Privacy Policy
How CommLeap collects, uses, shares and protects personal information — and the choices and rights you have.
Last updated:
The short version
Our website does not use analytics, advertising or tracking cookies. We collect the details you choose to send us (for example through our contact form) and use them to respond and to run our business. When our customers send messages through the CommLeap platform, we process that data on their behalf and under their instructions — they decide what is sent and to whom. You can contact us at any time at info@commleap.com to exercise your privacy rights.
Contents
- Who we are and what this policy covers
- Our two roles: controller and processor
- Information we collect
- How we use information
- Legal bases for processing (EU and UK)
- Cookies and similar technologies
- How we share information
- International transfers
- How long we keep information
- Security
- Your privacy rights
- Children
- Changes to this policy
- Contact us
1. Who we are and what this policy covers
CommLeap (“CommLeap”, “we”, “us” or “our”) provides an enterprise communications platform as a service (CPaaS), including access to the WhatsApp Business Platform as a Meta Tech Provider, SMS, Voice, Email and Verify APIs, an omnichannel inbox and campaign tools, and, when available, additional channels and features such as RCS Business Messaging and conversational AI. We are headquartered in the Greater Toronto Area, Ontario, Canada, and serve business customers around the world.
This Privacy Policy explains how we handle personal information when you:
- visit our website at commleap.com (the “website”);
- contact us, ask for a demo or quote, or otherwise interact with us as a prospective customer, partner or supplier;
- use the CommLeap platform, dashboards, APIs and related services (the “services”) as an authorized user of a customer account.
This policy does not cover the privacy practices of our customers. If you received a message from a business that uses CommLeap, that business’s own privacy notice explains how it handles your information. See Our two roles below.
2. Our two roles: controller and processor
Privacy laws distinguish between organizations that decide why and how personal information is processed and organizations that process it on someone else’s behalf. CommLeap acts in both capacities, depending on the information involved.
CommLeap as controller
We are responsible for (the “controller” of) personal information about website visitors, prospects, business contacts, and the account and billing contacts of our customers. This policy primarily describes how we handle that information.
CommLeap as processor or service provider
When customers use the services to send and receive messages, calls, emails and verification codes, they may upload or generate personal information about their own end users — for example phone numbers, email addresses, message content, delivery receipts and call records (“customer data”). For customer data, CommLeap acts as a processor (also called a service provider) on behalf of our customer, who is the controller. We process customer data only to provide the services and as instructed by the customer, under the terms of our customer agreement and data processing agreement (DPA).
Our customers are responsible for providing any required privacy notices to their end users and for obtaining any consent or opt-in needed to contact them. If you are an end user of one of our customers and want to access, correct or delete your information, or stop receiving messages, please contact that business directly. If you contact us, we will refer your request to the relevant customer where we can identify them, and assist them as required by our agreement and applicable law.
3. Information we collect
Information you give us
- Contact form and enquiries. When you use our contact form or email us, we collect your name, work email address, phone number, company name, role, the product or topic you are interested in, and the content of your message, plus anything else you choose to include. If you tick the optional marketing box on the form, we also keep a record of your consent, including when it was given.
- Business contact information. We may receive business contact details (such as name, job title, company, work email and phone number) when you meet us at events, exchange business cards, are referred to us by a partner or colleague, or correspond with us as a supplier or partner.
- Account information. If your organization becomes a customer, we collect information needed to set up and manage the account, such as the names, work email addresses, phone numbers and roles of authorized users, login credentials, billing contacts, and records of support requests and communications with us. Payment information for CommLeap’s own fees is handled as described in your order form. WhatsApp messaging charges are billed by Meta directly to the customer’s WhatsApp Business Account under Meta’s terms, so we do not collect payment information for them.
Information collected automatically
- Server and security logs. Like most websites, the servers that host our website record technical information when you visit, such as your IP address, browser type and version, device and operating system information, the pages requested, the referring page and the date and time of the request.
- Service usage information. When authorized users use the services, we collect information about how the services are used, such as log-in events, API requests, configuration changes, usage volumes and error logs, to operate, bill for, secure and improve the services.
We do not use analytics, advertising or tracking cookies on the website, and we do not use third-party tracking technologies. See Cookies and similar technologies.
Customer data
As described in section 2, customer data processed through the services is handled on behalf of our customers under our customer agreement and DPA, not under this policy.
4. How we use information
We use the personal information described in this policy to:
- Respond to enquiries. Answer questions, provide demos, quotes and proposals, and follow up on your requests.
- Provide and support the services. Set up and administer customer accounts, authenticate users, deliver the services, provide customer support, process billing and communicate about the account, including service and security notices.
- Keep our website and services secure. Monitor for and prevent fraud, abuse, spam, messaging traffic manipulation (such as SMS pumping), security incidents and violations of our Terms of Service.
- Improve our business. Understand how our services are used, fix problems and develop new features, generally using aggregated or de-identified information where possible.
- Comply with legal obligations. Meet our legal, regulatory, tax and accounting obligations, respond to lawful requests, and establish, exercise or defend legal claims.
- Marketing to business contacts. Send business contacts information about our products, events and industry news. We obtain consent where the law requires it — including express or, where the law permits, implied consent under Canada’s Anti-Spam Legislation (CASL) for commercial electronic messages. Our marketing emails identify us, include our contact information and provide an easy way to unsubscribe, and we give effect to unsubscribe requests without delay and within 10 business days, as CASL requires. You can also opt out at any time by contacting us. We will still send you non-promotional messages about your account or requests.
We do not sell personal information, we do not use customer data for our own marketing, and we do not use customer data to train shared AI models.
5. Legal bases for processing (EU and UK)
Where the General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal information, we rely on the following legal bases:
- Contract: where processing is necessary to perform a contract with you or your organization, or to take steps at your request before entering into one (for example, preparing a quote).
- Legitimate interests: where processing is necessary for our legitimate interests — such as responding to business enquiries, managing customer relationships, securing our website and services, preventing fraud and improving our offering — and those interests are not overridden by your rights and interests.
- Consent: where we ask for your consent, for example for certain marketing communications. You may withdraw consent at any time without affecting processing carried out before withdrawal.
- Legal obligation: where processing is necessary to comply with a legal obligation to which we are subject.
6. Cookies and similar technologies
At present, the website does not set analytics, advertising or other tracking cookies, and it does not include third-party trackers or social media pixels. The fonts used on the website are hosted on our own servers, so loading them does not send your information to third parties. The services may use cookies or similar technologies that are strictly necessary for signing in and keeping your session secure.
If we decide to add any non-essential cookies or similar technologies to the website in the future, we will update this policy first and, where required by law, ask for your consent before setting them.
7. How we share information
We share personal information only as described below:
- Service providers. We use trusted vendors to host and operate our website and services, handle contact form submissions, send and store email, provide customer support tools and process payments. Service providers may use personal information only to provide services to us and must protect it.
- Channel providers. To deliver messages and calls on our customers’ behalf, we necessarily pass message content and addressing information to the operators of the relevant channels — such as Meta (for WhatsApp), mobile network operators and carriers, and email mailbox providers. These providers process that information under their own terms and privacy policies. For WhatsApp, CommLeap is a Meta Tech Provider: each customer contracts with Meta for its use of the WhatsApp Business Platform, owns its WhatsApp Business Account and is billed by Meta directly for WhatsApp messaging. Meta processes WhatsApp messages as described in its own terms and policies, including, for the WhatsApp Cloud API, acting as a data processor for the business (see our Security page).
- Professional advisers. We may share information with our lawyers, accountants, auditors and insurers where needed for them to advise or serve us.
- Legal requirements and protection. We may disclose information if we believe in good faith that it is required by law, regulation, court order or other legal process, or is necessary to protect the rights, property or safety of CommLeap, our customers, end users or others, including to prevent fraud and abuse.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, sale of assets or similar transaction, personal information may be transferred as part of that transaction, subject to appropriate confidentiality protections.
- With your direction or consent. We may share information in other ways when you ask us to or agree that we may.
8. International transfers
CommLeap is based in Canada and serves customers worldwide, and our service providers and channel providers operate in multiple countries. As a result, personal information may be stored and processed outside the country or province where you live, including in Canada, the United States and other countries whose privacy laws may differ from those in your jurisdiction. When information is held in another country, it may be accessible to the courts, law enforcement and national security authorities of that country.
When we transfer personal information internationally, we take steps to protect it in line with this policy and applicable law. For personal information from the EEA, UK or Switzerland, this may include relying on adequacy decisions (the European Commission recognizes Canada as providing adequate protection for personal information transferred to organizations subject to PIPEDA, a finding it reaffirmed in January 2024, and the UK and Switzerland recognize Canada on a similar basis) or using standard contractual clauses or other approved safeguards. Customers can find the transfer terms that apply to customer data in our DPA.
9. How long we keep information
We keep personal information only for as long as it is needed for the purposes described in this policy, including to meet legal, accounting, tax and reporting requirements, resolve disputes and enforce our agreements. For example:
- enquiry and prospect information is kept while we are in active discussions and for a reasonable period afterward, unless you ask us to delete it sooner;
- account and billing records are kept for the life of the customer relationship and as long afterward as required by law;
- server and security logs are kept for a limited period for security and troubleshooting purposes;
- marketing preferences, including opt-out records, are kept so that we can continue to honor them.
Customer data is retained and deleted in accordance with the customer’s instructions, our customer agreement and DPA and, where available, the customer’s retention settings. When information is no longer needed, we delete it or de-identify it.
10. Security
We use administrative, technical and physical safeguards designed to protect personal information against loss, theft and unauthorized access, use, disclosure or modification. These include encryption in transit, access controls based on the principle of least privilege, and monitoring of our systems. Learn more on our Security page.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a security breach affecting your personal information, we will notify you and the relevant authorities where required by law.
11. Your privacy rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
- Access: ask whether we hold personal information about you and request a copy.
- Correction: ask us to correct information that is inaccurate or incomplete.
- Deletion: ask us to delete your information, subject to legal exceptions.
- Objection and restriction: object to, or ask us to limit, certain processing — including processing for direct marketing, which you can stop at any time.
- Portability: receive certain information in a structured, commonly used format, or have it transferred to another organization.
- Withdraw consent: withdraw consent you have previously given, subject to legal or contractual restrictions.
Canada
The Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws — such as Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25, and the private-sector privacy laws of Alberta and British Columbia — give you rights to access and correct your personal information and to withdraw consent. Quebec residents may have additional rights, such as the right to data portability and to be informed about certain automated decisions.
European Economic Area and United Kingdom
Under the GDPR and UK GDPR, you have the rights listed above, including the right to object to processing based on our legitimate interests and the right to lodge a complaint with your local data protection authority.
United States
Several U.S. states, including California under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), give residents rights to know what personal information is collected, used and disclosed; to access, correct and delete it; and to opt out of the sale or sharing of personal information or its use for targeted advertising. These laws apply only to businesses that meet their applicability thresholds, and some apply differently to information collected in a business-to-business context. CommLeap does not sell personal information, does not share it for cross-context behavioral advertising and does not use it for targeted advertising, and we will not discriminate against you for exercising your privacy rights.
How to exercise your rights
To make a request, email us at info@commleap.com with the subject line “Privacy request” and tell us what you would like us to do. We may need to verify your identity before responding, and we may ask for more information to help us locate your records. You may use an authorized agent where the law allows; we may ask for proof of their authority. We will respond within the time required by applicable law. If we cannot fully meet your request, we will explain why, subject to legal restrictions.
If your request concerns customer data — for example, messages you received from a business that uses CommLeap — please contact that business directly, as explained in section 2.
Complaints
If you have concerns about how we handle your personal information, please contact us first so we can try to resolve them. You also have the right to complain to a privacy regulator, such as the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the privacy commissioner in your province, the data protection authority in your EU member state, or the UK Information Commissioner’s Office.
12. Children
Our website and services are designed for businesses and are not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it. Customers must not use the services to collect personal information from children in violation of applicable law.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our services or the law. When we do, we will revise the “Last updated” date at the top of this page. If we make material changes, we will take reasonable steps to let you know, such as by posting a notice on our website or notifying customers by email, and we will obtain consent where required by law.
14. Contact us
If you have questions about this Privacy Policy or our privacy practices, or want to exercise your rights, please contact us:
- Company: CommLeap
- Person in charge of the protection of personal information (Privacy Officer): our Privacy Officer, reachable at info@commleap.com with the subject line "Privacy Officer"
- Email: info@commleap.com (use the subject line “Privacy request” for privacy matters)
- Mailing address: 47 Hanna Drive, Bowmanville, Ontario L1C 5M4, Canada
You can also reach us through our contact page.