LeadGrind Data Processing Agreement (DPA)
Last updated: 1st July 2026
This Data Processing Agreement forms part of the contract between Max Solomon, trading as LeadGrind ("Processor", "we") and the Brand entering into the LeadGrind Terms of Service ("Controller", "you"), and applies whenever we process personal data on your behalf ("Lead Data", as defined in our Privacy Policy) in connection with the LeadGrind service. It is intended to meet the requirements of Article 28 UK GDPR.
1. Subject matter and duration
We process Lead Data for the duration of your subscription to LeadGrind, and for any period after termination during which we retain data under Section 8 (Deletion and return of data).
2. Nature and purpose of processing
We store, route, and deliver Lead Data submitted through lead-capture forms you build on the LeadGrind platform, strictly in order to: (a) present your forms to your website visitors, (b) store submitted responses, (c) apply the lead-routing rules you configure, and (d) deliver leads to the Partners and via the delivery methods (webhook, email notification, CRM connection) you configure. We do not process Lead Data for any other purpose.
3. Types of personal data and categories of data subjects
- Data subjects: visitors to your website(s) who submit a form built on the LeadGrind platform.
- Categories of personal data: determined by the fields you configure in your forms. Typically includes name, email address, phone number, and postal address. May include financial or insurance-related information if your form collects it (e.g. loan amount, income) — you are responsible for confirming you have a lawful basis for any such field before adding it to a form, this Agreement does not authorise collection of any particular data field, only governs how we process what you choose to collect.
- We do not knowingly process special category data (UK GDPR Article 9) on your behalf. If your use case requires this, contact us before configuring such a form — additional safeguards would be required that are not currently built into the platform.
4. Processor obligations
We agree to:
- Process Lead Data only on your documented instructions — instructions given through your configuration of forms, routing rules, and delivery methods in the LeadGrind platform constitute your documented instructions for the purposes of this Agreement.
- Confidentiality — ensure that any person authorised to process Lead Data (our employees or contractors) is under an appropriate obligation of confidentiality.
- Security — implement appropriate technical and organisational measures to protect Lead Data, including encryption of data in transit (HTTPS), access controls, and [describe actual measures — e.g. database access restrictions, backup encryption — should be confirmed against actual infrastructure before publishing].
- Sub-processors — not engage a new sub-processor without giving you the opportunity to object, and ensure any sub-processor is bound by data protection obligations equivalent to those in this Agreement. Current sub-processors are listed in Section 6 of the Privacy Policy and will be kept up to date there.
- Assist with data subject rights — where a data subject exercises their rights (access, erasure, etc.) directly against us regarding Lead Data, we will inform you promptly and assist you in responding, since you are the controller responsible for the substantive response.
- Assist with your compliance obligations — including data protection impact assessments and consultation with the ICO, where reasonably required and taking into account the nature of processing and information available to us.
- Breach notification — notify you without undue delay after becoming aware of a personal data breach affecting Lead Data. [Add a specific timeframe — e.g. "within 72 hours" — once confirmed as operationally achievable; do not commit to a number without an actual incident-response process behind it.]
- Deletion and return of data — see Section 8.
- Audit rights — make available information reasonably necessary to demonstrate compliance with this Agreement, and allow for audits, subject to reasonable notice and confidentiality.
5. Controller obligations
You confirm that: you have a valid lawful basis under UK GDPR for collecting and processing the Lead
Data you configure your forms to collect; your instructions to us (via your platform configuration)
comply with applicable data protection law; and you are responsible for the content and legality of
your own privacy notice shown to your website visitors (editable from your Brand settings, published
at /privacy on your site).
6. Sub-processors
See Section 6 of the Privacy Policy for the current list. We will notify you of any intended change (addition or replacement) and give you a reasonable opportunity to object before the change takes effect for your data.
7. International transfers
[As flagged in 00-READ-ME-FIRST.md — pending AWS region confirmation. If any sub-processor
transfers Lead Data outside the UK, this section must describe the transfer mechanism relied upon.]
8. Deletion and return of data
On termination of your subscription, we will [delete / allow you to export, then delete — confirm actual intended behaviour] Lead Data within [PERIOD, e.g. 30 days] of termination, except to the extent retention is required by law. [Note: termination-triggered deletion is not yet automated — only the ongoing 24-month retention purge is. This section still needs that behaviour built, or the wording adjusted, before publishing.] During your subscription, Lead Data is retained per Section 5 of the Privacy Policy (24 months from submission date), automatically enforced by a daily scheduled job.
9. Liability
[Liability allocation between processor and controller for data protection breaches needs specific drafting — this is one of the sections most worth paying a solicitor for, given the direct financial exposure (ICO fines can reach the higher of £17.5m or 4% of global turnover) if this is drafted generically and something goes wrong.]