NZ Leads Privacy Policy
Effective and last updated: July 23, 2026
Document version: 2026-07-23
This Privacy Policy explains how NZ Leads Inc. (“NZ Leads,” “we,” “us,” or “our”) collects, uses, discloses, and retains Personal Data in connection with our websites, hosted business software, communications, support, and related services (collectively, the “Services”).
NZ Leads Inc.
857 N Orange Dr
Los Angeles, CA 90038
United States
Email: support@nzleads.com
Telephone: +1 (818) 446-6122
This Policy should be read with our Terms of Use, Cookie Policy, and Data Processing Addendum.
1. Scope
This Policy applies to:
- visitors to our websites and documentation;
- prospective and current business customers;
- account administrators and authorized users;
- people who communicate with our sales, support, or operations teams;
- individuals whose information is contained in data that a Customer submits to the Services, including leads, callers, message recipients, and Customer personnel; and
- people who receive or participate in calls, messages, or other interactions processed through the Services.
It does not govern a third-party website, lead source, communications network, payment page, publishing outlet, or integration acting under its own privacy policy.
The Services are intended for business use and are not directed to children.
2. Definitions
“Customer” means the business or other legal entity that obtains or uses the Services.
“Customer Data” means information, content, records, files, prompts, knowledge bases, messages, recordings, transcripts, contacts, credentials, and other material submitted to or processed through the Services for a Customer.
“Customer Personal Data” means Personal Data contained in Customer Data.
“End User” means a Customer’s lead, caller, message recipient, client, employee, contractor, or other individual whose Personal Data is processed through the Services.
“Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. It does not include information that has been lawfully made public, aggregated, or de-identified so that it cannot reasonably be linked to an individual.
“Service Provider” includes a processor, contractor, or vendor that processes information for a defined business purpose on our or a Customer’s behalf.
3. Our privacy roles
Our role depends on the processing activity.
NZ Leads as controller or business
NZ Leads generally determines the purposes and means of processing for:
- website visits and direct marketing;
- account registration and administration;
- billing, subscription, and transaction records;
- service security, fraud prevention, and abuse monitoring;
- support and direct communications with account users;
- legal compliance, policy acceptance, and dispute management; and
- product analytics using information for which NZ Leads determines the business purpose.
For those activities, NZ Leads acts as a controller, business, or equivalent responsible organization.
NZ Leads as processor or service provider
When we process Customer Personal Data to provide lead handling, messaging, calling, recording, transcription, AI assistance, integrations, press-release services, or related features according to Customer’s instructions, Customer generally acts as the controller or business and NZ Leads acts as the processor or service provider.
The Data Processing Addendum governs that processing. Customer is responsible for providing legally required notices, establishing a lawful basis, honoring End User rights, and configuring the Services lawfully.
This Policy does not replace a Customer’s own privacy notice. In particular, a call recipient must receive any notice and consent request required at the time of the call; posting this Policy or Customer’s acceptance of our Terms is not participant consent to call recording or transcription.
4. Personal Data we collect
Depending on how the Services are used, we collect the following categories.
4.1 Account and business information
- name, business name, job title, and role;
- email address, telephone number, and mailing or service address;
- account identifiers, usernames, authentication records, and permissions;
- business locations, connected sources, team membership, and administrative relationships; and
- policy acceptance, Order, consent, and account-configuration records.
4.2 Billing and commercial information
- billing contact and address;
- subscription, Billable Unit, source, location, plan, trial, renewal, cancellation, credit, and usage information;
- invoices, receipts, refunds, failed-payment records, and payment-dispute information;
- payment-method type, expiration information, and limited descriptors such as brand or last four digits when supplied by our payment processor; and
- processor customer, subscription, invoice, checkout, payment, and transaction identifiers.
Payment-card numbers and security codes are collected and processed by our payment processor, not stored in full by NZ Leads.
4.3 Lead, messaging, and integration data
- lead and End User names, telephone numbers, email addresses, postal codes, service requests, and other contact details;
- incoming and outgoing messages, attachments, conversation history, status, routing, and response data;
- connected platform account information, location identifiers, source metadata, calendar data, CRM records, and customer-selected integration payloads;
- OAuth access and refresh tokens and related authorization metadata;
- prompts, templates, knowledge-base material, service descriptions, prices, schedules, and automation settings; and
- AI-generated drafts, replies, classifications, summaries, and extracted information.
4.4 Voice, call, and communications data
- calling and called numbers, caller identity information, date, time, duration, direction, and disposition;
- audio recordings, voicemail, transcripts, summaries, sentiment or outcome labels, and post-call extracted fields;
- voice-agent instructions, scripts, dynamic variables, transfer details, and campaign information;
- recording and communication-consent metadata when collected;
- do-not-call, do-not-text, revocation, suppression, complaint, and opt-out records; and
- delivery, carrier, telephone-number, and communications-network metadata.
Call audio and voice-related information may be sensitive depending on its content and how it is used. We do not use voice recordings to identify or authenticate a person by a biometric voiceprint unless separately disclosed and lawfully authorized.
4.5 Press-release data
- drafts, headlines, quotations, media, links, company descriptions, contact details, approvals, and submission history;
- editorial review notes, compliance status, rejection reasons, distribution status, reports, and publication links; and
- credit purchases, consumption, restoration, and associated transaction records.
4.6 Device, usage, analytics, and session-replay data
- IP address, approximate location derived from IP, browser, device, operating system, language, and time zone;
- login, page, feature, click, navigation, referral, error, performance, and diagnostic events;
- cookies, pixels, local-storage identifiers, advertising or analytics identifiers, and campaign attribution;
- session-replay data that may recreate clicks, scrolling, navigation, page state, and other interactions; and
- support-widget and chat interactions.
Session-replay technology may load automatically on our websites and authenticated application. It may collect interaction metadata, rendered interface state, and content visible during a session. We use available technical safeguards for payment credentials and specifically designated sensitive elements, but users should not assume every displayed value or interaction is masked. We use replay for support, debugging, security, usability, product analysis, product improvement, and investigating account or payment disputes. Replay supplements, but is not the primary record of, a Customer’s billing consent. Payment credentials are handled on processor-hosted payment interfaces. Users should not place sensitive data into fields that do not request it. The Cookie Policy explains the available browser controls.
More information appears in our Cookie Policy.
4.7 Support, sales, and other communications
We collect emails, chats, call notes, support requests, feedback, survey responses, meeting information, and any attachments or information a person chooses to provide.
4.8 Inferences and de-identified information
We may derive likely preferences, feature usage, account health, fraud risk, or service-performance insights. We may aggregate or de-identify data and use it for analytics, security, capacity planning, and improvement. We do not attempt to re-identify data maintained as de-identified.
5. Sources of Personal Data
We receive Personal Data:
- directly from account users, Customers, End Users, and people who contact us;
- from Customers’ authorized users and uploaded files;
- from connected lead sources, advertising accounts, calendars, CRMs, communications channels, and other integrations;
- automatically from browsers, devices, cookies, analytics tools, session-replay tools, servers, and communications networks;
- from payment, identity, fraud-prevention, telephony, AI, transcription, hosting, support, and distribution Service Providers;
- from public sources and business contact databases where lawful; and
- from professional advisers, regulators, law enforcement, counterparties, or other people involved in a complaint, investigation, or dispute.
6. How we use Personal Data
We use Personal Data for the following business and commercial purposes:
- Provide and operate the Services, including accounts, lead intake, messaging, calls, recordings, transcripts, AI features, integrations, press releases, reports, and support.
- Perform Customer instructions, including transmitting data to destinations and integrations selected by Customer.
- Administer billing, including trials, subscriptions, usage measurement, proration, invoicing, credits, taxes, payment collection, cancellations, refunds, and receipts.
- Authenticate and secure, including access control, logging, backup, fraud detection, abuse prevention, incident response, and platform integrity.
- Communicate, including operational, billing, security, support, product, and legal notices.
- Analyze and improve, including troubleshooting, quality assurance, capacity planning, accessibility, feature adoption, and aggregate analytics.
- Comply and protect, including enforcing agreements, investigating complaints, honoring rights, responding to legal process, preventing unlawful communications, and protecting people and property.
- Establish, exercise, or defend claims, including preserving and presenting relevant evidence for payment inquiries, chargebacks, regulatory matters, or litigation.
- Market NZ Leads, including responding to inquiries and sending business-to-business marketing where permitted. Recipients may opt out of promotional email at any time.
- Facilitate business transactions, including financing, due diligence, merger, acquisition, reorganization, or sale of assets, subject to appropriate protections.
We do not use Customer Personal Data to train an NZ Leads generalized AI model for unrelated customers unless Customer expressly opts in. Third-party AI service providers process information under their applicable contractual commitments, the DPA, and Customer’s configuration or instructions. We may use aggregated or de-identified information that cannot reasonably identify Customer or an individual.
7. Legal bases where applicable
Where a law requires a legal basis, we rely on one or more of:
- performance of a contract or steps requested before entering a contract;
- our legitimate interests in providing, securing, supporting, and improving a B2B service, balanced against individual rights;
- Customer’s or an individual’s consent;
- compliance with a legal obligation; and
- protection of vital interests or establishment, exercise, or defense of legal claims.
Where NZ Leads acts as Customer’s processor, Customer determines the lawful basis for Customer Personal Data.
8. How we disclose Personal Data
We disclose Personal Data only as reasonably necessary for the purposes described above.
8.1 Service Providers
We use categories of Service Providers such as:
- cloud hosting, database, storage, backup, monitoring, and security providers;
- payment, invoicing, tax, fraud-prevention, and financial infrastructure providers;
- email, support, chat, analytics, session-replay, and communications providers;
- telephone-number, carrier, voice, messaging, recording, and transcription providers;
- AI model and content-processing providers;
- connected lead-source, advertising, calendar, CRM, automation, and business-system providers;
- press-release review, distribution, media-monitoring, and reporting providers; and
- legal, accounting, insurance, audit, and other professional advisers.
Service Providers receive only the information reasonably necessary for their function and are subject to contractual or other legal restrictions appropriate to their role.
8.2 Customer-directed integrations and recipients
We disclose data to a third party, account, webhook, CRM, calendar, communications channel, recipient, or other destination when Customer configures or instructs the transfer. The recipient’s own terms and privacy practices apply after it receives the data in its independent capacity.
8.3 Customer administrators
Customer administrators and authorized users may access information associated with Customer’s organization, sources, users, messages, calls, recordings, transcripts, reports, and billing.
8.4 Legal, safety, and dispute disclosures
We may disclose information when we reasonably believe disclosure is necessary to:
- comply with law, legal process, or a valid governmental request;
- protect the rights, safety, security, or property of NZ Leads, Customers, End Users, or the public;
- investigate fraud, abuse, unlawful communications, or security incidents;
- enforce our agreements and policies; or
- investigate or respond to a payment inquiry, refund request, chargeback, complaint, audit, or legal claim.
For payment disputes, recipients may include our payment processor, card networks, acquiring and issuing banks, insurers, advisers, regulators, and courts.
8.5 Corporate transactions
Information may be disclosed under appropriate confidentiality protections in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of some or all of our business or assets.
9. Sale, sharing, and targeted advertising
We do not sell Customer Data or End User Data for money. We do not disclose Customer Data or End User Data for cross-context behavioral advertising.
We may use analytics, attribution, or advertising technologies on public websites. Depending on the technology and jurisdiction, disclosure of website visitor identifiers or activity to such providers may be considered a “sale,” “sharing,” or use for targeted advertising even when no money changes hands. Our Cookie Policy explains available browser, cookie, and opt-out controls.
A Global Privacy Control or similar browser signal does not necessarily stop operational, security, support, product-analytics, or session-replay technologies from loading. We evaluate legally recognized signals and verified requests as required by applicable law. To request an opt-out applicable to your Personal Data or associate a browser signal with other information, email support@nzleads.com with the subject “Privacy Opt-Out.” We will verify and process the request as required by applicable law. We do not discriminate against a person for exercising a privacy right.
10. Google API Services User Data
When Customer connects a Google Local Services Ads (“LSA”) account, we access Google user data only to provide the Customer-authorized integration.
Data and permissions
The integration may request:
- Google Ads API access to identify accessible LSA accounts, retrieve LSA lead and conversation information, and send Customer-configured replies on Customer’s behalf;
- basic account email information to associate the connected account with the correct NZ Leads account; and
- basic profile information to display the connected account.
The Google Ads permission is used for LSA lead handling. We do not use it to create, modify, pause, or delete non-LSA advertising campaigns, budgets, bids, ad groups, ads, or keywords unless a future feature is separately and clearly disclosed and authorized.
Use, storage, and disclosure
We use Google user data to authenticate the connection, display and manage LSA leads and conversations, generate Customer-configured replies, send those replies, support the integration, and maintain authorized service records.
OAuth tokens are stored with access controls and are not exposed to the client application except as necessary for the authorization flow. Lead or conversation content may be transmitted to AI or infrastructure Service Providers only to perform the Customer-authorized feature, subject to applicable contractual restrictions.
We do not sell Google user data, use it for advertising, or use it to train generalized AI models. We do not transfer it except as necessary to provide or secure the integration, comply with law, or complete a transaction expressly initiated by Customer.
Customer may revoke access by disconnecting the source in the Services or removing NZ Leads from the Google Account permissions page. Revocation stops new access. We delete or render unusable associated OAuth tokens within a reasonable operational period, subject to backup cycles, security records, and legal obligations. Associated lead and conversation data is retained or deleted under the Customer’s instructions, account settings, DPA, and the retention criteria below.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including applicable Limited Use requirements.
11. Call participants and other End Users
If you received a call or message from a Customer using NZ Leads:
- the Customer is generally the business responsible for the contact, purpose, audience, and lawful basis;
- contact the Customer directly to opt out, revoke consent, ask about the communication, or exercise a right the Customer controls;
- you may also contact support@nzleads.com if you cannot identify or reach the Customer, or to report abuse involving the Services; and
- tell us the calling or messaging number, your number, approximate date and time, and the nature of the request so we can investigate without requesting unnecessary information.
A request to stop calling or messaging should be honored as required by law. We may preserve suppression information so a request is not inadvertently reversed.
12. Retention
We retain Personal Data only for as long as reasonably necessary and proportionate for the disclosed purpose. The applicable period depends on account status, Customer instructions, product settings, legal requirements, security needs, and pending disputes.
| Data category | Retention criteria |
|---|---|
| Account, contract, policy acceptance, Orders, invoices, payments, refunds, and tax records | For the business relationship and generally up to seven years after the relevant transaction or termination, or longer when required for tax, accounting, fraud prevention, or a legal claim. |
| Customer Data, leads, messages, prompts, knowledge bases, and integration content | While the account or applicable feature is active and afterward for the period needed for Customer export, ordinary deletion workflows, contractual instructions, backup and archival retention schedules, security, and legal obligations. |
| Call recordings, transcripts, summaries, and call content | According to Customer instructions, available retention settings, the applicable Order, and the period reasonably needed to provide the feature. Specific records may be retained longer for a complaint, consent question, safety matter, or legal hold. |
| Communication consent, opt-out, suppression, campaign, and compliance records | For the period Customer instructs or applicable communications law requires. Records subject to telemarketing recordkeeping requirements may need to be retained for at least five years. Suppression records may be retained longer to continue honoring an opt-out. |
| OAuth tokens and connected-account credentials | While the integration is active, then until revocation or deletion is completed through ordinary secure workflows and backup cycles. Limited audit records may be retained for security and compliance. |
| Security, access, device, fraud, and diagnostic logs | For a rolling period appropriate to detect, investigate, and prevent incidents; longer when linked to an incident, abuse investigation, or legal obligation. |
| Website analytics, cookie, attribution, and session-replay data | According to the configured lifespan of the relevant technology and the period reasonably needed for analytics, support, security, and product improvement. See the Cookie Policy. |
| Support and business communications | For the relationship and a reasonable period afterward to resolve requests, document decisions, improve support, and address disputes. |
| Press-release content and distribution records | For the account relationship, reporting and publication history, credit administration, publisher requirements, and legal or editorial recordkeeping. Public copies maintained by independent publishers are outside our control. |
Cancellation does not necessarily result in immediate deletion. We may isolate relevant records under a targeted legal hold during a complaint, investigation, chargeback, or litigation. When retention is no longer justified, we delete or de-identify information in active systems through ordinary deletion workflows. Copies may remain in restricted backups or archival disaster-recovery copies under applicable retention schedules; they are isolated from ordinary use and handled under the DPA.
13. Security
We maintain administrative, technical, and physical safeguards designed to protect Personal Data in light of its nature and risk. Measures include access controls, authentication, logging, encryption where appropriate, secure development and change practices, backup, vendor review, and incident response.
No transmission or storage method is completely secure. Customers must protect their credentials, configure permissions carefully, and avoid placing unnecessary sensitive information in prompts, messages, recordings, or free-text fields.
If we confirm a security incident involving Customer Personal Data, we will notify the affected Customer without undue delay as required by the DPA and applicable law.
14. International data transfers
We are based in the United States and may process information in the United States and other countries where we or our Service Providers operate. Those countries may have different data-protection laws.
Where required, we use an approved transfer mechanism, such as contractual clauses, and supplementary safeguards appropriate to the transfer. The DPA addresses Customer Personal Data transferred internationally.
15. Privacy rights
Depending on where you live and our role, you may have the right to:
- know or access Personal Data and information about its processing;
- correct inaccurate Personal Data;
- delete Personal Data;
- receive a portable copy;
- object to or restrict certain processing;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- limit certain uses or disclosures of sensitive Personal Data;
- withdraw consent for future processing;
- appeal a denied request; and
- complain to a privacy regulator.
These rights are subject to legal exceptions. For example, we may retain information needed to complete a transaction, protect security, honor an opt-out, comply with law, or establish or defend a legal claim.
Submitting a request
Email support@nzleads.com with the subject “Privacy Request” and describe the right you wish to exercise. You may also call +1 (818) 446-6122. We may request information reasonably necessary to verify identity, authority, account relationship, and jurisdiction.
An authorized agent may submit a request where permitted, but we may require proof of authorization and direct identity verification. We will respond within the period required by applicable law.
When NZ Leads processes Customer Personal Data solely as Customer’s processor or service provider, we may direct the request to Customer or assist Customer in responding.
16. California privacy notice
This section supplements the rest of the Policy for California residents and is intended as a notice at collection.
During the preceding 12 months, depending on use of the Services, we may have collected the categories below:
| Category | Examples | Business purposes | Categories of recipients | Retention |
|---|---|---|---|---|
| Identifiers and customer records | Name, email, phone, address, IP, account and platform identifiers | Account, service delivery, integrations, support, security, billing | Infrastructure, communications, support, payment, integration, professional-adviser providers; Customer administrators | Criteria in Section 12 |
| Commercial information | Orders, subscriptions, sources, usage, credits, invoices, transactions | Billing, fulfillment, accounting, disputes, service administration | Payment, tax, accounting, fraud, professional-adviser providers | Criteria in Section 12 |
| Internet or electronic activity | Pages, clicks, sessions, feature use, logs, session replay, referral data | Security, support, analytics, attribution, improvement | Hosting, security, analytics, session-replay, support providers | Criteria in Section 12 |
| Approximate geolocation | Region derived from IP, time zone, business or service location | Security, localization, scheduling, service delivery | Infrastructure, security, analytics, communications providers | Criteria in Section 12 |
| Audio, electronic, and communications information | Calls, recordings, transcripts, voicemail, messages, attachments | Customer-directed communications, AI features, quality, support, compliance | Telephony, messaging, recording, transcription, AI, storage, Customer-directed integrations | Criteria in Section 12 |
| Professional or employment-related information | Business, title, role, team, administrator relationship | B2B account administration and support | Customer administrators, infrastructure, support providers | Criteria in Section 12 |
| Sensitive Personal Data | Account credentials; content that may reveal sensitive facts; precise location only if a Customer supplies it | Authentication, security, Customer-directed service processing | Security and infrastructure providers; Customer-directed processors | Criteria in Section 12 |
| Inferences | Likely preferences, account health, feature use, fraud or support indicators | Security, support, analytics, improvement | Analytics, security, support providers | Criteria in Section 12 |
We collect these categories from the sources in Section 5 and use and disclose them for Sections 6 and 8. We do not use or disclose sensitive Personal Data to infer characteristics about a person beyond purposes permitted by law or Customer’s lawful instructions.
We do not knowingly sell or share Personal Data of people under 16. Section 9 describes our practices concerning sale, sharing, and website technologies.
California residents may exercise applicable rights through Section 15. We will not discriminate for exercising a right.
California’s Shine the Light law may allow certain residents to request information about disclosure of Personal Data to third parties for their direct marketing. NZ Leads does not disclose Customer Data or End User Data to third parties for their own direct marketing.
17. Other U.S. state privacy rights
Residents of states with comprehensive privacy laws may have rights similar to Section 15, including rights to opt out of targeted advertising, sale, or certain profiling and to appeal a decision. Submit a request using Section 15 and identify your state of residence.
18. European Economic Area, United Kingdom, and Switzerland
Where applicable, individuals may have rights under data-protection law to access, correct, erase, restrict, port, or object to processing and to lodge a complaint with a supervisory authority.
NZ Leads Inc. is the contact for processing for which we act as controller. For Customer Personal Data, the applicable Customer is generally the controller and should receive the request first.
19. Children
The Services are B2B services not directed to anyone under 18, and we do not knowingly permit minors to create accounts. Customers must not use the Services to intentionally collect Personal Data from children in violation of law. If you believe a child has provided Personal Data improperly, contact support@nzleads.com.
20. Changes to this Policy
We may update this Policy as our Services or legal obligations change. We will post the updated version and revise the date above. If a change materially affects how we use Personal Data, we will provide additional notice or seek consent where required.
We maintain policy version information so the notice applicable to a collection or transaction can be identified.
21. Contact
Questions, complaints, and privacy requests may be directed to:
NZ Leads Inc.
Attn: Privacy
857 N Orange Dr
Los Angeles, CA 90038
United States
Email: support@nzleads.com
Telephone: +1 (818) 446-6122