Privacy Policy
How we collect, use, share, and protect personal data of applicants, contractors, and visitors.
⚠️ DRAFT — Reviewed by counsel: [pending]. Effective date: [YYYY-MM-DD — set on publish]. Do not rely on this as legal advice.
LeadAdvisors ("we", "us", "our") operates the LeadAdvisors Portal at apps.leadadvisors.com and the public careers site at leadadvisors.com/careers. This notice explains how we collect, use, share, and protect personal data of:
- Applicants — anyone who applies for an independent contractor opportunity through our careers site.
- Independent contractors — engaged 1099 contractors using the staff portal.
- Visitors — anyone who browses our public pages.
This policy is global. Where local law requires more specific disclosures (EU/UK GDPR, California CCPA/CPRA, Philippine Data Privacy Act, Mexico LFPDPPP, Canadian PIPEDA, Brazil LGPD), the relevant regional schedule controls.
1. Who is the controller / business?
Controller / business: LeadAdvisors
Operating entity: [Anthony to confirm: registered legal entity name and country of incorporation]
Mailing address: [Anthony to confirm: registered address]
Privacy contact: legal@leadadvisors.net
For EU/UK applicants, our representative under Article 27 GDPR is: [Anthony to confirm: EU/UK representative — only required if we offer roles to data subjects in the EU/UK and have no establishment there].
2. What we collect
2.1 From applicants (when you apply at /careers/apply)
- Identifiers: first name, last name, email address, phone number (optional).
- Country (ISO-2 code, free-text in the current build).
- Resume / CV file (PDF or DOCX) and / or LinkedIn profile URL (optional).
- Cover note / "why interested" (optional).
- Role(s) applied for and pipeline stage history.
- Consent record: the version of the applicant privacy notice you accepted, the timestamp, and the IP address from which you submitted.
2.2 From candidate accounts
- Account email + hashed password (bcrypt). We never see your plaintext password.
- Profile fields you choose to add — phone, country, LinkedIn URL, parsed resume summary.
- Skills assessment results (see §2.4).
2.3 From engaged independent contractors
- Profile data: legal name, contact details, country, time zone, dialer IDs (Time Doctor, Five9, Ytel, Vici), assigned role, rate band.
- Identification: government-issued ID image (collected only when required for payout verification or compliance).
- Payout / wiring data: bank name, account number or IBAN, branch code, CLABE (Mexico), SWIFT/BIC, recipient type, payout method (Wise / bank transfer), payout currency, payout country. See Payout disclosure for full detail.
- Time and activity data captured by our partners' tools — see §2.5.
- Compensation summary records (rate, hours, billing period totals, deductions, net payable).
2.4 Pre-hire skills + psychometric assessments
- Question responses, automatically scored category outputs, time on task, anti-cheat events (tab-blur counts, copy/right-click attempts), reviewer notes if any. See Assessment consent.
2.5 Activity data captured by third-party operations tools
While engaged as a contractor, the following may be captured by tools we use to bill clients and reconcile hours:
- Time Doctor — keyboard/mouse activity samples, productive vs idle classifications, periodic screenshots (per Time Doctor configuration set on your account), URL and application titles where enabled.
- Five9 — agent state log: login, ready, on-call, after-call work, break, training, etc., with timestamps and reason codes.
- Ytel — login time, talk time, pause time, wait time, calls per day.
- Vici — login time, talk time, pause time, dispo, dead, break.
We import these as raw exports per source (CSV / XLSX) and reconcile the data inside the portal to compute billable hours.
2.6 Site analytics + monitoring (everyone)
- IP address, browser, device, locale, referrer, pages viewed, performance timings.
- Error reports when something breaks.
We rely on the third-party processors listed in §6 for analytics and error monitoring.
3. How we use it (purposes + lawful bases)
| Purpose | Legal basis (EU/UK GDPR) | What it covers |
|---|---|---|
| Recruit, evaluate, and contact applicants for roles | Consent (§9 art. 6(1)(a)) and / or our legitimate interest in running a recruiting process | Application processing, assessments, interview scheduling, decision recordkeeping |
| Decide whether to engage an applicant as a contractor | Pre-contract steps at the applicant's request (art. 6(1)(b)) | Final-stage interviews, references, conditional offer |
| Manage the active contractor relationship | Performance of the engagement contract (art. 6(1)(b)) | Provisioning, time / activity data, billing reconciliation |
| Pay contractors and meet record-keeping obligations | Contractual necessity + legal obligation (art. 6(1)(b)/(c)) | Payout flow, tax forms, audit trail |
| Operate, secure, and improve the portal | Legitimate interest (art. 6(1)(f)) | Authentication, audit logging, security, error monitoring, analytics |
| Comply with law (tax, anti-fraud, lawful requests) | Legal obligation (art. 6(1)(c)) | Responding to subpoenas, regulatory requests |
We do not use any decision purely automated against your application — every progression decision is reviewed by a human reviewer. We do not sell personal information.
4. Children
The portal is not intended for, and we do not knowingly collect data from, anyone under 18. Applicant accounts certify the user is at least 18.
5. Retention
| Data | Retention |
|---|---|
| Applications that did not progress | Up to 24 months from submission to consider you for future roles, then deleted unless you ask us to keep your record longer |
| Hired contractors — engagement file (contracts, profile, time, compensation) | Duration of engagement + the period required by tax / contracting law in the operating country [Anthony to confirm: retention floor per US, PH, MX] |
| Payout / banking detail | Duration of engagement + minimum required by financial-record retention rules; deleted on contractor request after termination unless retention is legally required |
| Pre-hire assessment answers + scores | Up to 24 months for unsuccessful applicants; for the duration of engagement for hired contractors |
| Site analytics / error logs | Up to 13 months |
Where stricter local retention rules apply, the stricter rule controls.
6. Sub-processors (vendors who process data on our behalf)
We rely on the following sub-processors as of the Last updated date above. The list is current to the best of our knowledge; we will update it when we add or remove a processor.
| Sub-processor | Service | Categories of data | Hosting region |
|---|---|---|---|
| Vercel, Inc. | Application hosting, analytics, speed insights, deployment | All portal data in transit; aggregate / anonymous analytics and performance metrics | US-East primary (per project config) |
| Neon | Managed Postgres database (apps.leadadvisors.com Neon project) | All portal data at rest | us-west-2 (current Neon region) |
| Resend | Transactional email (welcome, password reset, application receipts) | Email address, name, message body | US |
| Sentry | Error monitoring | Stack traces, IP, browser, request metadata; user email / id when available | US (default) |
| Time Doctor | Time tracking and productivity monitoring for engaged contractors | Keyboard / mouse activity, periodic screenshots, URLs / app titles per the contractor's plan | US (per Time Doctor config) |
| Five9 | Cloud contact center (Transfer Specialists) | Agent state, call activity | US |
| Ytel | Outbound dialer | Agent state, call activity | US |
| Vici | Predictive dialer | Agent state, call activity | [Anthony to confirm: Vici hosting region — self-hosted vs managed] |
| NextAuth.js (in-app library) | Session cookies + sign-in flow | Email, hashed password, session token | Runs inside our Vercel function — no third-party data sharing |
| [Anthony to confirm: payout processor] | Disbursing contractor payouts | Account holder, bank / IBAN / SWIFT / CLABE, currency, country, amount | [Anthony to confirm: processor region] |
| [Anthony to confirm: BG-check provider, if and when used] | Background check services | Identifiers + check results | [Anthony to confirm] |
We require sub-processors to handle personal data under written agreements with confidentiality, security, and (where applicable) Standard Contractual Clauses for cross-border transfers. See our DPA template.
7. Sharing outside our organization
We share personal data with:
- Sub-processors listed in §6, only as needed to deliver the portal.
- Clients (only after engagement) — limited identification (work name, dialer IDs, role) so the client can verify the contractor is on its program and reconcile hours billed. We do not share applicant data with clients.
- Professional advisers (lawyers, auditors, tax) under duty of confidentiality.
- Acquirers in connection with a corporate transaction, subject to equivalent commitments.
- Authorities and courts when legally required, or to defend our rights.
We do not sell personal information.
8. International transfers
Personal data is processed in the United States (where our portal infrastructure runs) and in the country where the contractor is located (typically the Philippines or Mexico). When we transfer personal data out of the EEA, UK, Switzerland, the Philippines, or Mexico, we use the appropriate transfer mechanism — typically the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, the Philippine Data Privacy Act outbound-transfer requirements, and Mexico's LFPDPPP cross-border transfer rules. A copy of the safeguards in place is available at legal@leadadvisors.net.
9. Your rights
Subject to local law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to fix data that is inaccurate.
- Deletion / erasure — ask us to delete your data, subject to retention obligations we can document.
- Portability — receive your data in a structured, machine-readable format.
- Restrict / object to processing based on legitimate interest.
- Withdraw consent where we relied on it (for example, applicant-stage processing). Withdrawal does not affect lawful processing before withdrawal.
- Lodge a complaint with your local data-protection authority (UK ICO, EEA supervisory authority, Philippine NPC, Mexico INAI, California Attorney General, etc.).
To exercise any of these, write to legal@leadadvisors.net. We respond within the period required by your local law (within 30 days for most jurisdictions).
9.1 California (CCPA / CPRA)
California residents may request to know, delete, correct, or opt out of "sharing" of personal information; we do not sell personal information. The categories of personal information collected, sources, business purposes, and recipients are described in §§2-7 above.
9.2 EU / UK / Switzerland (GDPR)
You may contact our privacy contact (§1) and lodge a complaint with your supervisory authority. Our representative (where required) is listed in §1.
9.3 Philippines (DPA)
You may contact our Data Privacy Officer at legal@leadadvisors.net [Anthony to confirm: appoint and identify a registered DPO if engaging PH-based contractors at scale; NPC requires this]. You may file a complaint with the National Privacy Commission.
9.4 Mexico (LFPDPPP)
You may exercise ARCO rights (Access, Rectification, Cancellation, Opposition) by writing to legal@leadadvisors.net.
10. Security
We rely on:
- TLS in transit (HTTPS-only; HSTS via Vercel platform).
- Bcrypt password hashing for portal accounts.
- Network and platform-level controls provided by Vercel and Neon.
- Role-based access inside the portal (admin, super-admin, HR, recruiter, staff, candidate, vendor — with separate views, see §6 of
CLAUDE.md). - Audit logging for sensitive actions [Anthony to confirm: roll-out of the audit log per Module B1].
- Secrets stored in Vercel Environment Variables, never in source control.
No method of transmission or storage is perfectly secure. We work to minimize risk and respond promptly to incidents.
11. Breach notification
If we determine a personal-data breach has occurred, we will notify you and the relevant supervisory authorities as required by law. For the purposes of any DPA we sign with a client, we will notify the client without undue delay and in any event within 72 hours of becoming aware of a breach affecting client data.
12. Changes to this policy
We may update this policy. Material changes will be flagged to active applicants and contractors by email and / or in-portal notice. The "Last updated" date at the top is authoritative.
13. Contact
legal@leadadvisors.net
[Anthony to confirm: physical mailing address, registered legal entity name, governing US state, and DPO appointment for PH operations.]
Questions or rights requests: legal@leadadvisors.net.