Legal
Last updated: 18 September 2026
This policy is for the LeadsFlow application: accounts, integrations, and lead data. The public website and contact form have a separate policy at leadsflow.dev/privacy.
LeadsFlow is operated by Ideal Web Construct SRL, Romania, registration J2024000515272, VAT RO48163800, Strada Ion Creangă 67, Camera nr. 1, Târgu Neamț, Neamț County, 615200 ("LeadsFlow", "we", "us").
Privacy contact: [email protected].
Lead data. We are a processor. The customer whose source produced the lead is the controller. They decide what is collected and where it goes. We process it to provide the service they asked for.
Account data. We are the controller for the customer's business and user accounts (names, work emails, login data, billing, support mail, usage logs).
Operations data. We are the controller for security, abuse, availability, and aggregate counts with no field values. Legal basis: legitimate interests (Article 6(1)(f) GDPR). This never includes lead field values. We do not sell lead data, mix it across customers, use it for ads, or use it to train models.
The controller is the business that ran the ad or form, not us. Email [email protected] with the address or phone you submitted, and the business if you know it. We will pass the request to that customer and tell you we did. We may ask you to confirm who you are.
Whatever the customer's source sends. Usually name, email, phone, location, form answers, plus source, form or campaign, and time received. If the source includes an IP address as a field, that is part of the payload. We do not take the submitter's IP from the HTTP connection.
Sources: HTTP posts from the customer's forms or partners; file import; Facebook and Instagram lead forms when the customer connects their Page.
We receive the lead, apply the customer's rules (duplicates, email checks, caps, routing, User-Agent filters), record the result, show it in the app, and send it to the destinations they configured.
Filtering is rule-based. No profiling, no scores on people. Email checks go to a validator the customer enabled on their own account. If they turn on our bot filter, we send it the email and, if they mapped them, IP and User-Agent from the payload. That service is ours.
The platform is not built for special-category data (Article 9 GDPR). Customers must not send it. We do not scan fields for it. If we learn they are sending it, we may suspend that intake.
When a customer connects a Facebook Page, we pull lead-form answers through the Meta Marketing API with the permissions they grant. That covers Facebook and Instagram forms on that Page.
We use that data to put those leads in their LeadsFlow account and send them to the destinations they set. Nothing else. We do not send it to ad networks, data brokers, or anyone who buys data. Customers may not use it for eligibility decisions on credit, insurance, employment, housing, or education.
Disconnecting the Page stops new retrieval. Leads already in the account stay until deleted as below. If Meta or the person asks us to delete data we got from Meta, email [email protected]. We delete it or forward the request to the customer, and confirm when it is done.
Amazon Web Services. Lead data sits in a transactional database and an analytical store used for search and reports. Logs, queues, storage, and transactional email are AWS services. There is no region picker at signup.
The configuration assistant runs on Amazon Bedrock in us-east-1 (United States). That is a transfer outside the EEA, covered by the AWS GDPR Data Processing Addendum (Standard Contractual Clauses, Module Three).
Sending a customer's own leads back to a customer outside the EEA is also a transfer. We handle that in the customer contract. Destinations the customer plugs in are their choice and their contract.
| Provider | What it does | Where |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, databases, storage, queues, logs, email, Bedrock for the assistant | AWS, including us-east-1 for Bedrock |
| PagerDuty, Inc. | On-call alerts. Gets service, alert type, time, severity. No lead fields. | United States |
We tell customers before we add or replace a sub-processor that handles lead data. Website vendors are on the website policy.
Helps customers build intakes and map fields. Runs on Bedrock in us-east-1. Prompts are not used to train a model. Capture sessions keep one sample request for one hour, then delete it. If someone points live traffic at a capture session, real field values can go to the model. Use dummy data. We do not redact values today.
CRMs, email tools (Ongage, Klaviyo, SendGrid, Mailgun, SparkPost), webhooks, and validators such as ZeroBounce. Those are the customer's accounts. We send what they tell us to send. After that, their contract with that provider applies. Webhook URLs may be http or https; we do not change them.
Name, work email, company, password hashes, session tokens, billing, support mail, usage logs. Contract for the account and billing; legitimate interests for security and service notices; consent for marketing mail; legal obligation for accounting.
Kept for the life of the account and 12 months after, unless law requires longer. Romanian accounting records: 10 years from the end of the financial year for registers and annual statements, 5 years for supporting documents including invoices.
Payloads and intake records stay for the life of the account. The intake record includes the duplicate-detection field (usually email) in clear text. Delivery logs have destination, status, and technical metadata, no payload. Capture sessions: one hour.
To delete a lead, email [email protected]. We remove it from every system we hold it in and confirm. Target: 5 working days. When an account closes we delete customer data from live systems the same way, except records the law requires us to keep.
Encrypted backups: up to 30 days, then overwritten. If we restore a backup, we re-apply deletions made after it was taken.
Test traffic must be fake. The platform does not treat tests differently.
If your data was a lead, ask the business that collected it. If you cannot tell who that is, use the form section above. We help the customer respond. We cannot decide the request ourselves or search every customer for you.
Account holders: access, rectification, erasure, restriction, portability, objection, and withdrawing consent, via [email protected]. We answer within one month, or tell you within that month if we need up to two more. We may ask you to prove who you are.
We do not make automated decisions with legal or similarly significant effects. Customer rules (duplicates, email checks, caps, routing, User-Agent filters) match fields and request attributes. What the customer does after delivery is theirs.
Complaints: ANSPDCP (Romania), or the authority where you live, work, or the issue happened.
For US state laws including California, we act as a service provider to the customer. We do not sell personal information or share it for cross-context ads. Direct those requests to the business that collected the data.
Business use only. We do not knowingly process anyone under 16. Customers must not send that data. The age of digital consent in the EEA is 13 to 16 depending on the country; the customer is responsible for the age that applies. If you think we hold a child's data, email [email protected].
Article 37 does not require us to appoint one. We route leads on customer instructions; we do not track or profile people. Special-category data and national ID numbers are banned. Privacy mail goes to [email protected].
We may update this policy. If a change materially affects how we process lead data, we email customers at least 30 days ahead. Other changes take effect when this page is updated.
Ideal Web Construct SRL (LeadsFlow)
Strada Ion Creangă 67, Camera nr. 1, Târgu Neamț, Neamț County, 615200, Romania