Last updated: June 2026
This page explains how LeadSMS processes personal data in accordance with the UK GDPR and EU GDPR. LeadSMS is operated as a sole trader business under the name LeadSMS.
LeadSMS is the data controller for personal data collected through the platform.
We collect account information such as name, email address, business details, authentication data, and usage data. We also store SMS and call-related metadata necessary to provide the service.
We use your data to provide the LeadSMS service, including provisioning Twilio numbers, handling missed-call messaging, managing conversations, billing, fraud prevention, and customer support.
We process data under the legal basis of contract (providing the service), legitimate interest (fraud prevention, abuse detection, service improvement), and legal compliance where required.
We share limited data with trusted third parties to operate the service, including:
These providers act as data processors under GDPR.
We retain personal data while your account is active. Certain logs and message data may be retained for fraud prevention, abuse detection, and legal compliance purposes. Data stored on AWS may be deleted subject to infrastructure retention limits or upon request where legally permissible.
You have the right to access, correct, export, or delete your personal data. You may also request restriction or objection to processing where applicable under GDPR.
LeadSMS may be accessed globally. Data may be processed in the United Kingdom, European Union, and United States depending on infrastructure and third-party providers.
If you have questions about this policy or your data, contact us via the support page.