← All Policies
1. Scope and Purpose
This Data Processing Agreement (DPA) supplements the Terms of Service and governs the processing of personal data by Leadboard (Processor) on behalf of the Customer (Controller). It applies to all personal data processed through the Leadboard CRM platform.
2. Data Processing Details
Leadboard processes the following categories of data on your behalf:
- Contact data: names, email addresses, phone numbers, job titles
- Communication data: email content, delivery status, engagement metrics
- CRM data: lead scores, deal values, notes, tags, custom fields
- Usage data: login timestamps, feature usage, IP addresses
3. Processor Obligations
Leadboard shall:
- Process personal data only on documented instructions from the Controller
- Ensure all personnel with access to personal data are under confidentiality obligations
- Implement appropriate technical and organizational security measures (Article 32)
- Assist the Controller with data subject access requests within the SLA timeframe
- Notify the Controller of any personal data breach within 72 hours
- Delete or return all personal data upon termination of the agreement
- Make available all information necessary to demonstrate compliance
4. Sub-processors
Leadboard uses approved sub-processors to deliver its services. A current list is available at /policies/sub-processors. We will notify you at least 30 days before adding a new sub-processor, and you may object if you have reasonable grounds.
5. International Transfers
Where personal data is transferred outside the EEA, Leadboard relies on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.
6. Security Measures
Leadboard implements the following security measures:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls with least-privilege principle
- Regular penetration testing and vulnerability assessments
- Automated anomaly detection for email sending patterns
- Incident response plan with defined escalation procedures
- Employee security awareness training
7. Audits
The Controller may audit Leadboard's compliance with this DPA once per year, with 30 days written notice. Leadboard will cooperate and provide access to relevant documentation and systems.
8. Contact
For DPA inquiries, contact dpa@leadboard.io.