LeadWiseSystem
Data Processing Agreement
Effective: July 19, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Denecke Media LLC, d/b/a LeadWiseSystem ("Processor," "we") and the organization subscribing to LeadWiseSystem ("Controller," "you"). This DPA satisfies the requirements of GDPR Article 28 and applies whenever we process personal data on your behalf.
By using LeadWiseSystem, you agree to this DPA. If your organization requires a countersigned copy, email legal@leadwisesystem.com.
1. Definitions
- Personal Data — any information relating to an identified or identifiable person that you upload to LeadWiseSystem (lead names, emails, phone numbers, notes, etc.)
- Processing — any operation performed on Personal Data (storage, retrieval, display, deletion)
- Sub-processor — a third-party service provider we use to deliver LeadWiseSystem
2. Scope and Purpose of Processing
We process your Personal Data only to provide the LeadWiseSystem service. This includes:
- Storing lead records you create (names, contact info, notes, communication logs)
- Sending emails on your behalf (reminders, follow-up notifications)
- Generating reports and analytics you request
- Processing subscription payments via Stripe
We do not process your data for any other purpose. We do not sell, share, or use your lead data for advertising or profiling.
3. Your Obligations as Controller
- You determine what Personal Data is uploaded to LeadWiseSystem
- You are responsible for having a lawful basis to collect and process your contacts' data
- You are responsible for responding to data subject access requests (DSARs) — we provide data export tools to help you fulfill these
4. Our Obligations as Processor
- Process Personal Data only on your documented instructions (i.e., the features you use within the application)
- Not process data for any purpose beyond providing LeadWiseSystem to you
- Ensure all personnel with access to data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see Section 6)
- Assist you in responding to data subject rights requests
- Delete or return all Personal Data upon account termination (see Section 8)
- Make available information necessary to demonstrate compliance and allow for audits
5. Sub-processors
We use the following sub-processors to deliver the service:
| Sub-processor | Purpose | Location |
| Amazon Web Services (AWS) | Cloud hosting, database, file storage, serverless compute | US East (Virginia) |
| Stripe | Payment processing | United States |
| Microsoft (Office 365 / Graph API) | Transactional email delivery | United States |
| Google Analytics 4 | Anonymous usage analytics (no personal data shared) | United States |
We will notify you before adding or replacing a sub-processor. If you object to a new sub-processor, you may terminate your account within 30 days.
6. Security Measures
We implement the following technical and organizational measures:
- Encryption in transit: All connections use TLS 1.2+ (HTTPS enforced)
- Encryption at rest: Database (PostgreSQL on AWS RDS) uses AES-256 encryption at rest
- Access controls: Multi-tenant architecture with org-scoped data isolation. Users can only access data within their own organization.
- Authentication: Passwords stored as bcrypt hashes. JWT-based session tokens with 24-hour expiry.
- Infrastructure: AWS Lambda (serverless) with no persistent servers to patch. AWS manages underlying infrastructure security.
- Backups: Automated daily database backups with 7-day retention
- Monitoring: Application error logging and proactive alerting for service health
7. Data Breach Notification
In the event of a personal data breach that affects your data, we will:
- Notify you without undue delay (within 72 hours of becoming aware)
- Provide details of the nature of the breach, categories of data affected, and approximate number of records
- Describe the measures taken or proposed to address the breach
- Cooperate with your obligations to notify supervisory authorities or affected data subjects
8. Data Retention and Deletion
- Active accounts: We retain your data for as long as your account is active
- Account termination: Within 30 days of account deletion, we permanently remove all your Personal Data from our production systems
- Backups: Data may persist in encrypted backups for up to 7 additional days, after which it is automatically purged
- On request: You can export all your data at any time via the application's export feature, or by emailing support@leadwisesystem.com
9. International Data Transfers
All data is stored and processed in the United States (AWS us-east-1 region). If you are located in the EU/EEA, the transfer of Personal Data to the US is governed by:
- The EU-U.S. Data Privacy Framework (DPF), to which AWS is certified
- Standard Contractual Clauses (SCCs) where required by applicable law
10. Data Subject Rights
We support your ability to fulfill data subject requests:
- Access / Portability: Export lead data via the application or request a full data export
- Rectification: Edit any lead record directly in the application
- Erasure: Delete individual leads or request full account deletion
- Restriction: Archive leads to restrict processing while retaining the record
11. Term and Termination
This DPA remains in effect for the duration of your LeadWiseSystem subscription. Upon termination, our data deletion obligations (Section 8) survive.
12. Contact
For questions about this DPA or to request a countersigned copy:
Denecke Media LLC
2140 E Southlake Blvd, Suite L-514
Southlake, TX 76092
legal@leadwisesystem.com
This DPA is provided as a self-service document. Enterprise customers requiring custom terms or a countersigned version can contact us at the address above.