Dayleeds

Data Processing

Last updated: August 22, 2026

Dayleeds LLC maintains a formal Data Processing Addendum (DPA) covering the United States and Canada. It is provided with paid pilot and subscription paperwork, and it is also available on request from support@dayleeds.com. This page summarizes it. Where the signed DPA and this summary differ, the signed DPA controls.

Roles

For the CRM data a customer connects, the customer generally acts as the controller or business and Dayleeds acts as the processor or service provider. Dayleeds processes that data on the customer's documented instructions, which include the signed agreement, the configuration the customer chooses, and the use of the service itself. For Dayleeds's own account, billing, and website data, Dayleeds acts as a controller and the Privacy Policy applies.

Subject matter and duration

The subject matter is the provision of the Dayleeds analytics service. Processing lasts for the term of the customer's pilot or subscription and the retention periods below.

Categories of data

Dayleeds processes supported HubSpot CRM records and sales-activity metadata: contacts, companies, owners and teams, and the associations between them, together with account, workspace, and billing information. Two boundaries define the rest:

  • Email. Sender and recipient identifiers, subject lines, timestamps, direction, send status, and delivery, bounce, open, click, reply, and other engagement metadata. Dayleeds does not intentionally ingest or store email bodies.
  • Calls. The assigned owner, timestamps, duration, call status, disposition or outcome, direction, and CRM associations. Dayleeds does not intentionally ingest or store call audio, recordings, or transcripts. The integration also does not request call titles, notes, or participant phone numbers.

Categories of data subjects

The customer's authorized users, and the contacts and company personnel recorded in the customer's HubSpot account whose activity appears in the synced data.

Customer obligations

The customer is responsible for having the rights, permissions, notices, and lawful bases needed for Dayleeds to process the connected data. Customers must not place sensitive or regulated data in subject lines or other free-text fields, and must not submit protected health information, student education records, government identifiers, payment card data, biometric identifiers, or call recordings or transcripts unless the parties first sign a written amendment covering that data.

Purpose and limits on use

Dayleeds uses customer data only to provide, secure, support, and administer the service and to follow lawful customer instructions. Dayleeds does not sell customer data, does not share it for cross-context behavioral advertising, and does not use it to train general-purpose or third-party AI models. Dayleeds may use aggregated or deidentified telemetry that cannot reasonably identify a customer or an individual to operate, secure, and improve the service.

Confidentiality and security

Personnel with access to customer data are bound by confidentiality obligations. Dayleeds maintains commercially reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data; the current controls are described on the Security page. No service can be guaranteed completely secure, and the DPA does not claim otherwise.

Security incidents

Dayleeds will notify the customer without undue delay after confirming a security incident affecting customer personal data, and will share the information reasonably available to it.

Subprocessors

Dayleeds uses the subprocessors listed on the Subprocessors page and remains responsible for their performance as required by the signed DPA. That page also states how customers are notified before a new subprocessor begins processing customer personal data.

Retention, deletion, and export

  • A workspace admin or owner can disconnect HubSpot and delete the workspace's synced data at any time from Settings, under Data and privacy. Deletion removes it from active systems when confirmed.
  • Every analytics view offers a CSV export of the data behind it, including Raw Data. Broader export requests go to support@dayleeds.com.
  • After termination, active customer data may be retained for up to 30 days for export or reactivation unless the customer asks for earlier deletion.
  • Backups containing customer data are deleted, overwritten, or rendered inaccessible within 90 days after deletion from active systems.
  • Contracts, billing, tax, fraud-prevention, security, and legal records may be retained for as long as legitimately necessary.

Assistance and audits

Dayleeds will provide reasonable assistance with data subject requests, and with security and impact assessments, taking into account the nature of the processing and the information available to it. Dayleeds will make available the information reasonably necessary to demonstrate compliance with the signed DPA.

Scope and international transfers

Dayleeds processes data in the United States and in the other provider locations listed on the Subprocessors page. The standard DPA covers the United States and Canada. Processing subject to EU, EEA, UK, or Swiss data protection law requires a separate written amendment.

Requesting the DPA

Write to support@dayleeds.com and we will send the current DPA for signature. It is also included with paid pilot and subscription paperwork.

Privacy · Terms · Security · Data processing · Subprocessors · Pricing

Back to Dayleeds · Contact support

PrivacyTermsSecuritySupportContact
Dayleeds is an independent product and is not affiliated with, endorsed by, or sponsored by HubSpot.