Consent (Art. 6(1)(a)): Where you have given explicit consent, such as for marketing communications or optional features.
    • Legal obligation (Art. 6(1)(c)): Processing required to comply with applicable laws and regulations.

    How We Use Your Information

    • To provide, maintain, and improve our CRM platform services
    • To process leads, quotes, and customer communications
    • To authenticate users and manage account access
    • To provide AI-powered project estimation and insights
    • To facilitate team collaboration and workflow management
    • To send service-related notifications and updates
    • To respond to support requests and inquiries
    • To detect, prevent, and address security issues and fraud
    • To comply with legal obligations and enforce our terms
    • To analyze usage patterns and improve user experience

    Data Sharing and Disclosure

    We do not sell your personal data. We may share information with:

    • Service Providers: Third-party vendors who assist in operating our platform (hosting, authentication, analytics) under strict data processing agreements.
    • Within Your Organization: Team members with appropriate permissions within your brand/organization.
    • Business Partners: Service providers assigned to projects, with only necessary information shared.
    • Legal Requirements: When required by law, court order, or to protect our rights and safety.
    • Business Transfers: In connection with mergers, acquisitions, or asset sales, with appropriate notice provided.

    Third-Party Services We Use

    Supabase: Database hosting and authentication (EU region available)

    Google: OAuth authentication services

    Facebook/Meta: OAuth authentication and Lead Ads integration

    Vercel: Application hosting and deployment

    International Data Transfers

    Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When such transfers occur, we ensure appropriate safeguards are in place, including:

    • Standard Contractual Clauses (SCCs) approved by the European Commission
    • EU-US Data Privacy Framework certification (where applicable)
    • Adequacy decisions by the European Commission
    • Binding Corporate Rules for intra-group transfers

    Data Retention

    We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

    • Account Data: Retained while your account is active, plus 30 days after deletion request for recovery purposes.
    • Lead and Customer Data: Retained according to brand settings, typically 3 years for business records, unless earlier deletion is requested.
    • Transaction Records: Retained for 7 years to comply with tax and accounting requirements.
    • Technical Logs: Retained for 90 days for security and debugging purposes.
    • Backup Data: Purged within 30 days of source data deletion.

    Your Data Protection Rights

    Under GDPR and applicable data protection laws, you have the following rights:

    • Right of Access (Art. 15): Request a copy of your personal data we hold.
    • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
    • Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
    • Right to Restriction (Art. 18): Request limitation of processing in certain circumstances.
    • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
    • Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
    • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
    • Right to Lodge a Complaint: File a complaint with your local data protection authority.

    Hungarian Data Protection Authority:
    Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
    Address: 1055 Budapest, Falk Miksa utca 9-11.
    Website: www.naih.hu

    To exercise any of these rights, please contact us at privacy@leadtowork.com. We will respond within 30 days as required by law.

    Data Security

    We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:

    • Encryption of data in transit (TLS/HTTPS) and at rest
    • Secure password hashing using industry-standard algorithms
    • Role-based access controls and multi-tenant data isolation
    • Row-level security policies for database access
    • Regular security assessments and monitoring
    • Secure OAuth 2.0 authentication flows
    • Automated backup and disaster recovery procedures

    Cookies and Similar Technologies

    We use cookies and similar technologies to enhance your experience:

    • Essential Cookies: Required for authentication, security, and basic functionality. Cannot be disabled.
    • Preference Cookies: Store your settings such as language and interface preferences (e.g., sidebar state).
    • Analytics Cookies: Help us understand how users interact with our platform to improve the service.

    You can manage cookie preferences through your browser settings. Disabling certain cookies may affect platform functionality.

    Children's Privacy

    Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately, and we will take steps to delete such information.

    Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

    • Posting the updated policy on our platform with a new effective date
    • Sending email notification for significant changes
    • Displaying a prominent notice upon login after updates

    We encourage you to review this policy periodically. Continued use of our services after changes constitutes acceptance of the updated policy.

    Contact Us

    If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

    Email: privacy@leadtowork.com
    Subject Line: Privacy Policy Inquiry
    Response Time: Within 30 days

    © 2026 LeadToWork. All rights reserved.