Lead Central AI – Master Privacy Policy

Effective Date: August 17, 2026

This Privacy Policy (“Policy”) is published by Lead Central AI (“Company,” “we,” “us,” or “our”) and governs the collection, use, disclosure, and protection of personal data across our primary software platforms, websites (leadcentralai.com), mobile tools, APIs, AI virtual reception assistants, and communication infrastructure.

By accessing our Site, using our Services, or deploying our AI agents, you (“Customer,” “User,” or “you”) agree to the data practices described in this Policy.

Key Legal & Privacy Enhancements Included

Comparative Consolidation Notice:

This master policy harmonizes and upgrades terms from former policies across our platform portfolio:

  1. Complete Functional Unification: Consolidates controller vs. processor distinctions, healthcare privacy rules, automated multi-channel messaging disclosures, and browser signal enforcement (Global Privacy Control) into a single document.

  2. Complete Usage & Re-Billing Transparency: Integrates the exhaustive billing and re-billing disclosures required for telephony, AI processing, marketplace connectors, and carrier pass-through fees.

  3. Standardized Security & Lifecycle Timelines: Establishes a uniform encryption standard (AES-256 / TLS 1.2+), explicit sub-processor categories, and a strict 90-day export / 30-day purge / 90-day backup deletion account termination lifecycle.

1. Dual Operational Roles: Controller vs. Processor

To maintain clarity under global data protection regulations (including CCPA/CPRA, HIPAA, VCDPA, and GDPR), Lead Central AI handles personal data under two distinct operational frameworks:

A. Lead Central AI as Data Controller

We act as a Data Controller when you interact directly with us—such as when you visit our website, request a demonstration, register for an account, subscribe to our platform, submit support tickets, or communicate with our sales team. In this role, we independently determine the purposes and means of processing your business contact information, billing records, and site usage analytics.

B. Lead Central AI as Data Processor (Service Provider / Business Associate)

When our business and healthcare customers utilize the Lead Central AI platform to manage their leads, contacts, and patient data—or to run automated campaigns, outbound AI calling, SMS workflows, and appointment reminders—we act strictly as a Data Processor (or “Service Provider” / “Business Associate”). Our customers control the underlying data, and we process it solely in accordance with their instructions, our Master Services Agreement, Data Processing Addendum (DPA), and Business Associate Agreement (BAA).

2. Comprehensive Information We Collect

We collect personal information directly from you, automatically through your device or browser, and through authorized third parties and service providers:

  • Identifiers & Business Contact Details: Name, business email address, phone number, company or practice name, job title, mailing address, and platform login credentials.

  • Commercial & Billing Data: Subscription plans, contract history, payment confirmations, last four digits of payment cards (full payment processing is tokenized directly via PCI-DSS compliant gateways like Stripe, Authorize.net, or Nuvei), and usage-based re-billing records.

  • Internet & Automated Device Information: IP addresses, device identifiers, browser type and version, operating system, referring URLs, page interaction logs, timestamps, and diagnostic data collected via cookies, web beacons, session replay tools, and platform APIs.

  • Communications & Recording Data: Email content, webchat logs, SMS/MMS message text, call recordings, voicemail audio, speech-to-text transcripts, call metadata, appointment communications, opt-in/opt-out consent records, and Do-Not-Call/Do-Not-Text preferences.

  • Protected Health Information (PHI): Processed exclusively when directed by a healthcare customer operating as a Covered Entity under an executed Business Associate Agreement.

3. Usage & Third-Party Disclosure Framework

We do not sell personal information for monetary compensation. We share personal information only as necessary to provide our platform, fulfill legal obligations, or operate our business:

A. Core Platform Operations

Data is used to deliver, maintain, secure, and improve our platform features, deploy AI voice and chat agents, execute automated messaging, manage customer accounts, process usage re-billing, prevent fraud, and maintain audit logs.

B. Sub-Processors & Infrastructure Providers

We share data with vetted third-party vendors bound by strict contractual confidentiality, security standards, and BAAs where applicable:

  • Infrastructure & Cloud Hosting: DigitalOcean, Vercel, Supabase, and Google Cloud Infrastructure.

  • Telecommunications & Email Pipelines: Twilio, SendGrid, and partner telecommunications carriers and message aggregators.

  • Product Analytics & Experience Tools: Amplitude, Mixpanel, Hotjar, HubSpot, and Google Analytics.

  • Advertising & Marketing Partners: Google Ads, Meta (Facebook/Instagram), LinkedIn, TikTok, Reddit, and X (formerly Twitter) for interest-based and targeted advertising.

4. Re-Billing & Usage-Based Cost Disclosures

Customer acknowledges and agrees that certain automated workflows, telephony services, AI modules, and third-party integrations incur usage-based charges that are re-billed to Customer’s account:

  • AI Services & Speech Engines: Re-billing for Content AI, Conversation AI, Funnel AI, Reviews AI, Pulse AI, nerD AI Insights, Workflow AI Assistants, Amazon Polly text-to-speech counts, and specialized AI Voice Agents (e.g., RoofMate, Rosy Real Estate, Self Selling Voice AI, Music Lessons, Marketing Agency templates).

  • Telephony & Messaging: Charges for inbound/outbound voice minutes, conference calls, IVR calls, answering machine detection (AMD), voicemail drops, local/toll-free phone number rentals, SMS/MMS segments, group messaging, and RCS messaging.

  • Carrier & Compliance Pass-Through Fees: Mandatory carrier surcharges, SMS/MMS carrier fees, A2P 10DLC registration fees, A2P Fast Track fees, and RCS activation fees.

  • Number Intelligence & Email: Charges for Caller Name Lookups (CNAM), number validation, incoming call spam intelligence, email transactions, email verifications, and dedicated SMTP services.

  • Marketplace Connectors & Third-Party Apps: Usage and subscription fees for integrated applications, including OpenDental Connector, MailChimp/MailSync for Workflows, WooCommerce for Workflows, ServiceM8, Social CRM, Spintax, GOFINFI-Soft Pull API, PayBridge Connect, B365 Field Service, blueMSG, Brandblast Content Engine, Clara AI, TikTok CAPI, Twilio integration fees, Vehicle Visualizer, Volt, and custom marketplace installations.

5. Automated Communications, Telephony & Mandatory Disclosures

When telephone numbers are provided to us or captured via Customer workflows:

  • Automated Dialing & AI Voice: Communications (operational, transactional, or promotional) may be initiated via automated telephone dialing systems, artificial/prerecorded voice technology, and interactive AI voice agents where permitted by law.

  • Consent & Opt-Out Mechanics: Customer is strictly responsible for securing prior express written consent under the TCPA and TSR. Standard message frequency varies, and message/data rates may apply. Recipients may opt out of automated SMS at any time by replying STOP, or request assistance by replying HELP.

  • Call Recording Compliance: Calls, web chats, and AI voice interactions may be recorded and monitored for quality assurance, training, analytics, and compliance. Customer assumes full responsibility for complying with federal and state wiretapping/consent laws by configuring mandatory pre-call audio disclosures (e.g., “This call may be recorded for quality and training purposes”).

6. Health Data & HIPAA Compliance

For Customers operating as Covered Entities under HIPAA:

  • Lead Central AI executes a standard Business Associate Agreement (BAA) upon request or account setup.

  • Data Encryption Standards: All PHI and sensitive customer data are protected using AES-256 encryption at rest and TLS 1.2+ encryption in transit across database, storage, and communication networks.

  • Patients or contacts seeking to exercise rights regarding their PHI should direct their request directly to their healthcare provider (the Data Controller).

7. Individual Privacy Rights & Cookie Controls

Depending on your geographic location, you may hold statutory rights under applicable privacy laws (e.g., CCPA/CPRA, VCDPA, CPA, CTDPA, GDPR, PIPEDA):

A. Summary of Privacy Rights

  • Access & Data Portability: Request confirmation of data processing and obtain a portable copy of your personal data.

  • Correction & Deletion: Request correction of inaccurate information or deletion of personal data, subject to lawful retention exceptions.

  • Opt-Out Rights: Opt out of targeted advertising, profiling, or the sharing of personal data for cross-context behavioral advertising.

  • Global Privacy Control (GPC): We recognize and honor browser-based Global Privacy Control (GPC) signals as a valid opt-out mechanism where mandated by law.

B. Submitting Requests

To submit a privacy request, contact us at privacy@leadcentralai.com. If your request relates to data managed by one of our business customers, we will forward your inquiry to that customer for processing.

8. Data Retention, Account Lifecycle & Security

  • Active Subscription Period: Data is retained for as long as Customer’s account remains active, as necessary to deliver platform features, or as required to meet audit and legal obligations.

  • Post-Termination Window: Upon account cancellation, Customer is provided a 90-day export window to download logs, contacts, recordings, and transcripts.

  • Permanent Purge Schedule: Following the 90-day export window, Customer data is permanently deleted from active production databases within 30 days and fully purged from encrypted disaster-recovery system backups within 90 days.

  • Security Measures: We maintain administrative, technical, and physical safeguards—including role-based access controls, security audits, and continuous monitoring—to protect personal data against loss, unauthorized access, or disclosure.

9. Children’s Privacy

The Lead Central AI platform and website are intended strictly for business professionals and are not directed to children under the age of 18 (or under 13 for general web activity). We do not knowingly collect personal information directly from children. If we discover that a child has provided us with personal data, we will take prompt steps to delete it.

10. Revisions to This Privacy Policy

Lead Central AI reserves the right to amend this Privacy Policy at any time to reflect software updates, carrier requirement adjustments, or legal changes. Material modifications will be announced by updating the “Effective Date” at the top of this Policy and posting a notification within the platform dashboard or via email.

11. Contact Information

For inquiries regarding this Master Privacy Policy, data privacy rights, or billing and re-billing compliance, please contact:

Lead Central AI Privacy & Compliance Operations

Email: privacy@leadcentralai.com

Website: https://leadcentralai.com