Leadboard CRM
  • Home
  • Features
  • Pricing
  • How It Works
  • Docs
  • Contact
LoginSign Up

Data Processing Agreement

Last updated: March 2026

← All Policies

1. Scope and Purpose

This Data Processing Agreement (DPA) supplements the Terms of Service and governs the processing of personal data by Leadboard (Processor) on behalf of the Customer (Controller). It applies to all personal data processed through the Leadboard CRM platform.

2. Data Processing Details

Leadboard processes the following categories of data on your behalf:

  • Contact data: names, email addresses, phone numbers, job titles
  • Communication data: email content, delivery status, engagement metrics
  • CRM data: lead scores, deal values, notes, tags, custom fields
  • Usage data: login timestamps, feature usage, IP addresses

3. Processor Obligations

Leadboard shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure all personnel with access to personal data are under confidentiality obligations
  • Implement appropriate technical and organizational security measures (Article 32)
  • Assist the Controller with data subject access requests within the SLA timeframe
  • Notify the Controller of any personal data breach within 72 hours
  • Delete or return all personal data upon termination of the agreement
  • Make available all information necessary to demonstrate compliance

4. Sub-processors

Leadboard uses approved sub-processors to deliver its services. A current list is available at /policies/sub-processors. We will notify you at least 30 days before adding a new sub-processor, and you may object if you have reasonable grounds.

5. International Transfers

Where personal data is transferred outside the EEA, Leadboard relies on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.

6. Security Measures

Leadboard implements the following security measures:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls with least-privilege principle
  • Regular penetration testing and vulnerability assessments
  • Automated anomaly detection for email sending patterns
  • Incident response plan with defined escalation procedures
  • Employee security awareness training

7. Audits

The Controller may audit Leadboard's compliance with this DPA once per year, with 30 days written notice. Leadboard will cooperate and provide access to relevant documentation and systems.

8. Contact

For DPA inquiries, contact dpa@leadboard.io.

Leadboard

The all-in-one CRM platform that helps teams manage leads, automate outreach, track deals, and send invoices; all from one place.

Product

  • Features
  • How It Works
  • Pricing

Company

  • Contact
  • About Us

Legal

  • All Policies
  • Privacy Policy
  • Terms of Service
  • Anti-Spam Policy

© 2026 Leadboard. All rights reserved.