Your files are production data.
We treat them that way.
Every record you upload is a real prospect and a real relationship. This page explains exactly how LeadQC handles it, what we do, what we never do, and how you can check for yourself.
Last reviewed 28 Sep 2026 · Questions: hello@zeplinix.com
- Encryption in transit
- Encryption at rest
- Workspace isolation
- DPA available
- Retention controls
- No training on customer files
- Auditability
- Explainable QC decisions
How your data moves
through LeadQC.
Four stages. One workspace, yours. Nothing leaves it except the three files you download.
- 01 · UploadInside the authenticated product
Files are uploaded in your LeadQC workspace after login, never through a public form or email. Your workspace is isolated from every other customer.
- 02 · ProcessLive checks, corrections, enrichment, your rules
Records are re-checked against current signals, corrected and enriched, then qualified against the QC rules you configured. Every decision is logged with its reason.
- 03 · DeliverThree files back to you
The error file, the corrected + enriched file and the GTM-ready file are produced for your workspace only. Nothing is shared, pooled or resold.
- 04 · Retain, then delete90 days, or sooner on request
Uploaded data and outputs are retained for 90 days so you can re-download them, then permanently deleted. Ask and we delete earlier.
What we do with your data.
What we never do.
The purpose is narrow by design: your records exist in LeadQC to be validated, corrected, enriched and qualified for you. That's the whole list.
- Run live validation, correction, enrichment and qualification on the records you upload. That is the only purpose we process them for
- Keep your outputs available for 90 days so your team can re-download them
- Log every processing decision so results are auditable and explainable
- Count how many records each run processed, so usage and billing are accurate. Counts only, never the contents
- Train models on your files
- Sell, share, resell or pool your data
- Use your prospects for our own outreach
- Mix your workspace with another customer's
- Keep files past the retention window without your instruction
- Accept production files through this website
The controls,
in plain language.
No badge wall. Each control below is something you can ask us to demonstrate before a single production file moves.
Data is encrypted in transit (TLS) and at rest. Credentials and keys are kept out of the codebase and web root.
Internal access to customer workspaces is least-privilege, limited to operating the service, and reviewed.
Each customer's files, rules and outputs live in their own workspace. There is no shared record pool.
Every rejection, correction and quality decision carries its reason in the outputs. Nothing disappears inside a black box.
90-day retention for re-download, then permanent deletion. Earlier deletion on request, confirmed in writing.
A Data Processing Agreement and the current sub-processor and hosting details are available on request before any production file moves.
SOC 2-aligned.
Not certified, and we say so.
Our controls are built and operated in line with the SOC 2 Trust Services Criteria for security, availability and confidentiality. We have not completed a third-party SOC 2 audit, and we won't describe ourselves as "compliant" or "certified" until we have.
Controls mapped to the Trust Services Criteria. Evidence walkthrough available on a call.
A Data Processing Agreement is available on request. Requests from data subjects are handled via hello@zeplinix.com.
Don't take this page's word for it either.
Ask.
Before production data moves, request the DPA, the sub-processor and hosting details, and a walkthrough of the controls. If you find a security issue, tell us first, we respond to responsible disclosure and will credit you if you wish.