Skip to content

Security and privacy

The data belongs to your audience. We just look after it.

A customer data platform holds the most sensitive thing a company has: who its people are. This page describes what is implemented today — and says what is not.

Isolation per project

Each project has its own space in the database. Not a filter applied at query time — separation at the storage level, so data in one project is unreachable from another even by a coding mistake.

Secrets never come back through the screen

Destination tokens and API keys live in a managed vault. The interface shows that a credential exists, never its value — including to the person who entered it.

Access per person and per token

Every AI integration uses a scoped, project-bound token, revocable at any time. Member invitations are per project, not per account.

You control what leaves

In every delivery you decide which fields travel. Whatever should not leave is stripped before sending, and every delivery is audited with what was sent.

First-party collection

Collection happens on behalf of your site, on your domain. The data belongs to your audience and stays under your control — we are the processor, you are the controller.

Exit without hostage-taking

API export, webhook delivery and SQL over raw data at any moment. There is no closed format holding your history in here.

Data protection

Who is who in this relationship

Under GDPR and the Brazilian LGPD, the party deciding why and how audience data is processed is the controller. CrazyLeads processor: processes data on your behalf, following your instructions.

  • Disclosing collection in your privacy policy is the controller’s responsibility
  • The legal basis for processing is chosen by you, according to your business
  • Data subject deletion requests can be fulfilled through the platform
  • History retention follows the plan you contracted

Transparency

What we do not have yet

We would rather write this down than have you discover it in due diligence.

SOC 2 or ISO 27001 certification

Not yet. The controls described above exist and work, but they have not been independently audited. If that is a requirement in your procurement process, talk to us before investing time in the evaluation.

A formal service level agreement

Available on the Business plan, under contract. On other plans there is no contracted SLA, and the documentation does not pretend otherwise.

Questions about data and privacy

Do you sell or share my data?

No. Your project data is used to operate the platform for you. It is not sold, does not feed third-party databases and is never crossed with another customer’s.

Where is the data hosted?

On cloud infrastructure we manage, with restricted access. Traffic between your site and the platform is encrypted in transit.

How do I handle a data subject deletion request?

You locate the person by email, phone or identifier and request removal. Deletion reaches the lead and the history attached to them.

Do I need a consent banner on my site?

That depends on the legal basis you adopt and the type of processing. The decision belongs to the controller; the platform respects whatever collection your site authorizes.

What happens to my data if I cancel?

You export whatever you want before closure, through the API or a query. After the closure period, the project data is removed.

Does AI over MCP see everything?

It sees what the token allows, in the active project. The token is generated by you, scoped, and revocable at any time.

Full documents: privacy policy and terms of use.

Security question before you start?

If your technical or legal team has a questionnaire, send it over and we answer item by item.