What we collect when you visit leadsace.io or talk to us, why we collect it, and what you can ask us to do about it.
LeadsACE is an independent growth agency based in Toronto, Canada, working with HealthTech and MedTech companies and with clinics and specialty practices. In this policy, "we" and "us" mean LeadsACE, and "you" means anyone who visits leadsace.io, books a call with us, or corresponds with us.
This policy covers the website and the enquiries, calls and emails that follow from it. Work we do for a client is also governed by the agreement signed with that client. Where this policy and a signed agreement disagree about that client's data, the signed agreement wins.
Questions about anything here go to hello@leadsace.io.
When you book a growth audit or email us, we receive your name, email address, phone number if you provide one, your company, and whatever else you choose to tell us about your business. Bookings run through Calendly, so Calendly receives that information too.
We record anonymised session activity: mouse movement, clicks, scroll depth, and where you stop reading. This is done by Microsoft Clarity, described in the next section. Text on the page is masked by default, so the replay shows shapes and interactions rather than readable content.
We record and transcribe most video calls so we can write accurate notes and follow up properly. The meeting platform announces recording at the start of the call. If you would rather we did not record, say so and we will turn it off.
Three tools touch your browser on this site. Here is all of them, what each one does, and whether it sets cookies.
| Tool | What it does | Cookies |
|---|---|---|
| Cloudflare Web Analytics | Counts page views and visits so we know how many real people read a page. It does not use cookies, does not fingerprint your device, and does not follow you to other sites. | None |
| Microsoft Clarity | Heatmaps and session replay, so we can see which parts of a page confuse people or get ignored. Page text is masked by default. Data is processed by Microsoft. | Yes |
| Calendly | Runs the scheduling page when you click through to book a call. Calendly sets its own cookies on its own domain, under its own privacy policy. | Yes, on calendly.com |
We do not run advertising pixels on this site, and we do not use cookies to build advertising profiles or to retarget you elsewhere.
You can block any of this through your browser settings or a content blocker, and the site will work normally without it. Microsoft explains Clarity and its opt-out at privacy.microsoft.com.
We do not use your personal information to train machine-learning models, and we do not make automated decisions about you that produce legal or similarly significant effects.
If you are in the United Kingdom or the European Economic Area, we rely on these bases under the GDPR:
We do not sell your personal information, and we never have. We share it with the service providers that run our operations, each bound by its own contract to protect it:
| Provider | Why |
|---|---|
| Cloudflare | Website hosting, security, and cookieless traffic analytics |
| Microsoft | Clarity heatmaps and session replay |
| Business email and documents | |
| Calendly | Call scheduling |
| Close | Our CRM, where enquiries and conversation history live |
| Fathom | Call recording, transcription and notes |
Beyond that, we disclose information only when the law requires it, when we need to establish or defend a legal claim, or if the business is ever transferred, in which case the acquirer inherits the obligations in this policy.
LeadsACE is a marketing and go-to-market firm. We are not a healthcare provider, and this website is not built to receive protected health information.
Do not send patient names, medical records, or any other protected health information through this website, through a booking form, or by ordinary email. If an engagement genuinely requires us to handle protected health information, we will sign a business associate agreement first and set up an appropriate channel for it. Anything sent to us outside that arrangement, we will delete.
Enquiries and CRM records are kept while there is an active or realistic business relationship, and for up to three years after our last contact, so that we can pick up a conversation where it left off. Session replays and heatmap data expire on Microsoft Clarity's own schedule, currently around thirty days. Traffic analytics are aggregate and hold no personal identifiers. Records we must keep for tax or accounting reasons are kept for as long as the law requires.
You can ask us to delete your information sooner, and we will unless we are legally required to keep it.
The site is served over HTTPS with HSTS. Access to our CRM, email and call recordings is limited to people who need it, protected by multi-factor authentication, and reviewed when someone stops working with us. Our providers are established vendors with their own security programmes.
No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your personal information, we will notify you and the relevant regulator as the law requires.
We are based in Canada and our providers operate in Canada, the United States and the European Union, so your information may be processed outside your home country. Where information moves out of the UK or EEA, our providers rely on the European Commission's standard contractual clauses or an equivalent approved mechanism.
Wherever you live, you can email hello@leadsace.io and ask us what we hold about you, ask us to correct it, or ask us to delete it. We will respond within thirty days, and we will not charge you or treat you differently for asking.
You have the right to access, correct, erase, restrict processing of, and port your data, to object to processing based on legitimate interests, and to withdraw consent. You can also complain to your national data protection authority, or to the Information Commissioner's Office in the UK.
Under PIPEDA you may access the personal information we hold about you and challenge its accuracy. Unresolved complaints can go to the Office of the Privacy Commissioner of Canada.
Under the CCPA and CPRA you may request the categories and specific pieces of personal information we collected, request deletion, and correct inaccurate information. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.
Browsers send these signals inconsistently and there is still no agreed standard for honouring them, so we do not claim to respond to Do Not Track headers. The point is largely academic here: we run no advertising trackers and sell nothing. If you send a Global Privacy Control signal, treat it as already satisfied by how this site works.
This is a business-to-business website. It is not directed at children, and we do not knowingly collect information from anyone under 16. If you believe a child has sent us personal information, email us and we will delete it.
When this policy changes we update the date at the top of the page. If a change materially affects how we handle your information, we will say so prominently rather than quietly editing the text.
LeadsACE, Toronto, Ontario, Canada.
Email hello@leadsace.io for anything about this policy, including access and deletion requests.
Our Terms of Service cover use of the website itself.