Privacy Policy
Effective and last updated: September 3, 2026
1. Who we are and when this Policy applies
This Privacy Policy explains how Leado Marketing Inc. (“Leado,” “we,” “us” or “our”) processes personal data in connection with Leado Marketing, the Marketing Intelligence Tool, our public websites, applications, reports, communications and related services (together, the “Service”). Our EU contact office is at Złota 59, 00-120 Warsaw, Poland. Privacy enquiries and requests may be sent to office@leadomarketing.com.
We process personal data under the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Polish Act of 10 May 2018 on the Protection of Personal Data and other laws that apply to the particular processing.
We act as controller for account administration, billing, security, product usage, support, our website, our own business communications and public-source market intelligence. When a business Customer imports or connects its contacts, customers, orders, events, forms, campaigns or similar data and tells us how to use it, the Customer normally acts as controller and Leado acts as its processor. In that case, the Customer’s privacy notice also applies and requests about that Customer Data should normally be directed to the Customer.
2. Personal data we process
- Account and organisation data: name, business email, telephone number, job title, organisation, workspace membership, preferred language, account settings and authentication records.
- Billing and transaction data: billing contact, company name and address, tax or VAT information, plan, invoices, payment status, usage allowances and transaction identifiers. Payment providers process full card or bank details; we generally receive only limited payment metadata.
- Customer Data from connected systems: contacts, customer profiles, email addresses, phone numbers, consent and suppression status, products, orders, carts, website and commerce events, attribution data, campaign membership and data selected through Shopify, WooCommerce, WordPress, Fitssey, custom websites or other integrations.
- Content and communication data: emails, templates, forms, form answers, surveys, popups, web-push messages, media, prompts, comments, support requests and configured automation instructions.
- Delivery and engagement data: sending, delivery, bounce, complaint, unsubscribe, open and click events, form submissions, page views, sessions, attribution touchpoints and responses. Open information may be affected by privacy proxies and similar technology.
- Public market-intelligence data: public advertisements, creatives, advertiser and page names, domains, public posts, public profile information, review content, business contact details, dates, estimated or reported reach and impressions, placements and other information available from public libraries, websites and platforms.
- Product usage and audit data: pages and dashboards visited, searches, filters, feature actions, session timing, feedback, saved preferences and records of changes or approvals.
- Device, network and security data: IP address, approximate country or city inferred from IP, timestamps, browser, operating system, device and session identifiers, request metadata, authentication and security events, errors and diagnostic logs.
- Cookie and campaign data: cookie choices and consent evidence, referral source, landing page, UTM parameters, advertising identifiers and analytics or pixel events, subject to the choices described below.
- Derived data: segments, recommendations, classifications, campaign families, benchmarks, scores, estimated metrics and other insights generated from the information above.
We do not intentionally require special-category personal data such as health, biometric, religious or political information. Customers should not submit it unless necessary, lawful and covered by a written agreement appropriate to that processing.
3. Where the data comes from
We receive data directly from users and Customer administrators; from websites, apps and forms using our scripts; from integrations authorised by a Customer; from payment, authentication, email-delivery and analytics providers; from devices and browsers; and from public advertising libraries, public websites, public social profiles and other lawfully accessible sources. We also derive data through rules, calculations and AI-assisted analysis.
4. Purposes and legal bases
Where Leado acts as controller, we process personal data for the following purposes and legal bases under the GDPR:
- Contract and requested steps: to register users, provide the Service, manage workspaces and subscriptions, deliver reports, respond to support requests and perform actions requested before entering a contract (Article 6(1)(b)).
- Legal obligations: to keep tax and accounting records, respond to binding legal requests and meet data-protection, consumer, communications and security duties (Article 6(1)(c)).
- Legitimate interests: to secure and operate the Service, prevent fraud and abuse, diagnose faults, improve features, measure product adoption, maintain audit evidence, defend claims, understand public market activity, identify relevant business prospects and communicate about similar business services where permitted (Article 6(1)(f)). We balance these interests against the rights and reasonable expectations of affected people.
- Consent: for optional analytics or marketing cookies, certain marketing communications and other processing where consent is requested (Article 6(1)(a)). Consent can be withdrawn at any time without affecting earlier lawful processing.
Where Leado acts as processor, the Customer determines the purpose and legal basis and we process Customer Data on the Customer’s documented instructions. A Customer may configure rules or automations that select recipients or trigger communications. Leado’s own recommendations are not intended to make decisions producing legal or similarly significant effects about an individual without human involvement.
5. AI-assisted processing
If a user invokes an AI-assisted feature, we may send the prompt and the minimum relevant context selected for that task to a contracted AI provider. Depending on the feature, that context may include public ad creative and metrics, product or brand information, draft campaign content, or Customer-selected contact and activity information needed to generate the requested result. We return and may store the output in the workspace. Rules-based recommendations identified as local are calculated without sending Customer Data to an external AI model.
We do not authorise service providers to use Customer Data for their own advertising. Unless separately agreed with the Customer, we do not use Customer Content to train a model for other Customers. Users should avoid placing unnecessary personal or confidential information in prompts and must review generated output before use.
6. Recipients and service providers
We disclose personal data only as needed to:
- cloud hosting, storage, content-delivery, database, monitoring and security providers;
- payment, invoicing and subscription-management providers;
- email, web-push, media-generation and other communication-delivery providers selected for a Customer action;
- AI model, transcription, translation or media-processing providers when the relevant feature is invoked;
- analytics, consent-management and advertising-measurement providers where the user has made the required choice;
- professional advisers, auditors and authorities where reasonably necessary or legally required; and
- a purchaser or successor in a genuine merger, financing, restructuring or sale, subject to appropriate confidentiality and data-protection safeguards.
Providers receive only the data needed for their function and are bound by contractual and confidentiality requirements appropriate to their role. We do not sell personal data. A current subprocessor summary and data-processing terms are available to business Customers on request.
7. Cookies and similar technologies
Necessary cookies and local-storage entries are used for login, security, load balancing, language, billing flow, consent choices and other functions requested by the user. They do not require optional consent where applicable law permits their use as strictly necessary.
Analytics technologies help us understand visits, navigation, scroll depth, time intervals, feature use and conversion steps. Marketing technologies help measure campaigns and attribute registrations or purchases. On our public website, optional analytics and marketing technologies are activated only according to the visitor’s consent choice where required by the GDPR and Polish Electronic Communications Law. You can accept, reject or change categories through our consent controls and can also remove cookies in your browser. Withdrawing consent does not affect processing already carried out lawfully.
We record limited evidence of the consent choice, such as the categories, timestamp, policy version and technical identifiers, so that we can honour and demonstrate the preference. Customer websites using Leado tracking must configure and present their own legally appropriate consent mechanism.
8. Direct marketing
We may send service messages needed to administer an account or contract. We send promotional electronic communications where the recipient has consented or another route is permitted under applicable law, and we respect the additional consent requirements of electronic communications law. Every eligible marketing message provides a practical way to opt out. An objection or unsubscribe is stored on a suppression list so that it can continue to be honoured.
We may research publicly listed business information to understand whether an organisation could benefit from the Service and to prepare relevant business outreach. We use contact channels only where permitted, limit the data to professional context and honour objections. A person may object at any time to processing for direct marketing, including related profiling.
9. International transfers
We and our service providers may process data in Poland, elsewhere in the European Economic Area, the United States and other countries. When personal data protected in the EEA is transferred outside the EEA, we use a lawful transfer mechanism such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with transfer assessments and supplementary measures where appropriate. Information about safeguards relevant to a Customer’s processing is available on request, subject to necessary protection of confidential or security information.
10. Retention
We keep personal data only for as long as needed for the purpose for which it was collected. Account and Customer Data are generally retained while the workspace is active and for a limited period afterwards to allow orderly closure, export, recovery and backup rotation. Billing, tax and accounting records are retained for the periods required by Polish law. Security, audit, consent, suppression and dispute records are retained for periods proportionate to security needs, proof of compliance and limitation periods. Public market-intelligence records are retained while relevant to the Service or until a justified deletion or objection request requires a different outcome.
Retention may be extended where data is needed to establish, exercise or defend legal claims, comply with a preservation duty or investigate abuse. When retention ends, data is deleted or irreversibly anonymised. Residual backup copies are isolated from ordinary use and expire through the backup cycle.
11. Security and incidents
We use technical and organisational measures appropriate to the nature and risk of the processing. These include access controls, least-privilege administration, secure authentication practices, encryption in transit, environment and secret separation, logging and monitoring, backups, software-maintenance processes, abuse controls and incident-response procedures. Access is limited to personnel and providers who need it and who are subject to confidentiality duties.
No internet service can guarantee absolute security. If a personal-data breach occurs, we will investigate, mitigate it and notify affected Customers, individuals or the supervisory authority where and within the period required by applicable law.
12. Your rights
Subject to the conditions in the GDPR, you may request access to and a copy of your personal data; rectification; erasure; restriction; portability; and information about relevant safeguards. You may object to processing based on legitimate interests and may object at any time to direct marketing. Where processing is based on consent, you may withdraw it at any time. You also have the right not to be subject to a solely automated decision that produces legal or similarly significant effects, except where the law permits it with safeguards.
Send requests to office@leadomarketing.com. We may ask for information reasonably necessary to verify identity and locate the data. If the request concerns data controlled by one of our Customers, we may direct it to or assist that Customer. Rights may be limited where an exception under applicable law applies.
You may lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warsaw, Poland, or with the supervisory authority in your country of habitual residence, work or the alleged infringement.
13. Children and Customer forms
Service accounts are intended for adults and we do not knowingly allow anyone under 18 to create an account. A Customer may use forms or integrations for services involving minors. In that situation, the Customer is responsible for an appropriate legal basis, age-specific notices and parental or guardian consent where required, while Leado processes the submitted data on the Customer’s instructions.
14. Required information
Data marked as required during account creation, checkout or a support process is needed to provide the requested service or enter into the contract. Without it, we may be unable to create an account, process payment, secure the workspace or respond to the request. Optional profile, marketing and analytics data is not required to use core paid functionality.
15. Changes to this Policy
We may update this Policy when our processing, providers, Service or legal obligations change. We will publish the new version and update the date above. If a change materially affects how we use personal data or the rights of existing users, we will provide an additional notice where appropriate. A Privacy Policy describes processing; continued use is not treated as consent where the law requires a separate consent choice.
16. Contact
Leado Marketing Inc.
EU contact office: Złota 59, 00-120 Warsaw, Poland
Email: office@leadomarketing.com