// Legal

Privacy Policy

How we collect, use, store, and protect personal data on leadsylabs.com

Effective date: June 5, 2026  ·  Version 2.0
Data controller
Individual Entrepreneur Leonid Shchekin
Operating as LeadsyLabs (trade name)
Identification Number: 345844786
Georgia, Tbilisi, Mtatsminda district,
Geronti Kikodze street N 13, apartment N6
Privacy inquiries: privacy@leadsylabs.com

1. Overview

This Privacy Policy (the “Policy”) explains how Individual Entrepreneur Leonid Shchekin, doing business as LeadsyLabs (the “Controller”, “we”, “us”, or “our”), processes personal data when you use the site leadsylabs.com, our Leadsy audit and account services, and related communications.

We designed this Policy to meet the requirements of the EU General Data Protection Regulation (GDPR) where it applies, and to provide transparent information to users in the United States and other regions, including where state privacy laws such as the California Consumer Privacy Act (CCPA, as amended by CPRA) may apply.

By using the Site or creating an account, you acknowledge that you have read this Policy. If you do not agree, please do not use our services.

2. Data controller

The data controller is:

  • Legal name: Individual Entrepreneur Leonid Shchekin
  • Trade name / brand: LeadsyLabs
  • Identification Number: 345844786
  • Registered address: Georgia, Tbilisi, Mtatsminda district, Geronti Kikodze street N 13, apartment N6
  • Website: leadsylabs.com
  • Privacy email: privacy@leadsylabs.com
  • General support: hello@leadsylabs.com

We do not currently appoint a Data Protection Officer. For privacy requests, contact privacy@leadsylabs.com.

3. Personal data we collect

Information you provide:

  • Name — when you register or contact us;
  • Email address — account login, audit delivery, and service notifications;
  • Phone number — optional, when placing an order or contacting support;
  • Website or property URL — submitted for AI visibility audits;
  • Payment-related information — billing details processed by our payment provider (we do not store full card numbers).

Information collected automatically:

  • IP address, browser type, device type, operating system;
  • Pages viewed, session duration, referral source;
  • Cookie identifiers and similar technologies (see Section 8).

We do not intentionally collect special categories of personal data (such as health, biometric, or political data) and ask that you do not submit them through our forms.

4. How we use personal data

We use personal data to:

  • Create and manage your account and dashboard;
  • Run free and paid AI visibility audits and deliver reports;
  • Process orders, invoices, and payments;
  • Respond to support requests and service communications;
  • Improve the Site, fix errors, and prevent abuse or fraud;
  • Comply with legal, tax, and accounting obligations;
  • Send service-related messages (you may opt out of non-essential marketing where applicable).

5. Legal bases for processing (GDPR)

Where GDPR applies, we rely on the following legal bases under Article 6:

  • Contract — to provide the service you requested (account, audits, paid deliverables);
  • Consent — for optional cookies/marketing where required, and when you tick acceptance boxes on forms;
  • Legitimate interests — to secure the Site, analyze aggregated usage, and improve our product, balanced against your rights;
  • Legal obligation — for tax, accounting, and regulatory record-keeping.

You may withdraw consent at any time where processing is consent-based. Withdrawal does not affect processing that was lawful before withdrawal.

6. International data transfers

We may use infrastructure and subprocessors located outside your country, including in the United States and the European Economic Area.

When personal data is transferred from the EEA, UK, or Switzerland to countries without an adequacy decision, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms required by applicable law.

Our hosting and email providers, analytics tools, and payment processors may process data in multiple jurisdictions. Details of key processors are listed in Section 7.

7. Third-party processors and disclosures

We share personal data only as needed to operate the service:

  • Payment processing — Stripe, Inc. (or another PCI-compliant provider we designate) processes card payments; see stripe.com/privacy;
  • Email delivery — transactional email providers to send audit results and account messages;
  • Analytics — Google Analytics (Google LLC) for aggregated traffic statistics; see Section 8;
  • Infrastructure — hosting and database providers that store account and audit data under contract;
  • Professional advisers — lawyers, accountants, or auditors when required;
  • Authorities — when required by valid legal process or to protect rights, safety, and security.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising as defined under California law.

8. Cookies and analytics

We use cookies and similar technologies to keep you signed in, remember preferences, and measure Site performance.

  • Strictly necessary cookies — required for login and core functionality;
  • Analytics cookies — Google Analytics helps us understand how visitors use the Site. Data may be processed on Google servers worldwide. Policy: policies.google.com/privacy.

Where required by law, we request your consent before non-essential cookies. You can also block or delete cookies in your browser settings; some features may not work correctly if you do.

9. Your privacy rights

If you are in the EEA, UK, or Switzerland (GDPR), you may have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate data;
  • Request deletion (“right to be forgotten”) in certain cases;
  • Restrict or object to processing in certain cases;
  • Data portability where processing is based on contract or consent;
  • Withdraw consent at any time;
  • Lodge a complaint with your local supervisory authority.

If you are a California resident (CCPA/CPRA), you may have the right to know, access, correct, and delete personal information, and to opt out of sale/sharing (we do not sell or share as defined above). You will not be discriminated against for exercising these rights.

How to exercise your rights: email privacy@leadsylabs.com with enough detail to verify your identity. We respond within 30 days, or as required by applicable law.

10. Security

We apply technical and organizational measures appropriate to the risk, including:

  • HTTPS encryption for data in transit;
  • Hashed password storage (we cannot read your raw password);
  • Access controls limited to personnel who need data to perform their role;
  • Regular backups and security updates.

No online service is 100% secure. Please use a strong, unique password and notify us promptly if you suspect unauthorized access to your account.

11. Data retention

  • Account data (name, email, phone) — for the life of your account, then deleted or anonymized within 30 days after closure;
  • Transaction and billing records — up to 7 years where required for tax and accounting;
  • Audit data (URLs and results) — up to 12 months from the last related audit unless you delete them sooner;
  • Server logs — typically up to 12 months.

We may retain data longer if required by law or to establish, exercise, or defend legal claims.

12. Changes to this Policy

We may update this Policy from time to time. The effective date at the top will change when we do. Material changes will be posted on leadsylabs.com/privacy.html. Continued use of the Site after an update means you accept the revised Policy, unless applicable law requires a different approach.

13. Contact us

LeadsyLabs · Individual Entrepreneur Leonid Shchekin · privacy@leadsylabs.com