Privacy Policy

Last updated: 26/07/2026

This Privacy Policy explains how LeadTapAI ("we", "us", "our") collects, uses, and protects personal data when you use the LeadTapAI SMS lead qualification and missed-call recovery service ("Service"), and when we contact leads and customers on behalf of our clients.

This Policy should be read alongside our Terms of Service.

1. Who This Policy Covers

This Policy applies to two groups of people:

2. What Data We Collect

From Clients, during onboarding and use of the Service:

From leads and customers, via SMS/call conversations handled on a Client's behalf:

We do not knowingly collect special category data (e.g. health information) beyond what a lead voluntarily includes in a message, and we do not use conversation data for any purpose beyond providing the Service.

3. Why We Use This Data (Legal Basis)

Purpose Legal basis
Providing the Service to Clients (onboarding, running the SMS agent, logging leads) Performance of a contract with the Client
Handling leads' messages to qualify and route enquiries Legitimate interests of the Client (responding to their own enquiries), acting as their processor
Billing and account administration Performance of a contract / legal obligation
Complying with opt-out (STOP) requests and Do Not Contact instructions Legal obligation under PECR

For leads and customers: the Client is the data controller for their own leads' data. We process that data only as instructed by the Client, as their data processor. Any questions a lead has about why they were contacted should first go to the Client whose business they enquired with.

4. Who We Share Data With

We share data only with sub-processors necessary to run the Service:

We do not sell personal data, and we do not share it with third parties for their own marketing purposes.

5. International Data Transfers

Some sub-processors may process data outside the UK. Where this happens, we rely on appropriate safeguards (such as the UK's International Data Transfer Addendum or adequacy regulations) to ensure data remains protected to UK standards.

6. How Long We Keep Data

7. Your Rights

Under UK GDPR, individuals have the right to:

Leads and customers should direct these requests to the Client's business first, since the Client is the data controller. We will assist Clients in responding to such requests as their processor.

Clients can contact us directly using the details in Section 9 below.

8. Opting Out of SMS Contact

Anyone who no longer wishes to receive messages via the Service can reply STOP to any SMS, or ask to be added to a Client's Do Not Contact list. We will action opt-outs promptly and will not contact that number again through the Service.

9. Contact

Questions about this Privacy Policy, or requests relating to your personal data, can be sent to [your business email].

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified to Clients by email at least 14 days before they take effect.