Legal
Privacy policy
Last updated 27 September 2026
The short version
This policy explains what personal data LeadShala collects, why, who we share it with, how long we keep it and the choices you have. The main points:
- We collect what you give us (such as your name, email and website when you book a call, fill in a form or write to us), recordings of calls when we have told you first, and basic technical data such as your IP address.
- We use it to reply to you, hold calls, do the work you hire us for, bill for it, keep our site safe and meet our legal duties.
- We don’t sell your personal data, share it for targeted advertising or use it to profile you.
- Our site doesn’t use analytics or advertising cookies. The booking calendar is run by Calendly, which offers its own cookie choices.
- You can ask to see, correct or delete your data, and you can complain to us or to a regulator. Write to contact@leadshala.com.
Who we are
LeadShala Digital Media (“LeadShala”, “we”, “us”) is a digital agency based at Apollo Premier, Vijay Nagar Square, Indore, Madhya Pradesh, India. We build apps and websites and run digital marketing for businesses, mainly in the United States, the United Kingdom and Australia. We run the website leadshala.com.
For the personal data described in this policy, we decide why and how it is used. In legal terms, that makes us the “controller” under the EU and UK General Data Protection Regulation (GDPR) and the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023.
You can reach us about anything in this policy at contact@leadshala.com. Our Grievance Officer is named in “Contact us” at the end of this policy.
What this policy covers
This policy applies when you:
- visit leadshala.com;
- book a call, request a teardown or send us a message through our site;
- talk to us by email, phone or video call;
- hire us, or work for a business that hires us or works with us.
It does not cover:
- personal data we handle for clients inside their own projects, such as their customers’ details in their ad accounts, websites or apps. For that data, the client’s privacy policy applies (see “When we work for our clients”);
- other websites and services, including the sites we link to. They have their own policies.
“Personal data” (also called personal information) means information about a person who can be identified from it, directly or indirectly.
The personal data we collect
What you give us
- Contact form. Your name, work email, website (if you add it), what you need help with, your message and the page you sent it from.
- Growth teardown. Your website address and the email address where we should send the video.
- Project planner. The sentence you type to describe your project. We use it to suggest services and questions on the page and don’t store it ourselves (see “AI and automated decisions”). If you then send us the plan, it goes into the contact form.
- Booking a call. When you book through our calendar, which is run by Calendly: your name, email, the time you choose, your time zone and any answers you add to the booking questions.
- Calls. What you say and share on our calls. When a call is recorded, the recording, transcript and summary (see “Calls we record”).
- Emails and messages. What you write to us, with your contact details and email signature.
- Working with us. If you or your business hires us: the names, job titles and business contact details of the people we work with; what we agree; project messages and files; invoices and payment records; and the access you give us to your accounts, such as ad accounts, analytics, code repositories and hosting. Where a platform allows it, we ask to be added as a user rather than for your password.
- Reviews. If you give us a review, your name, company, role, photo and words, which we publish as agreed with you.
What we collect automatically
- Technical data. When you visit our site, the servers that host it record standard technical data: your IP address, browser and device type, the pages you ask for, the page you came from, and the date and time. We use it to deliver pages, keep the site secure and fix problems.
- Spam checks. Our forms include hidden checks against spam, such as how fast a form is filled in, and our project planner holds your IP address in memory for 10 minutes after your last request, to stop repeated requests. It isn’t saved, and these checks aren’t used to identify you.
We don’t use analytics tools, advertising pixels, fingerprinting or other tracking technologies ourselves. The booking calendar, run by Calendly, uses its own cookies (see “Cookies and similar technologies”).
What we get from others
- Calendly and Google send us your booking details and calendar responses when you book or change a call.
- Your colleagues or contacts may give us your details when they introduce you to us or copy you into emails.
- Our clients give us the details of their staff and suppliers so that we can work together.
- Public sources, such as your business’s website, when we prepare for a call or a teardown you asked for.
What we don’t want
We don’t ask for sensitive data, such as health information, government ID numbers, or card or bank details. Please don’t send it through our forms or by email.
You don’t have to give us any personal data. But without your name and email, we can’t reply to you or book a call.
How we use your data and why
We use personal data only when the law allows it. Under the GDPR and UK GDPR, each use needs a “legal basis”. This is what we do and the basis we rely on:
- Reply to you, book and hold calls, and send the teardowns you ask for. Basis: taking the steps you ask for before a possible contract, and our legitimate interest in answering questions about our services.
- Record calls and keep notes of them. Basis: our legitimate interest in keeping an accurate record of what we discussed. We tell you about the recording, and you can say no. Separately, where a law requires everyone on a call to agree to recording, we only record with everyone’s agreement.
- Deliver our services, manage projects and work with our clients’ teams. Basis: our contract with you or your business, and our legitimate interest in working with the people our clients assign to a project.
- Invoice, collect payments and keep accounts. Basis: our contract, and our legitimate interest in meeting the tax and accounting laws that apply to us in India.
- Follow up on an enquiry or teardown you started. Basis: our legitimate interest in answering your request and offering our services. Every follow-up email lets you opt out, and we don’t send newsletters.
- Tell our clients about similar services. Basis: our legitimate interest, where the law allows this without consent; otherwise we ask first. You can opt out at any time.
- Publish a review you give us. Basis: your consent.
- Run and protect our site, stop spam and abuse, and fix problems. Basis: our legitimate interest in a site that works and is secure.
- Meet our legal duties, and establish or defend legal claims. Basis: legal obligations that apply to us, and our legitimate interest in meeting our legal duties in India and protecting our business.
- Sell or restructure our business, if that ever happens. Basis: our legitimate interest in running and developing our business.
Where we rely on legitimate interests, we have weighed them against your rights and interests. You can ask us about this, and you can object at any time (see “Your rights”).
In India, we use personal data you give us for the purpose you gave it, with your consent where the law needs it, and to meet our legal duties, as the Digital Personal Data Protection Act, 2023 allows. Where we rely on your consent, you can withdraw it as easily as you gave it, by writing to contact@leadshala.com. This doesn’t affect anything we did before.
We use personal data only for the purposes above or for purposes compatible with them. If we want to use it for something new, we will tell you first and, where the law needs it, ask for your consent.
Calls we record
On our video calls, we may use Calendly Notetaker, an AI note-taking tool. It records the conversation and creates a transcript and a summary, so we can focus on you rather than on taking notes.
You will always be told:
- For calls booked through our calendar, you get an email about an hour before, saying that the call may be recorded.
- In the call, the notetaker joins as a named participant, the meeting shows that it is being recorded, and the notetaker posts a message in the chat.
- We also remind you at the start of the call.
If you don’t want the call recorded, tell us before the call (reply to your booking email or write to contact@leadshala.com) or at the start of it. We will remove the notetaker, delete anything it has already captured, and the call goes ahead as normal. You can also ask us to stop at any point.
Recordings, transcripts and summaries are kept in our Calendly account, on servers in the United States. Only our team can see them, and Calendly handles them for us as our service provider. Calendly says it does not use customer data to train AI models. We use them only to prepare for and deliver the work we discussed with you.
We delete them on the schedule in “How long we keep it”, and you can ask us to delete them sooner.
Cookies and similar technologies
Cookies are small files that websites store on your device. Our own site does not set cookies, and we don’t use analytics, advertising pixels or other tracking technologies.
Our booking calendar is provided by Calendly. If your device is set to a European time zone (including the UK), the calendar loads only when you click to show it. Elsewhere, it loads when you scroll near it. When it loads, Calendly receives your IP address and browser details, uses some cookies that the calendar needs to work, and may show its own cookie banner where you can accept or reject its optional cookies. Calendly’s privacy notice covers these: calendly.com/legal/privacy-notice (opens in a new tab)
If you would rather not load the calendar, email us at contact@leadshala.com and we will book a time with you directly.
You can also block or delete cookies in your browser settings. If you block the cookies Calendly needs, the calendar may not work.
AI and automated decisions
We don’t make decisions about you based only on automated processing that have legal or similarly significant effects on you, and we don’t use computer programs to make decisions that could significantly affect your rights or interests.
We use AI tools in two places:
- Calendly Notetaker transcribes and summarizes calls, as described in “Calls we record”.
- Our project planner may use an AI model (Claude, made by Anthropic) to suggest services and questions from the sentence you type. When it does, the page labels the result “AI-assisted”. Anthropic processes the text for us as a service provider, may keep it for a limited time under its terms, and doesn’t use it to train its models. Please don’t type personal or confidential details into the planner.
Who we share it with
We don’t sell your personal data. We share it only with:
- Service providers that help us run our business and act on our instructions: the company that hosts our website; our email providers; the tools that pass form messages to us (an email delivery service or a workflow tool); Calendly (booking and call notes); Google (Google Meet and Google Calendar); Anthropic (the planner, when it uses AI); file storage and collaboration tools, such as Slack or Microsoft Teams when we share a channel with a client; and accounting, banking and payment providers. They may use your data only to provide their services to us.
- Professional advisers, such as accountants, auditors and lawyers, who must keep it confidential.
- Authorities, such as tax authorities, regulators, courts or the police, when the law requires it, or when it is needed to protect our rights, property or safety or those of others.
- A buyer or successor, if we sell, merge or restructure our business. They must protect your data as this policy describes.
- Anyone else you ask us to share it with, or with your consent.
Calendly and Google also handle some data as independent companies, for example for your own Calendly or Google account. Their own privacy policies apply to that: Calendly (calendly.com/legal/privacy-notice (opens in a new tab)) and Google (policies.google.com/privacy (opens in a new tab)).
When we work for our clients
When a business hires us, we may handle personal data that belongs to that business, such as its customers’ details in its ad accounts, analytics, CRM, website or app. We work inside the client’s own accounts wherever we can.
For that data, the client decides how it is used and we act only on the client’s instructions. In legal terms, we are the client’s “processor” or “service provider”. The client’s privacy policy explains how the data is used, and our agreement with the client sets out how we protect it. Where the law requires, we sign a data processing agreement with the client.
When we run ads for clients on platforms such as Google, Meta and LinkedIn, those platforms also process data under their own terms and policies.
If you are a customer of one of our clients and have a question about your data, please contact that business first. We will help them respond.
International transfers
We work from India, so your data is accessed and used in India. Our service providers store most of it in other countries, mainly the United States. For example, Calendly stores data in US data centers run by Google and Amazon Web Services.
When the GDPR or UK GDPR applies and we send personal data to a country that doesn’t have an adequacy decision, we use the safeguards the law provides, such as the European Commission’s Standard Contractual Clauses (with the UK Addendum for UK data) or our providers’ certification under the EU-U.S. Data Privacy Framework and its UK Extension. You can ask us for details or a copy of these safeguards.
If you are in Australia: the overseas recipients of your personal information are mainly in India and the United States.
Under Indian law, we may transfer personal data outside India, except to any country the Government of India restricts.
How long we keep it
We keep personal data only as long as we need it for the purposes in this policy. Then we delete it or make it anonymous. In practice:
- Enquiries, bookings and teardown requests that don’t lead to work: up to 2 years after our last contact with you.
- Call recordings, transcripts and summaries: up to 12 months after the call, or until the end of the project they relate to, if that is later.
- Client project records: for the length of the project and up to 8 years after it ends, so we can support the work and deal with any claims.
- Invoices, payment and accounting records: as long as Indian tax and accounting laws require, which can be up to 8 years.
- Technical logs: only as long as needed for security and to meet legal requirements.
We may keep data longer if the law requires it, or while we deal with a complaint or legal claim, and only for as long as that lasts. If you ask us to delete your data, we do so unless we must keep it for one of these reasons.
How we protect it
We hold personal data electronically, in our own accounts and with the service providers described above. We protect it with technical and organizational measures that fit the risk, including:
- encrypted connections (HTTPS) on our site;
- access limited to the people on our team who need it;
- strong passwords and two-step sign-in on our accounts where the service offers it;
- service providers that commit to protecting the data they handle for us.
No website or system is perfectly secure. If a breach of personal data is likely to put your rights at risk, we will tell you and the relevant authorities as the law requires.
Your rights
Wherever you live, you can ask us to:
- Access your data: tell you what we hold about you, how we use it and who we have shared it with, and give you a copy.
- Correct it: fix data that is wrong, or complete or update it.
- Delete it. We may need to keep some records the law requires, such as invoices.
- Object or restrict: stop or pause certain uses of your data.
- Port it: give you the data you gave us in a common, machine-readable format, or send it to another company where that is possible.
- Withdraw consent where we rely on it, at any time. This doesn’t affect what we did before.
- Complain to us, or to a regulator (see below).
Your right to object. You can object at any time to our use of your data based on legitimate interests, including call recording, and to direct marketing. If you object to marketing, we always stop.
How to make a request
Email contact@leadshala.com with “Privacy request” in the subject, or write to us at the address in “Contact us”. It’s free. We may ask you to confirm your identity, usually by replying from the email address we have for you, and we use that information only to check who you are. You can ask someone to act for you; we may ask for proof that you have authorized them.
We reply within one month, or sooner if the law where you live requires it. If a request is complex, we may take longer where the law allows, and we will tell you why. If we can’t do what you ask, we will explain why.
We will never treat you differently for using your rights.
EEA and UK
Under the GDPR and UK GDPR, you have all the rights above.
If you have a complaint, please tell us first. We will acknowledge it within 30 days, look into it and tell you the outcome without undue delay. You can also complain to a data protection authority: in the UK, the data protection regulator known as the ICO (ico.org.uk/make-a-complaint (opens in a new tab)); in the EEA, the authority in the country where you live or work, or where the issue happened (edpb.europa.eu/about-edpb/about-edpb/members_en (opens in a new tab)).
United States
Many US states, including California, Colorado, Connecticut, Virginia, Texas and Oregon, give their residents privacy rights. Depending on where you live, you may have the right to know what personal information we collect and why; to access, correct and delete it; to get a copy of it; and to opt out of its sale, of targeted advertising and of profiling. We honor these requests from all US residents, whether or not a state law applies to us.
We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising or profiling, or share it with third parties for their own direct marketing. We don’t collect sensitive personal information to infer things about you, and we have no actual knowledge of selling or sharing the personal information of anyone under 16.
California. In the last 12 months we collected these categories of personal information: identifiers (such as name, email and IP address); commercial information (services you asked about or bought, and invoices); internet activity (server logs); audio, electronic and visual information (call recordings); and professional information (job title and company). We collected them from the sources and use them for the purposes described in this policy. We keep identifiers, commercial and professional information as set out in “How long we keep it” (up to 2 years for enquiries and up to 8 years for client and accounting records), call recordings for up to 12 months or until the end of the project, and server logs only as long as needed for security. We disclosed each category for business purposes only to our service providers and professional advisers, and to authorities where the law requires.
Appeals. If we turn down your request, you can appeal by replying to our decision with “Appeal” in the subject. We will respond within 45 days. If you are not satisfied, you can contact your state’s Attorney General. California residents can also complain to the California Privacy Protection Agency (cppa.ca.gov (opens in a new tab)).
Do Not Track and Global Privacy Control. Our site doesn’t track you across other websites, so it doesn’t respond differently to Do Not Track signals, for which there is no agreed standard. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of the sale and sharing of your personal information.
Tracking by other companies. Apart from Calendly, as described in “Cookies and similar technologies”, we don’t allow other companies to collect personal information about your online activities over time and across websites through our site.
Australia
We handle personal information in line with the Australian Privacy Principles. You can browse our site without telling us who you are, and you can use a pseudonym when you contact us, but we need a working email address to reply to you or book a call.
You can ask to access or correct your personal information as described above. If you have a complaint, contact us first and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au/privacy/privacy-complaints (opens in a new tab)).
India
We give you these rights now, in line with the Digital Personal Data Protection Act, 2023 (whose main provisions apply from May 2027) and the Information Technology Act, 2000. You can ask for a summary of your personal data and how we use it, and for the identities of those we have shared it with; ask us to correct, complete, update or erase it; withdraw your consent; have your grievances addressed; and nominate another person to use your rights if you die or cannot act for yourself.
Please raise any grievance with our Grievance Officer (see “Contact us”). We will address it within one month. Once the Act’s complaint provisions apply (from May 2027), you can also complain to the Data Protection Board of India if you are not satisfied.
Other countries
If you live elsewhere, for example in Canada, New Zealand or Singapore, you may have similar rights under your local law. Contact us and we will help.
Children
Our site and services are for businesses and adults. They are not meant for anyone under 18, and we don’t knowingly collect personal data from children, including from children under 13. If you believe a child has given us personal data, contact us and we will delete it.
Links to other websites
Our site links to other websites, such as LinkedIn, Instagram, Facebook and GitHub. We are not responsible for how they handle personal data, so please read their privacy policies. Our own products, such as Elyxis and I’m Okay, are covered by their own privacy policies.
Changes to this policy
We may update this policy when our services, our tools or the law change. When we do, we change the “Last updated” date at the top. If a change is significant, we will tell you more directly, for example with a notice on our site or by email.
This version took effect on 27 September 2026.
Contact us
For questions, requests or complaints about this policy or your personal data:
- Email: contact@leadshala.com
- Post: LeadShala Digital Media, Apollo Premier, Vijay Nagar Square, Indore, Madhya Pradesh, India
- Grievance Officer: Jay Chak, Founder & CEO, contact@leadshala.com. We address grievances within one month.
If you are not satisfied with our answer, you can complain to the regulators listed in “Your rights”.