Roles: The agency is normally the controller of its prospects, applicants, customers, and other lead data. Leadsmith processes that data on the agency's documented instructions to provide the contracted service.
1. Scope and relationship
This information applies where an agency uses Leadsmith to receive, qualify, respond to, follow up with, or route lead and seller-signal data. The agency remains responsible for its notices, lawful bases, instructions, data quality, and communications with its data subjects. Leadsmith acts as processor for the agency customer data covered by the service.
Leadsmith may separately be a controller for its own account, billing, security, support, and website records. Those activities are described in the Privacy Policy.
2. Processing instructions and purposes
Leadsmith processes data only to provide, secure, maintain, and support the service, or on the agency's further documented instructions. Depending on the features enabled, the purposes include:
- receiving property or valuation enquiries and sending agency-approved or agency-configured responses;
- extracting qualification details, maintaining conversation history, scheduling follow-up, and presenting lead status;
- finding, ranking, and preparing outreach for seller signals from public property and company records;
- pushing selected lead, seller, and conversation information to the agency's configured CRM or webhook endpoint; and
- storing service records, providing support, diagnosing faults, and protecting the platform.
The agency must not instruct Leadsmith to process data in a way that breaches applicable law or the rights of data subjects.
3. Data and data subjects
Depending on the agency's use of the service, the processed data may include:
- names, email addresses, telephone numbers, property addresses, postcodes, property type, budget, timeline, motivation, messages, and conversation metadata;
- lead status, qualification fields, follow-up activity, notes, source, timestamps, and CRM identifiers;
- public seller-signal information such as planning applications, property transaction history, company-director changes, address, score, reasons, and outreach drafts; and
- technical information needed to operate a submission or integration, such as IP hash, user-agent, delivery status, and webhook audit details.
Data subjects may include prospective buyers, sellers, landlords, tenants, property owners, applicants, agency employees, and other people mentioned in an enquiry or CRM record. The agency should not send special-category or criminal-offence data unless it has a lawful, documented reason and has agreed appropriate safeguards with Leadsmith.
4. Confidentiality and security
People authorised to access agency customer data are subject to confidentiality obligations. Leadsmith uses access controls, authenticated and signed integration routes where appropriate, encryption in transit, restricted operational access, logging, backups, and monitoring designed to preserve confidentiality, integrity, and availability.
The agency is responsible for protecting its dashboard and integration credentials, limiting internal access, checking destinations before enabling a webhook, and reviewing the accuracy and appropriateness of its instructions.
5. Subprocessors and service providers
Leadsmith uses service providers to host and operate the application. Depending on the service feature, these may include:
- Polsia-hosted application infrastructure and platform proxies;
- Neon/PostgreSQL for application data storage;
- Postmark and other configured email delivery services;
- Stripe for subscription and payment processing;
- the AI provider reached through the Polsia AI proxy for drafting, extraction, and related AI features; and
- the agency's own CRM, webhook, or integration provider where the agency enables that destination.
We require relevant providers to protect data and process it only for the services they provide. We will update this information or notify customers through the agreed channel when a material change to a processor used for customer data requires notice or approval.
6. International transfers
Some providers or infrastructure may process data outside the UK. Where a restricted transfer applies, Leadsmith will use an applicable adequacy decision or another lawful safeguard, such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, together with supplementary measures where required.
7. Security incidents and rights assistance
Leadsmith will notify the agency without undue delay after becoming aware of a confirmed personal-data breach affecting the agency data, where required by law, and will provide reasonably available information about the incident and response. The agency remains responsible for deciding whether to notify the ICO or affected individuals.
Taking account of the processing and information available to us, Leadsmith will provide reasonable assistance with data-subject access, correction, deletion, restriction, portability, objection, and regulatory enquiries. Requests received directly from a data subject may be passed to the agency unless law requires Leadsmith to respond.
8. Deletion and return
On the agency's request or when the service ends, Leadsmith will delete or return agency customer data in accordance with the applicable agreement and technical capabilities, unless retention is required by law. Backup copies may remain for a limited period while they expire through normal backup cycles and remain protected from active use.
9. Audit and co-operation
Leadsmith will make information reasonably available to demonstrate compliance with processor obligations and will co-operate with proportionate audits or questionnaires, subject to confidentiality, security, and protection of other customers. The agency must provide reasonable notice and avoid access to unrelated customer data or systems.
10. Contact
Leadsmith data-processing contact
Include your agency name, the relevant account or integration, and enough detail for us to identify the request without sending unnecessary personal data.