Privacy Policy
Last updated: July 22, 2026
1. Who we are
agentlyleads is a product of CS2 Technologies Inc.(“we”, “us”), a company incorporated in Canada, Business Number 707258406RC001, at cs2technologies.ca. CS2 Technologies Inc. is the entity responsible for the AI-native CRM at agentlyleads.com and is the controller referred to below.
This policy explains how we handle personal data both as a controller (data about you, our customer — account, billing, and usage data) and as a processor (data our customers store in their CRM workspace about their own contacts and leads).
Privacy questions and data-rights requests: privacy@agentlyleads.com.
2. Data we collect as a controller
- Account data — name, email address, password hash, workspace name.
- Billing data — plan, subscription status, and payment events. Card details are held by Stripe, never by us.
- Usage and log data — IP addresses, browser/session metadata, and security logs kept to operate and protect the service.
- Support communications — messages you send us.
3. Data we process on behalf of customers
CRM records — contacts, companies, leads, deals, tasks, notes, emails, and files — belong to the customer workspace that created them. The customer is the data controller for this data; we process it only on their instructions, as described in our Data Processing Addendum. If your data appears in a customer’s workspace and you want it corrected or removed, contact that customer first; we assist them in fulfilling such requests.
4. How we use data
- To provide, secure, and improve the service (contract performance and legitimate interest).
- To bill for subscriptions via Stripe (contract performance).
- To send transactional email — sign-in verification, export links, notifications (contract performance).
- To power optional AI features, where content is sent to the AI provider the workspace has configured (see Subprocessors). We do not train models on customer data.
5. Email suppression and deleted workspaces
When someone unsubscribes from a customer’s emails, their address goes on that workspace’s suppression list so they are not contacted again. If a workspace is deleted, we retain an irreversible SHA-256 hash of each suppressed address (with the suppression reason) for up to 2 years, so a returning customer cannot accidentally re-mail people who opted out. The hash cannot be reversed into an email address.
6. Retention and deletion
Workspace data is retained while the subscription is active. Owners can delete their workspace from Settings; deletion completes after a 7-day grace window, after which all workspace records and stored files are permanently erased (except the hashed suppression tombstones described above). Owners can also export all workspace data at any time.
7. Sharing
We share data only with the subprocessors listed at /subprocessors, with authorities when legally required, and in connection with a merger or acquisition (with notice). We never sell personal data.
8. Security
Data is encrypted in transit (TLS) and at rest. Passwords are hashed with bcrypt. Access to production systems is restricted and logged. Each customer workspace is logically isolated.
9. Your rights
Depending on your location (including under GDPR and CCPA), you may have rights to access, correct, export, delete, or restrict processing of your personal data, and to object to processing or withdraw consent. Contact us at privacy@agentlyleads.com and we will respond within the time required by law. You may also lodge a complaint with your supervisory authority.
10. International transfers
Our infrastructure runs in AWS us-east-1 (United States). Where data is transferred from the EEA/UK, we rely on Standard Contractual Clauses and equivalent safeguards, as set out in the DPA.
11. Changes and contact
We will post updates to this policy here and notify customers of material changes. Questions: privacy@agentlyleads.com.