Privacy Notice
LeapFI (“LeapFI,” “we,” “us,” or “our”) provides AI governance, policy, procedure, AI development services to financial institutions (“Clients”). This Privacy Notice explains what information we collect, why we collect it, how we share it, how long we keep it, the rights available to you, and how information may be transferred internationally. It applies to visitors of leapfi.ai, individuals at our Client institutions who interact with our platform, and individuals whose personal information may appear within content Clients upload to our services.
Consent
By accessing or using leapfi.ai, by using the LeapFI platform as an authorized user of a Client, or by otherwise submitting information to us, you acknowledge this Privacy Notice and consent to the collection, use, and disclosure of your information as described below. If you do not agree with this Notice, please do not use leapfi.ai or submit personal information to us. Where LeapFI processes Client Content on behalf of a Client under a Master Services Agreement or other written agreement, that agreement, not this consent statement, governs our authority to process the data (see below).
1What We Collect
1.1 Content You or Your Institution Upload
When a Client uses our services, the Client and its authorized users may upload policies, procedures, model documentation, vendor-management records, incident-response plans, and related governance materials (“Client Content”). Client Content belongs to the Client and generally constitutes confidential and proprietary business information of the Client under the terms of our agreement with that Client. It may incidentally contain personal information about the Client’s employees, officers, or contractors (for example, names, titles, and business contact details referenced in a policy’s approval or ownership fields).
We process Client Content as a service provider / processor acting on the Client’s instructions. We do not treat it as our own for marketing or other unrelated purposes.
1.2 Account & Contact Information
- Name, business email address, employer/institution name, job title, and phone number
- Login credentials and authentication data
- Billing and business contact information for Client administrators
1.3 Communications
- Inquiries submitted through the contact form on our website, the name, business email address, institution name and type, and message you provide, which we collect and store solely to respond to and follow up on your inquiry
- Support requests, feedback, and correspondence with our team
- Records of privacy and data subject requests submitted to us
1.4 Usage, Technical & Cookie Data
General technical information, such as device and browser type, operating system, IP address, timestamps, pages viewed, and referring site, is collected automatically when you visit Leapfi.ai or use the platform. On its own, this information does not identify you personally.
2How We Use Information (Purposes)
- Provide you with services, respond to your requests, and meet our obligations to you
- Maintain, secure, and improve the platform, including troubleshooting and analytics
- Meet legal, regulatory, contractual, and recordkeeping obligations
- With consent or as permitted by law, send service updates or marketing communications, or offer of services (opt-out available at any time)
4Data Retention
We retain Client Content and account information for as long as needed to provide the services, as required by the applicable Client agreement, and thereafter for a defined period to meet legal, regulatory, and recordkeeping obligations common in financial services (generally up to 3 years following contract termination, unless a shorter period is agreed or a longer period is legally required).
If our written agreement with a Client requires the return or destruction of Confidential Information (including Client Content) upon termination, we will honor that obligation, subject to copies retained as required by law, regulation, backup processes, or our own recordkeeping practices.
We retain records of privacy and data subject requests (the DSR Log) for 3 years to demonstrate compliance. Data no longer needed is deleted or de-identified in accordance with our data retention schedule.
5Your Privacy Rights
Subject to applicable law, individuals may have the right to:
- Access the personal information we hold about them
- Correct inaccurate or incomplete personal information
- Delete personal information, subject to legal, contractual, or legitimate business exceptions
- Receive a copy of their personal information in a portable format
- Not be discriminated against for exercising these rights
Because much of the personal information we process is submitted by our Clients as part of Client Content, requests concerning that content may need to be directed to (or coordinated with) the relevant Client institution, which typically acts as the controller for that data. We will direct you accordingly if that applies to your request.
5.1 California and Other State Privacy Law Rights
Residents of California and other states with comprehensive privacy laws may have additional or more specific rights (for example, under the California Consumer Privacy Act, as amended). LeapFI does not sell or share personal information as those terms are defined under applicable state law.
5.2 How to Submit a Request
Submit a request via email: privacy@leapfi.ai
We will verify your identity before acting on a request and will respond within the timeline required by applicable law, generally within 45 calendar days for U.S. state privacy laws (extendable once by 45 additional days with notice) and within 30 calendar days for Canadian requests under PIPEDA (extendable with notice as permitted). Every request is logged, tracked to completion, and access to the log is restricted to authorized personnel.
6Security
We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including access controls, encryption, and monitoring appropriate to the sensitivity of Client Content. No system is completely secure, and we encourage prompt reporting of any suspected security issue to privacy@leapfi.ai.
7Children’s Privacy
Our services are intended for business use by financial institutions and their personnel. Our services are not directed to, and we do not knowingly collect personal information from, children under 13.
8International Data Transfers
LeapFI is based in the United States, and information we collect is generally processed and stored in the United States. If you access Leapfi.ai or our platform from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries, which may not offer the same level of data protection as your home jurisdiction.
9Relationship to Client Agreements
This Notice describes LeapFI’s general privacy practices. Where LeapFI processes Client Content or other personal information on behalf of a Client under a Master Services Agreement, data processing addendum, or other written agreement, the terms of that agreement, including its confidentiality, data return, destruction, and security provisions, govern our handling of that data and control in the event of any conflict with this Notice.
10Changes to This Notice
This Privacy Notice is subject to change. If we make changes, we will change the “Last Updated” date when we post the revised Notice. Changes will become effective when posted on the Site, and use of the Site following such revisions shall constitute acceptance of the revised Notice.
11Contact Us
Questions about this notice or our privacy practices, or requests to exercise your rights, can be directed to:
Email: privacy@leapfi.ai