Privacy notice
Effective 24 July 2026What myLeadStream processes
myLeadStream processes account email addresses, CRM records, activity notes and files supplied by authorised users so the service can operate. Access is isolated by workspace and controlled by assigned roles and feature permissions.
AI intelligence
When workspace AI is enabled, authorised records may be sent to the configured AI provider to create advisory summaries, searches, document extractions or photo labels. Provider storage is disabled by the application. AI results are linked to source-record identifiers, remain subject to workspace permissions and require human review for sensitive customer, financial, order, damage or completion decisions. The initial production rollout is shadow-only: AI cannot send messages, reschedule work or alter CRM records.
Google Places quick search
Quick Search and Smart Enrich use Google Maps Platform to display current business listing results. Google listing content is displayed live; a Google Place ID may be retained to identify a reviewed listing and prevent duplicates. Contact details saved through these tools are independently obtained from the business’s official public website or approved by an authorised user. Use of Google services is also governed by the Google Privacy Policy.
Apify Deep Discovery
When an authorised user starts a Deep Discovery or prospect refresh job, the chosen search terms or selected business names are sent to Apify. Normalised public business facts returned by the selected Actor may be saved as timestamped snapshots after user review. Reviewer personal data, reviews, social-profile enrichment and personal-contact enrichment are disabled by myLeadStream. Apify processes job data under its own privacy policy.
Security, access and retention
Short-lived login codes, revocable sessions, rate limits, workspace permissions, server-side feature controls and audit records protect the service. Private files are served only after a current workspace and feature-access check. AI-derived records are removed after the configured retention period; source CRM records and originals follow the organisation’s operational retention and lawful-recordkeeping requirements. Information that is no longer required should be deleted or de-identified by an authorised administrator.
Access, correction and incidents
Requests to access or correct personal information, privacy concerns and suspected data incidents should be directed promptly to the organisation that provided your myLeadStream access. The organisation remains responsible for its privacy notices, lawful collection and breach-response obligations.