Legal

Privacy Policy

Last updated: July 22, 2026

1. Who we are

agentlyleads is a product of CS2 Technologies Inc.(“we”, “us”), a company incorporated in Canada, Business Number 707258406RC001, at cs2technologies.ca. CS2 Technologies Inc. is the entity responsible for the AI-native CRM at agentlyleads.com and is the controller referred to below.

This policy explains how we handle personal data both as a controller (data about you, our customer — account, billing, and usage data) and as a processor (data our customers store in their CRM workspace about their own contacts and leads).

Privacy questions and data-rights requests: privacy@agentlyleads.com.

2. Data we collect as a controller

3. Data we process on behalf of customers

CRM records — contacts, companies, leads, deals, tasks, notes, emails, and files — belong to the customer workspace that created them. The customer is the data controller for this data; we process it only on their instructions, as described in our Data Processing Addendum. If your data appears in a customer’s workspace and you want it corrected or removed, contact that customer first; we assist them in fulfilling such requests.

4. How we use data

5. Email suppression and deleted workspaces

When someone unsubscribes from a customer’s emails, their address goes on that workspace’s suppression list so they are not contacted again. If a workspace is deleted, we retain an irreversible SHA-256 hash of each suppressed address (with the suppression reason) for up to 2 years, so a returning customer cannot accidentally re-mail people who opted out. The hash cannot be reversed into an email address.

6. Retention and deletion

Workspace data is retained while the subscription is active. Owners can delete their workspace from Settings; deletion completes after a 7-day grace window, after which all workspace records and stored files are permanently erased (except the hashed suppression tombstones described above). Owners can also export all workspace data at any time.

7. Sharing

We share data only with the subprocessors listed at /subprocessors, with authorities when legally required, and in connection with a merger or acquisition (with notice). We never sell personal data.

8. Security

Data is encrypted in transit (TLS) and at rest. Passwords are hashed with bcrypt. Access to production systems is restricted and logged. Each customer workspace is logically isolated.

9. Your rights

Depending on your location (including under GDPR and CCPA), you may have rights to access, correct, export, delete, or restrict processing of your personal data, and to object to processing or withdraw consent. Contact us at privacy@agentlyleads.com and we will respond within the time required by law. You may also lodge a complaint with your supervisory authority.

10. International transfers

Our infrastructure runs in AWS us-east-1 (United States). Where data is transferred from the EEA/UK, we rely on Standard Contractual Clauses and equivalent safeguards, as set out in the DPA.

11. Changes and contact

We will post updates to this policy here and notify customers of material changes. Questions: privacy@agentlyleads.com.