Privacy Policy
Last updated 21 July 2026
Who we are
LeadFlow is a customer relationship management (CRM) service operated by Velytron and available at leadflow.tennextsoft.com. It lets a business capture sales enquiries (“leads”), track follow-ups and keep a history of its conversations with potential customers.
This policy explains what personal data LeadFlow holds, why, who it is shared with, and how it can be deleted.
Our role, and yours
LeadFlow is used by businesses to manage their customer enquiries. For the lead data inside an account, the business using LeadFlow decides what is collected and why — they are the data controller. Velytron stores and processes that data on their behalf, as a processor, and does not sell it, rent it, or use it to build marketing profiles.
If you submitted an enquiry to a business and want to know what they hold about you, contact that business directly. If you cannot reach them, write to us at team@pazl.info and we will help you reach the right account owner.
What we collect
Lead information
Contact and enquiry details that a business collects about its potential customers: name, email address, phone number, company name, estimated deal value, enquiry source, status, notes and comments added by the team, scheduled follow-up times, and any documents or quotes uploaded against a lead.
This reaches LeadFlow in four ways:
- typed in manually by a member of the business’s team;
- imported from a CSV or Excel file the business uploads;
- received from Facebook Lead Ads, when a business connects its own Facebook Page and someone submits one of its lead forms;
- posted to a webhook endpoint by another tool the business uses.
Account information
For each person who signs in: full name, email address, role (agent or manager) and the company they belong to. Passwords are stored only as salted hashes and are never readable by us.
Integration credentials
If a business connects Facebook Lead Ads, we store its Meta app identifier and, encrypted, its app secret and Page access token. These are encrypted with AES-256-GCM before being written to the database and are never sent back to the browser.
How data is kept separate
LeadFlow is multi-tenant: several businesses use the same system. Every record carries the identifier of the company it belongs to, and access is enforced by row-level security in the database itself rather than only in application code. One company’s users cannot read another company’s leads, documents or integration settings.
Who we share it with
We do not sell personal data. We share it only with the service providers needed to run LeadFlow:
- Supabase — database, authentication and file storage. Data is hosted in the ap-south-1 (Mumbai, India) region.
- Vercel — application hosting and delivery.
- Meta Platforms— only where a business has connected Facebook Lead Ads, to receive that business’s own leads.
- OpenAI — see below.
The AI assistant, and what it sends
LeadFlow includes an assistant that answers questions in plain language, such as “who should I follow up with today?”. Please be aware of what this involves:
When a user asks the assistant a question, lead data relevant to that question is sent to OpenAI’s API to generate the answer. Depending on the question, this can include lead names, email addresses, phone numbers, company names, deal values, statuses, notes and the activity history of a lead.
The assistant can only read — it cannot change or delete anything — and it is restricted to the data of the company whose user is asking. If a business would rather no lead data left its account this way, it should not use the Assistant feature; contact us and we can disable it for that account.
How long we keep it
Lead records, activity history and documents are kept for as long as the business’s account is active, because the history is the point of the product. Individual leads and documents can be deleted from within the app at any time, which removes them permanently.
When an account is closed, its data is deleted within 30 days, except where we are required to retain something to meet a legal or accounting obligation.
Deleting your data
There are three ways data is removed:
- Inside the app — a signed-in user can delete an individual lead or document, which removes it and its history permanently.
- Disconnecting Facebook — using Integrations → Disconnect unsubscribes the Page from our app and deletes the stored access tokens and app secret immediately. Leads already received remain in the CRM until deleted separately.
- By request — email team@pazl.info from the address associated with the account, or the address you submitted an enquiry with, stating what you would like deleted. We will confirm your identity, action it within 30 days, and write back to confirm.
To remove LeadFlow’s access to your Facebook data entirely, you can also go to Facebook → Settings & Privacy → Settings → Business Integrations, select the app, and remove it.
Security
Traffic is served over HTTPS. Passwords are hashed. Integration secrets and access tokens are encrypted before storage. Access to each company’s data is enforced in the database. Incoming webhooks from Meta are verified against a cryptographic signature before their contents are trusted.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please report it to team@pazl.info.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete the personal data held about you, and to object to some processing. To exercise any of these, contact the business you dealt with, or write to us at team@pazl.info.
Changes to this policy
If we change how data is handled, we will update this page and revise the date at the top. Material changes affecting existing accounts will be communicated to account owners by email.
Contact
Velytron — team@pazl.info