This Data Processing Addendum (the "Addendum") applies where Leadity processes personal data on your behalf and you act as a controller, whether under the EU General Data Protection Regulation, the UK GDPR, or a United States state privacy law. It forms part of, and is governed by, our Terms of Service, and the Terms decide anything this Addendum does not. This is version 2026-09-16 of this Addendum.
1. Roles
Leadity holds a different role over each of the three kinds of personal data involved in the Service, and the distinction decides which of us owes what.
- Your account data. Your name, email address, billing records, support messages and the device signals described in the Privacy Policy. Leadity is the controller of this and decides why it is held. Part A of the Privacy Policy describes it.
- The business records in the product. Leadity decides what is collected, from where and for what purpose, so Leadity is the controller of its own database. When you order, export or download leads, you receive your own copy and become an independent controller of it. From that point you decide what happens to it, including any outreach, and Section 4 of the Terms of Service sets out what you are responsible for.
- What you submit to us. The lists of phone numbers and email addresses you submit to Validations, and the files and messages you send us, such as a support attachment or a profile picture. Leadity is a processor of these, acting on your instructions and for no purpose of its own.
The rest of this Addendum is about the third kind only. Where Leadity is the controller, the Privacy Policy governs rather than this document.
2. What we process for you
- Subject matter. Classifying and verifying the contact details you submit, and storing the files and messages you send us.
- Nature and purpose. Determining the line type of a phone number, determining whether an email address can receive mail, returning those results to you, and holding what you upload so that we can show it back to you and support you.
- Duration. For as long as your account is open, and after that for the period described in Section 7 of the Privacy Policy.
- Categories of personal data. Phone numbers and email addresses you submit, the results we return against them, and the contents of anything you upload or write to us.
- Categories of data subject. The people and businesses identified by the lists you submit, and the people who use your account.
3. Your instructions and confidentiality
We process this data only on your documented instructions, including on transfers, unless a law we are subject to requires otherwise, in which case we will tell you before processing unless that law forbids it. Placing an order and using the Service are your instructions, and this Addendum together with the Terms of Service is the complete record of them. If we believe an instruction breaches data protection law, we will tell you, and we may pause that processing until it is resolved.
Everyone we allow to process this data is bound by a duty of confidentiality, and access to production data is restricted and audited as described in Section 8 of the Privacy Policy.
4. Sub-processors
You give us general authorisation to engage sub-processors. The ones we use are named in Section 5 of the Privacy Policy, which is the list rather than a summary of one. There is deliberately no second copy here: two lists of the same providers drift, and the one in the Privacy Policy is the one we maintain.
We impose data protection obligations on each sub-processor that are no less protective than those in this Addendum, and we remain responsible to you for their performance. We give notice of a material change to that list by publishing a new version of the Privacy Policy, which asks you to read and accept it the next time you use Leadity. If you object to a new sub-processor on reasonable data protection grounds, tell us at support@leadity.io and you may stop submitting data and close your account without penalty.
5. Security
We maintain technical and organisational measures appropriate to the risk. They are described in Section 8 of the Privacy Policy and include hashing passwords with Argon2id, httpOnly session, device and support cookies, restricted and audited access to production data, logged administrative access to a customer account, and SPF, DKIM and DMARC on outbound mail. We review these as the Service changes. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
6. Personal data breach
If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay. The notice will describe what we know at the time, including the nature of the breach, the categories and approximate number of records involved so far as we can tell, the likely consequences, and what we are doing about it. Where we cannot provide all of that at once we will provide it in stages as it becomes available, and we will assist you with any notification you owe to a supervisory authority or to the people affected.
7. Assistance, records and audit
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests from people exercising their rights over data you submitted to us, and we will pass on any such request that reaches us directly rather than answering it ourselves. We will also assist you, so far as the information is ours to give, with data protection impact assessments and any prior consultation with a supervisory authority.
We will make available the information reasonably necessary to demonstrate compliance with this Addendum and will respond to reasonable written requests, which we may satisfy with our own documentation and answers. Unless a supervisory authority or a law requires otherwise, this applies once in any twelve month period.
8. International transfers
The Service and its data are hosted in the United States, as Section 10 of the Privacy Policy says, and some of the providers in Section 5 of that Policy operate outside it. Where you are established in the European Economic Area, the United Kingdom or Switzerland, the European Commission's Standard Contractual Clauses for transfers to processors are incorporated into and form part of this Addendum, with you as data exporter and Leadity LLC as data importer. For the United Kingdom, the UK International Data Transfer Addendum to those Clauses applies in the same way. Sections 2, 4 and 5 of this Addendum provide the descriptions those Clauses require. If you need a signed counterpart, ask at support@leadity.io.
9. Return and deletion
You can export the results of any validation run and download any file you uploaded for as long as your account is open, and we recommend doing so before you close it. After your account ends we delete or return the personal data we processed for you in line with Section 7 of the Privacy Policy, which is where our retention is stated.
We deliberately do not promise a shorter fixed period here. That Section says records are kept for at least twelve months after an account is deleted, and longer where the law requires it or where it is reasonably necessary for security, audit, fraud prevention, dispute resolution or enforcing our Terms. A thirty day deletion promise in this document would contradict a policy published on the same website, so this Addendum states what actually happens instead.
10. Changes to this Addendum
We may update this Addendum. When a change is material we publish it under a new version, and you will be asked to read and accept it the next time you use Leadity. Continuing to use the Service after accepting means the new version applies. If anything here is unclear, email support@leadity.io.
