Your data, in plain language.
This is an invite-only pilot of Leadwatch, a read-only checker for Typeform and HubSpot. Last updated: 17 September 2026. The operator must add their business identity, privacy contact and applicable contractual terms before accepting public customers.
What is checked
For each selected form, the checker reads completed responses, applies your chosen eligibility rule, and looks for a HubSpot contact with the normalized email. A match confirms contact existence only. It does not establish consent, sales, deals, delivery of a message or follow-up.
What is retained
- Your account email, workspace name, password hash and session information.
- Encrypted connection tokens and the selected email identity, masked emails in reports, source response IDs, contact IDs, timestamps, policy versions and result explanations.
- Default evidence retention is 30 days. Operational check history is retained for 90 days. Automated cleanup runs in the worker.
- Complete response bodies and unrelated CRM properties are not stored. No AI provider receives enquiry data.
Where it is processed
The application and database run on the operator’s Azure VPS in Sweden Central. Daily database backups currently remain on this same VPS, with seven-day retention; separate backup storage is not yet configured. Confirm your data-location requirements with the operator before connecting region-restricted data. Typeform and HubSpot process the authorized API requests. If email is enabled, Resend receives the owner’s email address and summary counts. If billing is enabled, Paddle handles payment information through its hosted flow.
Your controls
You can pause monitoring, disable alerts, export masked evidence, exclude an intentionally omitted response, or disconnect an account. Disconnection deletes stored connection credentials and pauses checks. Revoke app authorization within Typeform or HubSpot as well. Retained evidence expires according to the retention period; contact the workspace operator for earlier deletion, corrections or account removal.
Security and limitations
Connections and identity values use authenticated encryption; passwords are hashed and sessions use secure cookies over HTTPS. Access is scoped to your workspace. These measures reduce risk; they do not make any service risk-free. Source API delays, identity changes, intentional deletions and API outages can produce pending or inconclusive results.
Backups and support
Backup retention and restoration are operator responsibilities. A deleted record may remain in retained backups until they expire. During the pilot, use the contact that provided your invitation for support and privacy requests. This pilot notice is not a claim of GDPR, CCPA or other compliance certification.
Back to the demo →