Privacy policy
Last updated: 1 October 2026
Template notice: this is a starting-point draft, not legal advice. It is being completed and reviewed before being relied on.
This policy explains how [Legal entity name — to confirm] (“we”, “us”), which operates LeadFlow AI at https://leadflow.nexus-core.cloud, collects and uses personal data. It covers two groups of people: those who use LeadFlow AI, and people at businesses whose work details appear in it.
1. Who we are
[Legal entity name — to confirm] (company number [Company number — to confirm]), [Registered address — to confirm]. ICO registration: [ICO registration number — to confirm]. Contact: [privacy contact email — to confirm].
We are the data controller for account data and for the business information we compile. For data a customer adds to its own workspace (for example contacts it imports or notes it writes), the customer is the controller and we process that data on its behalf, under our terms.
2. If you use LeadFlow
We collect:
- your name, work email address and, if you choose Google sign-in, your Google account’s basic profile (name, email and photo). We never receive your Google password;
- the organisation you belong to in LeadFlow and your role in it;
- a record of actions you take in the app (for example who moved a company in the book and when), which we keep for accountability and security;
- technical data needed to run the service securely, such as sign-in sessions and request logs.
We use this to provide the service you or your organisation signed up for (contract), and to keep it secure and improve it (legitimate interests).
3. If your business details appear in LeadFlow
LeadFlow AI helps businesses find and contact other businesses. To do that we hold information about organisations and about people in their professional roles:
- company information from public sources, such as Companies House, The Gazette, public operator-licence and regulator registers, public procurement notices and business listings;
- work contact details of people in business roles (name, job title, work email and work phone), from public sources such as company websites and from business-data providers;
- records of contact made through LeadFlow: emails sent, whether they were delivered, bounced or marked as spam, call outcomes and next steps.
Our legal basis is legitimate interests: business-to-business prospecting, carried out in a way a professional would reasonably expect, with an easy way to object. We do not collect special-category data, and we do not send marketing emails to individuals or sole traders who have not agreed to receive them, as required by the Privacy and Electronic Communications Regulations (PECR).
To stop being contacted, reply to any email asking us to stop, or write to [privacy contact email — to confirm]. We will mark you as unsubscribed. LeadFlow blocks further outreach to anyone unsubscribed, and a spam complaint unsubscribes you automatically. We keep a minimal record of the opt-out so we can keep honouring it.
4. Automated scoring and AI
LeadFlow uses automated tools, including AI decision models, to sort and score companies (for example how well a company fits a customer’s ideal-customer profile, or which signals look recent). These judgements help people decide where to focus. They do not produce decisions with legal or similarly significant effects on individuals, and outreach is approved by a person before it is sent.
5. Who we share data with
We share data only with service providers who help us run LeadFlow AI, under contracts that protect it:
- Clerk: accounts and sign-in;
- Supabase: database (hosted in London, UK);
- Vercel: website hosting;
- Resend and Amazon Web Services: sending email (Ireland, EU);
- TypeSafe AI and our own servers: automated decisions and analysis;
- Google: maps and place information, and Google sign-in if you use it;
- if your organisation connects a CRM (such as HubSpot, Pipedrive, Salesforce or Zoho), the data it chooses to sync.
We do not sell personal data.
6. International transfers
Some providers are based in, or may process data in, the United States. Where data leaves the UK we rely on UK adequacy regulations (including the UK–US data bridge where the provider is certified) or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
7. How long we keep it
- account data: while your account is active, then deleted within 90 days of closure unless we must keep it longer by law;
- business and contact information: reviewed and refreshed, and removed when no longer relevant or on request;
- opt-out records: kept so we can keep honouring them;
- security and audit logs: up to 12 months.
8. Your rights
You can ask for a copy of your data, and ask us to correct it, delete it, restrict its use, or move it to another service. You can object to processing based on legitimate interests at any time, and an objection to direct marketing is always honoured. Write to [privacy contact email — to confirm]. We reply within one month.
9. Cookies
We use only cookies needed to run the service: sign-in session cookies (Clerk) and a preference cookie remembering which view you chose in the app. We do not use advertising cookies.
10. Security
Data is encrypted in transit, access is limited by role, and actions in the app are logged. No system is perfectly secure, but we work to protect your data and will tell you and the regulator about a serious breach as the law requires.
11. Complaints
Please contact us first at [privacy contact email — to confirm]. You can also complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, 0303 123 1113.
12. Changes
We will update this page when our practices change, and change the date at the top.