1. Applicable law
Our controller processing is governed primarily by the Data Protection (Bailiwick of Guernsey) Law, 2017. The Guernsey Office of the Data Protection Authority, or ODPA, is the independent supervisory authority. UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations can also apply where their territorial scope reaches a customer, contact or processing activity.
2. Data we collect
- Account data: email address, business name, password hash, role, terms acceptance, account dates and login dates.
- Security and service records: session tokens, IP addresses used in security and audit events, rate limit events, password reset token hashes, timestamps and actions taken in the application.
- Billing data: Paddle customer, checkout, payment and subscription references, product, amount, currency and entitlement status. We do not receive or store full card numbers.
- Support and contact data: messages you send, your contact details, the account concerned and the information needed to answer or resolve the request. If you contact us through WhatsApp, X or LinkedIn, that platform also processes the communication under its own terms.
- Sender setup: sender type, domain, DNS records, sender name, From address, Reply-To address, provider identifiers, readiness results, delivery feedback and encrypted SMTP or Twilio credentials where you choose to supply them.
- Uploaded lead data: names, email addresses, phone numbers, enquiry or contact dates, source, status, value, notes, suppression status and any other permitted fields contained in your file.
- Campaign data: campaign names, message subjects and bodies, schedules, approvals, recipients, send status, provider message references, replies received through configured webhooks, outcomes, bounces, complaints and opt-outs.
- First-party product events and support feedback: limited in-product milestones (such as saving the business profile) and feedback you choose to submit. These records stay with your desk, are included in its export and deletion lifecycle, and are not advertising analytics.
- Deletion and cleanup data: a pseudonymous tenant reference, provider reference, safe error class and completion status where a provider or local cleanup operation needs to be finished after active account deletion.
Do not upload payment card data, passwords, identity documents, children's data, criminal offence data or special category data in contact rows or column headings. The present service is not designed for those categories.
3. Where data comes from
We receive data directly from you when you visit, create an account, upload a file, configure a sender, approve a campaign, pay, request support or delete the account. We receive delivery, reply, complaint and billing events from providers acting on the relevant account. A customer's lead data comes from that customer and from responses made by its contacts through configured channels.
4. Why we use account data and our lawful bases
- Provide the account, free preview, audit, sending controls, export, support and billing: necessary to take steps at your request and perform the service contract.
- Authenticate users, prevent abuse, keep audit records, enforce sending safeguards and investigate incidents: our legitimate interests in operating a secure, accountable service and protecting customers, contacts and providers.
- Process payments, manage subscriptions and keep required financial records: contract and applicable legal obligations.
- Send password resets, account notices, billing notices and important service messages: contract, legal obligation and legitimate interests. These are not advertising emails.
- Respond to rights requests, complaints, legal process and regulator enquiries: legal obligation and legitimate interests in establishing, exercising or defending legal rights.
- Improve reliability and correct defects using de-identified operational information: legitimate interests, balanced against user rights. We do not use customer contact rows to train models or advertise to those contacts.
Where we rely on legitimate interests, you may object. We will stop unless we have compelling grounds to continue or the processing is needed for legal claims. Where consent is the proper basis for a future optional activity, it may be withdrawn without affecting earlier lawful processing.
5. How customer lead data is used
For customer lead data, we follow the customer's documented instructions to parse, clean, de-duplicate, segment, suppress, display, export and delete contacts; prepare and schedule campaigns; transmit approved messages; receive configured replies and feedback; enforce opt-outs; and keep operational records. Signed email unsubscribe actions and configured STOP texts update the suppression list. The customer must establish the lawful basis for the list and each message.
The free preview stores up to 100 rows per calendar month in that customer's isolated workspace. Contact details stay masked and preview rows cannot be exported or sent. A pending preview that is not confirmed is automatically discarded after 48 hours. A confirmed list remains until the customer deletes it or closes the account.
6. Providers and other recipients
We do not sell or rent personal data. We disclose only what is necessary to operate the service, follow customer instructions, protect rights or comply with law:
- Fly.io: hosts the application and customer databases on the London deployment and provides infrastructure snapshots.
- Tigris or compatible S3 object storage: stores compressed offsite database backups in access-controlled storage.
- Paddle: processes account and payment details in sandbox or, once legally enabled, live billing. Paddle does not receive uploaded lead databases.
- Resend or a configured system SMTP provider: delivers password resets, account notices and other service emails, receiving the account email address and message content required for delivery. Resend is the current production route.
- Anthropic: is called only when unusual column headings cannot be mapped deterministically. It receives the header labels, never the contact rows. Customers must keep personal data out of headings.
- Customer-selected SMTP, email or Twilio providers: receive the message and recipient information needed for the customer-instructed delivery. Those accounts and provider relationships are chosen by the customer.
- Professional advisers, regulators, courts, law enforcement or a successor operator: only where reasonably necessary and lawful, with appropriate confidentiality and notice where permitted.
The detailed processor list and notice procedure for customer lead data are in the DPA.
7. International transfers
The application is deployed in London, while some providers or support operations may process data in other countries. Where personal data is transferred to a country not recognised as providing adequate protection under the law that applies, we require an appropriate transfer mechanism, such as recognised standard contractual clauses, an applicable international data transfer agreement or another lawful safeguard. Provider location and safeguards may change, subject to the DPA subprocessor notice process where customer lead data is affected.
8. Retention and deletion
- Pending free-preview imports are automatically discarded after 48 hours if not confirmed.
- Confirmed leads, campaigns, messages, replies, suppressions, sender settings and account data remain while the account is open, unless deleted sooner through an available control.
- The essential login session lasts up to 30 days and ends sooner on logout, password reset, account deletion or expiry cleanup.
- Rate limit events used to stop repeated login, signup or reset abuse are kept for approximately 15 minutes. Password reset links expire after 30 minutes.
- Routine operational audit records are pruned on a rolling 90 day basis while the account is active.
- Self service account deletion removes the active customer database, account, sessions, sender connections and identifying audit history. It also requests cancellation or deletion from configured providers.
- Fly volume snapshots and compressed offsite backup objects can retain deleted data until their normal rolling cycle completes, for no longer than 30 days under the current configuration. Backups are isolated from ordinary product use. If a backup must be restored for disaster recovery, the deletion instruction must be re-applied.
- If external or local deletion cannot complete immediately, a restricted pseudonymous cleanup record remains until the task is resolved. A minimal pseudonymous deletion completion record may be retained where reasonably necessary to demonstrate and secure the deletion process. It does not retain the deleted lead list, login email, user ID or IP address.
- Paddle and other independent providers may retain transaction or security records for their own legal duties. Their notices govern that independent retention.
You can export account data before deletion. Deletion cannot be reversed once the active workspace is removed.
9. Security
Safeguards include a separate database for each customer's lead workspace, access-controlled application sessions, TLS in transit, scrypt password hashing, signed Secure HttpOnly SameSite Lax session cookies in production, AES-256-GCM encryption for stored sender credentials, restricted provider credentials, sending interlocks, rate limits, audit records, integrity checks and rolling backups.
Offsite database backups are compressed before upload and held in access-controlled object storage. The current application does not add its own client-side encryption layer to those backup objects, so we do not claim that it does. No system can guarantee absolute security.
10. Essential cookie
The application uses one essential cookie named lrd_sess to keep a signed-in user authenticated. It is HttpOnly, SameSite Lax, Secure in production and expires after no more than 30 days. The reviewed marketing site and application do not set advertising or non-essential analytics cookies. Because the cookie is strictly necessary for a requested login service, it cannot be disabled inside the app; you can remove it by logging out or through your browser settings.
11. Automated processing
The service automatically de-duplicates lists, identifies suppression signals and labels records as warm, lukewarm, cold or needs-more-context using available recency, engagement, outcome, value and customer-history fields. Records without reliable context stay in a needs-more-context group rather than being automatically prioritised. This helps the customer review its list. It does not make a decision about a person's legal rights, credit, employment, access to a service or another similarly significant matter. The customer decides whether any contact should be messaged.
12. Your rights
Depending on the processing and applicable law, you may have rights to be informed, access personal data, correct inaccurate data, request erasure, restrict processing, receive portable data, object, and challenge certain solely automated decisions. You may also withdraw consent where consent is the basis. Rights are not absolute, and we will explain any lawful limitation.
For your Lead Recovery Desk account data, use the account export and deletion controls or email info@leadrecoverydesk.com. We may need to verify your identity. We aim to respond within the period required by the law that applies.
If you are a lead in a customer's uploaded list, contact the business you originally dealt with. That business controls the data and should answer your request. We will assist it as processor where required.
13. Complaints
Please contact us first so we can investigate. You may complain to the Guernsey Office of the Data Protection Authority, the supervisory authority for the Data Protection (Bailiwick of Guernsey) Law, 2017. If UK data protection law applies to the relevant processing, you may also contact the UK Information Commissioner's Office. You may have a right to complain to another local authority where you live or work.
14. Children and restricted data
Lead Recovery Desk is a business service for adults and is not directed to children. We do not knowingly collect children's data for our own purposes. Customers must not upload it or the restricted categories listed above. If you believe restricted data has been uploaded, contact us so it can be isolated and removed.
15. Changes and contact
We update this notice when the service, providers, legal identity or law changes. Material changes affecting account users will be notified through the account email where reasonably possible. The current version and date appear below.
Privacy questions and requests: info@leadrecoverydesk.com.