This Data Processing Addendum supplements the Terms of Service and should be read with the Privacy Policy. It applies where GDPR, UK GDPR, or similar laws govern End User personal data processed through the Services.
1. Roles
The Merchant acts as data controller and Leafine acts as data processor for End User personal data processed through the Services.
The Merchant is responsible for the accuracy and lawfulness of Merchant Data, providing legally required notices to End Users, and obtaining the consents needed for Leafine to process Merchant Data on the Merchant's behalf.
2. Subject matter and duration
Leafine processes Merchant Data to provide, secure, maintain, and improve the Services and as otherwise described in the Privacy Policy. Processing continues while the Merchant has an account or active subscription and during applicable retention and deletion periods.
The Services include the Lea AI assistant, storefront chat widget, unified inbox, task automation, campaigns, analytics, APIs, and connected applications.
3. Nature and purpose of processing
Processing may include accessing, retrieving, hosting, storing, organizing, transmitting, displaying, generating technical representations, and taking authorized actions on connected Platforms, such as sending messages, updating orders, or publishing content.
Leafine processes data only to provide the Services, secure accounts, prevent fraud, investigate incidents, improve reliability and performance, personalize workflows and recommendations, comply with legal obligations, and enforce the Terms.
Leafine does not sell personal data, use it for third-party advertising, or use Google Workspace data to train or improve any AI or machine learning model.
4. Data and data subjects
Processed data may include:
- Account information: name, email, phone, company details, role, and billing contacts.
- Usage and technical data: logs, events, performance telemetry, diagnostics, IP address, device and browser type, operating system, language, timestamps, and identifiers.
- Order and communication data: products, orders, contact records, messages, emails, message subjects, sender names, and conversation history.
Data subjects may include the Merchant, Authorized Users, customers, shoppers, contacts, and other End Users interacting with the Merchant through the Services.
5. Confidentiality and security
Leafine applies defense-in-depth measures including encryption in transit and at rest, access controls, least privilege, audit logging, and continuous monitoring. Personnel and service providers with access to personal data are subject to confidentiality obligations.
Additional information is available in the Security Overview.
6. Subprocessors
Leafine uses subprocessors to provide the Services. The current complete list, including the data each provider receives and its purpose, is maintained on the Subprocessors page.
OpenAI is Leafine's only AI subprocessor. No other third-party AI provider receives Gmail data.
7. International transfers
Data may be processed in or transferred to countries outside the data subject's country, including transfers between the EU or UK and the United States.
Leafine uses appropriate safeguards such as Standard Contractual Clauses and technical measures to protect data during transfer.
8. Assistance and rights
Taking into account the nature of processing, Leafine will provide reasonable assistance for requests to access, correct, delete, restrict, object to processing, or port personal data, and for withdrawal of consent where applicable.
Leafine will also provide reasonable information needed for applicable data-protection obligations, including incident investigation and required notifications.
Requests may be sent to hello@leafine.com.
9. Retention, return, and deletion
Leafine retains personal data only as long as needed for the stated purposes or legal obligations. Typical defaults are account data for the subscription term plus up to 24 months, system logs up to 12 months, support tickets up to 24 months, and backups according to rolling schedules.
For 30 days following termination, the Merchant may request an export of Merchant Data in a commonly used format. Leafine will then delete or anonymize it according to the Privacy Policy, except where retention is required by law.
10. Platform data
Leafine accesses connected Platform data through approved APIs and processes it according to applicable developer terms and data policies, including the Google API Services User Data Policy and its Limited Use requirements.
For Gmail, Leafine requests only the https://www.googleapis.com/auth/gmail.modify scope and uses it as described in the Privacy Policy.