Home

Privacy Policy

Last Updated: 4 July 2026

1. Data Controller

The data controller under the EU/UK General Data Protection Regulation (GDPR) is:

WebStore Technologies Ltd. (Company No: 17220895)

71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

General: support@paplead.com | Billing: billing@paplead.com | WhatsApp: +90 554 110 31 32

2. Personal Data We Collect

Identity data: Name, email, phone number, company/business name

Communication data: WhatsApp message contents, voice message transcriptions, lead information

Technical data: IP address, browser and device information, session and access logs

Financial data: Subscription and invoice records (card details are never stored — our payment infrastructure is PCI-DSS compliant)

3. Purposes & Legal Bases (GDPR Art. 6)

  • Contract performance: Providing the SaaS service, WhatsApp bot management, lead tracking
  • Legitimate interest: Improving service quality, security, usage analytics
  • Legal obligation: Tax and commercial record-keeping requirements
  • Consent: Marketing communications (only if you opt in)
  • AI processing: Message contents are sent to AI models (OpenAI, Google Gemini) for analysis

4. Data Sharing & International Transfers

Your data may be shared with the following processors:

  • Supabase: Database and authentication (US/EU)
  • OpenAI / Google: AI model APIs — message analysis (US)
  • Evolution API: WhatsApp connectivity infrastructure
  • Lemon Squeezy: Payment processing (US)
  • Competent authorities: Where legally required

International transfers: The providers above may process data outside your country. Transfers rely on appropriate safeguards such as Standard Contractual Clauses where applicable.

5. Data Security

We apply SSL/TLS encryption, AES-256 database encryption, tenant isolation with Row Level Security (RLS), JWT-based authentication, regular security updates, access permission matrices and incident response procedures.

6. Retention Periods

  • Account data: While the account is active + 30 days after deletion
  • Messages: For the duration of the subscription, 30 days after cancellation
  • Payment records: As required by applicable tax law
  • Access logs: As required by applicable law

7. Your Rights

Under the GDPR you have the right to access, rectify and erase your data, restrict or object to processing, data portability, withdraw consent at any time, and lodge a complaint with your supervisory authority (e.g. the ICO in the UK).

8. Contact

To exercise your rights, contact us at support@paplead.com or +90 554 110 31 32 (WhatsApp). Requests are handled free of charge within 30 days.