Legal
Privacy Policy
This notice explains how LeadForge collects, uses, stores and shares personal data, including data used for client services, business outreach and authorised Gmail features.
Version: 2026-09-02
1. Who is responsible for your data
Rafael Canevaro trading as LeadForge is the controller of the personal data described in this policy unless LeadForge processes data solely on a client's documented instructions.
Rafael Canevaro trading as LeadForge is an unincorporated sole-trader business. LeadForge is a trading name, not a limited company, and does not have a Companies House company number.
Website: https://leadforgewebsites.co.uk
Email: rafael@leadforgewebsites.co.uk
2. Personal data we collect
Depending on how you interact with LeadForge, we may collect:
- Account/contact data: name, business name, work email, phone number where provided, role, authentication and security records.
- Client/project data: requirements, messages, files, website content, change requests, project status, prices, invoices and service history.
- Business lead/outreach data: business name, public business contact details, location, category, public website/social information, source identifiers, email-verification results, subscriber-type/permission records, outreach history, replies, bounces, objections and suppression records.
- Communications: messages and email content sent to or received from LeadForge, with metadata needed to manage conversations and delivery.
- Technical/security data: IP address where available, browser/device information, timestamps, security logs, error logs and session data.
- Google/Gmail data: where an authorised LeadForge manager connects an account, OAuth permissions/tokens and business email data required to read authorised mail, synchronise replies/delivery failures and send authorised messages.
3. Where data comes from
We receive data directly from users when they create an account, contact us, supply project information, communicate with us or connect a service. We may also obtain business contact information from public or commercially available business directories and datasets.
If personal data was obtained from another source and we plan to communicate with the individual, we provide or link to the relevant privacy information at the first communication where required, unless a lawful exception applies.
4. Why we use data and our lawful bases
- Providing requested services/accounts: contract or steps requested before a contract.
- Building and managing client websites: contract and legitimate interests in delivering, securing and improving the service.
- Support and business communications: contract and legitimate interests.
- Relevant B2B prospecting: legitimate interests where electronic-marketing rules allow the contact; consent or a valid soft opt-in where those rules require it.
- Suppressions, objections and hard bounces: legitimate interests and legal compliance, including retaining a minimal record so a person is not contacted again.
- Security/fraud prevention: legitimate interests and, where relevant, legal obligations.
- Tax, accounting and regulatory records: legal obligations and legitimate business-record interests where appropriate.
5. Business outreach and electronic marketing
LeadForge is intended to prospect businesses, not private consumers. For unsolicited electronic marketing, corporate subscribers such as limited companies and LLPs are treated differently from individual subscribers. Sole traders, ordinary partnerships and uncertain subscriber types are not intentionally sent unsolicited marketing email unless consent, a valid soft opt-in or another permitted basis has been recorded.
Where we use a named work contact's personal data for corporate B2B prospecting, we assess legitimate interests, keep the communication relevant and proportionate, identify LeadForge and provide an easy way to object.
You can object to direct marketing at any time by replying unsubscribe or emailing rafael@leadforgewebsites.co.uk. Direct-marketing objections are honoured and a minimal suppression record may be retained to prevent repeat contact.
6. Gmail and Google API data
LeadForge uses the Gmail API only after an authorised manager grants access. The integration may request read access and permission to send email for synchronising business conversations, identifying replies/delivery failures, displaying relevant correspondence, sending authorised campaign messages and sending replies requested through LeadForge.
OAuth credentials are kept server-side and are not exposed to ordinary browser users. LeadForge does not sell Google user data, use Gmail content for advertising, or transfer Gmail data for unrelated purposes.
LeadForge's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
A connected Google account can be disconnected and access can be revoked in Google security settings. Existing business records may be retained where still required for legitimate business, legal, security or suppression purposes.
7. Who we share data with
We disclose data only as needed to operate LeadForge, provide a requested service, protect the platform or comply with law. Providers may include Google Workspace/Gmail, Supabase (database/authentication/backend), Lovable and hosting infrastructure, Cloudflare (domain/DNS/network security), payment processors if enabled, and professional advisers/regulators/courts/law enforcement where required.
We do not sell personal data. Where LeadForge acts as a processor for a client, the Data Processing Addendum applies.
8. International transfers
Technology providers may process data outside the UK. Where UK transfer restrictions apply, we rely on an applicable UK adequacy regulation or appropriate contractual/organisational safeguards such as recognised contractual clauses or equivalent mechanisms.
9. Retention
We keep personal data only for as long as reasonably needed for the purpose it was collected, active services, legitimate business records, disputes, security, legal obligations and enforcement. Different records therefore have different retention periods.
OAuth credentials are retained only while the integration remains connected or until access is revoked/removed. Project/account records may be retained for an appropriate period after the relationship ends. Suppression records may be kept for longer because deleting them could cause an opted-out or invalid address to be contacted again. We periodically review data that no longer has a continuing purpose.
10. Security
LeadForge uses authenticated sessions, role-based access, server-side secret storage, restricted integration credentials, database access controls, logging and other technical/organisational measures appropriate to the service. No internet service can guarantee absolute security.
11. Cookies and browser storage
LeadForge may use strictly necessary cookies/browser storage for authentication, security and core functionality. Non-essential analytics, advertising or tracking technologies that require consent will not be intentionally enabled without an appropriate consent mechanism and an updated notice.
12. Your rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase or restrict data, object to processing, receive certain data in a portable format and withdraw consent where consent is the basis. You have an absolute right to object to personal data being used for direct marketing.
Contact rafael@leadforgewebsites.co.uk. We may need to verify identity. You may also complain to the UK Information Commissioner's Office.
13. Automated processing
LeadForge may use automated rules to organise leads, validate contact data, classify delivery outcomes, apply marketing-eligibility gates and prioritise workflow. We do not currently use solely automated processing to make decisions about individuals that produce legal or similarly significant effects.
14. Children
LeadForge's services are intended for business users and are not directed at children. We do not knowingly use children's personal data for business prospecting.
15. Changes and contact
We may update this policy as the service or law changes. The current version and date remain on this page. Material changes are communicated where reasonably required.
For contractual information, see our Terms of Service.