Privacy Notice
Last updated: June 8, 2026
1. Who we are
This service ("LeadForge") is operated by Richard Romero ("we", "us"), acting as the data controller for personal data processed through the LeadForge website and application. You can contact us about this notice at the email address shown on our website.
2. Personal data we collect
- Account data: name, email address, hashed password, login credentials.
- Lead and CRM data: contact details, company, role, and notes you submit through forms.
- Support data: messages and attachments you send to us.
- Usage and device data: pages viewed, actions taken, IP address, browser, device identifiers, and approximate location.
- Cookies and similar technologies: see Section 9.
3. Purposes and legal bases
- Creating and operating your account (performance of contract).
- Providing the service and core features such as lead capture and scoring (performance of contract).
- Customer support and communications about your account (performance of contract; legitimate interests).
- Security, fraud prevention, and abuse detection (legitimate interests; legal obligation).
- Product analytics and improvement (legitimate interests).
- Marketing communications, where permitted (consent or legitimate interests; you may opt out at any time).
- Complying with legal, tax, and accounting obligations (legal obligation).
4. How we share your data
We share personal data with the following categories of recipients:
- Service providers and subprocessors who help us run the service (cloud hosting, database, email delivery, analytics, customer support tooling).
- Paddle, our Merchant of Record, for the sale of our products, subscription management, payments, tax compliance, and invoicing. Paddle processes payment data and acts as an independent controller for that purpose.
- Professional advisers such as lawyers and accountants where reasonably necessary.
- Authorities where we are required to disclose data by law or to protect our rights.
5. International transfers
Some of our service providers may be located outside your country of residence. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
6. Data retention
We keep personal data only for as long as needed for the purposes described above, to comply with legal obligations (for example, tax records), to resolve disputes, and to enforce our agreements. When data is no longer needed it is deleted or anonymised.
7. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Request correction or deletion of your data;
- Object to or restrict certain processing;
- Request data portability;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact us at the email on our website. We respond within one month.
8. Security
We use appropriate technical and organisational measures including encryption in transit, access controls, and audit logging to protect personal data against unauthorised access, alteration, disclosure, or destruction.
9. Cookies
We use essential cookies to operate the service (for example, to keep you signed in) and may use analytics cookies to understand product usage. You can manage cookie preferences through your browser settings.
10. Changes to this notice
We may update this Privacy Notice from time to time. We will post the updated version on this page and update the "Last updated" date above.