LeadDesk
Privacy Policy
This notice is published under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and in accordance with the Digital Personal Data Protection Act, 2023. It sets out what personal data LeadDesk processes, on what basis, who it is shared with, how long it is kept, and how you may exercise your rights.
- Effective from
- 18 August 2026
- Last updated
- 18 August 2026
- Governing law
- India
1.Scope and application
LeadDesk (the “Service”) is operated by Trowcode, a business established in India (“we”, “us”, “our”), and made available at lsi.trowcode.com.
This notice applies to all personal data processed through the Service. It forms part of and is to be read with our Terms of Service. Where the two conflict on a matter of personal data, this notice prevails.
By creating an account or continuing to use the Service you acknowledge that you have read and understood this notice.
2.Definitions
In this notice, terms defined in the DPDP Act carry the meaning given there. Chiefly:
- Data Principal— the individual to whom personal data relates.
- Data Fiduciary— the person who determines the purpose and means of processing personal data.
- Data Processor— a person who processes personal data on behalf of a Data Fiduciary.
- Customer— the business that holds an account on the Service.
- Lead Data— personal data relating to prospective customers that a Customer brings into the Service.
- DPDP Act— the Digital Personal Data Protection Act, 2023, together with the rules made under it.
3.Our role: Fiduciary in one respect, Processor in another
The Service is business software, and our obligations differ according to which data is in question:
- Account Data. In respect of the data a Customer and its users give us in order to use the Service, we act as Data Fiduciary. We determine the purpose and means of that processing, and the rights in section 11 are exercised against us.
- Lead Data. In respect of prospective-customer data brought into the Service by a Customer, we act solely as Data Processor. The Customer is the Data Fiduciary. We process it only on the Customer’s documented instructions and under a contract as required by section 8(2) of the DPDP Act, and we do not determine its purposes.
If you responded to an advertisement placed by one of our Customers and wish your data to be accessed, corrected, or erased, the Customer is the Data Fiduciary and your request must be made to that business. Where you cannot identify or reach them, write to us under section 12 and we will forward your request and assist the Customer in responding.
4.Personal data we process
Account Data, provided by you: name, email address, and a password stored only in irreversibly hashed form. We never hold your password in readable text.
Lead Data, provided by the Customer or received on the Customer’s behalf: name, telephone number, email address, city, and the answers submitted on the Customer’s advertisement form. This reaches the Service in one of three ways — from Meta lead advertisements, from a Google Sheet the Customer connects, or from a file the Customer uploads.
Engagement records, generated in use: call outcomes and timings, notes, follow-up dates, pipeline stage changes, assigned owner, and deal values.
Connection credentials: authorisation tokens issued to us by Google and Meta when a Customer connects an account, retained so that background synchronisation continues without a further sign-in. These are dealt with in section 5.
Operational records: an audit log of significant actions taken in an account, together with IP addresses processed transiently for rate limiting, fraud prevention, and security. These serve our legitimate need to keep the Service secure and to demonstrate compliance.
We do not knowingly collect financial account details, government identifiers, health data, biometric data, or any other category of sensitive personal information under the SPDI Rules, and Customers must not introduce such data into the Service.
5.Data accessed through Google APIs
Connecting a Google account is optional and serves a single purpose: reading the one spreadsheet you choose, so that rows in it become leads in your account. Where you connect one, we request the following authorisations and no others:
- See and edit only the files you open with this app (drive.file). This authorisation extends strictly to the file you select through Google’s own file picker. We are not able to see, list, search, or open any other file in your Google Drive, and in respect of the selected file we only ever read.
- Your email address and basic profile (openid, email). Used solely to label the connection in Settings so that you can identify which account is connected.
From the selected spreadsheet we read the column headings and row values, and record them as leads within your account. We retain a long-lived Google authorisation token so that synchronisation can run in the background at regular intervals. We do not write to, alter, or delete anything in your spreadsheet or your Drive.
Limited Use
LeadDesk’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data to serve advertising; we do not sell it; we do not transfer it to others except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition; and we do not permit humans to read it except where you have given explicit consent for specific data, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
You may withdraw this authorisation at any time from Settings within the Service, which also revokes our token at Google; or independently from your Google Account permissions page. On withdrawal our access ends immediately, synchronisation stops, and the stored token is deleted. Leads already imported remain in your account and are dealt with under section 10.
Where a Customer instead connects a Meta account, we receive lead advertisement submissions and advertising expenditure figures for the pages and accounts authorised. The same principles apply: we hold only the token needed, we use it only for the Service, and it may be revoked at any time.
6.Purposes of processing
We process personal data only for the following purposes:
- To deliver leads into the correct user’s queue and to raise follow-up reminders.
- To score leads and produce reporting on which advertisements resulted in revenue.
- To authenticate users, maintain sessions, and prevent unauthorised access.
- To detect, investigate and prevent abuse, fraud and security incidents.
- To diagnose faults and to provide support when a Customer requests it.
- To comply with legal obligations and to establish or defend legal claims.
Account Data is processed on the basis of the consent you give when creating an account and for the legitimate uses permitted under section 7 of the DPDP Act. Lead Data is processed on the instructions of the Customer, who is responsible for establishing the lawful basis for it.
We do not sell personal data. We do not disclose it to advertisers or data brokers. We do not use Lead Data to train machine-learning models, and we do not use it for any purpose of our own.
7.Disclosure and processors
We engage a small number of processors, each bound by contract to process personal data only on our instructions and to maintain appropriate security safeguards:
- Cloud infrastructure providers, which host the application and the database.
- Google LLC, only where a Customer has connected a Google account, and only in respect of the spreadsheet selected.
- Meta Platforms, only where a Customer has connected a Meta account, for receipt of lead advertisements and expenditure figures.
We may also disclose personal data where compelled by law, by a court, or by a lawful request from a government or regulatory authority; where necessary to establish, exercise or defend legal claims; or to protect the rights, property or safety of any person.
In the event of a merger, acquisition or transfer of our business, personal data may be transferred to the successor, who will remain bound by this notice. We will give notice before any such transfer takes effect.
8.Transfer outside India
Our infrastructure providers may store and process personal data on servers located outside India. Such transfers are made in accordance with section 16 of the DPDP Act and are not made to any territory restricted by notification of the Central Government. Where data is transferred outside India, we remain accountable for it and require equivalent safeguards by contract.
9.Security safeguards
We implement reasonable security practices and procedures as required by section 8(5) of the DPDP Act and section 43A of the Information Technology Act, 2000. These include:
- Isolation of each Customer’s data into its own tenant, enforced within the database itself through row-level security rather than in application code alone, so that a defect in the application cannot expose one Customer’s records to another.
- Encryption of all traffic in transit using TLS.
- Irreversible hashing of passwords, and sessions that expire and may be revoked.
- Access controls limiting personnel access to what their role requires.
- An audit log of significant actions taken within an account.
No system can be guaranteed secure. In the event of a personal data breach we will notify the Data Protection Board of India and each affected Data Principal in the manner and within the time required by section 8(6) of the DPDP Act, and will describe the nature of the breach and the steps taken.
10.Retention and erasure
Account Data and Lead Data are retained for so long as the Customer’s account remains active, the Service being a record of that Customer’s commercial dealings. A lead deleted within the Service is removed from the Customer’s workspace immediately and is purged from backups on their ordinary rotation.
On closure of an account we will erase the personal data held in it within thirty (30) days, save where retention is required by law or is necessary for the establishment or defence of legal claims. A Customer may request an export of its data in a portable format before closure.
Where we act as Data Processor, we erase Lead Data on the Customer’s instruction or on erasure by the Customer of the account, in accordance with section 8(7) of the DPDP Act.
11.Your rights as a Data Principal
Under Chapter III of the DPDP Act you have the right:
- to obtain a summary of the personal data we process about you and the processing activities undertaken (section 11);
- to the correction, completion, updating and erasure of your personal data (section 12);
- to a readily available means of grievance redressal (section 13);
- to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity (section 14);
- to withdraw consent at any time, with effect for the future.
To exercise any of these rights, write to trowcode@gmail.com. We will verify your identity, respond without undue delay and in any event within thirty (30) days, and we will not charge you for doing so. Where we act as Data Processor for Lead Data, we will refer your request to the relevant Customer and assist them in answering it.
Section 15 of the DPDP Act places corresponding duties on Data Principals, including that a request must not be false or frivolous.
12.Grievance redressal
In accordance with section 13 of the DPDP Act and Rule 5(9) of the SPDI Rules, any grievance concerning the processing of personal data may be addressed to:
We will acknowledge a grievance within forty-eight (48) hours and will resolve it within thirty (30) days of receipt.
If your grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India in accordance with section 13(3) of the DPDP Act. You must first have exhausted the process in this section.
13.Children
The Service is intended for use by businesses and is not directed at children. We do not knowingly process the personal data of any individual below the age of eighteen (18) years, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children, as prohibited by section 9 of the DPDP Act. Customers must not introduce a child’s personal data into the Service without the verifiable consent of a parent or lawful guardian. Where we learn that such data has been processed without that consent, we will erase it.
14.Cookies and tracking
We do not use advertising cookies, tracking pixels, or third-party analytics of any kind. The only data stored in your browser is that necessary for the Service to function: your sign-in session and your light or dark appearance preference. Neither is used to profile you or shared with anyone.
15.Amendment
We may amend this notice from time to time. Where an amendment materially affects your rights, we will give notice within the Service or by email before it takes effect, and will update the “last updated” date above. Continued use of the Service after an amendment takes effect constitutes acceptance of it.
16.Contact
Questions about this notice, or about how we process personal data, may be sent to trowcode@gmail.com.