Introduction and operating company
This Privacy Policy applies to the LEADOXE website, LEADOXE CRM applications, customer support, and integrations enabled by a customer. LEADOXE CRM is owned and operated by VEYSAPP LLC, registered at Sharjah Media City, Sharjah, United Arab Emirates under business licence 2647741.01.
A company using LEADOXE controls the business information it places in its workspace and the people it authorises to access that workspace. This Policy does not replace that company's own privacy notice or its responsibility to use personal data lawfully.
Information we collect
Depending on how the Services are used, we may collect or process:
- Account and company information: names, business contact details, job roles, company settings, workspace membership, and support correspondence.
- CRM and lead information: contacts, enquiries, source details, projects, notes, activities, assignments, follow-ups, pipeline stages, and communication history.
- Technical and security information: IP address, browser and device information, session events, authentication records, audit events, errors, webhook records, and diagnostics.
- Integration information: identifiers, permissions, configuration, and events received from services a customer chooses to connect.
Meta and WhatsApp data
Customer-authorised connections
LEADOXE uses Meta Platform APIs made available to authorised businesses where enabled by the customer. LEADOXE does not claim to be a partner, representative, certified provider, or approved product of Meta.
When a customer authorises a connection, LEADOXE may process the Meta business, Facebook Page, Instagram account, advertising account, Lead Ads form, lead, campaign, or webhook information needed to operate that connection.
For the WhatsApp Business Platform, this may include WhatsApp Business Account and phone-number identifiers, message templates, business messages, media references, conversation events, and delivery or read status supplied through the authorised integration.
We use this information to create or update CRM records, preserve the enquiry source, present authorised business conversations, route work, support follow-up, and diagnose integration delivery. Customers control which supported business assets they connect and may revoke provider permissions.
How we use and share information
How we use information
- Provide, administer, maintain, support, and improve LEADOXE.
- Authenticate users, apply workspace roles, and protect accounts and customer data.
- Operate customer-authorised CRM, Meta, and WhatsApp workflows.
- Respond to support, service, billing, security, and legal requests.
- Investigate errors, misuse, and security events and comply with applicable obligations.
Service providers and third parties
We may share information with providers that help us host, secure, monitor, back up, communicate, bill, or support the Services. They may process information only to provide the relevant service and remain subject to their contractual and legal obligations.
Information may also be disclosed at a customer's direction, where required by law, or where reasonably necessary to protect users, the platform, or legal rights. We do not sell customer CRM lead or conversation data to advertising networks.
How we protect information
We use reasonable administrative and technical measures designed to protect information, including authentication controls, protected password handling, role-aware access, tenant-aware workspace boundaries, session controls, audit records, secure API connections, and operational monitoring where appropriate.
Access is limited according to role and operational need. No internet service or storage system can guarantee complete security, and customers remain responsible for protecting their credentials, reviewing authorised users, and promptly reporting suspected misuse.
Retention and deletion
We retain information for as long as reasonably needed to provide the Services, follow customer instructions, maintain security and audit history, resolve disputes, and meet legal or contractual obligations. Different categories may be retained for different periods; this Policy does not set a fixed numerical period.
When information is deleted from active systems, limited copies may remain in restricted backups until the normal backup cycle completes. We may retain limited records where required for security, fraud prevention, accounting, legal obligations, or legal claims.
To request deletion of LEADOXE, Meta, or WhatsApp integration data, follow the Data Deletion process or email privacy@leadoxe.com.
Your rights and contact information
Subject to applicable law and appropriate identity verification, you may request access to information about you, correction of inaccurate information, deletion, restriction, objection, or an available export. Where processing relies on consent, you may withdraw that consent for future processing.
If a LEADOXE customer placed your information in its workspace, contact that company first. We may refer the request to the customer or assist it because the customer generally decides why and how its CRM data is used.
Privacy roles and legal bases
VEYSAPP LLC acts as a controller for information used to manage this website, business enquiries, accounts, security, billing administration, and its direct customer relationship. For CRM, lead, conversation, and integration data placed in a customer workspace, the customer generally decides the purposes and means of processing and LEADOXE generally acts as its processor or service provider.
Depending on the context and applicable law, processing may rely on performance of a contract, steps requested before a contract, legitimate interests in operating and securing a business service, compliance with legal obligations, protection of legal rights, or consent where consent is required. Customers are responsible for identifying a lawful basis for the data and communications they control. These principles are intended to support applicable privacy requirements, including the UAE Personal Data Protection Law and, where its territorial scope applies, the GDPR; the exact rights and duties depend on the processing context and applicable law.
Cookies, analytics, and international transfers
Strictly necessary cookies or similar browser storage may support authentication, security, and essential preferences. The public website does not currently state that it uses cross-site advertising profiles. See the Cookie Policy for current categories and controls.
Service providers and connected platforms may process information in countries other than the requester's country. Where cross-border safeguards are required, we use reasonable contractual, organisational, and technical measures appropriate to the service and applicable law. Provider-specific transfers remain subject to the connected provider's terms and privacy practices.
Children's privacy
LEADOXE is a business service and is not directed to children. We do not knowingly invite children to create accounts or use the platform independently. Customers must not use LEADOXE to process children's information without the authority, notices, consents, and safeguards required by law. Contact the privacy address if you believe a child provided information directly to us.
Policy updates and complaints
We may update this Policy when processing activities, providers, product features, or legal requirements change. Material public changes will be reflected by a revised effective date and, where appropriate, an additional notice to affected customers.
Questions and complaints should first be sent to privacy@leadoxe.com. You may also have the right to contact the data-protection authority or regulator available under applicable law.
