Privacy Policy | Leanback
DATA PRIVACY

Privacy Policy

Effective Date: April 10, 2026. Your privacy is our priority.

1. Who we are and how to contact us

Leanback ("we", "us", or "our") is a productivity service that connects to your existing tools - such as Slack, Google Calendar, and other data sources - to help managers and team leaders manage daily work and project status.

For the purposes of applicable privacy laws, Leanback acts as the data controller in respect of personal data processed during your use of the service.

  • Legal entity: [Leanback Ltd. / your registered company name]
  • Registration number: [company registration number]
  • Registered address: [full registered address]
  • Privacy contact: privacy@leanback.com

We have determined that we are not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR at this stage of our operations. If this changes, we will update this policy and publish the DPO's contact details.

2. What personal data we process and why

To deliver its features, Leanback connects to third-party services that you authorise. Depending on which integrations you enable, this may include:

  • Messages and channel content from Slack
  • Events, attendees, and scheduling data from Google Calendar
  • Data from any other sources you choose to connect

This data is retrieved on demand, processed transiently in working memory to generate the output displayed to you, and then immediately discarded. It is never written to a Leanback database, log, cache, or any other storage system.

We process this data for the following purposes:

  • Providing the core features of the Leanback service
  • Displaying project status, task summaries, and scheduling information within the service
  • Responding to your in-session queries and requests
2a. Lawful basis for processing (GDPR / UK GDPR)

If you are located in the EU, EEA, or United Kingdom, we rely on the following lawful bases under Article 6 of the GDPR / UK GDPR:

  • Contractual necessity (Art. 6(1)(b)): Processing is necessary to perform the service you have signed up for. Without accessing your connected data sources, we cannot provide the functionality of Leanback.
  • Legitimate interests (Art. 6(1)(f)): For any incidental processing (e.g. maintaining the security and integrity of the service), we rely on our legitimate interest in operating a secure, functional service, balanced against your privacy interests. Given that no data is stored, we consider this balance to weigh in your favour.
3. Data retention

Leanback retains personal data for zero duration beyond the processing of your request. Data from connected services is held in working memory only for the time required to generate your requested output - typically a matter of seconds - and is discarded immediately thereafter.

We do not maintain logs, session records, or any persistent copies of data accessed from your connected services.

Note on infrastructure: Leanback is hosted on third-party cloud infrastructure (see Section 5). Those providers may retain standard infrastructure logs (e.g. access logs, error logs) that could include metadata such as IP addresses or request timestamps. This is governed by their own privacy policies, not ours. We select infrastructure providers who offer appropriate data processing terms.

4. Information we do not collect

Beyond transient in-memory processing described above, we do not collect, store, or retain:

  • Your name, email address, or contact details
  • Content from your connected services beyond the active session
  • Usage logs or behavioural analytics
  • Device identifiers or persistent IP address records
  • Cookies or tracking technologies
5. Third-party services and processors

Leanback integrates with third-party platforms including Slack, Google, and others you choose to connect. Your use of those platforms is governed by their own privacy policies. Leanback does not control how those services handle your data independently of our integration.

We also use third-party infrastructure providers (cloud hosting, API gateways) to operate the service. These providers act as data processors on our behalf. We ensure that appropriate data processing agreements (DPAs) are in place with each processor, consistent with GDPR Article 28.

We do not sell, rent, or share your personal data with any third party for marketing or commercial purposes.

6. International data transfers

Leanback is operated from Israel. Israel has been granted an adequacy decision by the European Commission, meaning it is recognised as providing an equivalent level of data protection to the EU. Transfers of personal data from the EU/EEA to Israel are therefore lawful without additional safeguards.

If we use cloud infrastructure located outside Israel or the EU/EEA (for example, in the United States), we ensure that transfers are protected by appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs) or equivalent mechanisms under UK law.

You may request details of the specific transfer mechanisms we rely on by contacting us at the address in Section 1.

7. Data security

Because we do not store your data, there is no Leanback-held dataset that could be subject to a data breach. Access to your connected services is made through official, authenticated APIs using only the permissions you explicitly grant. You can revoke these permissions at any time through the respective service's settings.

We implement appropriate technical and organisational measures to protect data during transient processing, including encrypted connections (TLS) for all data in transit.

Breach notification: In the unlikely event of a security incident affecting personal data during processing, we will notify relevant supervisory authorities within 72 hours where required by law, and will inform affected users without undue delay if the breach poses a high risk to their rights and freedoms.

8. Your rights

Depending on your location, you may have the following rights in relation to your personal data. Because Leanback does not store personal data, many of these rights have limited practical application - but we take them seriously and will respond to any request promptly.

RightApplies underNotes
AccessGDPR, UK GDPR, CCPA, Israeli PPLWe hold no persistent data, but we will confirm this in writing on request.
RectificationGDPR, UK GDPR, Israeli PPLNo stored data to correct. For data in connected services, please use those services directly.
Erasure ("right to be forgotten")GDPR, UK GDPRNo persistent data to erase. Disconnecting your integrations ends all access.
Restriction of processingGDPR, UK GDPRNo persistent data to erase. Disconnecting your integrations ends all access.
Data portabilityGDPR, UK GDPRNo stored data to export. Source data remains in your connected services.
Object to processingGDPR, UK GDPRContact us. You may also object by revoking integration permissions.
Do not sell / do not shareCCPA (California)We do not sell or share personal data. No opt-out required.
Lodge a complaintGDPR, UK GDPRYou have the right to lodge a complaint with your local data protection authority (e.g. your EU Member State's DPA, the UK ICO, or the Israeli Privacy Protection Authority).

To exercise any right, contact us at privacy@leanback.com. We will respond within 30 days (or within any shorter period required by applicable law).

9. California residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA provides you with specific rights. In the preceding 12 months, Leanback has:

  • Not sold any personal information
  • Not shared any personal information for cross-context behavioural advertising
  • Processed the following categories of personal information transiently: identifiers (where present in connected data), professional or employment-related information, and communications content - all solely to provide the service

You have the right to know, delete, correct, and opt out of the sale or sharing of your personal information. To submit a request, contact us at privacy@leanback.com. We will not discriminate against you for exercising your CCPA rights.

10. Children's privacy

Leanback is designed for professional use by adults and is not directed at children. We do not knowingly process the personal data of anyone under the age of 16 (or the applicable age of digital consent in their jurisdiction). If you believe a child has used Leanback, please contact us and we will take appropriate steps.

11. Provision of data - voluntary or mandatory

Connecting your data sources to Leanback is entirely voluntary. You may choose which integrations to enable and may revoke any connection at any time. However, Leanback cannot function without at least one connected data source, so revoking all connections will mean the service cannot be used.

12. Changes to this policy

We may update this Privacy Policy as Leanback evolves - for example, if we introduce data storage, new integrations, or new features. We will post any changes on this page with an updated effective date and version number. If changes are material, we will provide notice through the service at least 14 days before they take effect.

We maintain a version history of this policy. Prior versions are available on request.

13. Contact and supervisory authorities

For any privacy-related questions or to exercise your rights, contact us at:

  • [Leanback Ltd.]
  • [Registered address]
  • privacy@leanback.com

You also have the right to lodge a complaint with a data protection supervisory authority. Relevant authorities include:

  • EU: Your EU Member State's data protection authority (list at edpb.europa.eu)
  • UK: Information Commissioner's Office (ICO) - ico.org.uk
  • Israel: Privacy Protection Authority - gov.il
  • California: California Privacy Protection Agency - cppa.ca.gov
Contact us about privacy

If you have any questions or concern regarding this policy or our privacy practices, please reach out.

privacy@leanback.com