Last updated: 29 August 2026

Data Processing Addendum

This DPA is between the business customer and LEADRESTORE LTD, company number 17401203, and applies where the customer is the controller of customer/lead personal data and LeadRestore processes that data on the customer’s behalf. It forms part of the LeadRestore service agreement when a business creates an account and agrees to the LeadRestore Terms and this DPA.

Processor contact. Privacy and data-processing notices: privacy@leadrestore.co.uk. Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. LEADRESTORE LTD is registered in England and Wales.

1. Roles and scope

The customer is the controller (or, where applicable, a processor acting for another controller). LEADRESTORE LTD is the processor for personal data the customer submits to the service for lead-recovery analysis and related recovery-workspace functions.

2. Customer instructions

LeadRestore will process customer personal data only on documented instructions from the customer, including instructions inherent in using the service, unless UK law requires otherwise. Where legally permitted, LeadRestore will inform the customer before processing required by law. If LeadRestore believes an instruction breaches applicable data-protection law, it may suspend that processing and inform the customer where legally permitted.

3. Details of processing

Subject matter and purpose

Lead analysis, prioritisation, suggested human follow-up, recovery-history storage for signed-in users, account synchronisation and related technical/security operations.

Duration

For transient guest audits, processing lasts only as long as needed to complete the audit plus any limited provider/security retention described in the Privacy Notice. For signed-in recovery history, processing continues until the customer deletes the data/account or the service relationship ends, subject to narrow legal/security retention requirements.

Types of personal data

Typical fields may include name, business contact details, enquiry status, dates/days since contact, quote/order/opportunity value, product/service context, notes and follow-up status. LeadRestore is not intended for special-category data, payment-card data, bank-account data, passwords or government identifiers.

Categories of data subjects

Customers, prospects, applicants, members, guests, candidates or other business contacts whose records the customer lawfully holds and chooses to analyse.

4. Confidentiality and access

LeadRestore will limit access to customer personal data to authorised people and systems that need it to operate, secure or support the service. Every person authorised to process customer personal data will be subject to an appropriate duty of confidentiality.

5. Security

LeadRestore will maintain appropriate technical and organisational measures proportionate to the service and risk, including HTTPS transport, authenticated account access, server-side secrets, database access controls, security headers, strong-password controls, leaked-password protection and restricted administrative access.

6. Subprocessors

The customer gives general written authorisation for LeadRestore to use subprocessors necessary to provide the service. The current list is published at Subprocessors & Service Providers. LeadRestore will require applicable contractual/data-protection terms and equivalent Article 28 protections where required, and LeadRestore remains responsible to the customer for the performance of its subprocessors’ data-protection obligations.

Where LeadRestore intends to add or replace a material subprocessor that processes customer lead data, it will update the published list and give customers reasonable written notice before the change takes effect where reasonably practicable. A customer may raise a reasonable written data-protection objection during that notice period. LeadRestore and the customer will work in good faith to address the objection; if it cannot reasonably be resolved, the customer may stop using the affected processing or terminate the affected service before the new subprocessor is used.

7. International transfers

Where a provider relationship involves a restricted transfer under UK data-protection law, LeadRestore will rely on the applicable lawful transfer mechanism made available under the relevant provider agreement, such as an adequacy route, UK Addendum, IDTA or equivalent safeguard as applicable.

8. Data-subject requests

Taking into account the nature of the processing, LeadRestore will use appropriate technical and organisational measures and provide reasonable assistance to the customer with requests to exercise data-protection rights. If LeadRestore receives a request relating to data controlled by the customer, LeadRestore may direct the individual to the customer unless required to act otherwise.

9. Security incidents

LeadRestore will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data and will provide available information reasonably needed for the customer’s own notification and assessment obligations.

10. DPIAs and regulatory assistance

Taking into account the information available to LeadRestore and the nature of processing, LeadRestore will provide reasonable assistance with security obligations, personal-data-breach notifications, data-protection impact assessments and prior consultation obligations where required by applicable law.

11. Deletion or return

At the end of the service and at the customer’s choice, LeadRestore will delete or return customer personal data processed on the customer’s behalf and delete existing copies, unless UK law requires storage. LeadRestore provides self-service account export and deletion controls for signed-in users; where additional assistance is reasonably required, the customer can contact privacy@leadrestore.co.uk.

12. Audit information

LeadRestore will make available information reasonably necessary to demonstrate compliance with its processor obligations and will allow for and contribute to audits and inspections conducted by the customer or an auditor mandated by the customer. Audit arrangements must be proportionate, protect other customers and confidential security information, and where appropriate may rely first on available documentation or relevant third-party assurance.

13. Customer obligations

The customer is responsible for the lawfulness, accuracy and transparency of the personal data it provides; for its lawful basis and privacy notices; for honouring opt-outs and direct-marketing rules; and for not providing data LeadRestore does not need.

14. Priority

If this DPA conflicts with the general LeadRestore Terms on matters specifically concerning processor obligations, this DPA takes priority for those matters.

15. Contact and notices

Data-processing notices, subprocessor objections and requests under this DPA should be sent to privacy@leadrestore.co.uk.