TalkToLeads legal
This Addendum governs how TalkToLeads processes personal data on behalf of a client when delivering the Services. It forms part of the agreement between TalkToLeads and the Client, alongside the Terms of Service.
Draft policy — legal review required before accepting payment or processing client lead data.
This document is a working draft prepared for review. It is not legal advice and should not be relied on. Passages in [INSERT …] mark decisions still to be made. Current version: DRAFT-v0.1.
Draft addendum — not executable
This Addendum governs the processing of personal data contained in Client Data and Lead Data. It applies whenever TalkToLeads processes personal data on the Client’s behalf in the course of providing the Services.
Where this Addendum conflicts with the Terms of Service on the subject of data protection, this Addendum is intended to take precedence — subject to section 16.
Subject matter: lead response, qualification, routing, human handoff, follow-up, maintenance, support, reporting and troubleshooting.
Duration: the term of the Services, plus the closure and deletion period described in section 13, plus any period for which retention is required by law.
TalkToLeads uses reasonable technical and organisational safeguards designed to protect personal data. The specific measures are set out in Annex 2.
Annex 2 must reflect production reality
Taking into account the nature of the processing and the information available to us, TalkToLeads will provide reasonable assistance with:
Assistance that falls outside the standard scope of the Services, or that requires significant engineering effort, may be chargeable at rates agreed in advance.
Personal data may be processed outside the country in which it was collected, depending on hosting, provider locations and the integrations the Client selects. Where applicable law requires a transfer mechanism, appropriate safeguards will be put in place.
Liability under this Addendum is intended to be governed by the limitation of liability in the Terms of Service. Where this Addendum and the Terms conflict on data protection, this Addendum is intended to prevail.
| Item | Detail |
|---|---|
| Subject matter | Lead response, qualification, routing, human handoff, follow-up, maintenance, support and reporting. |
| Duration | Term of the Services, plus the closure and deletion period, plus any legally required retention. |
| Nature and purpose | Configuring and operating Workflows; sending communications on Client instructions; routing to Client personnel; monitoring; reporting; support; abuse prevention. |
| Types of personal data | Lead name and contact details, enquiry content, qualification answers, location/budget/timeline, consent and opt-out records, technical and log data. |
| Categories of data subjects | Prospects, customers, website visitors, property buyers/sellers/tenants/investors, project prospects, loan prospects, Client employees and contacts. |
| Client instructions | As set out in this Addendum, the Order, the approved Workflow configuration, and any later written instruction accepted by TalkToLeads. |
| Frequency of processing | Continuous, for the duration of the Services. |
Implementation-dependent — verify before publishing
| Measure | Description | Status |
|---|---|---|
| Role-based access control | Access to client systems and data is granted by role rather than individually. | [TO VERIFY] |
| Individual employee accounts | No shared logins; each person has their own credentials. | [TO VERIFY] |
| Founder-only employee administration | Creation, modification and removal of staff accounts restricted to the founder. | [TO VERIFY] |
| Multi-factor authentication | MFA/2FA on administrative and client-system access. | [TO VERIFY] |
| Tenant / organisation isolation | Client data is logically separated so one client cannot access another’s. | [TO VERIFY] |
| Row-Level Security | Database-level policies restricting row access by tenant and role. | [TO VERIFY] |
| Server-side secret handling | API keys and credentials held server-side, never exposed to the browser or written to normal UI logs. | [TO VERIFY] |
| Logging and audit trail | Administrative and access events recorded and retained. | [TO VERIFY] |
| Encryption | Encryption in transit and at rest. | [TO VERIFY — DO NOT CLAIM UNTIL ENGINEERING CONFIRMS] |
| Backup and restore | Regular backups with a tested restore procedure. | [TO VERIFY] |
| Vulnerability and patch management | Dependency and platform patching process. | [PLANNED — INSERT PROCESS] |
| Incident response | Documented detection, triage, containment and notification process. | [PLANNED — INSERT PROCESS] |
| Staff training and confidentiality | Confidentiality obligations and data-handling training for personnel. | [TO VERIFY] |
| Vendor / subprocessor controls | Review of provider security terms before engagement. | [TO VERIFY] |
The authoritative, continuously maintained list is published at Subprocessors. That page is incorporated into this Annex by reference, including provider name, service, purpose, data categories and status.
A provider marked *planned*, *optional* or *client-selected* on that page is not an active subprocessor for a given Client unless that Client has selected it or been notified of it.
| Purpose | Contact |
|---|---|
| Data protection and DPA questions | kaurpritpal112@gmail.com |
| Legal notices | kaurpritpal112@gmail.com |
| Data deletion requests | kaurpritpal112@gmail.com |
| Founder (direct) | kaurpritpal112@gmail.com |
Subprocessor objections and DPA queries can also be raised through the privacy and requests page.