Last updated 2026-07-30
This policy explains what data Digital Lead Marketing ("DLM," "we," "us") accesses, how we use it, and the choices you have. It applies to business clients of DLM's managed AI operations service (the "Service") and to visitors of this website.
For data about your leads, contacts, and customers ("Contact Data"), you — the client business — are the owner, and DLM acts as your service provider, working only on your instructions. For our own records about your business (billing, account administration), DLM is the data controller.
Depending on what you connect, the Service may access:
The Service uses the minimum access needed for the task, and only accounts and scopes you have authorized.
We use third-party providers to deliver the Service, including AI model providers (such as Anthropic), your CRM/marketing platform and its messaging carriers, chat platforms you choose for your operator channel (such as Discord or Telegram), our hosting infrastructure, and our payment processor (card data is held by the processor, not by DLM). A current list of subprocessors is available on request. Please don't paste highly sensitive data (Social Security numbers, full card numbers, medical information) into chat channels; we may redact or decline to process such data there.
The primary store of your Contact Data is your own CRM account, which you own and control — we do not keep an independent master copy. Working data we hold (task logs, AI conversation logs, working files) is kept only as long as needed for quality, audit, and dispute purposes, then deleted or de-identified. After termination, your accounts and data stay with you, our access is revoked, and we delete client-identifiable working data within a reasonable period, except records we must keep for legal, billing, or security purposes. Records of consent and opt-outs relating to campaigns are retained for as long as applicable law makes them relevant.
You may at any time: revoke or narrow our access; request an export of reports and working data we hold about you; request deletion of DLM-held working data (subject to the exceptions above); request our current subprocessor list; or restrict which systems the Service may touch. Opt-out requests from your contacts are honored promptly through your systems; access or deletion requests directed at your Contact Data are yours to fulfill as the data owner, with our reasonable assistance.
We use unique credentials and least-privilege access for each client account, store API keys and tokens outside of code and chat, use multi-factor authentication on DLM-controlled admin accounts, encrypt service traffic in transit, limit access to personnel who need it under confidentiality obligations, log AI actions taken in client accounts, and promptly revoke access on personnel change or client termination. No system is perfectly secure, and we do not promise absolute security; if we become aware of unauthorized access to client data in our control, we will notify the affected client without undue delay and cooperate on remediation.
Questions or requests about this policy: AccountRep@DigitalLead.Marketing · 971-350-8931.