Leadstar Trust Center
Security, privacy and artificial intelligence
Essential information for assessing Leadstar and preparing an enterprise deployment.
- Primary hosting
- Paris, France
- Raw conversations
- 30 days
- Collective reporting
- Threshold of 7
- Individual HR use
- Prohibited
- OpenAI safeguards
- DPA signed
- Rights requests
- Within one month
Applications, PostgreSQL, Redis and object storage deployed in Clever Cloud’s Paris region.
Scheduled deletion within the product.
No collective reporting below seven distinct contributors.
No recruitment, scoring, disciplinary action or automated individual decisions.
API data not used to train models by default; API call logging disabled.
Contact: eva+support@leadstar.co.
Prepare your security review
Contact Leadstar about your security questionnaire, DPA and deployment-specific requirements.
Security and resilience
Review technical measures, backups and deployment commitments in the security overview.
Subprocessors and transfers
The subprocessor list identifies each provider’s function and flows that may leave the EEA.
Privacy and permitted use
Individual conversations are not exposed to the client. Reporting is collective and requires at least seven contributors. Leadstar does not make individual HR decisions.
Controls applied to OpenAI processing
- OpenAI Data Processing Addendum entered into.
- API call logging disabled at Leadstar organisation level.
store: falseapplied to compatible calls so responses are not retained as OpenAI application state.
Enterprise deployment package
Before production, Leadstar and the client formalise the Article 28 GDPR DPA, active subprocessors, retention periods, data locations and applicable security measures.