Terms

How we look after your data

You're putting your entire pipeline into this. Here's exactly what happens to it.

Who can see what

Leadey has twelve permission modules and around forty-five individual permissions, and they're enforced on the server — not hidden in the interface.

That distinction matters. Plenty of tools hide a button and call it a permission. In Leadey, a rep whose inbox access is scoped to their own conversations has their request narrowed before the database is queried. There is no URL they can type to see someone else's.

  • Four built-in roles, unlimited custom roles, and per-person overrides on top
  • Scope axes, not just on/off — a rep can see all leads, only their campaigns' leads, or none
  • Every request re-verifies that the person is still a member of the organisation, so removing someone takes effect immediately rather than whenever their session happens to expire

How permissions work →

Your connected accounts

Every credential Leadey holds — mailbox tokens, calendar tokens, WhatsApp business tokens, SMTP passwords — is encrypted at rest.

When you connect LinkedIn, the login and any two-factor challenge happen on Unipile's own screens. Leadey never sees your LinkedIn password.

Recordings and documents

Call recordings, voicemails, lead documents and template attachments are stored in a private Cloudflare R2 bucket, namespaced per organisation, and served through short-lived presigned URLs. Nothing is publicly listable.

Outreach compliance

  • Do Not Contact follows the person. Flag someone once and every campaign they appear in respects it. The lead isn't deleted — it stays visible, marked, and calls require confirmation.
  • Unsubscribe handling. Automated emails carry a signed unsubscribe link. Unsubscribing, replying "stop", hard-bouncing or filing a complaint all add the address to your suppression list and exit any sequence they're in.
  • Regulatory bundles. Phone numbers are provisioned against properly documented bundles — UK CRN, US EIN, AU ABN — with address verification and document review.
  • Landline detection. SMS to a number positively identified as a landline is blocked before it's sent.

Who else touches your data

  • Clerk — Authentication and organisation management
  • Stripe — Payments
  • Twilio — Voice and SMS
  • AssemblyAI — Call transcription
  • OpenAI — Call summaries, scoring and drafting
  • Resend — System email
  • Cloudflare R2 — File storage
  • Unipile — LinkedIn connectivity
  • Meta — WhatsApp Business messaging

Data providers (Crustdata, TheirStack, BetterContact, Apify) receive search criteria, not your CRM.

Full detail in the Data Processing Addendum.

Security FAQ

Where is my data stored?

In our production database and, for files, a private Cloudflare R2 bucket. See the DPA for detail.

Can I export everything?

Yes, any time. Leads with every custom field as CSV, and read access to everything through the API.

What happens to my data if I cancel?

Export first — it's a single click. Retention after cancellation is covered in the Terms.

Do you train AI models on my data?

No. Transcription and summarisation are per-request calls to AssemblyAI and OpenAI. Your calls are not used to train anything.

Is Leadey GDPR compliant?

We provide a DPA, honour data subject requests, and give you the export and deletion tools to meet your own obligations. GDPR compliance is a shared responsibility — see our Acceptable Use and Outreach Compliance Policy.

Can’t find your answer, read our docs or contact us.

Explore

Pages
Buy