LeadAdapter

Data Processing Agreement

This agreement applies whenever you use LeadAdapter to process personal data about other people — which, given what the product does, is from the first automation you switch on. It is presented at signup for business accounts and forms part of the Terms of Service.

Last updated 5 September 2026 · Controller and provider: Profectify LLC, operating leadadapter.com.

1. Parties and roles

You, the customer, are the controller. Profectify LLC is the processor. Where you are yourself a processor for your own client — an agency, typically — you act as their processor and we act as a sub-processor, and this agreement flows down accordingly.

Each party complies with the GDPR and applicable national data-protection law in its own role.

2. Instructions

We process personal data only on your documented instructions. Your use of the product — the automations you configure, the lead pages you publish, the tools your agent calls — is the instruction. We do not process your lead data for our own purposes, and we do not use it to train models.

If we believe an instruction breaches data-protection law, we will tell you and may suspend that processing until it is resolved.

3. Confidentiality and staff

Everyone with access to personal data is bound by confidentiality and has access only to what their role requires. Production access is limited, authenticated and logged.

4. Security

We implement the technical and organisational measures described in Annex II, and we may update them provided the level of protection does not decrease.

5. Sub-processors

You give general authorisation for the sub-processors listed in Annex III. We give at least 30 days’ notice before a new sub-processor begins processing, so you have time to object on reasonable data-protection grounds; if we cannot resolve an objection, you may terminate the affected part of the service.

Each sub-processor is bound by written terms no less protective than this agreement, and we remain fully liable to you for their performance.

6. Data subject rights

The product gives you self-serve export, correction and deletion, which is how most requests are answered without us being involved at all. Where you need more, we assist you, taking into account the nature of the processing.

If a data subject contacts us directly about data we process for you, we refer them to you rather than answering on your behalf.

7. Personal data breach

We notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with what we know at the time and updates as we learn more. We do not wait for a complete picture before telling you.

8. Deletion and return

On termination you can export everything. We delete or anonymise personal data within 30 days, except where the law requires retention. Backups expire on a 30-day rolling cycle and are not selectively edited; data in a backup is gone when the backup is.

9. Audits

We provide the information needed to demonstrate compliance with Article 28 and allow audits, including inspections, by you or an auditor you mandate, on reasonable notice, no more than once a year unless an incident or a supervisory authority requires otherwise.

10. International transfers

Processing takes place in the EU/EEA. Where a sub-processor listed in Annex III involves a transfer outside the EEA, it is covered by the Standard Contractual Clauses together with supplementary measures where required.

Annex I — Description of the processing

Subject matter: provision of the LeadAdapter service. Duration: the term of the subscription plus the deletion window in section 8.

Nature and purpose: capturing engagement from LinkedIn posts, matching it against keywords, sending messages and connection requests through your own browser, hosting lead pages and tracked links, storing and enriching lead records, synchronising them to integrations you connect, and keeping an audit trail of all of it.

Categories of data subject: people who comment on or engage with your posts; visitors who submit a lead page; prospects you search for, enrich or contact; your own team members.

Categories of personal data: name; LinkedIn profile identifier and public profile URL; headline, employer and job title; location; profile photo URL; email address where you collect or enrich one; the content of comments and of messages sent and received; engagement and page-view events; hashed IP address and user agent of lead-page visitors; consent timestamps.

Special categories: none are requested by the product. Do not put them in a DM template or a lead-page form.

Annex II — Technical and organisational measures

Hosting at Hetzner Online GmbH, Nuremberg, Germany (EU), in the EU. Encryption in transit with TLS. Integration credentials and API keys encrypted at rest; API keys stored only as hashes. Passwords hashed with bcrypt. Visitor IP addresses stored only as a peppered hash.

Access control by workspace and role, with per-profile consent required before any action executes. Immutable audit log of every action, with actor, target, result and reason.

Rate limiting, cap enforcement and approval gates that constrain what the software can do even when instructed to do more. Emergency stop that cancels queued work for a profile.

Nightly database backups with 30-day retention and a documented restore procedure. Error monitoring configured to scrub credentials and message bodies.

Annex III — Sub-processors

The current list is below and is published at leadadapter.com/sub-processors, which is the authoritative version.

Sub-processor Purpose Location Transfer safeguard
Hetzner Online GmbH Hosting. The application, the database, the queues and the backups all run on Hetzner infrastructure in Germany. This is where your data physically lives. Germany (EU) Processing within the EU/EEA
Cloudflare, Inc. DNS, TLS termination, CDN and bot protection in front of the application. Sees request metadata and IP addresses in transit; stores no application data. EU edge, US parent Standard Contractual Clauses
Stripe Payments Europe, Ltd. Subscription billing, payment processing and VAT calculation. Receives the billing contact and payment details. Card numbers never reach our servers. Ireland (EU), US parent Standard Contractual Clauses
SMTP2GO Ltd. Transactional email delivery — sign-up confirmation, approval alerts, digests, offline warnings. Receives the recipient address and the message body. EU sending region Standard Contractual Clauses
Depaza The LLM gateway used for AI assistance such as suggesting automation keywords and drafting message copy. Receives the text you ask us to work on. EU-hosted models. EU Processing within the EU/EEA
Functional Software, Inc. (Sentry) Application error monitoring. Receives stack traces and request context when something breaks. Configured to scrub credentials and message bodies. EU region (de.sentry.io) Standard Contractual Clauses
Brevo (Sendinblue SAS)
Only if you enable it
Email marketing platform, used only when you connect it yourself as an integration. Receives the lead records you choose to sync to it. France (EU) Processing within the EU/EEA

Contact: [email protected]