LeadPro
Home FAQ Results Case studies
Book a call
Legal

Privacy Policy

Effective July 22, 2026 · Terms of Service →
On this page+
The short version
We collect only what you give us — your contact details and what you tell us about your business. We never sell it. Client project data stays on client-owned infrastructure, is covered by NDA, and is never used to train models for anyone else. Email us any time to see or delete what we hold.

Overview

This policy explains what LeadPro ("we," "us") collects when you visit this website, speak with us about a project, or engage us to build a system, how we use that information, and the choices you have about it.

Privacy is not a compliance exercise for us. The systems we build exist so that businesses can keep their own data on their own infrastructure instead of renting it back from a vendor, and we run our own house to the same standard. Where this policy commits us to something, we mean it as a term of doing business, not as a statement of intent.

Who this covers

This policy applies to visitors to this website, to people who contact us about prospective work, and to the individuals we deal with at client organisations during an engagement.

It does not govern the systems we build for clients once they are delivered. A system running on a client’s own infrastructure is that client’s to operate, and their own privacy policy governs the people who use it. Where we handle data inside such a system during a build or a support arrangement, we do so on that client’s written instructions, under the commitments set out below.

What we collect

What you give us. When you book a call, email us, or work with us, we receive what you choose to send: your name, email address, phone number, company, and whatever you tell us about your business, its systems, and the problem you want solved. During an engagement we also hold the ordinary records of a working relationship — correspondence, meeting notes, scoping documents, invoices, and signed agreements.

What this site collects. Basic technical logs generated by serving a web page — pages requested, browser and device type, approximate region derived from IP address — used in aggregate to keep the site working and to understand which pages are useful. There are no accounts on this site, no advertising pixels, no data brokers, and no social-media trackers.

What we do not collect. We do not buy contact lists, we do not enrich the information you give us with third-party profile data, and we do not build behavioural profiles of visitors.

How we use it, and on what basis

We use the information above to reply to you, to scope and deliver your project, to invoice and keep proper accounting records, to keep this website working and secure, and to meet obligations the law places on us.

For those in jurisdictions where a legal basis must be identified, ours are: performance of a contract, or steps taken at your request before entering one, for everything to do with scoping and delivering work; our legitimate interest in operating and securing a professional services business for correspondence, aggregate site analytics, and record-keeping; legal obligation for tax, accounting, and statutory retention; and consent where consent is the only proper basis, which you may withdraw at any time.

We do not sell personal information, and we do not send marketing you did not ask for. If you email us about a project, you hear back about your project.

Client project data

Building a system means handling the material a business runs on — customer records, documents, call logs, job history, financial data. Three commitments govern that work, and they are contractual, not aspirational:

It stays yours. Systems run on infrastructure you own or control. Your data lives there. Where we need a working copy to develop against, it is held in an access-controlled environment for the duration of the work and no longer.
It trains nothing else. We never use one client’s data to train models, seed retrieval systems, or build systems for anyone else. Nothing learned from your records leaves your engagement.
It is under NDA. Confidentiality is executed as standard on every engagement, before scoping begins. Access during a build is limited to the people performing the work, and revoked when their part of it ends.

In data-protection terms, for client project data we act as a processor on the client’s written instructions; the client remains the controller of their own records. Where required, we enter a data processing agreement setting out the subject matter, duration, and nature of the processing, the security measures applied, and the terms on which any sub-processor may be engaged.

When an engagement ends, we delete working copies of your data from our environments, except where a signed agreement or the law requires us to retain something specific. We confirm deletion in writing on request.

AI systems and your data

Most of the systems we build incorporate machine-learning models trained or tuned on the client’s own material. Two points matter for privacy, and we state them plainly.

First, training is confined to the engagement. A model tuned on your correspondence, pricing, and job history is yours; it is delivered with the system and it is not reused, transferred, or generalised into anything we build for another business.

Second, where a system is designed to run without external calls, it runs without them. On-premise and air-gapped deployments process everything on hardware the client owns, and we will tell you in writing, before you commit, if any part of a proposed design would send data to a third-party service — what it sends, to whom, and what the alternative would cost.

Cookies and analytics

This site uses at most functional cookies — for example, remembering a preference you set — and privacy-respecting, aggregate analytics that do not follow you across other websites.

We do not use advertising cookies, cross-site tracking, or fingerprinting. You can block or clear cookies in your browser without breaking anything on this site.

When we share

We share personal information only with the service providers that run our business, and only so far as each needs it to provide its service. Those fall into a small number of categories: email and calendar hosting, scheduling, invoicing and accounting, document storage and signature, and website hosting.

Each is bound by contract to use the information solely to provide the service to us, and none is permitted to sell it or use it for their own purposes. We name the specific providers on request. We also disclose information where the law genuinely requires it, and will tell you when we are permitted to.

If LeadPro were ever acquired or reorganised, this policy would continue to apply to information collected under it, and any successor would be bound by the client commitments above. We never sell or rent personal information.

How long we keep things

We keep information for as long as it serves the purpose it was collected for, and then for as long as the law requires:

Inquiries that do not become projects. Deleted on a rolling basis once the conversation is plainly over.
Correspondence and contract records. Kept for the life of the relationship and afterwards for the period tax, accounting, and limitation law requires.
Client project data. Removed from our environments when the engagement ends, as set out above.
Website logs. Retained briefly, in aggregate, for security and performance.

Where something must be retained for a legal reason after you have asked us to delete it, we keep only what the obligation covers, tell you what that is, and delete it when the period expires.

Security

We apply encryption in transit, encryption at rest for stored client material, access controls, least-privilege practices, and audited access in our own tooling — the same standards we build into client systems, up to and including air-gapped deployments where the work calls for it.

No method of storage or transmission is perfectly secure, and we will not claim otherwise. If a breach ever affects your information, we will notify you promptly, tell you plainly what happened and what it means for you, and notify regulators where required.

Your rights

Wherever you are, you can ask us what personal information we hold about you, ask for a copy of it, ask us to correct or delete it, ask us to restrict or object to a particular use, or ask us to transfer it to you or someone else in a portable form. You can withdraw consent at any time where consent was the basis for a use.

Email us and we will act on it — usually within days, and at most within the window your local law sets. The rights above are drawn from the GDPR, UK GDPR, and CCPA/CPRA among others; we apply them to everyone rather than sorting people by jurisdiction. We do not charge for a reasonable request, and we do not treat anyone differently for making one.

If you are not satisfied with how we handled a request, tell us and a person — not a form — will review it. You also have the right to complain to your local supervisory authority.

International transfers

If you contact us from outside the country where we operate, your information is processed where we and our providers run our services. Where information moves between jurisdictions, we rely on appropriate safeguards — standard contractual clauses or an adequacy decision, as applicable. Client systems deployed on-premise do not transfer data anywhere; that is frequently the reason clients choose them.

Children

This site and our services are directed at businesses and are not intended for children under 16. We do not knowingly collect information from children. If you believe we have, contact us and we will delete it.

Changes to this policy

If we change this policy we update the effective date above, and for material changes affecting active clients we tell those clients directly rather than relying on you to notice. The commitments governing client project data will not be quietly weakened; any change to them applies only to engagements entered after the change.

Contact

Privacy questions or requests, including anything in this policy you would like explained in plainer terms: leadpro@hey.com — we reply the same business day.