Privacy Policy
Last updated : May 31, 2026
This policy explains what personal data we collect, why, and what your rights are, in accordance with the General Data Protection Regulation (GDPR).
1. Data controller
The data controller is the publisher of the HeyLeo site (heyleo.io). For any question about your data: privacy@heyleo.io.
2. Data we collect
Account data: name, email address, authentication information (via Clerk).
Billing data: handled by Stripe (we do not store your card numbers).
Usage data: bot usage statistics (views, conversations, collected leads).
Lead data: the information your visitors provide to your bots is stored on your behalf; you act as the data controller for it.
3. Purposes and legal bases
Service provision and contract performance (Art. 6.1.b GDPR): account management, bot hosting, conversation processing.
Legitimate interest (Art. 6.1.f): security, fraud prevention, service improvement.
Legal obligation (Art. 6.1.c): billing and accounting.
Consent (Art. 6.1.a): non-essential analytics cookies.
4. Recipients and processors
We rely on processors: Clerk (authentication), Convex (database), Vercel (hosting), Stripe (payment), OpenAI (conversational generation), and possibly Twilio (SMS/OTP). Each only accesses the data needed for its service.
5. Transfers outside the EU
Some processors are located outside the EU (notably in the United States). These transfers are governed by appropriate safeguards (European Commission Standard Contractual Clauses).
6. Retention period
Account data is kept as long as the account is active. After account deletion it is erased within 30 days, unless a legal retention obligation applies (e.g. invoicing: 10 years).
7. Your rights
Under the GDPR, you have rights of access, rectification, erasure, restriction, objection and data portability.
Right to erasure: you can delete your account and all associated data directly from your workspace, or by writing to privacy@heyleo.io. Your request is handled within 30 days.
To exercise your rights, contact privacy@heyleo.io.
8. Cookies
We use cookies that are essential to operation and, subject to your consent, analytics cookies. See our Cookie Policy for details and how to manage your preferences.
9. Security
We implement reasonable technical and organisational measures to protect your data (encryption in transit, access control, secure hosting).
10. Complaints
You may lodge a complaint with your local data protection authority. In France, this is the CNIL: www.cnil.fr.