TalkToLeads legal
TalkToLeads respects your privacy. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you visit our website, submit a setup request, become a client, or interact with a TalkToLeads workflow.
Draft policy — legal review required before accepting payment or processing client lead data.
This document is a working draft prepared for review. It is not legal advice and should not be relied on. Passages in [INSERT …] mark decisions still to be made. Current version: DRAFT-v0.1.
TalkToLeads installs and maintains lead-response, qualification, routing, human-handoff and follow-up workflows for service businesses. We are not a CRM, a marketing agency, or a lead vendor.
| Detail | Value |
|---|---|
| Legal entity | [INSERT LEGAL ENTITY NAME] |
| Entity type | [INSERT ENTITY TYPE] |
| Country of establishment | India |
| Registered address | [INSERT REGISTERED BUSINESS ADDRESS] |
| Legal contact | kaurpritpal112@gmail.com |
| Privacy / grievance contact | kaurpritpal112@gmail.com |
| Founder (direct) | kaurpritpal112@gmail.com |
Pending confirmation
This policy applies to personal data relating to:
Two different relationships
We collect different categories of data for different reasons. Retention approaches below are summaries — section 10 has the detail.
| Data category | Examples | Why collected | Source | Retention approach |
|---|---|---|---|---|
| Website usage and cookie data | Cookie preferences, page views, CTA clicks, form-progress metadata, device and browser data, referral and UTM information | Operate the site, understand performance, remember your privacy choices | Your browser, subject to your consent choices | Per cookie duration — see Cookie Policy |
| Setup-request / application data | Name, business name, work email, phone or WhatsApp number, website URL, industry, country and time zone, lead volume, current tools, described business needs | Review whether a request fits our standard implementation scope, and respond to you | Submitted by you on the setup form | [INSERT PERIOD] for requests that do not become clients |
| Account and client-contact data | Named contacts, roles, routing owners, business addresses, communication preferences | Deliver and support the contracted service | Provided by the client during onboarding | Term of service, then per contract and law |
| Billing, invoice and payment-confirmation data | Invoice references, amounts, payment confirmation records, billing contact details | Issue invoices, confirm payment, meet accounting and tax obligations | You, and our payment provider | As required by applicable tax and accounting law |
| Client onboarding and workflow data | Lead sources, team structure, qualification requirements, approved message templates, routing rules, integration metadata, system configuration | Build, test, launch and maintain the agreed workflow | Provided by the client | Term of service, then per the DPA |
| Client lead / customer conversation data | Lead names, phone numbers, email addresses, enquiry messages, lead source, qualification answers, conversation activity, routing and handoff records | Operate the workflow the client has instructed us to run | The client’s own lead sources and channels | Per client instructions and the DPA |
| Consent and opt-out records | Records of consent captured, opt-out and suppression signals, timestamps | Honour choices and evidence that they were honoured | Leads, clients, and website visitors | Retained as long as needed to keep honouring the choice |
| Communications with us | Emails, messages, and notes from calls with our team | Answer enquiries, support clients, keep an account history | You | [INSERT PERIOD] |
| Support-ticket data | Issue descriptions, screenshots and logs you send us, resolution notes | Diagnose and resolve issues, track recurring problems | Client contacts | [INSERT PERIOD] |
| Employee and internal account data | Work identity, login and audit activity, client and project assignments | Operate our internal systems securely and control who can access what | Our own personnel systems | [INSERT PERIOD] |
| Security and audit logs | Access records, administrative actions, error and abuse signals | Protect systems, investigate incidents, prevent fraud and abuse | Generated by our systems | [INSERT PERIOD] |
We use personal data to:
What we do not do with client lead data
The grounds we rely on depend on where you are and which law applies. Depending on your jurisdiction, these may include:
This section matters most if you enquired with a business, not with us
Separately from operating client workflows, we process some data for our own purposes as an independent controller: securing and monitoring our platform, keeping audit and abuse-prevention records, maintaining billing and tax records, and producing aggregate operational statistics that do not identify individual leads. Those purposes are described in this policy rather than in the DPA.
Depending on our hosting arrangements, the providers involved, and the integrations a client selects, personal data may be processed in a country other than the one you are located in.
Where applicable law requires safeguards for such transfers, we will put appropriate safeguards in place.
Different categories are kept for different periods. Our default retention approach is [INSERT DEFAULT RETENTION PERIOD], adjusted per category as follows:
Backups are not instant
We use reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, loss, misuse and alteration.
Do not publish unverified security claims
No system or transmission method is completely secure. We cannot and do not guarantee absolute security. If you believe you have found a security issue, please contact us at the address in section 16.
Depending on your jurisdiction, you may have rights under applicable data-protection law, which may include:
To exercise a right, use the privacy request page. We may need to verify your identity, or your authority to act for someone else, before we can act on a request — this protects you from someone else obtaining your data.
We aim to respond within [INSERT RESPONSE TIMEFRAME — VARIES BY JURISDICTION]. Where applicable law sets a shorter or longer period, that period applies.
Our website and services are directed at businesses, not children. We do not knowingly collect personal data from children.
If you believe a child’s data has been provided to us, contact kaurpritpal112@gmail.com and we will take appropriate steps to delete it.
Clients remain responsible for ensuring their own workflows are not directed at children, and that any processing of children’s data meets the requirements of applicable law.
Our website and communications may link to sites and services we do not operate. Those are governed by their own privacy policies and terms, and we are not responsible for their content or practices.
We may update this policy as our service, providers, or legal obligations change. When we do, we update the version number and the “last updated” date shown at the top of this page.
Where a change is material and applicable law or our contract requires it, we will provide additional notice — for clients, through the account contact on file.
| Purpose | Contact |
|---|---|
| Privacy and grievance matters | kaurpritpal112@gmail.com |
| Legal matters | kaurpritpal112@gmail.com |
| Data deletion requests | kaurpritpal112@gmail.com |
| Founder (direct, if the above do not reach us) | kaurpritpal112@gmail.com |
| WhatsApp (general contact and meeting booking) | +91 74042 83363 |
| Registered address | [INSERT REGISTERED BUSINESS ADDRESS] |
The fastest route for a formal request is the privacy request page, which records your request and routes it to a named owner.
If you contact us on WhatsApp
Grievance Officer / DPO