← Leader.ai

Data Processing Agreement

Last updated: 13 July 2026  ·  Orlando Lupoi, trading as Leadersolutions (ABN 77 543 251 392)

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Orlando Lupoi, trading as Leadersolutions (ABN 77 543 251 392) (“Processor”) and the Client (“Controller”) and applies where Leader.ai processes personal information on the Client's behalf.

1. Definitions

“Personal Information” has the meaning given in the Privacy Act 1988 (Cth).

“Controller” means the Client who determines the purposes and means of processing personal information.

“Processor” means Orlando Lupoi, trading as Leadersolutions (ABN 77 543 251 392), who processes personal information on the Controller's behalf.

“Sub-Processor” means a third party engaged by the Processor to assist in processing personal information.

2. Scope of Processing

Leader.ai processes personal information as described in Schedule A below.

3. Processor Obligations

Leader.ai shall:

  • Process personal information only on documented instructions from the Controller
  • Ensure persons authorised to process the data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Notify the Controller without undue delay upon becoming aware of a data breach
  • Assist the Controller in responding to data subject access and correction requests
  • Delete or return all personal information at the end of the service relationship, as requested by the Controller
  • Make available all information necessary to demonstrate compliance with this DPA

4. Sub-Processors

The Controller authorises Leader.ai to engage sub-processors. Current sub-processors are listed in Schedule B. Leader.ai will notify the Controller of any intended changes and provide 14 days for the Controller to object.

5. International Transfers

Personal information is primarily stored in Australia (ap-southeast-2). Some sub-processors operate internationally. Leader.ai will only transfer personal information to overseas recipients where reasonable steps have been taken to ensure the recipient handles the information consistently with the Australian Privacy Principles.

6. Security

Leader.ai implements measures including:

  • AES-256 encryption at rest; TLS 1.2+ in transit
  • Row-level security on all database tables
  • Access controls enforcing least-privilege principles
  • Automated anomaly detection and audit logging
  • Annual penetration testing and vulnerability assessments

7. Data Breach Notification

In the event of a suspected eligible data breach (as defined under the Notifiable Data Breaches scheme), Leader.ai will notify the Controller within 72 hours of becoming aware, and provide details of the nature of the breach, the data affected, and remedial actions taken or proposed.

8. Audit Rights

The Controller may request an audit of Leader.ai's compliance with this DPA no more than once per 12-month period, with 30 days' written notice. Audit costs are borne by the Controller.

Schedule A — Processing Details

SubjectDetail
NatureAI-assisted lead qualification, messaging, scheduling, CRM sync
PurposeTo qualify, engage, and book prospective customers on behalf of the Controller
DurationFor the term of the Controller's subscription, plus any statutory retention periods
Data subjectsProspective customers (End Users) of the Controller's business
Categories of dataName, email address, phone number, conversation content, booking details, optional: company name, custom qualification fields

Schedule B — Sub-Processors

Sub-ProcessorRoleLocation
SupabaseDatabase, authenticationAustralia (ap-southeast-2)
AnthropicAI language model inferenceUSA
TwilioSMS deliveryUSA / Australia
Resend / SendGridEmail deliveryUSA
InngestBackground job orchestrationUSA
SentryError monitoring (PII-redacted)USA
StripePayment processingUSA / Australia

Contact

For DPA-related enquiries: privacy@leader.ai