Leadstar Trust Center

Security, privacy and artificial intelligence

Essential information for assessing Leadstar and preparing an enterprise deployment.

Primary hosting
Paris, France

Applications, PostgreSQL, Redis and object storage deployed in Clever Cloud’s Paris region.

Raw conversations
30 days

Scheduled deletion within the product.

Collective reporting
Threshold of 7

No collective reporting below seven distinct contributors.

Individual HR use
Prohibited

No recruitment, scoring, disciplinary action or automated individual decisions.

OpenAI safeguards
DPA signed

API data not used to train models by default; API call logging disabled.

Rights requests
Within one month

Contact: eva+support@leadstar.co.

Prepare your security review

Contact Leadstar about your security questionnaire, DPA and deployment-specific requirements.

Contact Leadstar

Security and resilience

Review technical measures, backups and deployment commitments in the security overview.

Subprocessors and transfers

The subprocessor list identifies each provider’s function and flows that may leave the EEA.

Privacy and permitted use

Individual conversations are not exposed to the client. Reporting is collective and requires at least seven contributors. Leadstar does not make individual HR decisions.

Controls applied to OpenAI processing

  • OpenAI Data Processing Addendum entered into.
  • API call logging disabled at Leadstar organisation level.
  • store: false applied to compatible calls so responses are not retained as OpenAI application state.

Enterprise deployment package

Before production, Leadstar and the client formalise the Article 28 GDPR DPA, active subprocessors, retention periods, data locations and applicable security measures.