This policy explains what LeadPro ("we," "us") collects when you visit this website, speak with us about a project, or engage us to build a system, how we use that information, and the choices you have about it.
Privacy is not a compliance exercise for us. The systems we build exist so that businesses can keep their own data on their own infrastructure instead of renting it back from a vendor, and we run our own house to the same standard. Where this policy commits us to something, we mean it as a term of doing business, not as a statement of intent.
This policy applies to visitors to this website, to people who contact us about prospective work, and to the individuals we deal with at client organisations during an engagement.
It does not govern the systems we build for clients once they are delivered. A system running on a client’s own infrastructure is that client’s to operate, and their own privacy policy governs the people who use it. Where we handle data inside such a system during a build or a support arrangement, we do so on that client’s written instructions, under the commitments set out below.
What you give us. When you book a call, email us, or work with us, we receive what you choose to send: your name, email address, phone number, company, and whatever you tell us about your business, its systems, and the problem you want solved. During an engagement we also hold the ordinary records of a working relationship — correspondence, meeting notes, scoping documents, invoices, and signed agreements.
What this site collects. Basic technical logs generated by serving a web page — pages requested, browser and device type, approximate region derived from IP address — used in aggregate to keep the site working and to understand which pages are useful. There are no accounts on this site, no advertising pixels, no data brokers, and no social-media trackers.
What we do not collect. We do not buy contact lists, we do not enrich the information you give us with third-party profile data, and we do not build behavioural profiles of visitors.
We use the information above to reply to you, to scope and deliver your project, to invoice and keep proper accounting records, to keep this website working and secure, and to meet obligations the law places on us.
For those in jurisdictions where a legal basis must be identified, ours are: performance of a contract, or steps taken at your request before entering one, for everything to do with scoping and delivering work; our legitimate interest in operating and securing a professional services business for correspondence, aggregate site analytics, and record-keeping; legal obligation for tax, accounting, and statutory retention; and consent where consent is the only proper basis, which you may withdraw at any time.
We do not sell personal information, and we do not send marketing you did not ask for. If you email us about a project, you hear back about your project.
Building a system means handling the material a business runs on — customer records, documents, call logs, job history, financial data. Three commitments govern that work, and they are contractual, not aspirational:
In data-protection terms, for client project data we act as a processor on the client’s written instructions; the client remains the controller of their own records. Where required, we enter a data processing agreement setting out the subject matter, duration, and nature of the processing, the security measures applied, and the terms on which any sub-processor may be engaged.
When an engagement ends, we delete working copies of your data from our environments, except where a signed agreement or the law requires us to retain something specific. We confirm deletion in writing on request.
Most of the systems we build incorporate machine-learning models trained or tuned on the client’s own material. Two points matter for privacy, and we state them plainly.
First, training is confined to the engagement. A model tuned on your correspondence, pricing, and job history is yours; it is delivered with the system and it is not reused, transferred, or generalised into anything we build for another business.
Second, where a system is designed to run without external calls, it runs without them. On-premise and air-gapped deployments process everything on hardware the client owns, and we will tell you in writing, before you commit, if any part of a proposed design would send data to a third-party service — what it sends, to whom, and what the alternative would cost.
We keep information for as long as it serves the purpose it was collected for, and then for as long as the law requires:
Where something must be retained for a legal reason after you have asked us to delete it, we keep only what the obligation covers, tell you what that is, and delete it when the period expires.
We apply encryption in transit, encryption at rest for stored client material, access controls, least-privilege practices, and audited access in our own tooling — the same standards we build into client systems, up to and including air-gapped deployments where the work calls for it.
No method of storage or transmission is perfectly secure, and we will not claim otherwise. If a breach ever affects your information, we will notify you promptly, tell you plainly what happened and what it means for you, and notify regulators where required.
Wherever you are, you can ask us what personal information we hold about you, ask for a copy of it, ask us to correct or delete it, ask us to restrict or object to a particular use, or ask us to transfer it to you or someone else in a portable form. You can withdraw consent at any time where consent was the basis for a use.
Email us and we will act on it — usually within days, and at most within the window your local law sets. The rights above are drawn from the GDPR, UK GDPR, and CCPA/CPRA among others; we apply them to everyone rather than sorting people by jurisdiction. We do not charge for a reasonable request, and we do not treat anyone differently for making one.
If you are not satisfied with how we handled a request, tell us and a person — not a form — will review it. You also have the right to complain to your local supervisory authority.
If you contact us from outside the country where we operate, your information is processed where we and our providers run our services. Where information moves between jurisdictions, we rely on appropriate safeguards — standard contractual clauses or an adequacy decision, as applicable. Client systems deployed on-premise do not transfer data anywhere; that is frequently the reason clients choose them.
This site and our services are directed at businesses and are not intended for children under 16. We do not knowingly collect information from children. If you believe we have, contact us and we will delete it.
If we change this policy we update the effective date above, and for material changes affecting active clients we tell those clients directly rather than relying on you to notice. The commitments governing client project data will not be quietly weakened; any change to them applies only to engagements entered after the change.
Privacy questions or requests, including anything in this policy you would like explained in plainer terms: leadpro@hey.com — we reply the same business day.