Introduction
Leanmote PTY LTD (ABN 40 647 226 417, Australia) and Leanmote SpA (RUT 77.915.981-7, Chile), collectively referred to as "Leanmote", "we", "our", or "us" knows that you care how information about you is used and shared, and we are careful to ensure that any such information that comes into our possession is properly looked after.
This Privacy Policy sets out the basis on which any personal data we collect from or about you on our website, www.leanmote.com, our platform, or any of the integrations/apps connected to it will be processed by us. It also sets out the steps that we take to ensure that any information provided to us is kept secure and is used only for the purposes for which it is provided.
We will be the data controller of your data which you provide to us or which is collected by us via our website and platform. This means that we are responsible for deciding how we hold and use personal information about you and that we are required to notify you of the information contained in this Privacy Policy.
Leanmote has appointed a Data Protection Team, who can be contacted using the details at the end of this Notice should you have any questions, complaints, or feedback about your privacy.
Personal Information
When you communicate with us via our website — for example, by submitting a query, requesting a demo, subscribing to our blog, commenting on a blog post, or using the chat function — we will collect the personal information that you provide to us for that purpose. You don't have to give us any of this personal information but, if you don't provide us with certain information, we may not be able to provide you with the information or service you have requested from us.
We will also collect technical information about your equipment, browsing actions and patterns to serve more relevant content to you on the site. We collect this personal data by using cookies, server logs and other technologies; full details as to how we use cookies can be found in our Cookie Policy.
We will only use your personal data to send you our newsletter and blog updates where you have consented to us doing so. Much of the information we hold will have been provided by you, but some may come from other internal sources, such as a Sales representative, or in some cases, external sources, such as marketing or event management agencies.
Purposes for which Personal Information may be used
The personal information that you provide to us or that we collect about you via our website will be used only for the following purposes:
- To provide information or services to you as requested by you.
- To the extent permitted by law, to let you know about information and services from Leanmote in which you may be interested, including via our newsletter.
- To review and understand the content on our website which users are most interested in.
- To improve the content of our website.
- To customize the content and/or layout of the website for each user.
- To notify you about updates to the website.
The legal basis for processing your personal data depends on the purpose for which it is used. When you accept our Terms and Conditions, processing is necessary for the performance of our contract with you — this covers the delivery of our core services. Where we send you marketing communications or newsletters, we rely on your prior consent. For analytics and service improvement activities, we rely on our legitimate interests in understanding how our platform is used and improving it over time.
Automated Decision Making
We do not carry out any solely automated decision-making using your personal information.
Change of Purpose
We will only use your personal information for the purposes for which we collected it unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose and permitted under data protection laws. If we need to use your personal information for an unrelated purpose, in most cases we will notify you and we will explain the legal basis which allows us to do so.
Disclosure
We currently share your data with the following trusted third-party sub-processors for the purposes of managing our business and providing the information and services you request from us:
| Provider | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and data hosting |
| Amazon Cognito | User authentication and identity management |
| Neo4j | Graph database storing user and organisational data |
| Intercom | Customer support, in-app messaging, and email delivery |
| Stripe | Payment processing and billing |
| Pipedrive | Customer relationship management |
| Google Analytics | Website traffic and usage analytics |
| PostHog | Product analytics and user behaviour tracking |
| Sentry | Error tracking and performance monitoring |
When we share your data with these third parties we only provide the information they need to perform their service. We have written contracts in place with them to ensure they only use your data for the purpose we specify and that your privacy is secure and respected.
We will also disclose your personal information to third parties:
- if we sell or buy any business or assets, in which case we will disclose your data to the prospective seller or buyer of such business or assets;
- if we or substantially all of our assets are acquired by a third party, in which case personal data held by us about our customers will be one of the transferred assets; and/or
- if we are under a duty to disclose or share your data to comply with any legal obligation, or to enforce or apply our Terms of Use and other agreements; or to protect the rights, property, or safety of us, our users, customers, and providers.
Data privacy guidelines for our integrations
We store the data from our integrations complying with the General Data Protection Regulation (GDPR). Below you'll find the specific treatment for each of them.
Atlassian (Jira, Bitbucket, Trello)
We assure you of the following rights complying with the GDPR:
- Right to erasure (Right to be Forgotten): If Leanmote stores the personal data of a user and the user requests for their data to be erased, we will erase the data.
- Right to rectify: If Leanmote stores the personal data for a user and the user changes their data, we erase or update the data.
- Right to be informed: We inform users if we collect and use their data.
We periodically report the personal data we are storing back to Jira using the personal data reporting API and based on the response back from Atlassian we update or erase the personal data for users accordingly. We repeat this process each cycle period (7 days).
We store the data following Atlassian guidelines:
- We track and report the age of personal data so Atlassian can determine if the personal data is stale.
- We store a single copy of personal data to ensure that all personal data is erased when necessary.
- When Leanmote is uninstalled we erase personal data that is no longer needed.
Slack
Use of channels:history
Our application utilizes the "channels:history" scope to enhance our service capabilities. We require access to the channel history to collect metadata about team interactions. This data helps us analyze communication patterns and improve team dynamics and performance metrics.
- Metadata Only: Our application only extracts metadata, such as message timestamps, user IDs, and interaction frequencies. We do not read or store the actual content of any messages.
- Data Processing: The collected metadata is used exclusively to generate insights about team interactions. We do not use this data for any other purpose.
- No Content Storage: We do not store or process any message content. Our focus is solely on metadata to ensure user privacy.
- Robust Security Measures: We implement industry-standard security practices including encryption, access controls, and regular security audits.
Our data handling practices are fully compliant with Slack's API Terms of Service and Privacy Policy. We regularly review and update our privacy practices to align with the latest security standards and regulatory requirements.
When you connect your Google account to Leanmote, we request limited, read-only access through Google OAuth. This includes:
- Calendars: ID, name, title, description, timezone, creation date.
- Events: calendar ID, event ID, title, creator, creation date, attendees list, start/end times, recurrence.
- Meet conferences: participant names, attendance duration, actual start/end times.
We use this data only to provide productivity, collaboration, and leadership insights. Google user data is not shared, sold, or used for advertising. You may revoke access at any time via your Google Account Permissions. If you revoke or uninstall the integration, related Google data will be deleted from our systems within 30 days.
Leanmote's use and transfer of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. We may use anonymized, aggregated data derived from Google user data to improve our services, without identifying individuals.
Retention of Information
Unless we need to keep your data for legal purposes (such as to defend against a legal claim), we will only retain your personal information for 24 months from your last interaction with us — for example, when you opted in or when you submitted a query on our website.
International Data Transfers
Leanmote operates globally with entities in Australia and Chile. Your personal data is stored and processed in the United States through Amazon Web Services (AWS). By accepting our Terms and Conditions and using our services, you acknowledge and consent to the transfer of your personal data to the United States.
We ensure that appropriate safeguards are in place for all international transfers in accordance with applicable data protection laws, including the Australian Privacy Act and Chilean data protection legislation. Our third-party sub-processors are contractually required to maintain equivalent levels of data protection.
Protection of Information
We have implemented appropriate technology safeguards, security policies, and other measures to protect data under our control from unauthorized access, improper use, alteration, unlawful or accidental destruction, or accidental loss. These include implementing suitable access controls, and ensuring that encryption and hashing are used and robust physical security controls are in place. We also protect your information by requiring that all our employees and others who have access to or are associated with the processing of your data respect your confidentiality.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authorities without undue delay, in accordance with applicable data protection laws and our Incident Response Policy.
Your Rights
Data protection laws provide you with the following rights:
- Right to access your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Right to correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Right to erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it.
- Right to restrict processing of your personal information, for example, if you want to establish its accuracy or the reason for processing it.
- Right to data portability — to obtain a copy of the personal information you've provided us with and to reuse it elsewhere or to ask us to transfer it to a third party of your choice.
- Right to object to the processing of your personal information where we are relying on a legitimate interest or where we are processing your personal information for direct marketing purposes.
You will not have to pay a fee to access your personal information (or to exercise any of the other rights above). However, we may charge a reasonable fee if your request for access is manifestly unfounded or excessive.
To request the deletion of your personal data, please follow these steps:
- Send an email to info@leanmote.com with the subject line "Data Deletion Request".
- Include your full name and any relevant account information to help us locate your data.
- Specify clearly in the body of the email that you are requesting the deletion of your personal information.
We will process your request in accordance with applicable data protection laws and regulations.
Changes to our Privacy Policy
We review this Privacy Policy at least once every twelve (12) months, in line with our SOC 2 compliance commitments, to ensure it remains accurate and aligned with our practices and applicable data protection laws. Reviews may also be triggered earlier by changes in applicable law, in our services or sub-processors, or in our security and privacy practices. Each review is documented, including the review date, the reviewer, and any resulting changes, and the outcome is approved by Leanmote management.
If we decide to change our Privacy Policy we will post the changes here and, where appropriate, notify you by email. The “Last updated” date shown at the top of this page identifies the most recently approved version. Please check back frequently to see any updates or changes to our Privacy Policy.
Contacting Us
If you have any queries, comments, or requests regarding this Privacy Policy or you would like to exercise any of your rights set out above, you can contact us in the following ways: