Pricing Get a demo

Data protection and GDPR

The European Union’s General Data Protection Regulation (GDPR) is one of the most important international legislative changes in data protection in decades. The purpose of the regulation is to increase the individual’s rights to manage and process their personal data and to harmonise legislation within the European Union.

Leadoo is firmly committed to the GDPR Data Protection Regulation.In addition to complying with the regulation ourselves, it is important for us to help our customers with their compliance efforts. This goal is achieved through training, instruction, and technical development of our software.

Leadoo’s updated GDPR compliant terms come to force on the 1st of May 2020:
Data processing Agreement (Customer)
Privacy Policy

Obligations as a Leadoo customer

Leadoo’s clients generally act as controllers for the personal data registers and data they are processing in Leadoo. The aim of the controller (client) is to define the purpose of the register, and the processor (Leadoo) is responsible for helping the client in the processing of information in an intended manner. Simply put, this means that the customer uses Leadoo for their intended purpose and Leadoo assists the customer in implementing this purpose. This means that we are also doing updates to the software so that this is going to be fast and easy.

The controller (customer) is responsible for ensuring that data is processed technically and administratively in accordance with the requirements of the regulation. The regulation includes significant changes to how and when registers can be maintained. In addition, the controller must ensure that their own activities are transparent towards the data subject, the data is valid, and correct restrictions are applied to the use of personal data. It is particularly important to remove unnecessary information and to safeguard the data subject’s legislative rights. According to the regulation, the data subject has the right to ask for their registered data, to update it and, in certain circumstances, to demand it’s deleted.

If you are a controller, we encourage you to review the content of the regulation. The European Data Protection Supervisor provides vast resources and up-to-date information on its website.

We also encourage you to analyse your situation with the assistance of a lawyer, as the services or training they provide may give you instructions directed specifically at your organisation. The responsibility to take care of this is on the controller (client) so we strongly advise to put some effort in.

Leadoo compliance with GDPR

We are proud to say that we have put a tremendous amount of work to make sure that everything is in order in respect to the European Union’s General Data Protection Regulation (GDPR). We have put in enterprise-level effort to look after our data protection and privacy as we understand the importance of this matter. This way also our enterprise customers can rely on us to do our part in the data protection chain.

Leadoo’s data protection mechanisms have been entrusted to the management of the entire company, as well as to a DPO (Marcin Lis) who is responsible for operations as part of the management team.

The tech team has set up and implemented the changes required by the regulation. Their task is to implement the data protection processes and changes and make them part of the company’s overall functions and services.

GDPR in the Leadoo software

Privacy policy generation

In order to use Leadoo to collect personal data, a privacy policy needs to be in place. The Leadoo software will provide even better tools for building the necessary kind of policy a customer needs to ensure they’re doing data collection by the book also for your competitions etc.

Automatic expiration of personal data

In order to avoid storing old and unnecessary data, Leadoo will set an expiration date for personal data by default. Our customers can change the expiration date by request according to their business needs and regulatory requirements.

Stricter requirements for consent

The GDPR enforces even stricter requirements for consent when collecting the data. By using Leadoo and strictly required fields, everyone can be sure that the data that enters the system is collected with proper permissions.

Ability to manage personal data

The GDPR gives more rights to individuals over their personal data. We at Leadoo provide possibility for our customers to find out what personal data is stored in their account and therefore fulfill requests coming from individuals. This includes the ability to by request print out a report on personal data by the individual, delete all related personal data etc.

Access to customer data

While we have always accessed customer data only purposefully and with the agreement of our customers, we have developed stricter controls on who can access the data inside the company.

Storing backups

Storing relevant backups is crucial to us for disaster recovery purposes. However, backups tend to hold information even after it is deleted from production systems. This is why we periodically run our backups through certain filters to ensure they contain only information we and our customers have permissions to store.

Data processing and subcontractors

Our objective is to provide the safest and highest quality service to our customers. Like many other SaaS services, we also use subcontractors and partners to provide our service. This means that our subcontractors also take part in the processing of personal data on a case-by-case basis. All our subcontractors go through an audit process, which ensures that they share our own tight security and privacy requirements. For more detailed answers, please contact our Data Protection Officer (Marcin Lis,  [email protected]). Here are the partners used today:

 

Name of controller Categories of processing Third countries data is transferred to Safeguards Agreements
Amazon Web Services Storage and processing of all customer data Servers in Ireland / US based company Automatic wiping of data after customer defined time delay. Encryption throughout. More at https://leadoo.com/security/ DPA
Clearbit OPTIONAL:Gathering company information from IP addresses to enrich the customer’s lead data US Only IP address, not considered as personal data, is sent over the wire to acquire company name Signed SCC
Zapier OPTIONAL:Integrations to the customer’s own 3rd party systems such as CRMs, ATSs etc. US Only implemented on the request of the customer in order to integrate with their 3rd party system, in which case the customer is in charge of fulfilling their privacy and GDPR related duties for transferring data into a 3rd party system and Leadoo only works as a proxy. DPA
Cyclr OPTIONAL:Integrations to the customer’s own 3rd party systems such as CRMs, ATSs etc. United Kingdom Only implemented on the request of the customer to integrate data to/from Leadoo with some other 3rd party system the customer has. DPA
Cronofy OPTIONAL:Calendar and email sending for calendar node in bot discussions United Kingdom Only implemented on the request of the customer to sync calendar data to Leadoo. Non-public DPA (Privacy docs
Microsoft OPTIONAL:AI chat module that uses ChatGPT or similar LLM model to answer chats. Servers in Sweden Only implemented on the request of the customer. May be used by customers to add any personal data in free text form. Non-public DPA
Scaleway Backup server France Storage of all data Non-public DPA
Benhauer sp. z o.o. (dba SALESmanago) All data Poland Customer success and group services through the same group company Non-public DPA

As part of a data processing agreement, our customers must accept our subcontractors’ use of personal data.

Data processing agreements

We fully understand our important role as a processor of valuable and confidential personal data and are serious about the responsibility that our customers give us. We have built a processing agreement with our customers in accordance with the Data Protection Regulation, which identifies the customer’s processing instructions for the registry. These guidelines are the foundation for all our processing operations.

We require all our customers to accept our data processing agreement so that we can ensure safe and lawful processing of personal data. We will process personal information you provide to Leadoo only and solely in accordance with the regulation. These terms you can find at the upper part of this page.

Leadoo employees undertake to participate in data protection and processing training to ensure that your data is reliably managed. All our employees are also subject to duty of confidentiality with respect to our customers’ data when they start working at Leadoo.

Retrieving and removing data

Leadoo provides a possibility for retrieving and removing individual data subject’s items. Also, if your customer relationship with us will nevertheless end, or if you want to retrieve or remove any personal information, we will provide you with the possibility to do this. Retrieving events, data subject, and other personal information is done by request.

You can submit a request for this to support(at)leadoo.com. In addition, on request, we can ensure that your personal data is removed on our own and on our subcontractors’ data bases upon termination of your customer relationship. We will permanently remove your information within the stated deadline unless we have a legitimate reason in public interest to maintain the data.

Data transmission internationally

Leadoo reserves the right to process information covered by its own registers in countries outside the European Union or the European Economic Area, provided that adequate security and data protection of these services is appropriately undertaken. We also try to minimise the amount of data that is being processed outside the EU, but because of the open nature of the Internet, we cannot completely restrict the processing.

Our support to you

Leadoo’s team provides assistance in questions to do with the data protection regulation. In addition, our customer success managers and customer service personnel provide user support and help with Leadoo’s data protection features.

This post has been brought to you by our friends from Cookie Information! They are true experts when it comes to cookie consents and staying extra safe with GDPR.

GDPR + marketing

98% of your website visitors just leave, without any kind of conversion. What if you could turn some of these 98% into loyal customers? Here’s how you can better understand your customers’ journey to target new audiences and retarget existing clients.

Only 2% of your website visitors convert.

The rest just come and go.

Wouldn’t you like to know who they are? And how you make them convert?

So do we.

That’s why we are always looking for new ways to get to know our potential clients a little better. Understanding customer journeys has been the soul of online marketing for years; and it continues to be.

Getting to know your customers requires a lot of data. This probably is not news to anyone. After GDPR it has become crucial to ask website visitors for a consent to collect their data.

Why?

We are constrained by law.

Yes, privacy laws like the ePrivacy Directive (the European cookie law) and the GDPR require us to obtain valid consent from our visitors before we collect their data.

This rule applies to us all.

Transparency and privacy are key factors for how buyers perceive your business.

So, now we’re going to show you how you can collect your users’ data to better understand your customers’ journey; all while being GDPR compliant!

How to collect GDPR compliant data

First, you should look for a good CMP.

What’s a CMP you might ask?

A Consent Management Platform (CMP) is a tool that collects your users’ valid consent to cookies on your websites and apps.

But why should you get a Consent Management Platform?

Because obtaining consent to cookies isn’t simply showing your visitors a banner on your website saying: “we use cookies – ok”.

GDPR consent is much more complex.

So, here is GDPR consent in a simplified form:

When you use cookies on your websites or apps that collect your visitors’ personal data (cookies from Google Analytics, Facebook, LinkedIn, TikTok or any other third-party service), you must:

And of course, remember to store all the consents securely for 5 years so you can show them to the Data Protection Authorities if they come knocking at your door. They do that sometimes.

Still sounds complicated?

Don’t worry, it’s not.

You can easily collect valid GDPR consent.

Cookie consent that complies with GDPR

There are actually only a handful of Consent Management Platforms in the world that will enable you to collect a cookie consent that complies with the GDPR.

Cookie Information is one of them.

We make sure you always:

· Collect valid GDPR consent to cookies from your users
· Stay compliant with national cookie rules and the GDPR
· Get the support you need to implement and maintain your Consent Solution
· Get through an audit by the Data Protection Authorities (we have your back!)

With a solution like Cookie Information, your websites and apps are always up to date with current legislation, so you can focus on collecting the data you need to grow.

Data, of course, is only information until you put it together in the right way. At that point it becomes insights; something you can act upon.

Transform information into insights

One of the ways to transform all the data you collect into insights is by using a Conversion Platform.

Now, what’s that?

A conversion platform is a tool designed to collect and analyse your website’s conversions.

Yeah, but I got Google Analytics“, you might say.

Sure, it’s undoubtedly a great tool. Still, GA will only take you so far if you sell B2B.

A conversion platform is more than just endless amounts of raw data in graphs and pie charts. It activates and converts your visitors with deeper insights and automation.

A conversion platform has many built-in conversion tools to convert and nurture your website visitors.

One platform we have been happy to discover is Leadoo.

Leadoo is a Conversion Platform. It collects and displays your potential buyers’ data so your marketing and sales department can understand each step of the buyers’ journey.

Leadoo activates and engages your leads, so you start building a rapport with them. This means that you can nurture them all the way to a hard conversion. 🚀

And that is the goal of any business, right?

But as said earlier, collecting data requires attention to data privacy regulations like the GDPR.

When you use a conversion platform like Leadoo, it is built on the premise that you ask your website visitors’ permission to collect and use their data.

How to integrate Cookie Information with Leadoo

When Cookie Information is your Consent Management Platform, it’s easy to integrate it with Leadoo.

You can use this simple javascript, which is actually the only thing you need to do to integrate the two tools.

if (!window.ldanalytics) window.ldanalytics = [];
window.ldanalytics.push(function(a) {
    a.toggleTracking(true, false);
});

Ready to start converting?

Spark up a discussion with our friendly little helper right here 👇🏻 

Leadoo’s guide to cookie consent and GDPR

Leadoo guide to cookie consent cover

How to use cookies and remain GDPR-compliant

Ah, cookies. Figuring out the correct approach to using cookies on your website can really cause your hair to turn grey if you’re unsure about how to do it.

Here’s our guide to help you understand and tick all the boxes with cookie consent. Get your copy below and stay 100% GDPR-compliant.


GDPR EU flag and map

The General Data Protection Regulation (GDPR) has been around for more than two years now, and it would not be an overstatement to say that it has shaken up the whole marketing industry. In this post, we will address the use of various tracking technologies in a GDPR-compliant manner – to offer interest-based advertising and stay accountable at the same time.

Cookies and compliance with privacy legislation

Although cookies are the most known technologies, websites also use other means to support functionality and track users, such as HTML5 local storage, Local Shared Objects, fingerprinting techniques, etc. However, we will use cookies as an umbrella term in this discussion, keeping in mind that it also covers other technologies.

It is also worth noting that we discuss here compliance with the EU privacy rules on cookies, which will not necessarily apply in the same way to the California Consumer Privacy Act (CCPA) and the Lei Geral de Proteção de Dados (LGPD). Using web analytics in the US, for example, is more relaxed and does not require prior consent. You should understand well which laws govern your activities.

Before moving to a question of lawfulness, it is crucial to differentiate cookies by categories based on the purposes they serve.

Leadoo and any other web analytics service provider uses cookies to recognize users’ behavior and deliver their services. However, each website owner’s responsibility as a data controller is to ask and collect visitors’ consent before starting tracking. It is essential to ask for permission, and whether all cookies require approval, we will discuss below.

GDPR and ePrivacy Directive

It may come by surprise, but the GDPR is not the only and, more importantly, not the first law to consider before using cookies. The GDPR sets forth the fundamentals of personal data protection: principles of processing, data subject’s rights, controller and processor’s duties, etc. In contrast, the ePrivacy Directive (aka a Cookie Law) guarantees respect for private life and protects personal data in electronic communications in particular.

In practice, it means that the ePrivacy Directive prevails over the GDPR in situations where electronic communications are involved. However, unlike the GDPR, the ePrivacy Directive does not have a direct effect, i.e., each EU country has its national law implementing the Directive’s provisions. While it might lead to some deviations between different jurisdictions, the core rules will remain the same.

Cookie consent foundations

Under the ePrivacy Directive, there is a general requirement to ask for user’s consent before using any cookies. Importantly, it does not matter whether any personal information is processed or not for it to apply. It is because placing cookies on a user’s device is considered as interference with that user’s private space and thus requires prior permission.

Notably, it is the GDPR that defines consent. Accordingly, it must be any freely given, specific, informed and unambiguous indication of wishes by which a data subject, by a statement or by clear affirmative action, signifies agreement to the processing of personal data. This wording contains quite a lot of meaning to grasp, and it could be a subject for a separate blog post to explain what a GDPR-compliant consent entails.

Leadoo has prepared a detailed, up-to-date guideline on asking for cookie consent to help its customers comply. As a preview, consider that a widespread practice of assuming or implying user’s permission from a mere act of browsing a website is no longer legal in Europe.

Cookie consent exception

From the categories mentioned above, only essential cookies fall under the ePrivacy Directive consent exception. The document refers to them as strictly necessary to provide an information society service explicitly requested by the subscriber or user. Noticeably, it is a very narrow exception. Most of the cookies that facilitate the use of a website, but are not strictly necessary and not explicitly requested, still need user consent. There is no mercy for analytical cookies, either.

Hope for the future

The current situation is about to change soon as a new ePrivacy Regulation is coming to replace the Directive. Similarly to the GDPR, it will be directly and uniformly applicable in all EU countries. Among the offered novelties are two additional cookie consent exceptions of our interest:

Consequently, it is mandatory to ask for the visitors’ consent to use any cookies other than strictly necessary. If you would like to receive detailed guidelines on how to do it correctly, contact your customer success person at Leadoo or download our comprehensive guide below! ⤵️ 

Leadoo is fully GDPR compliant. In addition to complying with the regulation ourselves, it is important for us to help our customers with their compliance efforts. This goal is achieved through training, instruction, and technical development of our software. See our full GDPR statement here

In essence, you can decide for yourself how to use Leadoo – you can use it in fully anonymous mode, in which case no marketing tracking is done. Most often, however, you will want to use it for marketing and analytics purposes – just like you’re using Google Analytics today – and this requires permission from the user. Leadoo bots can do this for you, or your own website can ask for consent and hand over that information to Leadoo.

When you start using the Leadoo service, your customer success manager will help you ensure that your website complies with GDPR.

For our own site, Leadoo.com, Leadoo operates as both the Processor and Controller for the data. However, for our customer’s sites, we only operate as the Processor. To understand what this means you can go to the specific explanation in our Privacy Policy here.

If you want to know more in-depth how we keep your data safe read this.

Most AI chatbot projects begin with excitement.

A team experiments with OpenAI, Anthropic, or Gemini APIs. They connect a chatbot to the website. They upload some documentation. Maybe they even launch a pilot within a few weeks. Technically, it works.
But then the real questions start appearing:

This is the moment many businesses realise:
AI chatbots are not just software projects. They’re ongoing conversion systems.

And successful conversion systems require strategy, optimisation, analytics, governance, and continuous improvement.

One of the biggest challenges with in-house chatbot projects is ownership. At launch, there’s usually enthusiasm and cross-functional collaboration. It is the newest and shiniest thing on the website after all.

But several months later, ownership often becomes unclear, especially as the difficult questions above start popping up. Without clear accountability, many AI chatbot projects quietly stagnate.

The chatbot remains live, but nobody is truly responsible for improving it. This is where businesses often underestimate the value of a specialist conversion partner.

With Leadoo AI, optimisation doesn’t stop after implementation. All our standard packages include dedicated Conversion Experts whose role is to continuously improve performance, refine journeys, identify friction points, and maximise ROI.

Because launching a chatbot is not the finish line. It’s the starting point. Check out the quality and value of our customer service for yourself on review sites like G2.

“With new AI-driven capabilities and continued investment in our platform, we’re focused on helping our customers achieve even greater results. I want to personally thank every customer – those who have been with us for years and those just getting started, for the trust they place in us.”

Many businesses measure chatbot success incorrectly or incompletely. They focus on number of conversations, engagement rates, or time on site.

But none of these metrics necessarily translate into business outcomes. The real question is:

Are my chatbots driving conversions? And if not:

Most DIY AI stacks provide logic and infrastructure, but very little meaningful conversion insight.

This creates a dangerous situation where teams assume the chatbot is successful simply because it exists. Leadoo AI approaches this differently.

Through advanced Conversion Insights, businesses can clearly understand how conversational journeys influence pipeline generation, lead quality, conversion rates, and customer behaviour.

More importantly, optimisation becomes continuous rather than reactive. Because AI without performance visibility quickly becomes expensive guesswork.

Security and compliance are unfortunately sometimes treated as secondary concerns during AI experimentation. Until legal teams get involved.

Or customer data starts flowing through prompts…

AI chatbots frequently process personally identifiable information. And many businesses underestimate the operational complexity of managing this securely and compliantly.

Key questions that any AI chatbot builder or provider MUST be able to answer include:

These concerns become even more significant for companies operating across multiple regions and jurisdictions. And in-house teams frequently cannot answer these without getting into an uncertain legal minefield. Leadoo’s platform is built with GDPR-compliant insights and enterprise-grade governance in mind – reducing risk while allowing businesses to scale conversational experiences confidently. Because compliance is not something you bolt on later.

This is one of the most overlooked challenges in AI chatbot development. Most AI tools provide the intelligence layer.

But they don’t solve the experience layer. And the experience layer is what users actually interact with. It includes: UI and conversational design; timings and triggers; mobile responsiveness; brand consistency; guardrails and fallback handling; and escalation paths.

In practice, companies often spend far more time designing and refining user experiences than building the AI itself. And without careful optimisation, AI chatbots can easily become inconsistent, off-brand or just generic (see the famous Air Canada example).

Worse still, poorly implemented, or just non-optimised, AI experiences can actively harm conversion rates and customer trust.

Leadoo AI combines conversational intelligence with conversion-optimised user experiences and built-in safeguards. Helping businesses deploy AI experiences that are not only intelligent, but commercially effective, with the help of Conversion Experts.

Because users don’t judge your chatbot on its architecture. They judge it on the experience. Here’s an example of how Leadoo AI can dramatically improve UX – even in a highly regulated industry.

Many companies pursue in-house AI chatbots because they assume it will reduce costs.

Initially, this can appear true. The first prototype may only require a developer and API access.

But costs rarely stay there. As adoption grows, complexity grows too. Before long, the organisation isn’t managing ‘a chatbot’. It’s managing an evolving AI platform.

And unlike Leadoo AI’s fixed package pricing, internal AI infrastructure costs are highly volatile with changes to AI models; token usage; and increasing computational requirements.

Internal teams also absorb hidden operational costs when it comes to maintenance, prompt tuning, analytics integrations and setup, QA and infrastructure monitoring.

What initially looked cheaper can quickly become significantly more expensive.

AI chatbots rarely operate in isolation. To create meaningful business outcomes, they need to connect with CRM, MA systems, analytics tools, or product databases.

Every integration introduces additional complexity, maintenance, and failure points. And when something breaks, diagnosing whether the issue sits within the AI or integration layers can become extremely time-consuming for internal teams. And can reignite the ownership question we mentioned earlier.

This is another reason most businesses eventually prefer managed conversational platforms over fragmented DIY stacks.

There’s no question that modern AI tools have democratised chatbot development. Businesses absolutely can build powerful AI experiences internally.

But the more important consideration is whether they should dedicate long-term internal resources to owning, managing, optimising, securing, scaling, and continuously improving those systems.

Because successful AI chatbots are not one-time projects. They are ongoing commercial programmes. And as shown, if they go wrong, it can be catastrophic for internal teams. For many businesses, the true challenge is not launching an AI chatbot. It’s sustaining one successfully over time.

That’s where Leadoo AI and our Conversion Experts shine.

General Terms and Conditions (“Terms”)

Updated: Jun 29, 2026

1. Scope of Terms

2. Definitions

3. Features of Services

4. Services and Support

5. Terms of Use

5a. Artificial Intelligence (AI Act Compliance)

6. Prices

7. Term and Termination

8. Customer Data, Use of Services and Statistical Information, Procedure for changing service provider

  1. switch Leadoo to a different provider of data processing services, in which case the Customer shall provide the necessary details of that provider;
  2. switch to an on-premises ICT infrastructure;
  3. erase its exportable data and digital assets.

8a. Licence to Customer Data

9. Intellectual Property Rights

9a. Feedback

10. Customer’s Systems and Support Service Disclaimer

11. Confidentiality

12. Reference Use

13. Changes to Terms and Notifications

14. Limitation of Liability

15. Personal Data, Privacy and Cookies

16. Support Services and Disclaimer of Warranties

17. Applicable Law and Settlement of Disputes

18. Miscellaneous
18.1.  Assignment and Subcontractors

18.2. Survival

18.3. Entire Contract

18.4. Severability

18.5. Amendment

18.6. Force Majeure

Leadoo shall not be liable for delays, defects or damages caused by factors due to an impediment beyond Leadoo’s reasonable control, which Leadoo cannot reasonably be deemed to have taken into account at the time of the conclusion of the Contract, and the consequences of which Leadoo could not reasonably have avoided or overcome. Such events of force majeure shall include, without being limited to, natural disasters, breakdown of electricity or networks, security attacks, failures in Internet or other public networks or data traffic, strikes and other labor disputes or acts of government. A labor dispute shall be considered a force majeure event also when Leadoo is the target or a party to such an action. The force majeure events suffered by Leadoo’s subcontractors are also deemed as force majeure events.

Important updates to our Main Services Agreement regarding the EU Data Act

As your trusted partner in growth, Leadoo is committed to staying ahead of the regulatory landscape to ensure your business remains compliant and competitive. In line with this commitment, we are proactively updating our Main Services Agreement (MSA) to align with the new EU Data Act.

These updates are designed to strengthen your rights regarding data portability and service flexibility — ensuring our partnership continues on a foundation of transparency and trust.

What is the EU Data Act

The EU Data Act is a new regulation designed to create a fairer and more innovative data economy within the European Union.
While the GDPR focuses on personal data protection, the Data Act complements it by establishing rules for access to and use of data. Particularly data generated by connected (IoT) products and digital services.

Its main goal is to unlock the value of data by ensuring it can be shared more easily and fairly between businesses, consumers, and public sector bodies in specific cases.
For our clients, the most significant change is the new framework for data portability, which gives you greater control and flexibility over your digital assets.

The new rules entered into force in January 2024 and became fully applicable from 12 September 2025.

Key Changes to Your Agreement

To ensure full compliance and provide you with greater control, we are updating two key areas of our Main Services Agreement.
Below is an overview of the changes for your clarity.

1. A More Flexible Termination Policy

Current VersionNew Version (effective from September 12, 2025)
The customer could only terminate the agreement in the event of unavailability of the System’s main functionalities.The customer can terminate the agreement at any time, with a maximum notice period of two months. In this case, an additional fee (corresponding to the fees for the remainder of the agreement) may apply. This fee does not apply when termination occurs due to circumstances for which Leadoo is responsible.

2. Enhanced Data Portability and Provider Switching

Current VersionNew Version (effective from September 12, 2025)
Lack of detailed provisions and procedures for transferring data to another provider as required by the Data Act.A new dedicated chapter has been introduced to regulate the process of transferring your data and digital assets in accordance with the EU Data Act. New appendices have been added to specify the technical conditions for migration.

What these changes mean for Our Partnership

To ensure our continued partnership remains fully compliant with the EU Data Act, we are updating our terms.

While you can choose to object to these changes, please note that the previous terms will not meet the mandatory legal requirements after 12 September 2025.
To avoid any disruption to your service, it is necessary to align our agreement with these new provisions. This ensures we can continue providing our service to you in a fully compliant and secure way.

Have Questions? We’re here to help

We understand that regulatory changes can raise questions, and our team is here to support you.
Please don’t hesitate to contact us if you have any further questions or concerns.

Privacy Policy

OVERVIEW

This privacy policy contains information about what personal data we collect and process about you in context of using our services available at leadoo.com and what rights you have relating to your personal data.

We use Leadoo’s tracking service to follow what users are doing on the site and combine this behavioral data with other data we can gather from e.g. chat interactions, IP addresses etc. Leadoo uses etag tracking in order to hook together the same users behavior over several sessions. Leadoo works as the Processor and Controller for the data on leadoo.com and only as the Processor for our customer’s websites. You can stop the tracking by emptying your browser’s cache after the visit. For more on how Leadoo works as a GDPR compliant processor, see https://leadoo.com/privacy-policy-processor/

If you choose to register to Leadoo platform we have to store your email and login information in order to offer the platform to you. Consent for processing this data is asked separately at the registration. If you don’t want to give consent to process your information, it is likely that we cannot provide any services to you.

CHANGES TO THIS PRIVACY NOTICE

We may change this privacy notice from time to time by updating this page in order to reflect changes in the law, our privacy practices and/or business operations. We encourage you to check this privacy notice for changes whenever you visit our website – Leadoo.com.

WHAT KIND OF PERSONAL INFORMATION DO WE COLLECT AND PROCESS?

When registering, contacting us or our customers, interacting with our bots or other technologies, by applying for a job or working with us or one of our partners or customers, you may be asked to enter your name, email address or other details to help you with your experience or to allow us to provide our services to you or contact you regarding our services or other requests sent to us. In the case of our customers the data is used for the purpose of our customers.

We also collect personal data about our website visitors with though major digital platforms such as Google Analytics, Hubspot, and others so that we may analyze our service use, market to you if requested, and develop our system further.

Read more about third party services below.

WHAT IS THE SOURCE OF YOUR PERSONAL INFORMATION?

Typically we collect personal information from you when you register on our site, place an order, subscribe to a newsletter, respond to a survey, fill out a form, use Live Chat, use any of our bots, open a Support Ticket or enter information on our site. Information is also generated about you when you use our products and services such as IP address and possible reverse look ups from the IP address for company details. In some cases we may request your consent for processing your data. Please note that you always have the right to withdraw such consent.

HOW DO WE USE YOUR INFORMATION?

We may use the information we collect from you in the following ways:

WHAT ARE THE LEGAL GROUNDS FOR PROCESSING YOUR PERSONAL DATA?

We make sure that we always have a legal basis to process your personal data. We may process your data on a several different basis: based on your consent, based on our legitimate interests related to such data such as promoting and developing our services and processing contact requests and applications sent to us, to fulfill and execute a contract and to meet legal obligations. The legal basis for data on our customer’s sites is fully the responsibility of our customers.

HOW DO WE PROTECT YOUR INFORMATION?

We take appropriate technical and organisational measures to secure the data we collect. However, please note: We do not use vulnerability scanning and/or scanning to PCI standards. We only provide articles and information. We do not use Malware Scanning.

Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) or Transport Layer Security (TLS) technology.

We implement a variety of security measures when a user places an order enters, submits, or accesses their information to maintain the safety of your personal information.

WHEN DO WE SHARE YOUR PERSONAL INFORMATION WITH OTHER ORGANISATIONS?

We may share information with the following third parties for the purposes listed above:

PUBLIC ATTESTATION OF TCF POLICIES

Leadoo participates in the IAB Europe Transparency & Consent Framework and complies with its Specifications and Policies.

HOW LONG IS THE DATA STORED?

Your personal data is not stored for longer period than is necessary for its purpose or required by contract or law. You always have the right to prohibit us from processing your data for marketing purposes.

DOES LEADOO USE COOKIES AND WHAT ARE THOSE?

Yes. Cookies are small files that a site or its service provider transfers to your computer’s hard drive through your Web browser (if you allow) that enables the site’s or service provider’s systems to recognize your browser and capture and remember certain information.

We use cookies to:

You can choose to turn off all cookies on our site from the cookie banner that appears when you visit our site for the first time.

We also use other advanced fingerprinting methods to track a user outside cookies. These work essentially in the same way as Cookies but also work in cases where cookies don’t work. We only use these methods when you have given explicit permission. On our Customers and Partner’s websites it is the responsibility of the said Customer and Partner to ensure Leadoo’s tracking is not loaded before explicit consent.

THIRD-PARTY DISCLOSURE

We do not sell, trade, or otherwise transfer your Personally Identifiable Information to outside parties unless you give us your consent. This does not include website hosting partners, commercial partners and other parties who assist us in operating our website, conducting our business, or serving our users, so long as those parties agree to keep this information confidential. We may also release information when it’s release is appropriate to comply with the law, enforce our site policies, or protect ours or others’ rights, property or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses.

List of 3rd party systems

For a full list of 3rd party systems and links to their individual DPAs, please see our Data Protection and GDPR. As a controller we also use the following 3rd party services:

Recipient/s Purpose Lawful purpose
Cyclr & Zapier Integrations between systems Legitimate interest
Webinar co-host Co-marketing of services from webinar co-hosts Legitimate interest
Twentythree Webinar hosting platform Legitimate interest
Hubspot CRM & Marketing Automation platform Legitimate interest
Planhat Customer management platform Legitimate interest
Google Analytics & Tag Management platform  Legitimate interest

 

WHAT RIGHTS DO I HAVE RELATING MY PERSONAL DATA?

Here is a list of the rights that all individuals have under data protection laws. They don’t apply in all circumstances. If you wish to use any of them, we’ll explain at that time if they are engaged or not.

Data protection laws are supervised in Finland by the Finnish Data Protection Ombudsman. If you have questions belonging to the jurisdiction of the Data Protection Ombudsman, or if you wish to lodge a complaint regarding processing of personal data, you may contact the Data Protection Ombudsman’s office as instructed at tietosuoja.fi.

HOW CAN I USE MY RIGHTS?

You can execute and use your rights by sending a request to: [email protected]

In such case, we ask you to provide us your name, contact details, phone number as well as a copy of valid personal ID, such as a driver’s license or passport, so we can verify your identity.

WHAT ARE YOUR MARKETING PREFERENCES AND WHAT DO THEY MEAN?

We may use your home address, phone numbers, email address and social media or digital channels (for example, Facebook, Google and message facilities in other platforms) to contact you according to your marketing preferences.

You can opt out of any email or text marketing by following the unsubscribe links. If you receive a marketing call from us, you can ask the person who called you to opt you out. You can also send us an email ([email protected]) and request opt out.

CONTACTING US

If there are any questions regarding this privacy policy, you may contact us using the information below.

Data Processing Agreement (Customer)

On 25 May 2018, the European Union’s General Data Protection Regulation (GDPR) took effect. It is one of the most important international legislative changes in data protection in decades. The purpose of the regulation is to increase the individual’s rights to manage and process their personal data and to harmonise legislation within the European Union.

Leadoo is firmly committed to the Data Protection Regulation and we have been studying it’s content and impact. In addition to complying with the regulation ourselves, it is important for us to help our customers with their compliance efforts. This goal will be achieved through training, instruction, and technical development of our software.

Leadoo’s updated GDPR compliant terms come to force on the 1st of May 2020. By using Leadoo you agree to comply with this data protection agreement.

1. Service agreement and purpose of this DPA

This DPA has been entered into in connection with the agreement concerning the provision of Leadoo’s services entered into between the Parties two parties (“Service Agreement”) and this DPA sets additional requirements and details regarding the Supplier’s handling of personal information relating to the Customer’s employees, contractors, partners or other parties (“Personal Data”) on behalf of the Customer in accordance with and as required by the Service Agreement. Subject-matter, nature and purpose of the Processing are defined and agreed under the Service Agreement.

The DPA shall form an integral part of the Service Agreement, meaning that applicable parts of the Service Agreement (including its provisions on governing law and dispute resolution) shall apply also to this DPA. However, in the event of a conflict, the provisions of this DPA shall prevail over the provisions of the Service Agreement.

2. Duration of the process

Personal Data will be processed by the Supplier for the duration of the Service Agreement unless a longer or shorter period is agreed between the Parties in the Service Agreement or elsewhere in writing.

3. Types of personal data processed

For each event, Customer shall define what data is to be collected. Regarding each event, Supplier shall collect and store the processed data as defined by Customer. This type of data may include, for example, person’s name, required contact information, and as well as other necessary additional information needed for registration, using the service, and payment. The responsibility of defining this information is on Customer alone.

Details may be further specified under the Service Agreement.

4. Definitions

The capitalized terms used herein shall have the meaning ascribed to them below or in the text of this DPA.

“Affiliate” shall mean any legal entity which is directly or indirectly owned or controlled by a Party or directly or indirectly owning or controlling a Party or under the same direct or indirect ownership or control as a Party for so long as such ownership or control lasts.

“Data Protection Laws” shall mean EU Data Protection Regulation (2016/679) and the data protection laws under the governing law of the Service Agreement applicable to the Processing hereunder from time to time. The Parties acknowledge and agree that in the time period prior to the EU Data Protection Regulation (2016/679) becoming applicable (expected on 25 May 2018), interpretation of this DPA shall be based on applicable data protection laws under the governing law of the Service Agreement.

“Personal Data” shall mean any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“Personal Data Breach” shall mean a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed hereunder.

“Processing” shall mean any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, of Personal Data.

“Sub-Processor” shall mean a processor contracted by the Data Processor to perform Processing hereunder, in part or in whole, on the Data Processor’s behalf.

5. Rights and obligations of the parties

Both Parties shall be responsible to ensure that the Processing is made in accordance with the Data Protection Laws which apply to each Party as well as good data processing practices.

The Data Controller shall

  1. give the Data Processor documented and comprehensive instructions on the Processing, which instructions shall comply with the Data Protection Laws;
  2.  have the right and obligation to specify the purpose and means of Processing of Personal Data;
  3.  represent that all the data subjects of the Personal Data have been provided with all appropriate notices and information and establish and maintain for the relevant term the necessary legal grounds for transferring the Personal Data to the Data Processor and allowing the Data Processor to perform the Processing contemplated hereunder;
  4.  represent that if the Data Controller represents its Affiliates or third parties under this DPA, it has the legal grounds to enter into this DPA with the Data Processor and allow the Data Processor to process the Personal Data according to the terms of this DPA and the Service Agreement; and
  5.  confirm that the Processing stipulated under this DPA meets the Data Controller’s requirements including, but not limited to, with regard to intended security measures, and it has provided the Data Processor with all necessary information in order for the Data Processor to perform the Processing in compliance with the Data Protection Laws.

The Data Processor shall

    1.  perform the Processing only on and as per the documented, legitimate and reasonable instructions from the Data Controller unless required to do otherwise by Data Protection Laws, in which latter case the Data Processor shall inform the Data Controller of such deviating legal requirement (provided the Data Protection Laws do not prohibit such notification). For the avoidance of doubt, the Data Controller shall at all times be deemed to have instructed the Data Processor to provide the Service as defined and agreed under the Service Agreement;
    2.  ensure that persons authorised to perform the Processing hereunder have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality as further stated under this DPA;
    3.  take all security measures required to be taken by data processors under the Data Protection Laws as further stated under this DPA;
    4.  respect the conditions referred to under Data Protection Laws for engaging any Sub- Processor as further stated under this DPA;
    5.  insofar as this is possible and taking into account the nature of the Processing, assist the Data Controller by appropriate technical and organisational measures for the fulfillment of the Data Controller’s obligation to respond to requests for exercising the data subject’s rights laid down in under the Data Protection Laws;
    6.  assist the Data Controller in ensuring compliance with its legal obligations, such as data security, data breach notification, data protection assessment and prior consulting obligations, as required of the Data Processor by the Data Protection Laws, taking into account the nature of Processing and the information available to the Data Processor;
    7. maintain necessary records and make available to the Data Controller all information necessary to demonstrate compliance with the obligations of the Data Processor, as laid down in the Data Protection Laws, and allow for and contribute to audits, including inspections, conducted by the Data Controller or any auditor mandated by the Data Controller as further agreed under this DPA; and
    8.  at the Data Controller’s instructions, delete or return to the Data Controller all the Personal Data after the end of the provision of the Services relating to Processing, and delete existing copies unless applicable laws require storage of the Personal Data. Deletion and return methods may be further agreed between the Parties;

    Unless otherwise agreed, the Data Processor shall have the right to invoice any costs resulting from the above assistance under 5) and 6) above in accordance with the Data Processor’s prevailing price list.

6. Security processing

Both Parties shall implement and maintain appropriate technical and organisational measures to protect the Personal Data, taking into account:

  1.  the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, and
  2.  the risks that are presented by the Processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to the Personal Data transmitted, stored or otherwise processed.

Such measures include, inter alia as appropriate:

    1.  the pseudonymisation and encryption of the Personal Data;
    2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
    3.  the ability to restore the availability and access to the Personal Data in a timely manner in the event of a physical or technical incident; and
    4. a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of the Processing.

    The Data Controller shall inform Data Processor of all issues (including but not limited to risk assessment and the inclusion of special categories of Personal Data) related to the Personal Data provided by the Data Controller which affect the technical and organizational measures that should be employed under this DPA.

7. Sub-processors

The Data Processor may from time to time use Sub-Processors to process the Personal Data hereunder. Sub-Processor(s) used in the provision of Services are listed as a part of the agreement. Sub-Processors agreed and used under the existing Services and Service Agreement shall be considered approved Sub-Processors by the Customer.

Such use will be under written contract and the Data Processor will require the Sub-Processor to comply with the data protection obligations applicable to the Data Processor under this DPA or obligations which provide for the same level of data protection.

The Data Controller agrees that the Data Processor has a general consent to use the Data Processor’s Affiliates as Sub-Processors when Processing Personal Data.

The Data Processor will inform the Data Controller in advance on any intended changes concerning the addition or replacement of Sub-Processors.

Approved Sub-processors at the time of the agreement are:

Name of controller Categories of processing Third countries data is transferred to Description and additional safeguards Agreements
Amazon Web Services Storage and processing of all customer data Servers in Ireland / US based company Privacy shield and automatic wiping of data after customer defined time delay. DPA
Clearbit Gathering company information from IP addresses to enrich the customer’s lead data US Only IP address, not considered as personal data, is sent over the wire to acquire company name Signed SCC
Zapier Integrations to the customer’s own 3rd party systems such as CRMs, ATSs etc. US Only implemented on the request of the customer in order to integrate with their 3rd party system, in which case the customer is in charge of fulfilling their privacy and GDPR related duties for transferring data into a 3rd party system and Leadoo only works as a proxy. DPA
Cyclr Integrations to the customer’s own 3rd party systems such as CRMs, ATSs etc. United Kingdom Only implemented on the request of the customer in order to integrate with their 3rd party system, in which case the customer is in charge of fulfilling their privacy and GDPR related duties for transferring data into a 3rd party system and Leadoo only works as a proxy. DPA
Cronofy Calendar and email sending for calendar node in bot discussions United Kingdom Only implemented on the request of the customer to sync calendar data to Leadoo. Non-public DPA
Bugsnag App stability monitoring US Only technical data is transferred, not directly identifiable with a person for technical logging. DPA
Microsoft OPTIONAL: AI chat module that uses ChatGPT or similar LLM model to answer chats. Servers in Sweden Only implemented on the request of the customer. May be used by customers to add any personal data in free text form. Non-public DPA

Scaleway

Storage of all data

France

Backup server

Non-public DPA

Benhauer sp. z o.o. (dba SALESmanago)

Customer success and group services

Poland

Group company

Non-public DPA

As part of a data processing agreement, our customers must accept our sub-processors above.

8. Transfer of personal data

The Data Processor will only transfer Personal Data out of the territory of the member states of the European Union, the European Economic Area, or other countries which the European Commission has found to guarantee an adequate level of data protection (collectively, the “Approved Jurisdictions”) with the Data Controller’s prior written consent or that the Customer has explicitly approved.

The data from outside of EU may be transferred to EU, processed and may be transferred back to any country / area.

If required by applicable legislation, the Data Processor shall enter into relevant contractual arrangements with required parties (including with the Data Controller itself or any of the Data Controller’s Affiliates) for the lawful transfer of Personal Data from the Approved Jurisdiction to third countries.

Such contractual arrangements shall be carried out in accordance with the standard data protection clauses adopted or approved by the European Commission (“Standard Contractual Clauses”). As an alternative to entering into the Standard Contractual Clauses, the Data Processor may rely upon an alternative transfer safeguard permitting and providing for the lawful transfer of Personal Data outside of the Approved Jurisdictions, provided that such safeguard is in compliance with applicable legislation.

In case of conflict between the Standard Contractual Clauses or any other alternative transfer safeguard permitting the lawful transfer of Personal Data outside the Approved Jurisdictions and the DPA, the Standard Contractual Clauses or such alternative framework shall always take precedence over the Service Agreement and this DPA.

 

9. Notification of personal data breach

The Data Processor shall without undue delay (24h) notify the Data Controller if it, or one of its Sub-Processors, becomes aware of a Personal Data Breach. Information shall be provided to the contact person named by the Data Controller, if not otherwise agreed between the Parties.

The Data Processor shall without undue delay inform the Data Controller of the circumstances giving rise to the Personal Data Breach, and any other related information reasonably requested by the Data Controller and available to the Data Processor.

Additionally, to the extent it is available, the Data Processor shall provide to the Data Controller the following information:

  1.  a description of the nature of the Personal Data Breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned;
  2.  a description of the likely consequences of the personal data breach; and
  3.  a description of the measures taken or proposed to be taken by the Data Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

10. Auditing

The Data Controller and its customers whose data may be processed hereunder shall be entitled to audit the Data Processor’s performance of its Processing obligations under this DPA (“Audit”).

The Data Controller shall use external auditors who are not competitors of the Data Processor, to conduct such an Audit. The Parties shall agree well in advance on the time and other details relating to the conduct of such Audits.

The Audit shall be conducted in such a manner that the Data Processor’s undertakings towards third parties (including but not limited to the Data Processor’s customers, partners and vendors) are in no way jeopardized. All the Data Controller’s representatives or external auditors participating in the Audit shall execute customary confidentiality undertakings towards the Data Processor.

The Data Processor shall always allow any relevant regulatory authority supervising the Data Controller’s business to conduct Audits of the Data Processor’s operations, in which case relevant parts of the Parties’ agreement hereunder shall apply.

The Data Controller shall bear all Audit expenses, and compensate the Data Processor for any and all costs incurred as a result of the Audit.

11. Confidentiality

The Data Processor shall:

  1.  keep any Personal Data received from the Data Controller confidential;
  2.  ensure that persons authorized to process the Personal Data have committed themselves to confidentiality; and
  3. ensure that Personal Data is not disclosed to third parties without the Data Controller’s prior written consent, unless the Data Processor is obliged by mandatory law or decree to disclose such information.

In case data subjects or governmental authorities make a request concerning Personal Data, the Data Processor shall, as soon as reasonably possible, inform the Data Controller about such requests before providing any response or taking other action concerning the Personal Data.

In case any applicable authority prescribes an immediate response to a disclosure request, the Data Processor shall inform the Data Controller as soon as reasonably possible, unless the Supplier is prohibited by mandatory law or authority order to disclose such information.

12. Limitation of liability

The limitations of liability set out under the Service Agreement shall apply also to this DPA.

The Parties agree that the general principle of division of responsibilities between the Parties relating to administrative fines imposed by any relevant supervisory authority or claims by data subjects under this DPA is based on the principle that the respective Party needs to fulfill its own obligations under the Data Protection Laws. Hence, any administrative fines imposed or damages ordered should be paid by the Party that has failed in its performance of its legal obligations under the Data Protection Laws, as decided by the relevant supervisory authority or competent court authorized to impose such fines or damages. Therefore, the limitations of liability set out under the Service Agreement shall not, however, apply such fines.

13. Term and Termination

This DPA shall be in effect as long as the Parties have Service Agreements between them in force.

All provisions which by nature are intended to survive the termination of this DPA shall remain in full force and effect regardless of the termination of this DPA.