LeadStream Data Processing Agreement
This agreement is part of the LeadStream Terms of Service between the client ("Data Fiduciary", "you") and Manthrix Industries Private Limited, CIN U62011UW2026PTC254001 ("Data Processor", "Manthrix"). It covers personal data of your website visitors that LeadStream processes for you under the Information Technology Act, 2000 and its rules, and the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as their provisions come into force ("data protection law").
1. Subject and duration
Manthrix processes visitor personal data only to provide LeadStream to you, for as long as your account exists and then as described in clause 9.
2. Data and data principals
| Data principals | Data | Purpose |
|---|---|---|
| Visitors to your website(s) | name, email, phone number (contact form); consent record (time, text version, your business name and privacy link as shown, page address); chat messages; a random browser ID and a hashed network address (abuse limits) | answer visitors with an AI assistant, pass you the contact details of visitors who want to be contacted, keep proof of their consent |
3. Your instructions
Manthrix processes visitor data only on your documented instructions: these terms, your dashboard settings (websites, Knowledge Base, capture mode, alerts, lead retention period) and your actions there (correct, export, delete). Manthrix does not use visitor data for its own purposes or to train AI models, and tells you if it believes an instruction breaks data protection law.
4. Confidentiality and security
- Access to production data is limited to Manthrix's authorised staff, who are bound to confidentiality.
- Safeguards: encrypted connections; per-client data separation in every query; passwords hashed; no card or UPI details stored; backups; a security log (sign-ins, exports, deletions, admin actions; no personal content) kept 1 year; a written incident runbook. These are Manthrix's reasonable security safeguards under data protection law.
5. Sub-processors
You authorise these sub-processors. Manthrix emails you at least 15 days before adding or replacing one. If you object, you may end the agreement before the change takes effect and get a pro-rata refund of unused fees.
| Sub-processor | Service | Visitor data | Location |
|---|---|---|---|
| Cloudflare, Inc. | hosting and database | all | global network, may be outside India |
| Groq, Inc. | AI replies | chat messages and your Knowledge Base; the visitor's first name when given (never email or phone) | USA |
| Resend (Plus Five Five, Inc.) | email delivery to you | lead name, email and phone in alert and summary emails | USA |
| Meta Platforms (WhatsApp), only when WhatsApp alerts are switched on | alert delivery to you | lead name, email and phone | may be outside India |
Manthrix binds each sub-processor to data-protection terms no weaker than this agreement. Transfers outside India are made only where Indian law allows them; if the Government of India restricts transfers to a country, Manthrix stops or moves that transfer and tells you.
6. Visitor requests
- Your dashboard lets you find every lead of a person by email or phone, give them a copy (download), correct their details, and delete one lead or every lead of that person (their chats go with them). Each request is logged without the person's details (a hash), as proof that it was handled.
- If a visitor's request reaches Manthrix directly, Manthrix forwards it to you within 2 working days and does not answer the visitor on your behalf unless you ask.
7. Personal data breach
Manthrix tells you within 24 hours of becoming aware of a breach affecting your visitors' data, with what is known (nature, data, number of visitors, likely consequences, measures taken), and updates you as it learns more, so that you can notify the Data Protection Board of India and your visitors as data protection law requires. Manthrix makes its own reports to CERT-In where CERT-In's directions apply.
8. Retention
- Chat text: deleted 48 hours after the last message. Where data protection law requires processed data or processing logs to be kept longer (for example the one-year minimum in the Digital Personal Data Protection Rules, 2025), you instruct Manthrix to keep them for that period only, locked away from normal use, and to delete them when it ends.
- Leads: deleted automatically after the period you choose (6, 12, 24 or 36 months; default 24) or when you delete them.
- Chat records without a lead: 12 months.
- A record that a deletion or export happened (no personal data): 3 years.
9. End of the agreement
When your account is deleted (by you, or 90 days after it ended), Manthrix deletes all visitor data of your account at once (leads, chats, consent records) and your Knowledge Base and settings, except data that clause 8 requires to be kept. Backups are overwritten within 30 days. You can download all leads before deleting your account.
10. Audits and information
Manthrix gives you the information reasonably needed to show compliance with this agreement (this document, a security summary, the sub-processor list) and answers reasonable audit questions in writing within 15 days, up to once a year, or after a breach. On-site audits are not included.
11. Liability
Each party is responsible for its own duties under data protection law. Section 9 of the Terms of Service (Liability) applies to this agreement.