Effective Date: June 15, 2026
Entity: LockingLead.ai ("Company", "We", "Us", or "Our")
This Privacy Policy and Data Processing Framework delineates the data governance, privacy standards, and compliance obligations governing the use of the LockingLead.ai artificial intelligence and automation infrastructure (the "Services"). This document is architected to ensure strict compliance with applicable United States data protection regulations, including the California Consumer Privacy Act (CCPA), as amended.
By utilizing LockingLead.ai, you (the "Client", "Business", or "Data Controller") agree to the terms explicitly set forth herein.
In the context of the Services provided, the legal relationship regarding data is strictly defined as follows:
Data Controller: You, the Client, are the Data Controller. You determine the purposes, conditions, and means of the processing of personal data collected from your end-consumers.
Data Processor: LockingLead.ai acts exclusively as the Data Processor. We process consumer data solely on your documented instructions to facilitate lead routing, automated communications, and AI-driven conversion systems.
To execute our AI automation and lead routing protocols, LockingLead.ai processes the following categories of Personally Identifiable Information (PII) on behalf of the Data Controller:
Identifiers: Full names, telephone numbers, and email addresses.
Communication Data: Inbound and outbound social media direct messages (DMs), SMS texts, and email correspondence routed through our system.
Behavioral & Contextual Data: Historical session logs and conversation histories, stored securely via our semantic memory systems to maintain conversational context and continuity.
To deliver enterprise-grade performance, LockingLead.ai utilizes secure, vetted third-party Sub-processors. We transmit necessary data payloads to the following infrastructure partners strictly to execute the Services:
GoHighLevel: Acts as the foundational CRM and primary communications gateway for message delivery and lead management.
Make.com: Serves as the data routing middleware, executing webhook logistics and conditional logic across workflows.
Google Gemini API: Functions as the core AI semantic analysis and generation engine to process natural language, assess lead intent, and generate automated responses.
We maintain a zero-tolerance policy for data exploitation.
LockingLead.ai explicitly guarantees that neither your proprietary business data nor your end-consumers' PII or communication logs will ever be used, harvested, or sold to train public generative AI models or foundational large language models (LLMs). All data transmitted to our AI Sub-processors (e.g., Google Gemini API) is executed via secure API endpoints utilized strictly for real-time inference, semantic reasoning, and maintaining localized context memory.
LockingLead.ai is engineered exclusively for commercial marketing, customer acquisition, and general lead conversion. Our infrastructure is NOT designed, secured, or audited for the storage or transmission of highly sensitive, regulated data.
WARNING TO DATA CONTROLLERS: You are strictly prohibited from configuring, prompting, or utilizing LockingLead.ai chat interfaces, SMS workflows, or email sequences to solicit, collect, or transmit extreme sensitive data from consumers. This includes, but is not limited to:
Financial Data: Full Payment Card Industry (PCI) data, credit card numbers, bank account details, or financial passwords.
Government Identifiers: Social Security Numbers (SSN), driver's license numbers, or passport data.
If a consumer volunteers this information unprompted, it is the Client's legal responsibility to immediately redact, purge, and report the exposure in accordance with applicable state and federal laws.
If the Client operates within the medical, aesthetic, med-spa, or healthcare sector, you are subject to the Health Insurance Portability and Accountability Act (HIPAA).
DISCLAIMER: LockingLead.ai is NOT a HIPAA-compliant Electronic Health Record (EHR) system. The Services are strictly prohibited from being used to collect, store, transmit, or process Protected Health Information (PHI) as defined by HIPAA. Clients are strictly prohibited from requesting diagnostic information, medical histories, or treatment specifics via LockingLead.ai automated channels.
Should a Client purposefully or negligently utilize LockingLead.ai to process PHI or other prohibited sensitive data, the Client assumes full, indemnified liability. LockingLead.ai expressly disclaims any and all legal responsibility, regulatory fines, or civil damages arising from the Client's violation of this clause.
As a Data Processor, LockingLead.ai does not "sell" or "share" consumer data for cross-context behavioral advertising as defined by the CCPA. We assist the Data Controller in fulfilling verified consumer rights requests, which may include:
Right to Know/Access: Consumers may request details on what personal data is being processed.
Right to Delete: Consumers may request the erasure of their conversation histories and PII from our memory banks.
Right to Opt-Out: Consumers may opt-out of automated SMS/Email processing at any time (e.g., via standard "STOP" commands).
Process for Rights Execution: Because LockingLead.ai is the Processor, end-consumers must submit their privacy requests directly to you, the Data Controller. Upon receiving a verified request from the Client, LockingLead.ai will execute the necessary data retrieval or purging protocols within the mandated 45-day statutory window.
We implement commercially reasonable, industry-standard cryptographic protocols to protect data in transit and at rest. Data is retained within the LockingLead.ai architecture only for as long as the Client maintains an active subscription or until the Client initiates a manual purge of the system's semantic memory. Upon termination of the Services, all consumer data and session logs will be permanently scheduled for deletion in accordance with our data lifecycle policies.