CRM Integration Privacy Policy
Last updated:
This notice covers the Deeplead marketplace app and its Deeplead Persona email conversation channel connecting Deeplead to your CRM through LeadConnector. It supplements our Privacy Policy. For this integration, the specific practices below apply. The Google/Gmail sections of the main policy describe a separate connection; this CRM channel uses supported SMTP inboxes and stores conversation data as described here.
Who handles your information
Julian Wagner, trading as Deeplead, provides and supports this app. Contact privacy@deeplead.io about personal data, or support@deeplead.io for integration support. Your business determines why its contacts are contacted and which conversations are connected. When we process those contacts and messages on your business’s instructions, we act as its processor. We act as controller for our own account administration, security and support activities. Your CRM provider separately handles data under its own agreement with you.
Data we access and store
- Connection data: your Deeplead account identifier, CRM business account and conversation provider identifiers, authorization records, and access and refresh tokens used to maintain the connection. Authorization happens through the CRM; the app does not ask for your CRM password.
- Contact and conversation data: contact and conversation identifiers, email addresses, sender and recipient details, subjects, message text and HTML, timestamps, thread references, and contact email restrictions such as Do Not Disturb and unsubscribe status.
- Reply and service records: replies submitted through the connected channel, the submitting team member’s identifier when provided, links to the original inbox and campaign recipient, sending and sync status, delivery receipts and errors. These records help preserve threads and prevent duplicate sends.
Data comes from your connected CRM, the relevant conversations already held in Deeplead, and messages submitted by your team. The current channel excludes OAuth-connected inboxes from thread import and does not support sending attachments, CC or BCC. Unsupported content submitted to the channel may still be included in the stored request even when the send is rejected.
Why we use it and the access requested
We use this information to connect the authorized business account, import eligible inbound and outbound email history into its CRM conversations, route a team member’s reply through the original Deepleadsending inbox, maintain the email thread, report status, enforce contact restrictions, and investigate failed or duplicate operations. A reply can also stop pending automated follow-ups in Deeplead.
The app requests access to read contacts, read and write conversations, and read and write conversation messages. Contact access supports account and email restriction checks; conversation and message access supports history import, reply verification and status updates. Any separately configured contact, note or opportunity sync is a distinct connection; uninstalling this app does not disconnect that service.
The integration’s purpose is conversation sync and reply delivery, not selling contact data, advertising profiling or training general-purpose AI models. Separate Deeplead campaign or AI features are outside this channel’s functionality and remain subject to their applicable settings and disclosures.
Legal bases
Where the GDPR applies and we act as controller, we process account information to perform our contract with you, or for our legitimate interest in administering a business customer’s account. We process security and troubleshooting records for our legitimate interests in protecting the service and resolving errors, and retain information where required by law. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. For your business’s contact and message data, your business determines the applicable legal basis and we process it on its instructions. Granting app permissions does not itself establish consent from the people you email.
Sharing, storage and protection
Eligible email history is sent to your connected CRM and becomes accessible under its account permissions. A reply passes through Deeplead and the original email provider to the recipient. Our hosting, database, background job and operational support providers process the data needed to run these services. Authorized personnel may access relevant records to provide support, address security incidents or comply with law.
Connection tokens are encrypted before database storage. The integration uses HTTPS for CRM communication, verifies signed reply requests, and checks the connected account, message, contact and inbox before sending. Message content and operational records are stored in our application databases. These controls reduce risk; no service can guarantee absolute security.
Your CRM, email provider and our service providers may process information outside your country, including outside the European Economic Area. Applicable data protection law requires an appropriate transfer basis where relevant. Contact privacy@deeplead.io for information about the providers, processing locations and transfer arrangements applicable to your account.
Retention, disconnection and deletion
We retain connection records while needed to operate the connection. Stored conversations and send/sync records support your account history, delivery troubleshooting and duplicate prevention. Retention depends on whether your account remains active, outstanding delivery issues, deletion instructions and applicable legal requirements. Uninstalling the app does not automatically erase these records.
Revoke or uninstall the app through your CRM’s connected-app settings, and contact support@deeplead.io to have us disable the Deeplead side and review any pending sends. Email already handed to a sending provider cannot be recalled. Any separate contact sync or outreach campaign must be stopped separately.
To request deletion of connection tokens, stored integration records or account data, email privacy@deeplead.io and identify the relevant business account. We verify your authority before acting. Any information retained to meet legal obligations or resolve claims remains subject to appropriate access restrictions. Copies already in your CRM, recipients’ mailboxes or other providers are controlled separately and require requests to those parties. Disconnection and data deletion do not by themselves cancel subscriptions.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction or portability of your personal data, object to processing, and withdraw consent where applicable. You may also complain to your local data protection authority. Contact privacy@deeplead.io to exercise these rights. If the data belongs to a customer’s outreach activity, contact that business as controller; we can help route your request and assist it in responding. We respond within the time limits required by applicable law.
Changes to this notice
We will update the date above when this notice changes and communicate material changes through appropriate account notices. We will obtain additional authorization or consent where required before introducing new data uses. See also the CRM Integration Terms.