Privacy Policy
Effective date: 1 January 2026  |  Version 1.0  |  Operated by Apiwave s.r.o.
🌐 ČeskΓ‘ verze  Β·  Terms of Service

Table of Contents

  1. Who We Are & How to Contact Us
  2. Scope of This Policy
  3. Our Role: Controller vs. Processor
  4. Personal Data We Collect
  5. How We Use Your Data & Legal Basis
  6. Email Integration & Data Processing
  7. Who We Share Your Data With
  8. International Data Transfers
  9. Data Retention
  10. Your Rights under GDPR
  11. Cookies & Tracking
  12. Children's Privacy
  13. Security
  14. Changes to This Policy

1 Who We Are & How to Contact Us

leanDeals is a CRM platform operated by Apiwave s.r.o., a company incorporated under the laws of the Czech Republic.

Legal EntityApiwave s.r.o.
CountryCzech Republic, European Union
Privacy Contactinfo@lean-deals.com
Websiteapp.lean-deals.com

For all privacy-related enquiries, requests, or complaints, please contact us at info@lean-deals.com. We will respond within 30 days.

2 Scope of This Policy

This Privacy Policy explains how leanDeals collects, uses, stores, and shares personal data when you:

This Policy does not cover data that Clients process within the Service about their own customers or contacts β€” that is addressed in our Data Processing Agreement (DPA), which governs our role as a data processor acting on your instructions.

3 Our Role: Controller vs. Processor

3.1 leanDeals as Data Controller

When we collect and process data about you directly β€” such as your account registration data, billing information, and usage data β€” we act as the data controller. This Privacy Policy describes our practices in that capacity.

3.2 leanDeals as Data Processor

When you use the Service to store, manage, and process data about your own contacts, customers, or employees (i.e., "Client Data"), we act as a data processor on your behalf. As a processor, we process Client Data solely according to your instructions as set out in our Data Processing Agreement (DPA).

You are the data controller for the personal data of your contacts stored in leanDeals. You are responsible for ensuring you have a lawful basis to store and process that data, and for responding to data subject requests from your contacts. If your contacts want to exercise their rights (access, deletion, etc.) regarding data you hold in leanDeals, they must contact you directly.

3.3 Data Processing Agreement

If you are subject to the GDPR as a data controller and use leanDeals to process Personal Data on your behalf, a Data Processing Agreement (DPA) is available upon request. Please contact info@lean-deals.com to obtain the DPA.

4 Personal Data We Collect

4.1 Account & Registration Data

DataPurpose
Full nameAccount creation, identification
Work email addressLogin, notifications, support
Company nameWorkspace creation, billing
Password (hashed)Authentication
Country / regionTax calculation, compliance

4.2 Billing & Payment Data

Payment processing is handled by Paddle as Merchant of Record. We do not store full credit card numbers or bank account details. We receive from Paddle: subscription status, invoice history, billing contact name, and the last four digits of your payment card for display purposes only.

4.3 Usage & Technical Data

DataPurpose
IP addressSecurity, fraud prevention, geolocation for compliance
Browser type and versionCompatibility, error diagnosis
Feature usage patternsProduct improvement (anonymised)
Error logsBug fixing, quality assurance
Login timestampsSecurity, audit trail

4.4 Email Integration Data

If you enable the email integration feature, we process email metadata as described in Section 6.

4.5 Communications Data

If you contact us via email, chat, or other means, we retain records of those communications to handle your enquiry and improve our support.

4.6 Special Categories of Data

We do not intentionally collect special categories of personal data (such as health data, racial or ethnic origin, political opinions, religious beliefs, or biometric data). Please do not store such data in the Service.

5 How We Use Your Data & Legal Basis

Purpose Data Used Legal Basis (GDPR Art. 6)
Providing and operating the Service Account data, usage data Art. 6(1)(b) β€” Contract performance
Processing payments and managing billing Billing data, account data Art. 6(1)(b) β€” Contract performance
Sending transactional communications (e.g., account confirmations, invoices, security alerts) Email address Art. 6(1)(b) β€” Contract performance
Providing customer support Account data, communications data Art. 6(1)(b) β€” Contract performance
Ensuring security and preventing fraud Technical data, IP address Art. 6(1)(f) β€” Legitimate interests
Product analytics and improvement (anonymised/aggregated only) Usage data (anonymised) Art. 6(1)(f) β€” Legitimate interests
Compliance with legal obligations (e.g., tax records) Billing data Art. 6(1)(c) β€” Legal obligation
Sending product updates and marketing (only with your consent) Email address Art. 6(1)(a) β€” Consent

Where we rely on legitimate interests (Art. 6(1)(f)), we have assessed that our interests are not overridden by your rights and freedoms. You may object to such processing at any time β€” see Section 10.

6 Email Integration & Data Processing

6.1 How It Works

The optional email integration feature enables you to connect your Gmail (via Google OAuth 2.0), Microsoft Outlook (via Microsoft OAuth 2.0), or other email accounts (via IMAP/SMTP) to leanDeals to synchronise email activity with your CRM records.

6.2 What We Process

We process the following email metadata when the integration is active:

We do not store full email body content.

6.3 Legal Basis

The email integration operates under Art. 6(1)(b) (contract performance) for the account holder, and you, as data controller, are responsible for having a valid legal basis to process the email data of third parties (e.g., your contacts) whose email addresses appear in the synced emails.

6.4 OAuth Tokens

OAuth access tokens and refresh tokens for Gmail and Outlook are stored in encrypted form in our database. We use these tokens solely to fetch email metadata on your behalf. You can revoke access at any time through your Google or Microsoft account settings, or by disconnecting the integration in leanDeals.

6.5 IMAP Credentials

IMAP usernames and passwords are stored in encrypted form. You are responsible for using appropriate app-specific passwords and for reviewing your email provider's policies regarding IMAP access.

6.6 Google API Disclosure

leanDeals's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7 Who We Share Your Data With

We do not sell your personal data. We share your data only with trusted third-party service providers ("sub-processors") who assist us in delivering the Service, subject to contractual data protection obligations. Our sub-processors fall into the following categories:

Category Purpose Data Transfer Location
Cloud infrastructure provider Hosting and server infrastructure for the application European Union
Database-as-a-service provider Database hosting, authentication, and storage European Union
Payment processor (Merchant of Record) Subscription billing, invoicing, tax remittance United Kingdom / EU
Transactional email provider Sending account notifications, system emails European Union
CI/CD and source code hosting Automated deployment pipelines (no Client Data access) United States (SCCs in place)

We may also disclose your data: (i) when required by law, court order, or regulatory authority; (ii) to protect the rights, property, or safety of leanDeals, its users, or the public; (iii) in connection with a business transfer, merger, or acquisition (with notice provided to affected users).

We will never sell your personal data or share it with third parties for their own marketing purposes without your explicit consent.

8 International Data Transfers

Our primary infrastructure is hosted in the European Union. Where any data transfer occurs outside the EU/EEA (for example, in connection with our CI/CD pipeline provider), we ensure appropriate safeguards are in place in accordance with GDPR Chapter V, including:

You may request more information about the specific safeguards applicable to any international transfer by contacting us at info@lean-deals.com.

9 Data Retention

Data Type Retention Period Reason
Account and profile data Duration of Subscription + 90 days after termination Service continuity, re-activation option
Client Data (CRM records) Duration of Subscription + 90 days after termination Data recovery window
Billing records 10 years Legal obligation (Czech accounting law)
Email metadata (if integration enabled) Duration of Subscription + 90 days after termination Consistent with Client Data retention
Support communications 3 years from last contact Legitimate interest (dispute resolution)
Security and access logs 12 months Security, fraud prevention
Anonymised usage analytics Indefinitely Product improvement (no personal data)

After the applicable retention period, data is permanently and securely deleted from our systems, including backups.

10 Your Rights under GDPR

If you are located in the European Union or European Economic Area, you have the following rights with respect to your personal data that we process as a data controller:

βœ“ Right of Access (Art. 15)

Request a copy of the personal data we hold about you.

βœ“ Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete personal data.

βœ“ Right to Erasure (Art. 17)

Request deletion of your personal data ("right to be forgotten") where we no longer have a legal basis for processing it.

βœ“ Right to Restriction (Art. 18)

Request that we restrict processing of your personal data in certain circumstances.

βœ“ Right to Data Portability (Art. 20)

Receive your personal data in a structured, commonly used, machine-readable format.

βœ“ Right to Object (Art. 21)

Object to processing based on legitimate interests or for direct marketing purposes.

βœ“ Withdraw Consent (Art. 7)

Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

βœ“ Right to Lodge a Complaint

Lodge a complaint with your national data protection authority (in Czech Republic: ÚOOÚ).

How to Exercise Your Rights

To exercise any of these rights, please contact us at info@lean-deals.com. We will respond within 30 days (extendable by two additional months for complex requests, with prior notice). We may request identity verification before processing your request.

Note: These rights apply to data we process as a data controller (e.g., your account and billing data). For data you store in leanDeals about your own contacts (Client Data), you are the data controller. Requests from those individuals must be directed to you.

11 Cookies & Tracking

11.1 Cookies Used

We use a limited number of cookies strictly necessary to operate the Service:

Cookie Type Purpose Duration
Session cookies Maintain your authenticated session Session (deleted on browser close)
Authentication token Keep you logged in between sessions Up to 30 days
Preference cookies Remember your UI settings (language, theme) Up to 12 months

11.2 No Third-Party Tracking

We do not currently use third-party advertising cookies or behavioural tracking technologies within the authenticated Service environment.

11.3 Managing Cookies

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.

12 Children's Privacy

The Service is not intended for, and must not be used by, individuals under the age of 18. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected personal data from a minor, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us at info@lean-deals.com.

13 Security

We implement industry-standard technical and organisational measures to protect your personal data, including:

Despite these measures, no system is completely secure. In the event of a personal data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with GDPR Articles 33 and 34 (within 72 hours of becoming aware, where feasible).

14 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will notify you by email or by a prominent notice within the Service at least 30 days before the changes take effect.

The "Effective date" at the top of this document indicates when this version took effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

For any privacy-related questions, please contact us at info@lean-deals.com.