Privacy Policy
Privacy Policy
Last updated: 11 September 2026
This Privacy Policy explains how Yertay Kemelbekov, an individual trading as "Leadalise," based in Almaty, Republic of Kazakhstan ("Leadalise," "we," "us"), collects, uses, and protects personal data in connection with the Leadalise platform (the "Service"). It applies to (1) Customers who register for and use the Service, and (2) individuals whose business contact data is processed through the Service on behalf of our Customers.
We aim to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and applicable US state privacy laws, in addition to relevant data protection law in the UAE, for the markets we serve.
1. Two Roles We Play
As a data controller — for account, billing, and usage data of our Customers (the businesses who subscribe to Leadalise).
As a data processor — for business contact data (names, job titles, business email addresses, company affiliations, and inferred buying signals) that our Customers process through the Service about third parties (e.g., prospects at target companies). In this capacity, we act on our Customers' instructions, as described in our Data Processing Agreement, which is published in full and applies automatically to every subscription.
As a controller for the assembly of our business data set — before any Customer asks for a given company, we obtain and maintain business data from licensed providers and public sources, and we decide what to collect and how to structure it. We describe that role explicitly rather than presenting the whole pipeline as processing on instruction, because the two activities genuinely differ and the rights that attach to them differ with it (see Section 8).
2. What We Collect
2.1 From Customers (account holders)
- Account and profile data: name, business email, company, role.
- Billing data: handled by Paddle.com Market Limited, our Merchant of Record. We receive limited billing metadata (e.g., plan tier, subscription status) but Paddle — not Leadalise — processes and stores full payment card and tax details. See Paddle's Privacy Policy.
- Usage data: features used, searches performed, ICP criteria configured, log and device data, cookies (see Section 7).
- Content you provide: CRM data you import, competitor lists, feedback you submit.
2.2 About third-party business contacts (processed on behalf of Customers)
- Business-context data sourced from licensed third-party data providers and publicly available sources: company firmographics, publicly listed job changes, company news, technology usage signals, and similar business signals.
- Business contact details (name, business email, job title, employer) where lawfully available through licensed sources, used to support Customers' B2B sales and prospecting.
- We do not knowingly collect sensitive personal data (e.g., health, religion, sexual orientation) about individuals, and our signal set is limited to business/professional context.
3. Sources of Data
We obtain business and contact data from:
- Licensed third-party data providers under contract (e.g., business data enrichment APIs);
- Publicly available sources such as company job boards, press releases, and public regulatory filings;
- Data our Customers directly upload or connect (e.g., their CRM).
We do not source personal data through scraping of platforms whose terms of service prohibit automated collection, and we do not collect data from professional social networks in a manner inconsistent with their terms or applicable law.
4. How We Use Data
- To provide the Service: account scoring, signal monitoring, and report generation for our Customers.
- To operate and secure the Service, including fraud prevention and abuse monitoring.
- To communicate with Customers about their account, billing (via Paddle), and material changes to the Service.
- To improve the Service, including calibrating scoring models, using aggregated or de-identified usage data where feasible.
- To comply with legal obligations.
We do not sell personal data and we do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act, and we do not use business contact data processed on behalf of Customers for our own independent marketing purposes. We have not sold or shared personal data in the preceding 12 months.
We do not use personal data to train our own machine-learning models, and the AI providers we use to generate report content are contractually barred from training on the content we send them.
5. Legal Bases (GDPR/UK GDPR)
- Contract — to provide the Service to Customers.
- Legitimate interests — for Customers' and our legitimate interest in B2B sales and marketing activity based on business-context data, balanced against individual rights (data subjects can object — see Section 8).
- Legal obligation — for tax, accounting, and regulatory compliance.
- Consent — where required by local law for specific processing (e.g., certain direct-marketing communications), obtained by the Customer as the sender of any communications.
Customers are responsible for ensuring they have an appropriate legal basis for contacting individuals under the laws applicable to those individuals.
6. Data Sharing
We share personal data with:
- Paddle.com Market Limited — as Merchant of Record for billing, tax, and payment processing.
- Sub-processors providing infrastructure under contractual data protection terms consistent with GDPR Article 28. These include our managed database and application platform (Supabase, hosted on Amazon Web Services), our front-end hosting provider (Vercel), the cloud provider hosting our signal-processing workflows (Google Cloud) and the network provider in front of them (Cloudflare), a transactional email provider (Resend), AI model providers used to generate reports (accessed through OpenRouter), and a product-analytics provider (PostHog). Where you connect your own CRM, data is also exchanged with that provider on your instruction. The current list with processing locations is published in Annex I of our DPA, and changes to it are notified 30 days in advance.
- Licensed data providers — as sources of business data, not as recipients of Customer data (data flows inbound from these providers).
- Authorities, where required by law.
We do not share personal data with data brokers or use it for purposes unrelated to operating the Service.
7. Cookies and Similar Technologies
We store on your device only what is strictly necessary to operate the Service — authentication and session management. We do not use advertising cookies, and we do not track your activity across other websites.
We do use a product-analytics provider (PostHog) to understand how our pages and the Service are used, but we run it without storing anything on your device: it keeps no cookie and no local-storage entry, so it cannot recognize you on a later visit. Because nothing non-essential is stored on your device, no consent banner is required. The only exception is a marker you set yourself to keep your own visits out of our analytics; it stores nothing but that choice and you can remove it at any time. You can still block or delete cookies via your browser settings, though this may affect core functionality.
8. Data Subject Rights
Individuals whose business contact data is processed through the Service (e.g., a prospect contacted by one of our Customers) have rights under GDPR/UK GDPR and similar laws, including the right to access, correct, delete, restrict, or object to processing of their personal data, and the right to lodge a complaint with a supervisory authority.
To exercise these rights, contact support@leadalise.com.
We act on removal requests directly, without sending you elsewhere first. Where we hold your business contact details in our own data set, we will remove them on request — no proof of residency, no stated reason required, and no account with us needed. Where the request concerns how a specific Customer of ours is using your data, we will additionally refer you to that Customer as the controller of that use, or assist them in responding, consistent with our DPA. We aim to respond within 30 days.
You may also object at any time to our processing of your business contact data on legitimate-interest grounds, and we will stop unless we have compelling legitimate grounds that override your interests.
How you may first hear about us. Because we obtain business contact data from licensed providers and public sources rather than from you, you may not have had a prior relationship with us. This Policy, together with the removal and objection routes above, is how we provide the information required by GDPR Article 14 to individuals whose data we hold; where we would otherwise need to notify you individually and doing so would involve disproportionate effort, we rely on Article 14(5)(b) and make this Policy publicly available instead.
US residents in states with comprehensive privacy laws (e.g., California, Colorado, Virginia, Connecticut, Utah, Texas, Oregon and Montana) have similar rights under applicable state law, including the right to know, delete, correct, and opt out of sale, sharing and certain profiling; contact us to exercise them, and we will not discriminate against you for doing so. As stated in Section 4, we do not sell or share personal information as those terms are defined by the CCPA.
9. Data Retention
- Customer account data is retained for the duration of the subscription and a limited period afterward for legal, accounting, and dispute-resolution purposes.
- Business signal and contact data is retained for as long as the account it relates to is monitored by a Customer. Signals age out of scoring automatically, and older signals are periodically purged.
- We delete or anonymize personal data when it is no longer necessary for the purposes described in this Policy, unless a longer retention period is required by law.
10. International Transfers
Leadalise is operated from the Republic of Kazakhstan, and personal data may be processed on cloud infrastructure located outside the European Economic Area (EEA) and the United Kingdom.
Where personal data of individuals in the EEA or UK is transferred outside those areas, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with the data-protection terms in our infrastructure providers' data processing agreements. The specific modules, options and populated annexes are set out in Section 12 of our DPA rather than described only on request.
11. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and restricted access to production data. The Service runs on infrastructure operated by several providers, including a managed database and application platform hosted on Amazon Web Services, a front-end hosting provider, and a virtual machine hosted with Google Cloud for our signal-processing workflows. All maintain industry-recognized security certifications. No system is completely secure, and we cannot guarantee absolute security.
12. Children's Data
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal data from individuals under 16.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified via email or in-app notice. The "Last updated" date reflects the most recent revision.
14. Contact
Data protection inquiries: support@leadalise.com Operator: Yertay Kemelbekov, an individual trading as Leadalise Location: Almaty, Republic of Kazakhstan
The operator is established outside the EEA and the UK. Individuals in the EEA or UK with data protection concerns may contact us at the address above in English, and we will respond in accordance with applicable law. We have not appointed a representative in the Union or the United Kingdom under Article 27 GDPR; if we do, this section will name them and give their contact details.
You may also lodge a complaint with the supervisory authority in your country of residence, place of work, or the place where you believe an infringement occurred.