Legal
Data Processing Agreement
Version 1 ยท In effect from 2026-10-06.
This agreement is between you, the customer who holds a Leadgible account, and Ariel Retes, trading as Leadgible, an individual, of Davao City, Philippines ("we", "us"). It forms part of our Terms of Service, and you accept it when you accept them: there is nothing further to sign, and you can print or save this page as your copy.
It applies whenever we process personal data for you: the personal data in the answers people give your funnels, and what the product works out from those answers. For that data you decide what is asked, why, and what happens to the answers - you are the controller and we are your processor. The personal data in your own account - your name, your email address and how you sign in - is different: we decide what happens to that, and our privacy policy governs it.
1. Words used here
Personal data, processing, controller, processor, data subject, personal data breach, supervisory authority and sub-processor mean what they mean in the GDPR (Regulation (EU) 2016/679) or, where it applies instead, the UK GDPR. Data protection law means those and any other law on personal data that applies to the processing. Your personal data means the personal data we process for you under this agreement.
2. What we process, and on whose instructions
2.1 We process your personal data only to provide the service, and only on your documented instructions. Your instructions are the Terms, this agreement, and what you set up in the product: the funnels you publish, the rules they are scored by, where a lead is routed, and the integrations you connect.
2.2 If a law we are subject to requires us to process your personal data in another way, we will tell you before we do, unless that law forbids it.
2.3 If we believe an instruction of yours infringes data protection law, we will tell you, and we need not follow it until you confirm or change it.
2.4 Annex 1 describes the processing: whose data it is, what data, what we do with it, where, and for how long.
3. Who may see it
Leadgible is run by one person, the individual named above, who has access to your personal data only to run the service and is bound by this agreement. Anyone we give access to in future will be bound by a written duty of confidentiality before they have it.
4. Keeping it secure
We protect your personal data with the technical and organisational measures in Annex 2, which describe what the product does rather than what it might. We may change them to keep pace with risk, but never so that they protect your data less.
5. Sub-processors
5.1 You authorise us to engage the sub-processors listed at leadgible.com/sub-processors, for what the list says each one does. The list, with its dated change log, is Annex 3.
5.2 We email the Owner of every organisation at least 30 days before a new sub-processor is engaged. The email says who it is, what it will be given, why, and from when, and the change is dated on that page the day it is announced.
5.3 You may object to a new sub-processor on reasonable grounds relating to data protection, by writing to privacy@leadgible.com before it is engaged. We will look for a way to meet your objection. If there is none, you may end your subscription before the sub-processor is engaged, and we will refund the part of what you paid in advance that you will not use.
5.4 Every sub-processor is bound by a written contract that protects your personal data at least as well as this agreement does, and we remain responsible to you for what it does with it.
6. Where it goes, and the Standard Contractual Clauses
6.1 The primary database is in North America. Answers, extractions and transcripts are stored in object storage, not the database. We run the service from the Philippines, where we are established.
6.2 Where you are in the European Economic Area, or the GDPR otherwise applies to your processing, the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this agreement and apply to every transfer of your personal data to us: Module Two (controller to processor), between you as data exporter and us as data importer; and Module Three (processor to processor), to any transfer we make onward to a sub-processor that is not itself covered by an adequacy decision or its own Standard Contractual Clauses. Standard Contractual Clauses cover the primary datastore, not only the sub-processor list.
6.3 In those clauses: the optional Clause 7 (docking) applies; in Clause 9, Option 2 applies - general written authorisation, with the notice in section 5.2; the option in Clause 11 does not apply; in Clause 13, the supervisory authority is the one competent for you; and, under Clauses 17 and 18, they are governed by the law of Ireland, and disputes arising from them are resolved by the courts of Ireland. Their Annex I is Annex 1 here, their Annex II is Annex 2, and their Annex III is Annex 3.
6.4 Where you are in the United Kingdom, or the UK GDPR otherwise applies, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018 (version B1.0, in force 21 March 2022), is incorporated as well. Its Table 1 is completed by Annex 1, its Table 2 by sections 6.2 and 6.3, and its Table 3 by Annexes 1 to 3; under its Table 4, neither party may end it as its Section 19 allows.
6.5 Where the clauses or the Addendum conflict with the rest of this agreement, they prevail.
7. If personal data is exposed
7.1 If personal data we hold is exposed, we will tell the customers affected without undue delay, and in any event within 48 hours of becoming aware of it.
7.2 We tell your organisation's Owner by email, with what you need to assess it and to tell your own supervisory authority if you must: what happened, which categories of data and roughly how many people and records it concerns, the likely consequences, what we have done and will do about it, and whom to contact. What we do not know yet, we say so, and when we will.
7.3 Telling you is not an admission of fault or of liability.
8. Helping you meet your obligations
8.1 With the people whose data it is. You can read every lead in the dashboard and export a workspace's leads as a spreadsheet, which answers most requests to see or copy an answer set. To erase one person's record, write to privacy@leadgible.com naming the lead, or the person's email address, and we erase it within 30 days under our written procedure, and tell you when it is done. To correct one, write to us the same way, and we correct it by hand without undue delay. If a person asks us directly, we pass the request to you and tell them that you are the one to ask.
8.2 With security, breaches, impact assessments and consultations with a supervisory authority. We give you the information about our processing that you reasonably need, including this agreement and its annexes.
9. When the service ends
9.1 While the service runs you can export your leads at any time. The service ends when you ask us in writing to close your organisation; cancelling a paid plan returns you to Free, which is not an end. Within 30 days of the end - or of a written request to delete sooner - we delete your personal data, unless a law requires us to keep it, and we confirm the deletion if you ask.
9.2 Your plan sets how far back leads are kept while the service runs. The scheduled purge is not yet in service. Until it is, a lead is kept until it is deleted on your request or at the end of the service, as section 9.1 says.
9.3 Deleted data stays restorable from the database's own history for 30 days after its deletion, and not after. We restore from that history only to recover the service, and we delete again anything a recovery brings back.
9.4 What a deletion cannot reach by name, and what it keeps and why, is in Annex 1.
10. Showing that we comply
10.1 We make available to you the information you reasonably need to show that we meet this agreement and Article 28 of the GDPR.
10.2 We allow and contribute to audits, including inspections, by you or by an independent auditor you appoint who is bound to confidentiality: once a year, on 30 days' written notice, at your cost, and in writing or remotely first - and more often only after a personal data breach, where there are indications that we are not complying with this agreement, or when a supervisory authority requires it.
11. Liability
Each party's liability under this agreement is subject to the limits in the Terms, except where the Standard Contractual Clauses or data protection law do not allow a limit.
12. How long it lasts, changes, and which document prevails
12.1 This agreement lasts for as long as we process your personal data for you, and survives the end of your subscription until section 9 is done.
12.2 We may change this agreement to follow the law, a decision of a supervisory authority, or a change in the service. If a change materially affects you we will tell your Owner before it takes effect, and the version and date at the top of this page change with it.
12.3 On data protection, this agreement prevails over the Terms; the Standard Contractual Clauses and the UK Addendum prevail over both.
12.4 This agreement is governed by the law the Terms name, the laws of the Philippines, except that the Standard Contractual Clauses and the UK Addendum are governed as they themselves require.
Annex 1 - The processing
The parties. The data exporter, and controller: you, the customer, as named in your account, contacted through your organisation's Owner at the account's email address, using Leadgible to collect and qualify enquiries. The data importer, and processor: Ariel Retes, trading as Leadgible, an individual, of Davao City, Philippines, contacted at privacy@leadgible.com, providing the Leadgible service. Both sign by the customer accepting the Terms, which incorporate this agreement, on the date of acceptance.
Whose personal data. The people who answer your funnels; and the people you name to receive a lead, whose addresses you enter for notifications and routing.
What personal data.
- Every answer given, including free text written in the respondent's own words.
- A lead may carry a name, email, phone and company.
- An IP address, by the mode you choose. IP capture has three modes. The default is anonymised. Masking happens before the row is written, not on read.
- How the visit arrived: an approximate country, region, city and timezone; campaign parameters; the referring page and the landing page; the device and browser; and how long each step took.
- What the product works out from it: a score, the band it falls in, the sentence explaining why, and the facts a model extracts from free text.
- Special categories of personal data are not what the service is for. The Terms forbid collecting health information, government identifiers, payment card numbers or credentials for another service.
What we do with it.
- Collect it through your funnels; store it; score and band it by your rules; route it and notify the people you choose; show it in your dashboard; and export it when you ask.
- A model reads the submissions your funnels collect: Cloudflare Workers AI, through Cloudflare's AI Gateway, once a submission is complete. Contact fields are stripped from model prompts unless opted in per field. Any other model provider is reached only through a key you connect yourself. Every call asks the gateway to keep no log of what the model is shown or replies.
- Platform email is sent by Cloudflare, with no third-party key.
How often. Continuously, whenever one of your funnels is submitted.
How long. For as long as the service runs for you, and then as section 9 says. What a deletion cannot reach by name expires by itself: A model's reply, which can quote the answers, is cached for 24 hours. A submission rate limit keyed by the respondent's IP address lasts five minutes. A deletion keeps the cost of each model call, which holds nothing a person wrote, and our record that the deletion happened.
Where. As section 6.1 says, and with the sub-processors in Annex 3.
The competent supervisory authority. The one competent for you under Clause 13 of the Standard Contractual Clauses.
Annex 2 - Technical and organisational measures
- Between customers. Every query for a workspace's data is bound to that workspace in the data-access layer, below the code that handles a request, so one customer's request cannot reach another's rows.
- In transit. Every connection is encrypted, and every response tells a browser to use HTTPS only.
- Credentials you connect. Customer credentials are held under envelope encryption. A stored credential is never returned by any route.
- Inside your organisation. Access follows roles - Owner, Admin, Editor, Reviewer, Viewer and Client. A Viewer without the permission to see them receives no contact details, and exporting leads is a permission of its own.
- Signing in. Two-factor sign-in is available to every account.
- IP addresses. Anonymised by default, and masked before they are written, as Annex 1 says.
- Models. Contact fields are kept out of what a model is shown, and nothing it is shown is kept in the gateway's log, as Annex 1 says.
- Abuse. A bot-mitigation challenge runs on the funnel pages we host. The challenge does not cover a funnel embedded on a customer's own website; rate limiting, an origin allowlist and a hidden field protect that instead.
- A record of changes. Changes to your organisation's settings, members, exports and overrides are written to a log the database itself refuses to rewrite, except to carry out an erasure you ask for, which is itself recorded.
- Incidents. A written escalation path, and notice within 48 hours (section 7).
- People. One person runs the service, and anyone given access in future is bound to confidentiality first (section 3).
- Sub-processors. Each is bound in writing (section 5.4).
Annex 3 - Sub-processors
The list at leadgible.com/sub-processors - who each one is, what it is given and why, and whether it is engaged - with its dated change log.
Contact
Ariel Retes, trading as Leadgible
Davao City, Philippines
privacy@leadgible.com