Privacy Policy

What personal data LeadInbox collects, why we hold it, who we share it with, and the rights you have over it.

Last updated: 30 August 2026

1. Who we are

LeadInbox is operated by DeskLink Ltd, trading as DeskLink AI. In this policy, "we", "us" and "our" mean DeskLink Ltd.

Registered in England and Wales, company number 17076467.

You can reach us at contact@desklink.ai. Our postal addresses are in section 17.

2. What this policy covers

This policy applies to the LeadInbox web application at https://www.leadinbox.ai, our marketing site, and the emails and notifications we send. It explains how we handle personal data under the UK GDPR, the EU GDPR and the Data Protection Act 2018.

It does not cover the messaging platforms and email providers you connect to LeadInbox. Those services have their own privacy policies, and your use of them is governed by your agreement with each of them.

3. Controller and processor roles

Our role depends on the data. Both roles apply at the same time to different categories of data.

  • We are the controller of data about you as our customer: your account details, billing records, support correspondence, and how you use the product.
  • We are a processor of the data you bring into LeadInbox from your connected channels — the messages, contacts and pipeline records belonging to your business. You decide what is synced, what is kept and what is deleted. You are the controller of that data and are responsible for having a lawful basis to process your own contacts' personal data.

When we act as a processor we handle that data only on your instructions and to provide the service, unless the law requires otherwise.

4. Data we collect

Account data. Your name, email address, password hash, workspace name, user role, one-time sign-in codes, and settings you choose in the app.

Billing data. Plan, subscription status, invoice history, billing name and email. Card details are entered directly with Stripe and are held by Stripe — we never see or store full card numbers.

Connected channel data. When you connect an account, we sync and store message content, attachments, subject lines, timestamps, thread and chat identifiers, and the names, email addresses, phone numbers, profile handles and avatars of the people you correspond with.

Channel credentials. OAuth tokens and channel session credentials needed to keep your accounts connected. These are held by our channel provider, Unipile, and referenced by us through an account identifier. You can disconnect an account at any time, which revokes our access.

CRM data you create. Contact records, notes, tags, pipeline stages, lead activity and reply templates.

Usage and device data. IP address, browser and device type, pages viewed, feature usage, timestamps, and error and request logs. We use these to run, secure and debug the service.

Push notification tokens. If you enable browser notifications, we store the push subscription token for your browser so we can alert you to new messages.

Your AI provider key. If you enable AI features, we store the API key you supply for the provider you choose, so we can call that provider on your behalf. See section 7.

5. Where connected-channel data comes from

LeadInbox does not scrape platforms and does not buy contact lists. Message and contact data reaches us in one way only: through accounts you connect yourself, using each platform's own authorisation flow, via our integration provider Unipile.

Supported channels include WhatsApp, LinkedIn, Instagram, Messenger, Telegram, X (Twitter), Gmail, Outlook, IMAP email. You choose which accounts to connect. When you send a reply from LeadInbox, it is delivered out through that same connected account.

Disconnecting an account stops all further syncing from it. You can also delete conversations and contacts from within the app.

6. Why we use data, and our lawful bases

  • To provide the service — syncing your channels, showing your inbox, storing contacts and pipeline data, sending your replies. Basis: performance of a contract.
  • To take payment and keep accounts — subscriptions, invoices, tax records. Basis: contract, and legal obligation for accounting records.
  • To secure and improve the product — abuse prevention, fraud checks, debugging, aggregate usage analysis, capacity planning. Basis: legitimate interests in running a secure, reliable service.
  • To send service messages — sign-in codes, password resets, billing notices, material changes to the service. Basis: contract.
  • To send marketing email and web push notifications — product news and tips. Basis: consent, which you can withdraw at any time by unsubscribing or turning notifications off in your browser.
  • To meet legal requests — responding to lawful requests from authorities and defending legal claims. Basis: legal obligation, or legitimate interests.

We do not sell personal data, and we do not use the content of your connected inboxes for advertising or to train our own models.

7. AI features and your own provider key

AI lead scoring, conversation insights, reply suggestions and stage suggestions are optional. They run only on an API key that you connect yourself — from Anthropic, OpenAI or Google. We do not resell AI usage and we do not provide a shared model on your behalf.

When you enable an AI feature and it runs, the conversation text needed for that request is sent to the provider you chose, using your key. That processing happens under your own agreement with that provider and is subject to their terms and privacy policy, including any data-retention or model-training settings on your account with them. If that is not appropriate for the data in your inbox, do not enable AI features.

AI output is stored in your workspace alongside the conversation so you can review it. You can turn AI features off, remove your key, and delete stored AI output at any time.

8. Subprocessors

We use the following third parties to run LeadInbox. Each is bound by a contract requiring them to protect the data and to use it only to provide their service to us.

ProviderPurposeData involved
UnipileConnects and syncs messaging and email channelsMessage content, contact identifiers, channel credentials
SupabaseDatabase, authentication and file storageAccount data, conversations, contacts, attachments
VercelApplication hosting and content deliveryRequest metadata and logs
StripeSubscription billing and payment processingBilling name, email, payment card details (held by Stripe)
ResendTransactional email (sign-in codes, password resets)Email address and message content of those emails
ProgressierWeb push notifications for new messagesPush subscription token, notification title and preview
Anthropic, OpenAI or GoogleAI scoring, insights and reply suggestions — only when you connect your own API key, and only to the provider you chooseConversation text sent for analysis at the moment a feature runs

We may also share data with professional advisers, or with authorities where the law requires it. If we ever sell or restructure the business, customer data may transfer to the buyer under the same protections; we will tell you if that happens.

We will give notice of a new subprocessor by updating this page before the change takes effect.

9. International transfers

We operate from the United Kingdom and the United Arab Emirates, and several of the providers listed above are based in, or host data in, the United States. That means personal data may be transferred outside the UK and the European Economic Area.

Where we make such a transfer, we rely on appropriate safeguards — typically the UK International Data Transfer Addendum or the EU Standard Contractual Clauses with the provider, or an adequacy decision where one applies. You can ask us for details of the safeguards used for a specific transfer.

10. How long we keep data

We keep your account and workspace data for as long as your account is active, and for a limited period afterwards to close out the relationship, handle disputes, and meet legal, tax and accounting obligations. Billing and invoice records are kept for the period UK law requires.

Conversations, contacts and pipeline records that you delete in the app are removed from active systems and then cleared from routine backups on our normal backup cycle. Disconnecting a channel stops new data arriving; data already synced stays until you delete it or close your account.

When you close your account, we delete or anonymise your workspace data other than what we must retain by law. You can ask us to delete it sooner.

11. Security

We take the measures we consider appropriate for a service of this kind. In plain terms:

  • Data is encrypted in transit using TLS.
  • Data is stored in managed cloud infrastructure with encryption at rest provided by our hosting and database providers.
  • Every record carries a tenant identifier and is protected by database row-level security, so one customer's workspace cannot read another's.
  • Access to production systems is limited to staff who need it, and protected by individual accounts and multi-factor authentication.
  • Payment card details never touch our servers — Stripe handles them directly.

We do not currently hold a security certification such as SOC 2 or ISO 27001, and we will not claim one until we do. No system is perfectly secure. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant regulator as the law requires.

12. Cookies, analytics and the Meta pixel

We use strictly necessary cookies to keep you signed in and to keep the app secure. These cannot be turned off without breaking the service.

Our marketing site loads a Meta advertising pixel. It sets cookies and reports page views and sign-up events to Meta so we can measure and target our advertising. This is not loaded inside the signed-in application. You can limit it through your browser settings, a tracking blocker, or your Meta ad preferences.

13. Push notifications

Web push notifications are optional. If you allow them, your browser issues a subscription token which we store to send you alerts about new messages. A notification may include the sender's name and a short preview. Revoke permission in your browser, or turn notifications off in the app, and we stop sending them.

14. Your rights

Where we are the controller of your data, you have the right to:

  • ask for a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • ask us to delete data, where no legal reason to keep it applies;
  • receive data you gave us in a portable, machine-readable format, or have it sent to another provider;
  • object to processing based on our legitimate interests, and object to direct marketing at any time;
  • ask us to restrict processing while a dispute is resolved;
  • withdraw consent, where we relied on consent.

Email contact@desklink.ai to exercise any of these. We reply within one month. There is no charge unless a request is clearly unfounded or excessive.

If the request concerns data we hold as a processor for one of our customers — for example, a message thread inside their workspace — we will point you to that customer, who is the controller, and support them in answering you.

You can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA. We would rather you came to us first so we can put things right.

15. Children

LeadInbox is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

16. Changes to this policy

We update this policy when the service or the law changes. The date at the top shows the most recent revision. If a change materially affects your rights, we will tell you by email or in the app before it takes effect.

17. How to contact us

For any privacy question, email contact@desklink.ai or write to us:

London

Unit 1 Ripple RoadBarkingIG11 0RJUnited Kingdom

Dubai

1832-1834 Tamani Arts BuildingAl Asayel St, Business BayDubaiUnited Arab Emirates

See also our Terms of Service and Refund & Cancellation Policy.