Enterprise Privacy Policy

Privacy Policy & Data Protection

Your trust is our highest priority. This policy outlines how LeadAI safeguards your business information, conversations, visitor interactions, and qualified leads.

Document Status

Official Platform Policy

Last updated: September 14, 2026

Zero Training on Customer Data

We never use your organization’s conversations, lead records, or uploaded knowledge documents to train public or foundational AI models.

AES-256 & TLS 1.3 Encryption

All database records are encrypted at rest with AES-256 and transmitted securely with TLS 1.3 over modern cryptographic ciphers.

Strict Multi-Tenant Isolation

Tenant data is logically separated using strict database tenant guards, preventing cross-tenant leakage or unauthorized access.

GDPR & CCPA Compliant

Full compliance with global privacy standards, granting leads and users complete rights to data export, rectification, and erasure.

1. Introduction & Scope

Welcome to LeadAI ("Platform", "we", "us", or "our"). LeadAI provides an enterprise-grade AI-powered lead generation, visitor qualification, customer engagement, and conversation automation service.

This Privacy Policy applies to all services, software applications, chat widgets, administrative dashboards, and APIs offered by LeadAI. By accessing or using our platform, you acknowledge that you have read and agree to the practices described herein.

2. Information We Collect

We collect information strictly necessary to provide intelligent lead qualification, appointment booking, and customer support. The categories of information collected include:

A. Workspace Account Data

Administrator and user credentials including full name, business email address, hashed passwords, workspace organization name, and billing details.

B. Visitor & Lead Information

Information provided by website visitors during chat conversations, such as name, email address, phone number, company name, requirements, and scheduled appointment slots.

C. Conversational Transcripts

Full text messages exchanged between website visitors and automated AI agents or human sales representatives, stored for review, lead scoring, and CRM integration.

D. Technical & Telemetry Data

IP address, approximate geographic location, browser user agent, referring URL, timestamp, and device type to safeguard against spam and abuse.

3. AI & Large Language Model Transparency

Strict Zero Data Retention Guarantee with AI Providers

We process AI conversations via enterprise endpoints (e.g. OpenAI Enterprise / Anthropic API). Under our enterprise business terms:

  • No Training: AI providers do not use your inputs, prompts, or chat transcripts to train their models.
  • Zero Retention: Prompts sent to LLMs are ephemeral and are not persistently stored by LLM providers.
  • Knowledge Isolation: Your proprietary knowledge base documents are indexed exclusively for your tenant.

4. How We Use Your Data

LeadAI utilizes collected data solely for the following commercial purposes:

  • Automating live responses to your prospective customers through tailored conversational agents.
  • Calculating engagement and purchase-intent Lead Scores (Cold, Warm, Hot) to prioritize sales outreach.
  • Dispatching immediate notifications (Email, SMS, WhatsApp, Webhooks) when qualified leads submit details.
  • Syncing lead records to your connected CRM, Google Sheets, or third-party webhooks.
  • Preventing malicious traffic, bot spam, and denial-of-service attempts.

5. Multi-Tenancy & Data Segregation

LeadAI is built upon a secure, multi-tenant architecture. Every tenant workspace operates in an isolated logical boundary:

Database Tenant Guards: Every database read, write, query, and aggregation automatically enforces a mandatory tenantId scope. Cross-workspace data leakage is strictly prevented at the core driver layer.

Role-Based Access: Within a tenant, users are partitioned into Admin (full management) and Salesperson (individual lead management), guaranteeing internal least-privilege access.

6. Security & Encryption Standards

We employ defense-in-depth security measures to protect stored information:

Encryption at Rest

All primary MongoDB databases, logs, and backups are encrypted at rest using industry-standard AES-256 encryption.

Encryption in Transit

All communications between web clients, customer websites, embed widgets, and our cloud APIs require HTTPS with TLS 1.3.

Credential Security

Passwords are salted and cryptographically hashed with Bcrypt (cost factor 12). Plaintext passwords are never stored or logged.

API Token Hashing

Third-party integration keys and Webhook tokens are stored using irreversible cryptographic digests.

7. Data Retention & Erasure

We retain your workspace leads and conversation records for as long as your account remains active. If a workspace subscription is terminated:

  • You may export all leads and conversation records in CSV/JSON format at any time directly from the dashboard.
  • Upon verified workspace deletion request, all tenant records, agents, knowledge base vectors, and leads are purged from active databases within 30 days.

8. Your Rights (GDPR & CCPA)

Depending on your jurisdiction, data subjects possess fundamental rights regarding their personal data:

Right to Access: Request a copy of all personal records held about you.
Right to Rectification: Request correction of inaccurate or incomplete contact data.
Right to Erasure: Request permanent deletion of your information ("Right to be Forgotten").
Right to Restrict Processing: Limit how we process your personal data in certain scenarios.

9. Cookies & Chatbot Widget Data

Our lightweight embeddable chat widget utilizes localized browser storage (LocalSession storage) strictly to maintain continuity of the visitor’s conversation while navigating between pages on your website. We do not use intrusive cross-site third-party tracking cookies or sell visitor browsing history to advertisement networks.

10. Contact Our Privacy & Legal Team

If you have questions regarding this Privacy Policy, wish to exercise your data subject rights, or require a Data Processing Addendum (DPA) for your organization, please contact our designated Data Protection Officer:

LeadAI Legal & Compliance

Data Protection Office