Q: Hi, Can you please explain a bit more about your GDPR compliance and data security?
You advertised this tool with Quote:
“You have to make sure you’re compliant with regulations like CAN-SPAM and GDPR to avoid hefty fines.
What If You Didn’t Have To Stress Out About Any Of This? What If There Was A Simple Software… “
I’ve read the boilerplate privacy policy on your website https://leadpal.net/privacy-policy/ and I do not see how my company would be GDPR compliant when using this tool.
Just claiming that Leadpal or this tool is GDPR compliant does not make Leadpal or me as a client GDPR compliant.
I see 3 potential issues:
1.) Who is Leadpal? LLC registered? Registration number? Business address?
On your website it states “Made with ❤️ love in Atlanta” .
-That’s just not good enough if my company gets sued or issued a fine.
2) My dashboard is hosted on Leadpals controlled servers, without any mention of encryption, security measures taken , server company used etc. - In the ideal scenario my instance would be encrypted and I am the only one having the key.
3) If I use your pre-made “apps” as you call them… Basically Leadpals pre-authorised e.g. “continue with Google” or “Continue with “whatever brand of social media” … those log-in “apps or (scripts) ” have been Api connected / authorised by those social media companies/services to Leadpals .
That means if I use the Leadpals code snippets to receive my website visitor data /leads - then my customers/visitors personal data points are automatically in Leadpals’s database. -Right?
So, I would have to tell my European customers that their personal data is stored and handled by “ Leadpol Made with ❤️ love in Atlanta” ?
- As you have explained here to some other user in the question section,to avoid this I would have to “ built my own apps/scripts” with my custom domain/s.
However, even if I were to “build my own app/ scripts” to-be used with your software/dashboard and my company’s domain/s get individually authorized for Api access and “Log-in with X” from the respective social media companies - we are still back to issue point 1 and 2 :
1. I don’t know who Leadpal is.
2. Leadpal has full access to all my customers details because the dashboard/ software is controlled by Leadpal and Leadpal does not mention any security measures, encryptions etc…
Don’t get me wrong, the software looks great!
However, under GDPR my company is required by law to know how my vendors operate including their security framework and how they manage data.
Without that knowledge, I don’t know the risk my vendor/s present and therefore by using this tool my company would NOT be GDPR compliant and my company would be liable in the case of misuse and/or inappropriate handling and processing of data.