IQLeadIQ

Data Processing Agreement

Version 2026-06-07 · template · to be completed at signing

Before we sign: this is the standard template. Custom clauses or customer-specific addenda are handled by email — privacy@leadiq.center. For most customers the template works unchanged.

1. Parties

Processor: LeadIQ B.V. (in formation), established in the Netherlands, represented by its founder. Hereinafter: "LeadIQ".

Controller: the organisation named on the most recent Stripe billing address or trial sign-up form. Hereinafter: "Customer".

2. Subject matter & duration

This data processing agreement governs how LeadIQ processes personal data on behalf of Customer in the context of the LeadIQ software (a clarity layer on top of monday.com).

The agreement runs for as long as Customer has an active LeadIQ subscription and ends 30 days after termination — a period used for the final data export or deletion.

3. Nature, purpose and categories of processing

Full overview and retention periods: /privacy.

  • Account metadata (workspace name, primary contact email)
  • User accounts (email, role) — only after auth activation
  • Sales rep records (name, email, salary components) — manager-only visibility
  • Column mappings, ICP rules, activity metadata, audit trail
  • No CRM data or lead PII — that is fetched live from monday.com and never persisted

4. Security measures

  • EU data residency (Supabase Frankfurt, Vercel EU)
  • Encryption in transit (TLS 1.3) and at rest (AES-256 via Supabase storage)
  • monday.com OAuth tokens stored encrypted, scopes limited to what is strictly needed
  • Row-level security in Postgres scoped by account_id; service-role key server-side only
  • Audit trail for write actions (180-day retention)
  • Production access via 2FA-protected accounts; no shared credentials
  • Incident procedure: notification within 72 hours per GDPR art. 33

5. Sub-processors

Current list: /privacy, section "Sub-processors". Customer consents to the processors listed there. LeadIQ notifies Customer by email (see section 7) of any addition or replacement of sub-processors, with a reasonable objection period.

6. Transfers outside the EEA

LeadIQ processes personal data within the EEA. Sub-processors without an EU establishment (if applicable in future expansions) operate under the European Commission's Standard Contractual Clauses (Module 3, processor-to-processor).

7. Contact & notifications

All privacy and security correspondence runs through privacy@leadiq.center.

8. Data subject rights

LeadIQ supports Customer in handling data subject requests (access, rectification, erasure, data portability). Self-service tooling is available in Settings → Privacy & data.

9. Liability

LeadIQ's liability under this agreement is limited to the amount Customer paid to LeadIQ in the 12 months preceding the event giving rise to the damage, except in cases of intent or gross negligence. This does not affect the supervisory powers of the competent data protection authority.

10. Governing law & disputes

This agreement is governed by Dutch law. Disputes are submitted to the competent court in Amsterdam.