01Introduction and scope
This Data Processing Agreement (DPA) forms part of the Terms of Service or other written agreement (the Agreement) between Leadiy (Pvt) Ltd (Leadiy, Processor) and the customer (Customer, Controller) for use of the Service.
This DPA applies where, and to the extent that, Leadiy processes Customer Personal Data on behalf of the Customer as a processor. It reflects the parties' agreement on the processing of personal data in accordance with applicable data-protection law. Where there is a conflict between this DPA and the Agreement on data protection, this DPA prevails.
This DPA is a template designed to support common data-protection requirements (including the GDPR-style controller/processor model). It is not legal advice. Customers with specific regulatory needs should review it with their own advisers, and enterprise customers may sign a negotiated DPA that supersedes this one.
02Definitions
- Applicable Data Protection Law means the data-protection and privacy laws that apply to the processing, such as the EU/UK GDPR, the CCPA/CPRA, and Sri Lankan data-protection law, as applicable.
- Customer Personal Data means personal data contained within Customer Data that Leadiy processes on behalf of the Customer under the Agreement.
- Controller, Processor, Data Subject, Personal Data, Processing, and Personal Data Breach have the meanings given in Applicable Data Protection Law.
- Subprocessor means a third party engaged by Leadiy to process Customer Personal Data.
- Standard Contractual Clauses (SCCs) means the clauses approved for lawful cross-border transfers of personal data, where applicable.
03Roles of the parties
As between the parties, the Customer is the Controller (or a processor acting on behalf of its own controller) and Leadiy is the Processor of Customer Personal Data. Each party will comply with its obligations under Applicable Data Protection Law.
The Customer is responsible for the accuracy, quality, and legality of Customer Personal Data, for the means by which it acquired that data, and for establishing a lawful basis for the processing — including for any discovery, enrichment, scoring, and outreach it configures using the Service.
04Customer instructions
Leadiy will process Customer Personal Data only on the documented instructions of the Customer, including as set out in the Agreement, this DPA, and the Customer's configuration and use of the Service, unless required to process otherwise by law (in which case Leadiy will inform the Customer where legally permitted).
The Customer instructs Leadiy to process Customer Personal Data as necessary to provide, secure, support, maintain, and improve the Service and to comply with the Agreement. Leadiy will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
05Confidentiality of processing
Leadiy will ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and receive appropriate training, and that access is limited to those who need it to provide the Service.
06Security measures
Leadiy will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. A summary of these measures is set out in Annex 2.
07Subprocessors
The Customer provides general authorisation for Leadiy to engage Subprocessors to process Customer Personal Data to provide the Service (for example, cloud hosting, AI processing, email delivery, analytics, and support providers). A current list of key Subprocessor categories is set out in Annex 3.
Leadiy will impose data-protection obligations on its Subprocessors that are substantially similar to those in this DPA, and remains responsible for their performance. Leadiy will provide a mechanism to notify the Customer of intended changes to Subprocessors and will give the Customer a reasonable opportunity to object on reasonable data-protection grounds.
08Assistance with data-subject rights
Taking into account the nature of the processing, Leadiy will provide reasonable assistance to the Customer, by appropriate technical and organisational measures and insofar as possible, to help the Customer respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law.
If Leadiy receives a request from a Data Subject relating to Customer Personal Data, it will, where legally permitted, direct the Data Subject to the Customer or handle the request under the Customer's instructions.
09Personal data breach notification
Leadiy will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its own breach-notification obligations. Notification of a breach is not an acknowledgement of fault or liability.
10Data protection impact assessments
Taking into account the nature of processing and the information available to it, Leadiy will provide reasonable assistance to the Customer with data-protection impact assessments and prior consultations with supervisory authorities, where the Customer is required to carry these out under Applicable Data Protection Law.
11International transfers
Leadiy may transfer and process Customer Personal Data in Sri Lanka and in other countries where Leadiy or its Subprocessors operate. Where such transfers are subject to Applicable Data Protection Law, Leadiy will rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses or an adequacy decision, as applicable.
12Return and deletion of data
On termination or expiry of the Agreement, Leadiy will, at the Customer's choice and to the extent applicable, delete or return Customer Personal Data, and delete existing copies, unless retention is required by law. Deletion may be subject to routine backup cycles, after which data is overwritten or destroyed in the ordinary course.
13Audits and compliance
Leadiy will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, confidentiality, frequency limits, and Leadiy's security and operational requirements. Where available, Leadiy may satisfy audit requests by providing relevant third-party reports or documentation.
14Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together.
15Term and termination
This DPA takes effect when the Customer accepts the Agreement or begins using the Service and continues until Leadiy has ceased all processing of Customer Personal Data on behalf of the Customer. Provisions that by their nature should survive termination will survive.
16General
Except as amended by this DPA, the Agreement remains in full force and effect. This DPA is governed by the same law and dispute-resolution terms as the Agreement. If any provision of this DPA is held invalid, the remaining provisions continue in effect.
17Annex 1 — Details of processing
| Item | Details |
|---|---|
| Subject matter | Provision of the Leadiy customer-acquisition and business-intelligence platform. |
| Duration | For the term of the Agreement, plus any legally required retention period. |
| Nature and purpose | Hosting, storage, discovery, enrichment, verification, scoring, analysis, AI processing, reporting, email sending, support, security, and service improvement. |
| Types of personal data | Account and user contact details; business and public-source contact details (names, emails, phone numbers, roles, social handles); email/campaign content and engagement events; usage and log data; and any personal data contained in Customer Data or prompts. |
| Categories of data subjects | Customer's authorised users; the Customer's own contacts and prospects; individuals associated with businesses discovered, enriched, or contacted through the Service. |
| Frequency | Continuous, for the duration of the Customer's use of the Service. |
18Annex 2 — Technical and organisational measures
- Access controls, authentication, and least-privilege access to systems and data.
- Encryption of data in transit, and encryption of sensitive stored credentials such as SMTP passwords.
- Network and application security controls, logging, and monitoring of security events.
- Regular backups and documented recovery processes.
- Staff confidentiality obligations, security awareness, and vendor/subprocessor review.
- Change management and separation of environments where appropriate.
- Incident-response processes for detecting, assessing, and responding to security events.
19Annex 3 — Subprocessors
Leadiy engages Subprocessors in the following categories to provide the Service. Specific providers may change over time in line with the subprocessor-change process above.
| Category | Purpose |
|---|---|
| Cloud hosting & infrastructure | Hosting the application, databases, and storage. |
| AI & model providers | AI-assisted enrichment, scoring, summarisation, translation, and drafting. |
| Payments (merchant of record) | Subscription billing and payment processing (LemonSqueezy). |
| Email & deliverability | Transactional email and, where used, campaign sending infrastructure. |
| Analytics & logging | Product analytics, error logging, and performance monitoring. |
| Support tools | Customer support, ticketing, and communications. |
20Contact
For questions about this DPA or to raise a data-protection matter, contact:
Leadiy (Pvt) Ltd
303, New Kandy Road, Kothalawala, Kaduwela, Greater Colombo, Sri Lanka
Email: privacy@leadiy.com
Questions about this document?
Reach our team at support@leadiy.com. See also our Terms, Privacy Policy, Data Processing Agreement and Refund Policy.