LeadHeed Privacy Policy
Last Updated On: 8 January 2026
At LeadHeed, we are committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our platform (https://leadheed.com/) and services. By using LeadHeed, you agree to this Privacy Policy.
LeadHeed Limited (“LeadHeed”, “we”, “our”, or “us”) is a company incorporated in Hong Kong. We provide customer relationship management (CRM) and communication platform services globally via https://leadheed.com.
This Privacy Policy explains how we collect, use, process, and protect personal data when users access our platform and services.
By using LeadHeed, you agree to the terms of this Privacy Policy.
1. Data Controller
LeadHeed Limited is the data controller responsible for your personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (“PDPO”). While we take reasonable steps to protect your personal data, it is important to note that no system is completely secure, and we cannot guarantee the absolute security of your data.
Contact Details:
- Email: privacy@leadheed.com
- Phone: +14088313268
- Address: LeadHeed Limited, Hong Kong
For users located in the European Economic Area (EEA), United Kingdom, California, or other jurisdictions, LeadHeed complies with applicable data protection regulations, including GDPR and CCPA where applicable.
1.1 Data Processing Agreement (DPA)
Where LeadHeed processes personal data on behalf of customers acting as data controllers, LeadHeed acts as a data processor.
A Data Processing Agreement (DPA) governing such processing is available upon request and will be executed with all customers who use LeadHeed services to process personal data, in accordance with applicable data protection laws, including the PDPO.
The DPA sets out LeadHeed’s obligations regarding:
- Processing personal data only on documented instructions;
- Confidentiality and appropriate security measures;
- Appointment and oversight of subprocessors;
- Personal data breach notification;
- Assistance with data subject rights; and
- Deletion or return of personal data upon termination of services.
Customers may request a copy of the DPA by contacting privacy@leadheed.com
2. Information We Collect
We may collect the following categories of personal data:
2.1 Account Information
- Name
- Email address
- Phone number
- Company name
- Job title
- Login credentials
- Subscription details
2.2 Usage & Technical Data
- IP address
- Device identifiers
- Browser type
- Operating system
- Platform interactions
- Feature usage logs
2.3 Payment Information
Processed securely through third-party payment providers. LeadHeed does not store full payment card details.
2.4 Communications
- Customer support interactions
- Messages sent and received via integrated communication channels
3. Omnichannel Messaging Integrations
LeadHeed allows customers to integrate third-party communication platforms, including:
- WhatsApp Business Platform
- Facebook Messenger
- Instagram Messaging
These integrations are enabled only after the customer connects their account and provides authorization.
Important:
- LeadHeed processes messages solely on behalf of customers.
- Messaging is customer-initiated unless otherwise permitted by platform rules.
- Message logs are stored securely to provide CRM functionality.
- Customers are responsible for obtaining lawful user consent before messaging end users.
- End users may withdraw consent at any time.
- Customers may disconnect integrations at any time.
LeadHeed does not send unsolicited promotional messages.
4. Legal Basis for Processing (Hong Kong PDPO)
We use personal data for the following purposes:
- Account management: To create, manage, and authenticate your LeadHeed account and send account-related notifications
- Service delivery: To provide CRM and omnichannel communication features included in your subscription
- Security and fraud prevention: To monitor platform access, detect suspicious activity, and protect user accounts
- Platform improvement: To analyse usage patterns and improve platform performance and features
- Customer support: To respond to your inquiries and resolve issues
- Legal compliance: To meet obligations under applicable laws and regulations
- Communications: To send service updates, policy changes, and important notices
We process personal data based on the following lawful grounds under the PDPO:
- Contractual necessity: To perform obligations under your subscription or agreement
- Legitimate interests: Including security, fraud prevention, service improvement, and business operations, where such interests are not overridden by your rights
- User consent: Where you have provided consent
- Legal obligation: To comply with applicable Hong Kong laws or regulatory requirements
5. Data Sharing
LeadHeed may share personal data with the following third-party service providers who process data on our behalf:
- Amazon Web Services (AWS): Cloud infrastructure and data storage for the LeadHeed application
- Hostinger: Web hosting for leadheed.com
- Meta Platforms (Facebook, Instagram, WhatsApp): Underlying messaging infrastructure for omnichannel integrations
- Crisp: Live chat and customer support communications
- Payment processors: Secure processing of subscription payments. LeadHeed does not store full payment card details.
We may also share data with:
- Legal or regulatory authorities: Where required by law, regulation, or court order
- Business transfers: In connection with a merger, acquisition, restructuring, or sale of assets
We do not sell personal data to third parties.
6. International Data Transfers
As a global platform, data may be processed in:
- Hong Kong
- United States
- Other jurisdictions where our infrastructure providers operate
We implement appropriate safeguards including contractual protections and security controls.
7. Data Retention
Personal data is retained only as long as necessary to:
- Provide services
- Meet legal obligations
- Maintain security and audit logs
To request deletion of your data, visit our Data Deletion Request page at leadheed.com/data-deletion or email privacy@leadheed.com with the subject line: “Data Deletion Request -[Your Registered Email]”. We will process your request within 30 days of identity verification.
8. Data Subject Rights
Depending on location, users may have the right to:
- Access personal data
- Correct inaccuracies
- Request deletion
- Restrict or object to processing
- Data portability
- Withdraw consent
To exercise your rights:
- Online form: leadheed.com/data-deletion
- Email: privacy@leadheed.com
- Live Chat: Available via the LeadHeed platform
9. Security Measures
We implement:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest
- Role-based access control
- Secure AWS infrastructure
- Logging and monitoring systems
- Regular security reviews
However, no system is 100% secure.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Enhance user experience
- Analyse platform usage and performance
- Improve services and functionality
Users may control cookies via browser settings.
For more information, please refer to our Cookies Policy.
11. Children’s Privacy
LeadHeed services are not intended for children under the age of 18.
We do not knowingly collect personal data from children.
12. Changes to This Privacy Policy
LeadHeed may update this Privacy Policy from time to time. Updates will be published on https://leadheed.com/legal/privacy-policy/.
Continued use of the Platform after changes take effect constitutes acceptance of the updated Policy.
13. Contact Us
For any questions, requests, or concerns regarding this Privacy Policy, please contact:
- Email: privacy@leadheed.com
- Phone: +14088313268
- Live Chat: Available via the LeadHeed platform