leanDeals
Privacy Policy
Effective date: 13 August 2026  |  Version 1.1  |  Operated by Apiwave s.r.o.
🌐 ČeskΓ‘ verze  Β·  Terms of Service

Table of Contents

  1. Who We Are & How to Contact Us
  2. Scope of This Policy
  3. Our Role: Controller vs. Processor
  4. Personal Data We Collect
  5. How We Use Your Data & Legal Basis
  6. Email Integration & Data Processing
  7. Who We Share Your Data With
  8. International Data Transfers
  9. Data Retention
  10. Your Rights under GDPR
  11. Cookies & Tracking
  12. Children's Privacy
  13. Security
  14. Changes to This Policy

1 Who We Are & How to Contact Us

leanDeals is a CRM platform operated by Apiwave s.r.o., a company incorporated under the laws of the Czech Republic.

Legal EntityApiwave s.r.o.
CountryCzech Republic, European Union
Privacy Contactinfo@lean-deals.com
Websiteapp.lean-deals.com

For all privacy-related enquiries, requests, or complaints, please contact us at info@lean-deals.com. We will respond within 30 days.

2 Scope of This Policy

This Privacy Policy explains how leanDeals collects, uses, stores, and shares personal data when you:

This Policy does not cover data that Clients process within the Service about their own customers or contacts β€” that is addressed in our Data Processing Agreement (DPA), which governs our role as a data processor acting on your instructions.

3 Our Role: Controller vs. Processor

3.1 leanDeals as Data Controller

When we collect and process data about you directly β€” such as your account registration data, billing information, and usage data β€” we act as the data controller. This Privacy Policy describes our practices in that capacity.

3.2 leanDeals as Data Processor

When you use the Service to store, manage, and process data about your own contacts, customers, or employees (i.e., "Client Data"), we act as a data processor on your behalf. As a processor, we process Client Data solely according to your instructions as set out in our Data Processing Agreement (DPA).

You are the data controller for the personal data of your contacts stored in leanDeals. You are responsible for ensuring you have a lawful basis to store and process that data, and for responding to data subject requests from your contacts. If your contacts want to exercise their rights (access, deletion, etc.) regarding data you hold in leanDeals, they must contact you directly.

3.3 Data Processing Agreement

If you are subject to the GDPR as a data controller and use leanDeals to process Personal Data on your behalf, a Data Processing Agreement (DPA) is available upon request. Please contact info@lean-deals.com to obtain the DPA.

4 Personal Data We Collect

4.1 Account & Registration Data

DataPurpose
Full nameAccount creation, identification
Work email addressLogin, notifications, support
Company nameWorkspace creation, billing
Password (hashed)Authentication
Country / regionTax calculation, compliance

4.2 Billing & Payment Data

Payment processing is handled by Paddle as Merchant of Record. We do not store full credit card numbers or bank account details. We receive from Paddle: subscription status, invoice history, billing contact name, and the last four digits of your payment card for display purposes only.

4.3 Usage & Technical Data

DataPurpose
IP addressSecurity, fraud prevention, geolocation for compliance
Browser type and versionCompatibility, error diagnosis
Feature usage patternsProduct improvement (anonymised)
Error logsBug fixing, quality assurance
Login timestampsSecurity, audit trail

4.4 Email Integration Data

If you enable the email integration feature, we process email metadata as described in Section 6.

4.5 Communications Data

If you contact us via email, chat, or other means, we retain records of those communications to handle your enquiry and improve our support.

4.6 Special Categories of Data

We do not intentionally collect special categories of personal data (such as health data, racial or ethnic origin, political opinions, religious beliefs, or biometric data). Please do not store such data in the Service.

5 How We Use Your Data & Legal Basis

Purpose Data Used Legal Basis (GDPR Art. 6)
Providing and operating the Service Account data, usage data Art. 6(1)(b) β€” Contract performance
Processing payments and managing billing Billing data, account data Art. 6(1)(b) β€” Contract performance
Sending transactional communications (e.g., account confirmations, invoices, security alerts) Email address Art. 6(1)(b) β€” Contract performance
Providing customer support Account data, communications data Art. 6(1)(b) β€” Contract performance
Ensuring security and preventing fraud Technical data, IP address Art. 6(1)(f) β€” Legitimate interests
Product analytics and improvement (anonymised/aggregated only) Usage data (anonymised) Art. 6(1)(f) β€” Legitimate interests
Compliance with legal obligations (e.g., tax records) Billing data Art. 6(1)(c) β€” Legal obligation
Sending product updates and marketing (only with your consent) Email address Art. 6(1)(a) β€” Consent

Where we rely on legitimate interests (Art. 6(1)(f)), we have assessed that our interests are not overridden by your rights and freedoms. You may object to such processing at any time β€” see Section 10.

6 Email Integration & Data Processing

6.1 How It Works

The optional email integration feature enables you to connect your Gmail (via Google OAuth 2.0), Microsoft Outlook (via Microsoft OAuth 2.0), or other email accounts (via IMAP/SMTP) to leanDeals to synchronise email activity with your CRM records.

6.2 What We Process

We process the following email metadata when the integration is active:

We do not store full email body content.

6.3 Legal Basis

The email integration operates under Art. 6(1)(b) (contract performance) for the account holder, and you, as data controller, are responsible for having a valid legal basis to process the email data of third parties (e.g., your contacts) whose email addresses appear in the synced emails.

6.4 OAuth Tokens

OAuth access tokens and refresh tokens for Gmail and Outlook are stored in encrypted form in our database. We use these tokens solely to fetch email metadata on your behalf. You can revoke access at any time through your Google or Microsoft account settings, or by disconnecting the integration in leanDeals.

6.5 IMAP Credentials

IMAP usernames and passwords are stored in encrypted form. You are responsible for using appropriate app-specific passwords and for reviewing your email provider's policies regarding IMAP access.

6.6 Google API Disclosure

leanDeals's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7 Who We Share Your Data With

We do not sell your personal data. We share your data only with trusted third-party service providers ("sub-processors") who assist us in delivering the Service, subject to contractual data protection obligations. Our sub-processors fall into the following categories:

Category Purpose Data Transfer Location
Cloud infrastructure provider Hosting and server infrastructure for the application European Union
Database-as-a-service provider Database hosting, authentication, and storage European Union
Payment processor (Merchant of Record) Subscription billing, invoicing, tax remittance United Kingdom / EU
Transactional email provider Sending account notifications, system emails European Union
CI/CD and source code hosting Automated deployment pipelines (no Client Data access) United States (SCCs in place)
Traffic and advertising measurement (Google) Google Analytics 4 and Google Signals on our website β€” only with your consent and with no access to Client Data (see 11.3) Ireland / United States (EU-US DPF)
Behaviour analytics (Microsoft) Microsoft Clarity β€” session recording and heatmaps on our website; only with your consent and with no access to Client Data (see 11.3) Ireland / United States (EU-US DPF)
Advertising measurement (Meta) Meta Pixel β€” measuring Facebook and Instagram ad performance; only with your consent and with no access to Client Data (see 11.3) Ireland / United States (EU-US DPF)

We may also disclose your data: (i) when required by law, court order, or regulatory authority; (ii) to protect the rights, property, or safety of leanDeals, its users, or the public; (iii) in connection with a business transfer, merger, or acquisition (with notice provided to affected users).

We will never sell your personal data or share it with third parties for their own marketing purposes without your explicit consent.

8 International Data Transfers

Our primary infrastructure is hosted in the European Union. Where any data transfer occurs outside the EU/EEA (for example, in connection with our CI/CD pipeline provider), we ensure appropriate safeguards are in place in accordance with GDPR Chapter V, including:

If you consent to marketing cookies (see 11.3), a limited set of data about your website visit is additionally shared with three recipients in Ireland β€” Google Ireland Limited, Microsoft Ireland Operations Limited and Meta Platforms Ireland Limited β€” and may be onward transferred to their parent companies in the United States (Google LLC, Microsoft Corporation, Meta Platforms, Inc.). Those transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework, in which all three are certified participants, supplemented by Standard Contractual Clauses. Without your consent none of these transfers takes place.

You may request more information about the specific safeguards applicable to any international transfer by contacting us at info@lean-deals.com.

9 Data Retention

Data Type Retention Period Reason
Account and profile data Duration of Subscription + 90 days after termination Service continuity, re-activation option
Client Data (CRM records) Duration of Subscription + 90 days after termination Data recovery window
Billing records 10 years Legal obligation (Czech accounting law)
Email metadata (if integration enabled) Duration of Subscription + 90 days after termination Consistent with Client Data retention
Support communications 3 years from last contact Legitimate interest (dispute resolution)
Security and access logs 12 months Security, fraud prevention
Anonymised usage analytics Indefinitely Product improvement (no personal data)

After the applicable retention period, data is permanently and securely deleted from our systems, including backups.

10 Your Rights under GDPR

If you are located in the European Union or European Economic Area, you have the following rights with respect to your personal data that we process as a data controller:

βœ“ Right of Access (Art. 15)

Request a copy of the personal data we hold about you.

βœ“ Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete personal data.

βœ“ Right to Erasure (Art. 17)

Request deletion of your personal data ("right to be forgotten") where we no longer have a legal basis for processing it.

βœ“ Right to Restriction (Art. 18)

Request that we restrict processing of your personal data in certain circumstances.

βœ“ Right to Data Portability (Art. 20)

Receive your personal data in a structured, commonly used, machine-readable format.

βœ“ Right to Object (Art. 21)

Object to processing based on legitimate interests or for direct marketing purposes.

βœ“ Withdraw Consent (Art. 7)

Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

βœ“ Right to Lodge a Complaint

Lodge a complaint with your national data protection authority (in Czech Republic: ÚOOÚ).

How to Exercise Your Rights

To exercise any of these rights, please contact us at info@lean-deals.com. We will respond within 30 days (extendable by two additional months for complex requests, with prior notice). We may request identity verification before processing your request.

Note: These rights apply to data we process as a data controller (e.g., your account and billing data). For data you store in leanDeals about your own contacts (Client Data), you are the data controller. Requests from those individuals must be directed to you.

11 Cookies & Tracking

11.1 Essential cookies

We need the following cookies to operate the Service and this website. They do not require your consent, because the Service would not work without them, and they cannot be switched off:

Cookie Type Purpose Duration
Session cookies Maintain your authenticated session Session (deleted on browser close)
Authentication token Keep you logged in between sessions Up to 30 days
Preference cookies Remember your UI settings (language, theme) Up to 12 months
cc_cookie Stores your cookie choice so we do not ask on every visit 6 months

11.2 First-party analytics β€” only with your consent

We measure how visitors move through our website and signup so we can improve them. We collect this data ourselves, on our own infrastructure, and share it with no third party. We store the event name, timestamp, page address, traffic source (UTM parameters) and a random identifier held in your browser (ld_anon_id).

We do not store your IP address. It is immediately replaced with an irreversible salted SHA-256 hash used solely for abuse protection.

Legal basis. This measurement runs solely on the basis of your consent under Art. 6(1)(a) GDPR and Section 89(3) of Czech Act No. 127/2005 Coll., on Electronic Communications. Until you give consent, the measurement script does not load at all. Data is retained for 24 months. If you withdraw consent, we delete the stored identifiers from your browser.

11.3 Google Tag Manager, advertising measurement and session recording

Our website uses Google Tag Manager. It is a single script, but it runs tools belonging to three different companies:

Tool Controller What it does
Google Analytics 4 Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
Measures traffic and, through Google Signals, how well our advertising performs.
Microsoft Clarity Microsoft Ireland Operations Limited
One Microsoft Place, Dublin 18, Ireland
Records how your visit unfolds β€” mouse movement, clicks, scrolling and the content of the pages you view β€” and turns it into heatmaps and replayable recordings.
Meta Pixel Meta Platforms Ireland Limited
Merrion Road, Dublin 4, Ireland
Measures which Facebook and Instagram ads brought people interested in leanDeals.

Without your consent not one of them loads. The Google Tag Manager code on the page stays blocked until you choose "Accept all" in the cookie bar or enable the "Marketing and behaviour analytics" category. Until then we send Google, Microsoft and Meta no data whatsoever, including your IP address.

Nothing loads from a foreign domain before you decide. The font and the CSS framework this site uses are hosted on our own server, precisely so that merely rendering the page does not announce you to anyone. The only request that leaves before you decide goes to our own domain, and it is the record of your choice described in 11.5.

On session recording specifically. Clarity records how you move around the page and makes that recording available to us for replay. Consenting to "Marketing and behaviour analytics" includes this β€” if you would rather not be recorded, leave that category off, or switch it off at any time. The rest of the site works exactly the same.

Third-party cookies. If you consent to marketing, Microsoft sets cookies on its own domains (MUID, MR, SRM_B, ANONCHK and SM on clarity.ms and bing.com). Those are not ours and we cannot delete them for you β€” refusing stops them being set again, and you can clear them in your browser settings. The cookies created on our own domain (_ga, _ga_JT1PQL0BTN, _fbp, _clck, _clsk) we delete ourselves when you withdraw consent.

If you do consent, these companies may process your IP address, cookie identifiers, browser information and details of how you move around our website. Towards Google we use Google Consent Mode v2, which passes your current choice as four separate signals, so changing your settings immediately changes the scope of processing. Clarity and the Meta Pixel have no such continuous signal β€” with them, what matters is that they never start without consent.

The legal basis is your consent under Art. 6(1)(a) GDPR and Section 89(3) of the Electronic Communications Act. You may withdraw consent at any time (see 11.4); withdrawal does not affect the lawfulness of processing carried out before it.

Transfers outside the EU. Google Ireland Limited may transfer data to Google LLC in the United States. The transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework, in which Google LLC is a certified participant, supplemented by Standard Contractual Clauses. See the Google Privacy Policy for details.

11.4 Managing and withdrawing consent

You can change your choice at any time via the "Cookie settings" link in the footer of any page. This opens a dialog where you can switch individual categories on or off. Withdrawing consent is as easy as giving it.

You can also control cookies through your browser settings. Disabling essential cookies may affect the functionality of the Service.

11.5 Record of your decision

Whenever you make a choice in the cookie bar β€” consent, refusal, or a later change β€” we store a record of it on our own server. We have to be able to demonstrate that we asked and what you answered; this is required by Art. 7(1) GDPR and by Google's EU User Consent Policy. A cookie sitting in your own browser, which you can clear at any time, is not evidence of anything.

What the record contains: the random consent identifier that is also stored in your cc_cookie; the time of the decision; which categories you allowed and which you refused; the version of the banner wording you saw; the language; the address of the page you decided on; browser information; and an irreversible salted SHA-256 hash of your IP address. We do not store your IP address.

What it does not contain: any identifier from our traffic measurement. The proof of consent and the data about how you move around the site are kept apart and never joined β€” otherwise a legal obligation would turn into surveillance.

The legal basis is not consent but our legal obligation and legitimate interest in being able to demonstrate it, under Art. 6(1)(c) and (f) read with Art. 7(1) GDPR. That is why a record is created even when you refuse everything. We keep it for 3 years from the decision β€” longer than the consent itself (6 months), because the evidence has to outlive any dispute it might be needed for. After that it is deleted automatically.

12 Children's Privacy

The Service is not intended for, and must not be used by, individuals under the age of 18. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected personal data from a minor, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us at info@lean-deals.com.

13 Security

We implement industry-standard technical and organisational measures to protect your personal data, including:

Despite these measures, no system is completely secure. In the event of a personal data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with GDPR Articles 33 and 34 (within 72 hours of becoming aware, where feasible).

14 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will notify you by email or by a prominent notice within the Service at least 30 days before the changes take effect.

The "Effective date" at the top of this document indicates when this version took effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

For any privacy-related questions, please contact us at info@lean-deals.com.