Security & GDPR
Last updated: June 2026
This page covers how we protect your data technically and operationally, and your rights under the General Data Protection Regulation (GDPR). For a full description of what data we collect and why, see our Privacy Policy.
How we protect your data
LeaderLeads is a product of LeaderHQ, operated by Know Freedom Technologies. We apply the following measures to keep your data secure:
- Encryption in transit. All data between your device and our servers is encrypted using TLS 1.2 or higher. We do not serve the application over unencrypted HTTP.
- Encryption at rest. Stored data — including contact records, card content, and lead information — is encrypted at rest in our database infrastructure.
- Access controls. Internal access to production data is restricted to authorised personnel on a need-to-know basis. We do not grant broad database access to staff without a legitimate operational requirement.
- Authentication. User accounts are protected by password-plus-OTP two-factor authentication. Passwords are hashed using industry-standard algorithms; we never store plaintext passwords.
- Vendor security. We use reputable, SOC 2-compliant infrastructure providers. Third-party services we integrate with are assessed for security posture before use.
Lawful basis for processing (GDPR Article 6)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction covered by GDPR-equivalent legislation, we process your personal data on the following lawful bases:
- Contract performance. Processing necessary to provide the LeaderLeads service you have signed up for — creating your card, storing your lead inbox, sending Memory Moment emails.
- Legitimate interests. Processing necessary for fraud prevention, security monitoring, and product improvement — where those interests are not overridden by your rights.
- Consent. Where we send optional marketing communications, we do so only with your consent, which you may withdraw at any time.
- Legal obligation. Processing required to comply with applicable law.
Your rights as a data subject
Under GDPR (and equivalent legislation), you have the following rights regarding your personal data. To exercise any of them, email us at privacy@leaderhq.io with your request. We will respond within 30 days.
- Right of access. You may request a copy of the personal data we hold about you.
- Right to rectification. You may ask us to correct inaccurate or incomplete data. Most card and profile data can be corrected directly in your dashboard.
- Right to erasure ("right to be forgotten"). You may request deletion of your account and associated personal data. We will action this within 30 days, subject to any legal retention obligations.
- Right to data portability. You may request your data in a structured, machine-readable format (JSON or CSV).
- Right to restrict processing. You may ask us to pause processing of your data while a dispute is resolved.
- Right to object. You may object to processing based on legitimate interests, including any direct marketing.
- Rights related to automated decision-making. We do not make decisions about you solely by automated means that produce legal or similarly significant effects.
Data retention
We retain your personal data for as long as your account is active and for a reasonable period afterward to allow for account recovery, dispute resolution, and legal compliance. Specifically:
- Account and card data: retained for the life of your account plus 90 days after deletion request.
- Lead and contact records: retained with your account; deleted on account erasure request.
- Memory Moment images: retained until you delete them or request account erasure.
- Transactional emails and logs: retained for up to 12 months for fraud and security purposes.
- Billing records: retained for 7 years as required by applicable financial regulations.
Sub-processors and third-party services
We use the following categories of third-party processors to operate LeaderLeads. Each is bound by a data processing agreement consistent with GDPR requirements:
- Cloud infrastructure: servers, databases, and object storage
- Transactional email: delivery of OTP codes, Memory Moment emails, and account notifications (Postmark)
- Payment processing: Stripe — we do not store card numbers; all payment data is handled by Stripe directly
- Analytics: aggregated, anonymised product usage analytics only — no personally identifiable data shared
A full list of sub-processors is available on request at privacy@leaderhq.io.
Data Processing Agreement (DPA)
If you use LeaderLeads in a business context and require a Data Processing Agreement for your own GDPR compliance, email privacy@leaderhq.io with "DPA Request" in the subject line. We will provide a signed DPA within 5 business days.
Supervisory authority
If you are in the EEA or UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection supervisory authority. In the United States, please contact us directly at privacy@leaderhq.io and we will work to resolve your concern promptly.
Contact
LeaderHQ / Know Freedom Technologies30 N. Gould Street, Suite N
Sheridan, WY 82801
privacy@leaderhq.io