← Back to Leadia

Privacy Policy

Effective: May 5, 2025

1. Who We Are

Leadia ("we", "us", "our") is a software-as-a-service platform that provides autonomous revenue operations tools for vertical small businesses. Our registered email is privacy@getleadia.com.

2. Information We Collect

We collect information in three ways:

Information you provide directly

  • Account registration (name, email, business name)
  • Waitlist sign-up (name, email, practice type, consent)
  • Payment information (processed by Stripe; we do not store card numbers)
  • Support communications

Information collected automatically

  • Usage data (pages visited, features used, session duration)
  • Device and browser information
  • IP address (hashed for TCPA compliance logs; we do not retain raw IPs)
  • Cookies and similar tracking technologies (see Section 7)

Information from your contacts

When you use Leadia to manage your business contacts, you provide us with personal data about those individuals (names, phone numbers, email addresses). You are the data controller for that data; we process it on your behalf as a data processor.

3. How We Use Your Information

  • Providing and operating the Leadia platform
  • Processing payments and managing subscriptions
  • Sending transactional emails (account alerts, receipts)
  • Sending marketing communications where you have consented
  • Improving product features through aggregated analytics
  • Complying with legal obligations (HIPAA, TCPA, GDPR, CCPA)
  • Detecting and preventing fraud and abuse

4. TCPA Disclosure

By signing up for Leadia or submitting our waitlist form, you consent to receive automated marketing text messages from Leadia at the phone number you provide. Message frequency varies. Message and data rates may apply.

You can opt out at any time by replying STOP to any text message. You can also contact us at privacy@getleadia.com to remove your number from our marketing lists.

We maintain a consent version registry and audit trail as required for TCPA safe-harbour compliance. Consent records are retained for a minimum of 5 years.

5. HIPAA Notice (Medspa Vertical)

If you operate a medical spa or healthcare-adjacent business and use Leadia to process Protected Health Information (PHI), Leadia acts as your Business Associate under HIPAA. A Business Associate Agreement (BAA) is required before using Leadia to process PHI.

PHI stored in Leadia is encrypted at rest using AES-256-GCM with a separate master key from standard PII. PHI access is logged in a separate audit log for HIPAA compliance. AI calls involving PHI are routed through Microsoft Azure OpenAI, which provides a signed HIPAA BAA.

To execute a BAA, contact legal@getleadia.com.

6. Data Retention and Deletion

We retain your account data for the duration of your subscription plus 90 days after cancellation, after which it is permanently deleted.

Contact records belonging to your business are deleted within 30 days of a verified erasure request. Some data (consent records, audit logs) may be retained longer as required by law (TCPA: 5 years; financial records: 7 years).

To submit a data deletion request (GDPR Art. 17 / CCPA), email privacy@getleadia.com with subject line "Data Deletion Request".

7. Cookies

We use cookies and similar technologies for authentication (session cookies), security (CSRF protection), and analytics (PostHog). We do not use third-party advertising cookies.

You can disable cookies in your browser settings, but some parts of the platform may not function correctly without them.

8. Third-Party Services

We share data with the following processors as necessary to operate our platform:

  • Supabase -- database and authentication (SOC 2 Type II)
  • Vercel -- application hosting (SOC 2 Type II)
  • Stripe -- payment processing (PCI DSS Level 1)
  • Resend -- transactional email (SOC 2 Type II)
  • Twilio -- SMS messaging (ISO 27001, HIPAA BAA available)
  • OpenAI / Azure OpenAI -- AI features
  • Upstash -- rate limiting (SOC 2 Type II)
  • Sentry -- error tracking (ISO 27001)

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data (GDPR Art. 15, CCPA)
  • Correct inaccurate data (GDPR Art. 16)
  • Delete your data (GDPR Art. 17, CCPA "Right to Delete")
  • Receive a copy of your data in a portable format (GDPR Art. 20, CCPA)
  • Opt out of the sale of personal information (CCPA -- we do not sell data)

To exercise any right, email privacy@getleadia.com. We will respond within 30 days.

10. Changes to This Policy

We may update this policy from time to time. We will notify active users of material changes by email at least 14 days before they take effect. Continued use of Leadia after the effective date constitutes acceptance of the updated policy.

11. Contact

Questions or requests: privacy@getleadia.com