LeadAdapter

Privacy Policy

This policy covers leadadapter.com and the LeadAdapter application. It is written to be read, not to be survived.

Last updated 5 September 2026 · Controller and provider: Profectify LLC, operating leadadapter.com.

Two roles, and which one applies

For your own account — your name, email address, password, workspace, subscription — Profectify LLC is the controller and this policy applies.

For the people your LinkedIn activity touches — commenters, lead-page visitors, prospects, the contents of your leads database — you are the controller and we are your processor. What we may do with that data is set by the Data Processing Agreement, not by this policy.

What we process, and why

Account data: name, email, hashed password, locale, timezone, last seen. Basis: performance of the contract.

Billing data: company name, billing address, VAT number, subscription state. Card details go directly to Stripe and never reach our servers. Basis: contract and legal obligation.

LinkedIn profile metadata: the URN, public identifier, display name, headline and avatar of the profile you connect, plus the timestamp of your consent. We never receive, request or store your LinkedIn password or session cookies. Basis: contract.

Operational logs: the audit trail of actions taken in your workspace, extension heartbeats, job results, and error reports. Basis: legitimate interest in operating and securing the service, and your interest in being able to see what was done in your name.

Lead data you collect: whatever your automations, lead pages and enrichment produce. You are the controller; see the DPA.

Where it is stored

The application, its database, its queues and its backups run at Hetzner Online GmbH, Nuremberg, Germany (EU). Personal data is not replicated outside the EU/EEA by us.

A small number of sub-processors are reachable from outside the EU. Each is listed publicly along with the safeguard that covers it.

How long we keep it

Audit and action records: 24 months by default, configurable per workspace within what the law allows.

Account data: for the life of the account, then deleted or anonymised on request or on closure.

Backups: retained for 30 days on a rolling basis, after which deleted data is gone from backups too.

Billing records: kept as long as accounting law requires, which is longer than everything above and is not something we can shorten on request.

Cookies and tracking

This website sets one cookie: the session cookie Laravel uses to remember your language choice and to protect forms against cross-site request forgery. It carries no identifier we can use to profile you.

There is no analytics script, no advertising pixel, no session recorder and no third-party embed on this site or in the application. That is why there is no cookie banner: there is nothing to consent to.

Fonts are served from our own servers, not from a third-party font CDN, so reading this page does not send your IP address anywhere else.

Your rights

You can request access, correction, deletion, restriction, portability, or object to processing based on legitimate interest. Export and deletion are also self-serve inside the application — export is JSON, and deletion cascades and anonymises the audit trail rather than leaving your name in it.

Write to [email protected]. We answer within 30 days. If you are not satisfied, you may complain to your national supervisory authority — in Denmark, Datatilsynet.

Security

TLS in transit. Integration credentials encrypted at rest. Passwords hashed with bcrypt. Visitor IP addresses stored only as a peppered hash, never in the clear. Access to production is limited to the people who operate it and is logged.

Report a vulnerability to [email protected]. We will not pursue you for a good-faith report.

Changes

Material changes are announced by email to workspace owners before they take effect. The date at the top of this page is the last edit.

Contact: [email protected]