GDPR and Data Rights
Our approach to data protection
LeadRX is designed with data protection as a core architectural principle. We handle health-adjacent personal data (workout results, readiness signals, and performance notes) alongside standard personal data (contact information, billing records) and apply enhanced protections proportional to data sensitivity.
Data subject rights
LeadRX supports the following data subject rights through our Data Subject Access Request (DSAR) system:
Right of Access (Art. 15) โ Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16) โ Request correction of inaccurate personal data through a module-owner task and evidence workflow.
Right to Erasure (Art. 17) โ Request deletion of your personal data, subject to legal retention obligations (e.g., financial records for 7 years). When erasure is executed, PII fields are anonymized and health-adjacent data is nulled or replaced with aggregate-safe values.
Right to Restriction (Art. 18) โ Request that processing for a specific purpose is restricted while the request is assessed.
Right to Data Portability (Art. 20) โ Receive your data in a structured, commonly used format.
Right to Object (Art. 21) โ Object to processing for a specific purpose, subject to legal or contractual exceptions.
All DSAR requests require identity verification before processing begins. Requests are tracked through a documented lifecycle: received, verified, in progress, completed, or rejected with rationale. Access and portability packages include manifests, checksums, expiry, and audit evidence. You can submit a request through your organization administrator or by contacting privacy@leadrx.eu.
Data classification
We classify all personal data by sensitivity level and apply controls accordingly:
Public (C1) โ Organization names, location names. No special handling required.
Internal (C2) โ Class schedules, settings, feature flags. Business data that is not personally identifiable.
Confidential PII (C3) โ Names, email addresses, phone numbers, dates of birth, billing records. Standard GDPR personal data protections apply.
Health-Adjacent Sensitive (C4) โ Workout results, fitness scores, readiness signals, and coaching performance notes. Enhanced protections, configurable retention, and consent-based processing apply.
Restricted Credentials (C5) โ Password hashes, session tokens, device secrets. Never exposed in APIs or logs; stored with cryptographic protections.
Retention
Our retention schedule is aligned to legal requirements and data minimization principles. Person PII is retained for the duration of organizational membership and erased or anonymized after a valid DSAR unless a legal retention exception applies. Health-adjacent data defaults to 3 years (configurable per organization). Communications are retained for up to 2 years. Financial records are retained for a minimum of 7 years. Import preview data and generated export datasets have dedicated 30-day cleanup rules. Audit logs are retained for 7 years for compliance.
Subprocessors
LeadRX uses a limited set of subprocessors to deliver the platform. Organization administrators are notified before new subprocessors are added. The current subprocessor list is maintained as a living compliance artifact and is available upon request by contacting privacy@leadrx.eu.
Data Processing Agreements
Organizations using LeadRX can request a Data Processing Agreement (DPA) that documents the processing activities, security measures, and obligations of both parties under GDPR. Contact legal@leadrx.eu to request a DPA.
Contact the data protection team
Privacy inquiries: privacy@leadrx.eu
For more information about how we handle your data, see our Privacy Notice.
This page was last updated in May 2026.