Data Practices & Security
Effective date: 16 August 2026
Last updated: 16 August 2026
Version: 1.0
Operator: Abdurrahman Ersin Alagöz, trading as ClarifyLeads, Istanbul, Türkiye
Contact: [email protected]
This page gives a plain-language overview of how ClarifyLeads handles data. The Privacy Policy is the controlling detailed notice.
What ClarifyLeads is
ClarifyLeads is B2B research and lead-operations software. It helps business users research companies, review public business evidence, normalise or extract business-contact details, check user-provided numbers on supported communication channels, assess fit, organise selected records and manage follow-up in a private workspace.
ClarifyLeads does not send outreach messages. A validation or discovery result is not permission to contact anyone.
Data-minimisation principles
We aim to:
- process only the fields reasonably needed for the selected tool;
- separate user accounts and jobs;
- keep raw uploads and temporary processing material for short periods;
- avoid storing private message content for channel-presence checks;
- prevent sensitive data and children's data from being submitted;
- give users control over saved CRM and profile records;
- delete live user data when an account is validly deleted, subject to legal records and backup rotation; and
- disclose when a feature sends selected data to an external search, AI, payment or communication provider.
Standard retention at a glance
| Data | Standard retention |
|---|---|
| User uploads and job payloads | 24 hours |
| Runtime/intermediate processing files | 24 hours |
| Successful downloadable results | 7 days |
| Failed/cancelled job files | 72 hours |
| Orphan job folders | 48 hours |
| Job metadata/history | 30 days |
| Temporary uploads and general temp files | 24 hours |
| Routine logs | 14 days |
| Detailed company-search coverage / semantic records | Up to 180 days where enabled |
| CRM and saved workspace data | Until the user deletes it or closes the account |
| Database/manual production backups | Maximum 30 days under normal rotation |
| Deploy / rollback artefacts | 14 days / 30 days |
| Billing, tax, refund, fraud and dispute records | As legally or operationally required |
Automated lifecycle controls are intended to apply these periods. Limited delays may occur for queued cleanup, provider confirmation, service recovery, backup rotation, legal hold or security investigation.
Connected-channel sessions
- Telegram and Zalo: designed to disconnect after the last active validation job reaches a final state, and also on manual logout or account deletion.
- WhatsApp: may remain connected between validation jobs to support repeat checks. It is disconnected on manual logout, account deletion or inactivity cleanup.
- Stale local session data: targeted for cleanup after 24 hours of inactivity. Active jobs are protected from cleanup.
- Provider confirmation: if a provider does not confirm remote logout, ClarifyLeads may preserve limited local state for a controlled retry rather than falsely report successful deletion.
The channel tools check presence or availability only; they do not provide outbound messaging.
AI and search providers
A feature may send selected business terms, website text, company information, product descriptions, evidence excerpts or business-card text to an external AI or search provider. Do not submit passwords, payment data, private messages, special-category data or unnecessary confidential information.
AI-generated scores, summaries and classifications are reviewed aids rather than guaranteed facts. The user decides what to accept, reject, defer, save or act on.
Where processing occurs
The current backend environment processes data in Germany. The current WordPress/frontend environment is operated in Türkiye. Payment, AI, search, authentication and communication providers may process data in other jurisdictions.
The current provider categories and feature dependencies are listed at Service Providers, Subprocessors and Independent Platforms.
Security approach
ClarifyLeads uses measures designed to reduce risk, including:
- authenticated access and scoped backend sessions;
- transport encryption for supported production connections;
- separation of application secrets from source code;
- user and job ownership checks;
- request validation and output escaping;
- restricted file types and size limits;
- idempotency and anti-duplicate controls;
- rate, credit and workflow controls;
- provider logout and session-cleanup routines;
- limited log and artefact retention;
- account-deletion workflows scoped to the requesting user; and
- security and abuse investigation records where needed.
These measures do not make any internet service risk-free. Users must protect credentials, exported files and connected devices.
Your responsibilities
Use only data you are authorised to process. Keep records accurate and relevant. Delete data that is no longer needed. Honour objections and opt-outs. Do not submit sensitive data or use channel checks for surveillance, harassment or curiosity.
Read the Acceptable Use Policy and Anti-Spam Policy before using results for outreach.
Account deletion
Account deletion is designed to remove live account, CRM, saved-profile, job and connected-session data after active-job safeguards and cleanup complete. Payment, tax, fraud, security and dispute records may remain where law or legitimate protection of rights requires. Backup copies may remain only until the normal maximum 30-day rotation completes.
Questions and rights requests
Contact [email protected].