Privacy Policy
Effective date: 16 August 2026
Last updated: 16 August 2026
Version: 1.0
Operator: Abdurrahman Ersin Alagöz, trading as ClarifyLeads, Istanbul, Türkiye
Contact: [email protected]
This Privacy Policy explains how ClarifyLeads collects, uses, discloses, stores and protects personal data when you visit, register for or use the Service. It also explains how we handle business-contact information and other data submitted by customers.
1. Controller identity and contact
ClarifyLeads is a trading name of Abdurrahman Ersin Alagöz, a sole proprietor operating from Istanbul, Türkiye.
For account, website, security, support and service-administration data, ClarifyLeads generally acts as the data controller. For Customer Data that a business customer submits and controls in its private workspace, ClarifyLeads generally acts as a processor or service provider on that customer's documented instructions.
Contact: [email protected]
Registered business details: Legal Notice
Role labels depend on the facts and applicable law; calling a party a “processor” does not change a role that law assigns differently.
2. Scope
This Policy applies to:
- visitors to clarifyleads.io;
- account holders and authorised users;
- people who contact support or interact with billing;
- data contained in user-submitted files, searches, CRM records or connected-channel checks; and
- technical and security data generated by the Service.
It does not govern a third party's independent website, platform, checkout or service. Those parties provide their own notices.
3. Personal-data categories
We may process the following categories, depending on the feature used.
| Category | Examples |
|---|---|
| Account and identity data | Name, username, email, business name, role, country, profile and account identifiers |
| Authentication and security data | WordPress authentication state, backend session identifier, OAuth identifiers, login time, IP address, browser/device information, security events |
| Billing and subscription data | Plan, billing interval, order/customer/subscription identifiers, status, renewal/expiry date, invoice and portal references, tax location, refund or chargeback status |
| Customer-submitted business data | Company names, domains, websites, products, markets, business-contact names, job titles, work email addresses, phone numbers, notes, files and user instructions |
| CRM and workspace data | Companies, contacts, lifecycle status, priority, tags, follow-up dates, activities, review decisions and exported selections |
| Channel-validation data | Phone numbers submitted for checking, selected provider, connection/session status, provider authentication material and technical logout/cleanup records |
| File and extraction data | CSV/XLSX/TXT content, images of business cards, extracted text, document metadata and generated result files |
| Search and intelligence data | Search terms, countries, cities, products, sectors, candidate companies, source URLs, evidence excerpts, match scores, summaries and review actions |
| Support and communications | Messages, attachments, issue details and correspondence history |
| Usage and job data | Tool selected, job identifier, status, timing, credit cost, error category, result metadata and feature interaction |
| Cookies and browser storage | Authentication cookies, local job status, credit display cache, CRM display preferences, page state and temporary idempotency keys |
We do not need or request payment-card numbers. Payment credentials are collected by the payment provider at checkout. We may receive limited billing and transaction metadata needed to activate and administer a subscription.
4. Sources of data
We collect data:
- directly from you or your organisation;
- automatically from your device and use of the Service;
- from a connected account or platform when you initiate a channel check or social login;
- from payment and subscription providers;
- from public websites, company sites, maps, business directories, search providers and public trade datasets; and
- from other users who lawfully submit business-contact data to their organisation's workspace.
A business contact may therefore appear in Customer Data even if that person has no ClarifyLeads account. The customer that submitted the record is responsible for its lawful basis, transparency and intended use.
5. Purposes and legal grounds
Depending on applicable law, we rely on contract, steps requested before contract, legitimate interests, legal obligation and consent. Our principal purposes are:
| Purpose | Typical legal ground |
|---|---|
| Create and administer accounts | Contract; requested pre-contract steps |
| Authenticate users and secure the Service | Contract; legitimate interests in security and abuse prevention |
| Run tools, jobs, exports and CRM functions | Contract; customer instructions |
| Process payments, subscriptions, taxes and refunds | Contract; legal obligation; legitimate interests in billing integrity |
| Provide support and operational notices | Contract; legitimate interests |
| Detect fraud, spam, misuse and security incidents | Legitimate interests; legal obligation where applicable |
| Improve reliability, debug faults and measure service performance | Legitimate interests, using proportionate technical data |
| Generate search, extraction, AI and match outputs | Contract; customer instructions; legitimate interests in providing requested functionality |
| Comply with legal process and protect rights | Legal obligation; establishment, exercise or defence of legal claims |
| Use non-essential analytics or marketing technology | Consent where required |
Where we rely on legitimate interests, we consider necessity, proportionality, reasonable expectations and possible impact. You may object where applicable.
6. Customer Data and processor role
A business customer normally determines why it uploads business contacts, runs a check, saves a CRM record or uses a result. For that processing, the customer is responsible for:
- identifying a lawful basis;
- giving required notices;
- honouring objections, opt-outs and rights requests;
- limiting collection to relevant business data;
- setting an appropriate retention period; and
- ensuring any outreach complies with applicable communication rules.
ClarifyLeads processes Customer Data to provide the requested Service, maintain security, troubleshoot, meet legal duties and follow the agreement. The Data Processing Addendum provides additional processor terms.
We do not sell Customer Data submitted to a customer's private workspace for money or use it for another customer's independent marketing campaign.
7. Public business information
The Service may find or derive information from publicly accessible business sources. Public availability does not necessarily make every reuse lawful. We seek to focus on business-relevant information, but a business email address, direct phone number or named professional contact can still be personal data.
Results may be cached, normalised, deduplicated, scored or combined with other business evidence. Customers must verify accuracy and assess whether their planned use is lawful and proportionate.
A person who believes a ClarifyLeads-controlled public-data record is inaccurate or unlawfully processed may contact [email protected]. If the record exists only inside a customer's private workspace, we may direct the request to that customer and assist as required.
8. AI and automated processing
Some features send selected prompts, website text, business-card text, company information, product descriptions, evidence excerpts or structured fields to an AI provider to produce an output requested by the user. We aim to send only data reasonably needed for that feature.
ClarifyLeads uses automated processing to assist with extraction, classification, search planning, profiling, matching and summarisation. These outputs support human review. ClarifyLeads does not intend them to make decisions that produce legal or similarly significant effects on individuals.
Do not submit sensitive personal data, private message content, passwords, payment data or confidential material to an AI-assisted feature unless the feature and your agreement expressly permit it.
9. Channel connections
ClarifyLeads channel tools are designed to check whether user-provided numbers appear to be available on supported communication channels. They do not provide outbound messaging.
When you connect a channel, we may process provider authentication/session material, technical account identifiers, submitted phone numbers and status responses. We do not intentionally collect message content for the channel-presence purpose.
Session lifecycle differs by provider:
- Telegram: designed to log out and remove local session material after the last active Telegram validation job reaches a terminal state, or on manual logout or account deletion.
- Zalo: designed to log out and remove local session material after the last active Zalo validation job reaches a terminal state, or on manual logout or account deletion.
- WhatsApp: may remain connected between jobs to support repeated checks. It is removed on manual disconnect, account deletion or inactivity cleanup. Provider-side deletion must be confirmed; if confirmation fails, cleanup may be retried rather than falsely reported as complete.
- Stale/abandoned local session material: targeted for cleanup after 24 hours of inactivity, while active jobs are protected from deletion.
Provider systems may retain their own security, account or transaction records under their policies.
10. Disclosures and recipients
We disclose data only as reasonably necessary to the following categories:
- hosting, storage, database, network and backup providers;
- payment, tax, fraud, invoicing and subscription providers;
- AI model and text-processing providers where an AI feature is used;
- search, maps, places, proxy and public-data providers where a research feature is used;
- WhatsApp/Meta, Telegram or Zalo when the user initiates a check;
- authentication providers when social login is used;
- email and support providers;
- professional advisers, auditors and insurers under confidentiality duties;
- a buyer or successor in a genuine business transaction, subject to appropriate safeguards; and
- courts, regulators, law-enforcement or other parties where disclosure is legally required or necessary to protect rights and safety.
Current and feature-dependent providers are described in Service Providers, Subprocessors and Independent Platforms.
Payment processing is currently supported by Lemon Squeezy. Depending on the transaction, the payment provider may act as merchant of record and an independent controller for checkout, payment, tax, fraud and statutory records.
11. External resources
The current CRM interface may request company logos or favicons from third-party image services using the company domain being displayed. This can reveal the requested domain and ordinary request metadata, such as IP address and browser information, to that provider. We may replace, proxy or disable these resources. The live Cookie Policy should be consulted for current details.
12. International processing and transfers
The current backend environment processes data in Germany, and the current WordPress/frontend environment is operated in Türkiye. Providers used for payment, search, AI, authentication and communication channels may process data in other countries where they operate.
Where a transfer is subject to data-transfer restrictions, the parties must use a legally recognised mechanism appropriate to the transfer. Depending on the law and parties, this may include adequacy arrangements, standard contractual clauses, binding corporate rules, approved standard contracts, contractual safeguards, explicit consent where valid, or a statutory exception.
Because transfer mechanisms depend on the provider, data type and customer location, customers requiring a specific localisation or transfer arrangement should contact [email protected] before submitting regulated data.
13. Retention schedule
We retain personal data only for the time reasonably needed for the purpose, contractual commitments, security, dispute handling and legal duties. Standard technical periods are:
| Data category | Standard period or criterion |
|---|---|
| Job payloads and user uploads | Up to 24 hours |
| Runtime and intermediate files | Up to 24 hours |
| Successful job result files | Up to 7 days |
| Failed or cancelled job files | Up to 72 hours |
| Orphan job folders | Up to 48 hours |
| Job metadata and history | Up to 30 days |
| Upload temporary files | Up to 24 hours |
| General temporary files | Up to 24 hours |
| Routine application logs | Up to 14 days |
| Detailed search coverage and semantic records | Up to 180 days where the feature retains them; higher-level account records may remain until deletion |
| CRM, saved profiles, settings and workspace records | Until the customer deletes them or closes the account |
| Telegram, Zalo and WhatsApp local session material | According to Section 9; stale material targeted after 24 hours of inactivity |
| Database and manual production backups | Maximum 30 days under normal rotation |
| Deploy artefacts | Up to 14 days |
| Rollback artefacts | Up to 30 days |
| Billing, tax, invoice, refund, fraud and dispute records | For the period required by applicable law or reasonably needed to establish, exercise or defend claims |
| Support correspondence | For as long as reasonably necessary to resolve the issue, maintain a support history and handle disputes |
A shorter or longer period may apply where law requires it, a legal hold is in place, fraud or security investigation is ongoing, a provider is completing deletion, or technical restoration temporarily reintroduces a backup copy. Restored deleted data must not be returned to ordinary use and should be re-deleted through the normal lifecycle.
Automated lifecycle controls are intended to apply these periods. A limited deletion delay may occur because of queued cleanup, provider confirmation, temporary service interruption, backup rotation, legal hold or a security investigation.
14. Account deletion
An account-deletion request is designed to remove the user's live account, profile, job records and artefacts, CRM data, saved business profiles, channel sessions and user-specific temporary data. Deletion may be blocked while jobs are active to prevent corruption or cross-user loss.
Some information may remain temporarily in backups for no more than the normal rotation period, or longer where necessary for tax, payment, refund, chargeback, fraud, security, legal or dispute obligations. A payment provider may retain independent transaction records even after the ClarifyLeads account is deleted.
Account deletion does not itself cancel or refund an already-completed purchase. Cancel the subscription separately before deleting the account.
15. Security
We use administrative, technical and organisational measures designed to protect data, including access controls, authentication, transport encryption, secret separation, input validation, job isolation, scoped deletion, provider logout, audit-oriented records and retention limits.
No internet service can guarantee absolute security. You are responsible for protecting account credentials, connected devices and exported files. Do not send passwords, API keys, payment-card data or special-category data through ordinary support messages.
If we become aware of a personal-data breach, we will investigate, mitigate and notify affected customers, persons or authorities where and within the time required by applicable law.
16. Your rights
Depending on where you are and which law applies, you may have rights to:
- learn whether and how personal data is processed;
- request access or a copy;
- correct inaccurate or incomplete data;
- request deletion, destruction or anonymisation;
- restrict or object to processing;
- withdraw consent without affecting prior lawful processing;
- receive portable data where applicable;
- object to certain automated processing;
- learn the recipients of data;
- request compensation or complain to a competent authority; and
- exercise the rights granted by Article 11 of Türkiye's Personal Data Protection Law and, where applicable, the GDPR or other local law.
Send requests to [email protected]. State the relevant account, relationship and request. We may ask for proportionate information to verify identity and authority. We will respond within the period required by applicable law.
If ClarifyLeads is processing a record only on behalf of a customer, we may forward the request to that customer or ask you to contact it directly. We will assist the customer as required by the Data Processing Addendum.
17. Cookies and browser storage
We use necessary authentication cookies and functional browser storage. The supplied application code does not intentionally deploy advertising or behavioural-analytics cookies. A live WordPress theme, plugin, Tag Manager, CDN or payment checkout may introduce additional technology and must be assessed separately.
See the Cookie Policy for the current inventory and choices.
18. Children and sensitive data
The Service is not intended for anyone under 18. Do not use it to research, profile, validate or store data about children.
Do not submit special-category or highly sensitive data, including health, biometric, genetic, political, religious, sexual-life, precise private-location, government-identification, financial-account, password or private-communications data, unless an enterprise agreement expressly authorises the category and safeguards.
19. Changes
We may update this Policy for legal, technical, provider or product changes. Material changes will be communicated through the Service, by email or by another reasonable method where required. The date and version at the top identify the current text.
20. Contact and complaints
Privacy questions and rights requests:
ClarifyLeads
Operator: Abdurrahman Ersin Alagöz
Location: Istanbul, Türkiye
Email: [email protected]
Registered address: see Legal Notice
You may also complain to the competent data-protection authority in your jurisdiction. We encourage you to contact us first so we can investigate promptly.