Privacy Policy

Effective Date: August 2025 Last Updated: June 2026

1. Introduction

Welcome to LeadNest.ai, a product owned and operated by Bizionic Technologies Midwest Inc., an Illinois corporation ("LeadNest," "Bizionic," "we," "our," or "us").

LeadNest.ai is an omnichannel customer engagement, communication, artificial intelligence, and customer relationship management platform that enables organizations to communicate with customers across multiple channels including SMS, MMS, WhatsApp, Email, Push Notifications, Web Push, In-App Messaging, Voice, AI-powered assistants, APIs, CRM, Forms, Meetings, Cloud Storage, Analytics, and related services.

We are committed to protecting your privacy and processing personal information lawfully, fairly, transparently, and securely.

This Privacy Policy explains:

  • What information we collect;
  • How we collect it;
  • Why we collect it;
  • How we use it;
  • How we protect it;
  • When we share it;
  • How long we retain it; and
  • Your rights regarding your personal information.

This Privacy Policy should be read together with our:

  • Terms of Service
  • Acceptable Use Policy
  • Cancellation & Refund Policy
  • Security & Compliance Policy
  • Cookie Policy
  • Data Processing Agreement (where applicable)
  • HIPAA Business Associate Agreement (where applicable)

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.

2. Scope of this Privacy Policy

This Privacy Policy applies to personal information processed by LeadNest.ai in connection with:

  • LeadNest.ai websites
  • Mobile applications
  • APIs
  • SDKs
  • Customer engagement platform
  • Messaging services
  • CRM modules
  • AI Services
  • Meeting platform
  • Cloud storage
  • Forms and surveys
  • Analytics
  • Customer Support
  • Marketing activities
  • Enterprise Services

This Privacy Policy applies whether you access the Services through:

  • Desktop browsers
  • Mobile devices
  • APIs
  • Third-party integrations
  • OAuth providers
  • Connected applications

This Privacy Policy does not apply to:

  • Third-party websites;
  • Third-party applications;
  • Customer-owned applications;
  • Services not controlled by LeadNest.

Those services remain governed by their respective privacy policies.

3. Who This Privacy Policy Applies To

This Privacy Policy applies to the following categories of individuals.

Category Description
Platform Customers Organizations and individuals who register for or purchase LeadNest Services.
Authorized Users Employees, contractors, administrators, or representatives authorized to access Customer Accounts.
Website Visitors Individuals visiting LeadNest.ai websites or landing pages.
Mobile Application Users Individuals using LeadNest-powered mobile applications.
End Users Individuals who receive communications sent by Customers through the LeadNest platform, including SMS, MMS, WhatsApp, Email, Push Notifications, Voice, In-App Messaging, and Web Push Notifications.
Healthcare Organizations Healthcare providers, hospitals, clinics, medical professionals, and other healthcare organizations using HIPAA-enabled Services.
Patients Where LeadNest processes Protected Health Information ("PHI") on behalf of healthcare organizations acting as Covered Entities or Business Associates.
Developers Developers integrating with LeadNest APIs, SDKs, Webhooks, OAuth integrations, or developer tools.
Business Partners Business contacts, vendors, resellers, implementation partners, consultants, and prospective customers.

4. Data Controller & Data Processor

Depending upon the Services provided, LeadNest may act either as a Data Controller or a Data Processor.

When LeadNest Acts as a Data Controller

LeadNest acts as a Data Controller when processing personal information relating to:

  • Website visitors;
  • Marketing communications;
  • Sales inquiries;
  • Customer support;
  • Billing and subscriptions;
  • Vendor management;
  • Business contacts;
  • Events and webinars;
  • Employment and recruitment;
  • Platform administration.

In these situations, LeadNest determines the purposes and means of processing personal information.

When LeadNest Acts as a Data Processor

LeadNest acts as a Data Processor when processing Customer Data on behalf of Customers using the Services. Examples include:

  • Sending SMS campaigns
  • Sending Email campaigns
  • Sending WhatsApp messages
  • Delivering Push Notifications
  • Managing CRM records
  • Storing customer contacts
  • Processing analytics
  • AI-assisted workflows
  • Managing meetings
  • Processing healthcare information

Customers remain responsible for ensuring they have appropriate legal authority to process the personal information they submit through the Services.

Customer Responsibilities

Customers are responsible for:

  • Obtaining lawful consent;
  • Providing required privacy notices;
  • Responding to data subject requests;
  • Managing user permissions;
  • Complying with applicable privacy laws.

LeadNest processes Customer Data only in accordance with Customer instructions, applicable agreements, and applicable law.

5. Information We Collect

The categories of information we collect depend on how you interact with the Services.

Identity Information

We may collect:

  • Full name
  • Email address
  • Telephone number
  • Company name
  • Job title
  • Business address
  • Country
  • Profile photograph (optional)

Account Information

We may collect:

  • Username
  • Password (encrypted or hashed)
  • Multi-factor authentication settings
  • Security questions
  • Login history
  • API keys
  • OAuth credentials
  • Account preferences

Messaging Information

We may process:

  • Email addresses
  • Mobile numbers
  • WhatsApp numbers
  • Push subscription identifiers
  • Device tokens
  • Message status
  • Delivery status
  • Bounce information
  • Read receipts
  • Click tracking
  • Engagement history
  • Consent records
  • Opt-in timestamps
  • Opt-out history

CRM Information

Customers may store:

  • Contacts
  • Leads
  • Opportunities
  • Companies
  • Activities
  • Notes
  • Sales pipelines
  • Customer interactions
  • Custom fields

Technical Information

We automatically collect certain technical information including:

  • IP address
  • Browser type
  • Browser version
  • Device identifiers
  • Device type
  • Operating system
  • Language settings
  • Time zone
  • Internet service provider
  • Network information
  • Session identifiers
  • Referring URLs
  • Error logs
  • Diagnostic information

Usage Information

We collect information regarding how the Services are used, including:

  • Login history
  • Platform usage
  • Feature usage
  • API requests
  • Workflow execution
  • Reports generated
  • Search history
  • Settings changes
  • Campaign activity
  • Analytics events

Payment Information

Where applicable, we collect:

  • Billing address
  • Subscription information
  • Invoice history
  • Payment status
  • Tax information

Payment card information is processed by PCI-DSS compliant third-party payment processors and is not stored by LeadNest except where necessary for billing administration.

AI Service Information

When Customers use AI-powered Services, we may process:

  • User prompts
  • AI requests
  • AI-generated responses
  • Workflow context
  • AI usage analytics
  • Performance metrics

AI-generated outputs should always be reviewed by Customers before being relied upon or distributed.

Healthcare Information

Where HIPAA-enabled Services are used, LeadNest may process Protected Health Information ("PHI") solely as instructed by the applicable Covered Entity or Business Associate and pursuant to a signed Business Associate Agreement (BAA).

Cookies & Device Information

LeadNest uses cookies, SDKs, pixels, and similar technologies to:

  • Maintain user sessions
  • Authenticate users
  • Improve performance
  • Prevent fraud
  • Measure usage
  • Personalize experiences
  • Support analytics

Additional information regarding cookies is provided in the Cookie Policy.

6. Google Workspace & Google API Data Usage

LeadNest.ai allows Customers to securely connect Google Workspace services, including Google Calendar, to enable scheduling, availability checking, meeting management, and related collaboration features.

LeadNest accesses Google Workspace data only with the explicit authorization of the user and only for the functionality requested by the user.

Google Calendar Permissions

Where authorized by the user, LeadNest may request permissions including:

  • View calendar settings
  • View calendar availability
  • View calendars and events
  • Create calendar events
  • Modify calendar events
  • Delete calendar events

LeadNest requests only the minimum permissions required to provide requested functionality.

Google API Services User Data

LeadNest's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use Requirements.

Google Workspace API data is used solely to provide requested platform functionality. LeadNest does not:

  • Sell Google user data;
  • Use Google user data for advertising;
  • Share Google user data for marketing purposes;
  • Build advertising profiles using Google Workspace data.

Artificial Intelligence Restrictions

Google Workspace API data is never used to train generalized artificial intelligence models, machine learning models, or similar technologies. Google Workspace information is processed only to provide user-requested functionality.

Revoking Access

Users may revoke Google account access at any time through:

  • Google Account Security Settings;
  • Google Connected Apps;
  • LeadNest Account Settings (where available).

Upon revocation, LeadNest will no longer access Google Workspace data except where necessary to comply with legal obligations or complete previously initiated operations.

7. How We Collect Information

LeadNest collects information from multiple sources depending on how the Services are used. We may collect information:

  • Directly from you when you create an account, submit forms, communicate with us, or use the Services.
  • Automatically through your interactions with our websites, applications, APIs, SDKs, cookies, and analytics tools.
  • From third-party integrations and connected services that you authorize, such as Google Workspace or other supported platforms.
  • From Customers who upload or synchronize contact data into the Services.
  • From service providers that support billing, authentication, messaging, hosting, analytics, fraud prevention, and other operational functions.
  • From publicly available sources where permitted by applicable law.

8. How We Use Your Information

LeadNest uses personal information only for legitimate business purposes and in accordance with applicable law. We may use personal information to:

  • Provide, operate, maintain, and improve the Services.
  • Create and manage user accounts.
  • Deliver SMS, MMS, Email, WhatsApp, Voice, Push, Web Push, and In-App communications.
  • Manage customer relationships, contacts, leads, campaigns, and workflows.
  • Process payments, subscriptions, invoices, and billing.
  • Authenticate users and protect account security.
  • Detect, investigate, and prevent fraud, abuse, unauthorized access, and other security incidents.
  • Monitor platform performance, reliability, and service quality.
  • Provide customer support and respond to inquiries.
  • Generate reports, analytics, and business insights.
  • Develop, test, and improve platform features and functionality.
  • Comply with legal, regulatory, contractual, and industry obligations.
  • Support healthcare customers in accordance with applicable HIPAA requirements where a Business Associate Agreement is in place.

LeadNest does not sell personal information and processes Customer Data only for the purposes authorized by the Customer or otherwise permitted by applicable law.

9. Messaging Privacy & Communications

LeadNest provides an omnichannel communications platform that enables Customers to send transactional and promotional messages through various communication channels, including SMS, MMS, WhatsApp, Email, Voice, Push Notifications, Web Push Notifications, and In-App Messaging.

LeadNest processes messaging data solely to provide the Services requested by Customers and in accordance with applicable laws, industry standards, and contractual obligations.

Consent Management

Customers are solely responsible for obtaining all legally required permissions before sending communications through the Services. Where applicable, LeadNest may process and store consent records including:

  • Date and time of consent
  • IP address
  • Consent source
  • Web form or application
  • Double opt-in status
  • Privacy Policy acceptance
  • Terms of Service acceptance
  • Campaign source
  • Opt-in method

LeadNest may retain consent records to satisfy carrier audits, regulatory inquiries, legal obligations, or contractual requirements.

SMS & MMS Messaging

Customers using SMS or MMS services are responsible for complying with all applicable messaging regulations, including:

  • Telephone Consumer Protection Act (TCPA)
  • CTIA Messaging Principles
  • 10DLC registration requirements
  • Carrier-specific messaging policies
  • Applicable local telecommunications laws

LeadNest processes SMS and MMS data only for message delivery, routing, analytics, reporting, fraud prevention, and compliance purposes.

WhatsApp Business Messaging

LeadNest supports WhatsApp Business messaging through approved service providers. Customers using WhatsApp messaging are responsible for complying with:

  • WhatsApp Business Messaging Policy
  • Meta Platform Terms
  • Applicable messaging regulations
  • Recipient consent requirements

LeadNest processes WhatsApp message metadata solely to provide messaging functionality and related analytics.

Email Communications

LeadNest processes email communications to enable Customers to send transactional and marketing emails. Email processing may include:

  • Delivery status
  • Bounce information
  • Spam reports
  • Open tracking
  • Click tracking
  • Unsubscribe requests
  • Delivery diagnostics

Customers remain responsible for complying with applicable anti-spam legislation, including the CAN-SPAM Act, CASL, GDPR, and other applicable laws.

Push Notifications

LeadNest may process:

  • Device tokens
  • Push subscription identifiers
  • Delivery status
  • Notification opens
  • Engagement metrics
  • Device information necessary for notification delivery

Voice Communications

Voice services may process:

  • Phone numbers
  • Call metadata
  • Call duration
  • Routing information
  • Quality metrics
  • Recording preferences where enabled

Call recordings are processed only where enabled by the Customer and permitted by applicable law.

Opt-Out Requests

LeadNest supports recipient opt-out mechanisms. Recipients may unsubscribe using supported methods such as:

  • Reply STOP
  • UNSUBSCRIBE
  • Account preferences
  • Customer-managed preference centers

LeadNest processes opt-out requests promptly and maintains suppression records as required by applicable law.

HELP Requests

Where required by applicable messaging regulations, HELP requests may provide support contact information, business identification, and additional messaging disclosures.

Message Retention

Message content and metadata are retained only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, investigate abuse, and enforce agreements.

10. Artificial Intelligence (AI) Services

LeadNest offers AI-powered features designed to assist Customers with communication, automation, analytics, workflow optimization, and customer engagement. AI Services may include:

  • AI Assistants
  • AI Chat
  • AI Workflow Automation
  • AI Campaign Generation
  • AI Recommendations
  • AI Summaries
  • AI Content Generation
  • AI Analytics
  • AI Classification
  • AI Search
  • AI Translation

AI Processing

When Customers use AI Services, LeadNest may process:

  • User prompts
  • Conversation history
  • Workflow context
  • Customer-provided information
  • Generated outputs
  • AI performance metrics

Processing occurs solely to provide the requested AI functionality.

Customer Responsibility

Customers remain solely responsible for reviewing, validating, approving, and verifying all AI-generated outputs before relying upon them. AI outputs should not be considered professional advice. Customers should independently verify information before using AI-generated content in:

  • Medical decisions
  • Legal matters
  • Financial decisions
  • Regulatory filings
  • Clinical documentation
  • Business decisions

AI Training

Unless explicitly disclosed and authorized, LeadNest does not use Customer Data or Google Workspace API data to train generalized artificial intelligence or machine learning models. Where third-party AI providers are used, processing is performed subject to contractual privacy and security obligations.

AI Limitations

Artificial intelligence systems are probabilistic in nature. AI-generated content may:

  • contain inaccuracies;
  • omit relevant information;
  • generate unexpected results; or
  • require human review.

LeadNest does not warrant the accuracy, completeness, legality, or suitability of AI-generated outputs.

12. How We Share Information

LeadNest does not sell personal information. We share information only where necessary to provide the Services, comply with legal obligations, protect our rights, or with Customer authorization. Information may be shared with:

  • Cloud infrastructure providers
  • Messaging providers
  • Payment processors
  • Authentication providers
  • Analytics providers
  • AI providers
  • Customer-authorized integrations
  • Professional advisors
  • Regulatory authorities where required by law

Corporate Transactions

Personal information may be transferred in connection with:

  • Merger
  • Acquisition
  • Corporate restructuring
  • Financing
  • Asset sale
  • Bankruptcy proceedings

Any successor entity will remain subject to obligations substantially consistent with this Privacy Policy.

Legal Compliance

LeadNest may disclose personal information where required to:

  • Comply with applicable law;
  • Respond to lawful requests;
  • Protect legal rights;
  • Prevent fraud;
  • Protect public safety;
  • Enforce agreements.

13. Third-Party Service Providers & Subprocessors

LeadNest works with carefully selected third-party providers to deliver and support the Services. Examples include providers for:

  • Cloud hosting
  • Data storage
  • Content delivery networks
  • Messaging services
  • Email delivery
  • Payment processing
  • Identity verification
  • Authentication
  • Artificial intelligence
  • Customer support
  • Monitoring
  • Security
  • Analytics

Each provider is contractually required to process information only for authorized purposes and implement appropriate security measures. LeadNest maintains and may publish a current list of significant subprocessors.

14. International Data Transfers

LeadNest operates globally. Personal information may be transferred to and processed in countries where LeadNest, its Affiliates, or its authorized service providers operate.

Where required by applicable law, LeadNest implements appropriate safeguards for international transfers, which may include:

  • Standard Contractual Clauses (SCCs)
  • Contractual data protection commitments
  • Adequacy decisions
  • Other legally recognized transfer mechanisms

Customers are responsible for ensuring they have appropriate legal authority for international transfers relating to Customer Data.

15. Data Retention

LeadNest retains personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy or as required by applicable law. Retention periods vary depending on the nature of the information, contractual obligations, legal requirements, customer settings, and operational needs. Examples include:

  • Account information: for the duration of the account and a reasonable period thereafter.
  • Messaging records: as required for delivery, analytics, auditing, and legal compliance.
  • Consent records: for the period required by applicable laws, carrier requirements, or regulatory obligations.
  • Billing records: in accordance with applicable accounting and tax requirements.
  • Security logs: for security monitoring, fraud prevention, and incident investigation.
  • Healthcare information: as required under applicable healthcare regulations and contractual agreements.

After the applicable retention period, information is securely deleted, anonymized, or otherwise disposed of in accordance with LeadNest's data retention and destruction practices.

16. Data Security

LeadNest maintains administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Security measures may include:

  • Encryption in transit
  • Encryption at rest
  • Multi-factor authentication (MFA)
  • Role-based access controls (RBAC)
  • Security monitoring
  • Audit logging
  • Network security controls
  • Vulnerability management
  • Penetration testing
  • Backup and disaster recovery procedures
  • Incident response processes
  • Employee security training

While LeadNest implements commercially reasonable safeguards, no system or method of transmission over the Internet can be guaranteed to be completely secure. Customers are also responsible for maintaining the security of their accounts, credentials, devices, and integrations.

17. Cookies & Similar Technologies

LeadNest uses cookies, pixels, local storage, SDKs, web beacons, and similar technologies to improve the functionality, security, performance, and usability of the Services. These technologies help us recognize devices, maintain secure sessions, remember user preferences, analyze platform performance, and enhance the overall user experience.

Essential Cookies

Essential cookies are required for the operation of the Services and cannot be disabled. These cookies support functions such as:

  • User authentication
  • Session management
  • Security verification
  • Load balancing
  • Fraud prevention
  • Platform functionality

Functional Cookies

Functional cookies remember user preferences and settings, including:

  • Language preferences
  • Time zone
  • Dashboard settings
  • Notification preferences
  • Accessibility settings

Analytics Cookies

Analytics cookies help LeadNest understand how the Services are used. Information collected may include:

  • Pages visited
  • Feature usage
  • Navigation behavior
  • Session duration
  • Error reports
  • Performance metrics

Analytics data is used to improve the Services and user experience.

Performance Cookies

Performance technologies help monitor:

  • Platform speed
  • Response times
  • System reliability
  • Service availability
  • Application performance

Advertising Cookies

LeadNest does not use Customer Data or Google Workspace API data for advertising profiling. Where advertising cookies are used on LeadNest websites, they relate solely to LeadNest's own marketing activities and are subject to applicable consent requirements.

Managing Cookies

Most web browsers allow users to:

  • Accept or reject cookies
  • Delete stored cookies
  • Configure cookie preferences
  • Receive notifications before cookies are stored

Disabling certain cookies may affect the availability or functionality of certain Services. Additional information is available in our Cookie Policy.

18. Your Privacy Rights

Depending on your location and applicable law, you may have certain privacy rights regarding your personal information. LeadNest will respond to verified requests in accordance with applicable legal requirements.

Right of Access

You may request confirmation of whether we process your personal information and obtain access to that information.

Right to Correction

You may request correction of inaccurate or incomplete personal information.

Right to Deletion

You may request deletion of your personal information where permitted by applicable law. Certain information may be retained where necessary to:

  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements
  • Prevent fraud
  • Protect security
  • Maintain required business records

Right to Restrict Processing

Where permitted by law, you may request restriction of certain processing activities.

Right to Data Portability

Where applicable, you may request a copy of your personal information in a structured, commonly used, and machine-readable format.

Right to Object

You may object to processing based on legitimate interests where permitted by applicable law.

Right to Withdraw Consent

Where processing is based upon consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted before withdrawal.

Marketing Preferences

You may opt out of promotional communications by:

  • Updating account preferences
  • Using unsubscribe links
  • Replying STOP to supported messaging channels
  • Contacting our Privacy Team

Transactional communications necessary to provide the Services may continue where legally permitted.

California Privacy Rights

Residents of California may have additional rights under applicable California privacy laws, including rights to:

  • Know
  • Access
  • Correct
  • Delete
  • Limit certain processing
  • Appeal decisions where applicable

LeadNest does not sell personal information as defined under applicable California law.

European Privacy Rights

Individuals located within the European Economic Area (EEA), United Kingdom, or Switzerland may exercise rights provided under the General Data Protection Regulation (GDPR) or applicable local privacy legislation.

India Privacy Rights

Individuals located in India may exercise applicable rights under the Digital Personal Data Protection Act (DPDPA), including rights relating to access, correction, erasure, grievance redressal, and withdrawal of consent, where applicable.

19. Children's Privacy

LeadNest Services are intended for business and professional use. The Services are not directed toward children under the age of thirteen (13), and LeadNest does not knowingly collect personal information from children. Where applicable law establishes a higher minimum age, the applicable age requirement shall apply.

If LeadNest becomes aware that personal information has been collected from a child in violation of applicable law, reasonable steps will be taken to delete such information. Parents or legal guardians who believe a child has provided personal information may contact our Privacy Team.

20. Healthcare Information (HIPAA)

Certain LeadNest Services are designed to support healthcare organizations. Where LeadNest processes Protected Health Information ("PHI"), it acts solely pursuant to:

  • A signed Business Associate Agreement (BAA);
  • Applicable healthcare regulations; and
  • Customer instructions.

LeadNest implements administrative, technical, and physical safeguards designed to protect PHI in accordance with applicable contractual obligations and legal requirements. Healthcare Customers remain responsible for:

  • Patient consent;
  • Clinical decisions;
  • Regulatory compliance;
  • Medical record accuracy; and
  • Appropriate use of PHI.

LeadNest does not provide medical advice or clinical decision-making services.

21. Customer Responsibilities

Customers using LeadNest are responsible for ensuring their use of the Services complies with applicable privacy and data protection laws. Customers agree to:

  • Obtain all necessary consents before collecting or processing personal information.
  • Maintain accurate privacy notices.
  • Respect recipient communication preferences.
  • Honor opt-out requests without undue delay.
  • Ensure the accuracy of uploaded information.
  • Maintain appropriate administrative and technical safeguards.
  • Respond to data subject requests where they act as the Data Controller.
  • Comply with applicable messaging, healthcare, financial, and privacy regulations.

Customers remain responsible for the legality of the data they upload to the Services.

22. Third-Party Websites & Integrations

The Services may contain links to third-party websites or integrate with third-party applications and services. Examples include:

  • Google Workspace
  • Microsoft 365
  • Meta
  • Stripe
  • Payment providers
  • Cloud providers
  • CRM systems
  • Developer integrations

LeadNest does not control the privacy practices of third-party websites or services. Users should review the privacy policies of third-party providers before using their services. Authorizing an integration may permit the exchange of information between LeadNest and the third-party service in accordance with your instructions and the provider's terms.

23. Security Incidents & Breach Notification

LeadNest maintains an incident response program designed to identify, investigate, contain, and remediate security incidents. Where required by applicable law, LeadNest will notify affected Customers or regulatory authorities following a confirmed security incident involving personal information.

Notification timelines may vary depending on applicable legal requirements, including but not limited to:

  • GDPR
  • HIPAA
  • U.S. state privacy laws
  • DPDPA
  • Other applicable regulations

Notifications may include:

  • Nature of the incident
  • Categories of information affected
  • Measures taken
  • Recommended protective actions
  • Contact information for further assistance

LeadNest continually reviews and improves its security practices to strengthen protection against evolving threats.

24. Changes to this Privacy Policy

LeadNest may update this Privacy Policy from time to time to reflect changes in:

  • Applicable laws;
  • Regulatory guidance;
  • Industry standards;
  • Platform functionality;
  • Business operations; or
  • Security practices.

Material changes will be communicated through appropriate channels, which may include:

  • Platform notifications
  • Email notifications
  • Website announcements
  • Updated publication dates

The "Last Updated" date at the beginning of this Privacy Policy indicates when the most recent changes became effective. Continued use of the Services following the effective date of any revised Privacy Policy constitutes acknowledgment of the updated Policy.

25. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us.

LeadNest.ai — A Product of Bizionic Technologies Midwest Inc.

26. Definitions

For purposes of this Privacy Policy:

Term Definition
Personal Information Any information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular individual.
Customer Data Any information, files, contacts, messages, media, or other content submitted, uploaded, or processed by a Customer through the Services.
Protected Health Information (PHI) Individually identifiable health information processed on behalf of a Covered Entity or Business Associate under HIPAA.
Data Controller The entity that determines the purposes and means of processing personal information.
Data Processor The entity that processes personal information on behalf of, and under the instructions of, a Data Controller.
Subprocessor A third party engaged by LeadNest to process personal information on LeadNest's behalf in connection with the Services.
Business Associate Agreement (BAA) A contract required under HIPAA governing the handling of Protected Health Information between a Covered Entity and a Business Associate.
End User An individual who receives, interacts with, or accesses communications sent through the Services by a Customer.
AI Services Artificial intelligence, machine learning, automation, and related technologies offered as part of the Services.
Services The LeadNest.ai Platform, together with all software, applications, APIs, messaging services, AI services, and related products described in this Privacy Policy.
Platform The LeadNest.ai websites, software, applications, APIs, infrastructure, and associated technologies.
Cookies Small data files placed on a device to support authentication, preferences, analytics, and similar functionality.

Appendix A – Google API Services User Data Disclosure

Reason: This Appendix is required for Google OAuth verification.

LeadNest's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google Calendar Permissions

Where authorized by the user, LeadNest may request permissions including viewing calendar settings and availability, viewing calendars and events, and creating, modifying, or deleting calendar events. LeadNest requests only the minimum permissions required to provide requested functionality.

Google Workspace API Usage

Google Workspace API data is used solely to provide requested platform functionality, such as scheduling, availability checking, and meeting management.

Google API Limited Use Compliance

LeadNest's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

No AI Training

Google Workspace API data is never used to train generalized artificial intelligence models, machine learning models, or similar technologies.

No Advertising

Google user data is not used for advertising, marketing, or to build advertising profiles.

No Sale of Google Data

Google user data is not sold to any third party.

Revoking Google Access

Users may revoke Google account access at any time through Google Account Security Settings, Google Connected Apps, or LeadNest Account Settings (where available). Upon revocation, LeadNest will no longer access Google Workspace data except where necessary to comply with legal obligations or complete previously initiated operations.

Appendix B – Data Retention Schedule

The table below summarizes retention periods for the categories of information described in Section 15 (Data Retention). Actual retention periods may vary based on contractual terms, Customer configuration, and applicable legal requirements.

Data Category Retention Period
Account Information Account lifetime + 90 days
Billing Records As required by applicable tax and accounting law
Consent Records As required by law or carrier requirements
Campaign Analytics Customer configurable or contractual period
Security Logs Up to 12 months
Backup Data 30–90 days
Google Workspace Data Only while authorized and necessary to provide requested functionality
AI Processing Logs As necessary for service delivery and security
Healthcare Data (PHI) As required under HIPAA and contractual obligations

Appendix C – Subprocessor List

LeadNest engages the following third-party service providers ("Subprocessors") to help deliver and support the Services. Each Subprocessor is contractually bound to process personal information only for authorized purposes and to implement appropriate technical and organizational security measures.

Provider Purpose
Amazon Web Services (AWS) Cloud Infrastructure & Storage
Cloudflare CDN & Security
Twilio SMS & Voice Delivery
Meta WhatsApp Business Messaging
Stripe Payment Processing
Razorpay Payment Processing (India)
Google Cloud Infrastructure & APIs
Microsoft Identity & Productivity Services
OpenAI AI Services
Anthropic AI Services

LeadNest may update its Subprocessors from time to time. The current list is maintained on this page.

Appendix D – Regional Privacy Disclosures

This Appendix summarizes region-specific privacy rights and disclosures. It supplements, and does not replace, the rights and information described elsewhere in this Privacy Policy.

GDPR (European Union)

For individuals located in the European Economic Area, LeadNest processes personal information in accordance with the General Data Protection Regulation (GDPR). Depending on the nature of processing, LeadNest may act as a Data Controller or Data Processor. Where LeadNest acts as a Processor on behalf of a Customer located in or serving individuals in the EEA, processing is governed by a Data Processing Agreement incorporating Standard Contractual Clauses where applicable. Individuals in the EEA may lodge a complaint with their local supervisory authority.

UK GDPR

Individuals located in the United Kingdom have rights under the UK General Data Protection Regulation and the UK Data Protection Act 2018, substantially similar to those described under GDPR above. Complaints may be directed to the UK Information Commissioner's Office (ICO).

CCPA / CPRA (California)

California residents have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including the rights to know, access, correct, delete, and limit the use of certain personal information, and to opt out of the sale or sharing of personal information. LeadNest does not sell or share personal information as defined under the CCPA/CPRA. California residents may exercise these rights by contacting our Privacy Team.

Other Applicable U.S. State Privacy Laws

Residents of certain U.S. states, including but not limited to Virginia, Colorado, Connecticut, and Utah, may have rights substantially similar to those described above, including rights to access, correct, delete, and opt out of certain processing activities such as targeted advertising and profiling. LeadNest honors applicable state-specific rights requests in accordance with each state's requirements.

DPDPA (India)

Individuals located in India may exercise rights under the Digital Personal Data Protection Act, 2023 (DPDPA), including rights relating to access, correction, erasure, and grievance redressal. LeadNest has designated a contact for grievances relating to personal data processed under the DPDPA, reachable through our Privacy Team.

LGPD (Brazil, if applicable)

Where LeadNest processes personal information of individuals located in Brazil, such processing is conducted in accordance with the Lei Geral de Proteção de Dados (LGPD), including applicable legal bases, data subject rights, and security obligations.

PIPEDA (Canada, if applicable)

Where LeadNest processes personal information of individuals located in Canada, such processing is conducted in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.