Laiki

Last updated: 07/11/2026

Privacy policy

This policy explains how Laiki collects, uses, stores, shares and protects personal data related to the lead management, digital marketing, integrations, dashboards and workflows platform.

1. Introduction

Laiki is a digital marketing analytics and management platform that helps companies organize leads, integrate campaign data, build dashboards and automate workflows. This policy describes our privacy practices for platform users, customers, leads and other data subjects.

By using the platform or interacting with Laiki, you acknowledge that your personal data may be processed in accordance with this policy, the applicable terms and data protection law.

2. Roles in data processing

Laiki acts as controller when it processes personal data for its own purposes, such as account creation, authentication, billing, support, communications, security and platform administration.

Laiki acts as processor when it processes personal data on behalf of a customer, including data about leads, contacts, campaigns, integrations, webhooks and workflows configured by the customer. In those cases the customer defines the purpose, the legal basis and the processing instructions.

For the contractual processing terms between Laiki and customers, see also the Data processing agreement.

3. Information we collect

3.1 Account and profile data

  • name, email, phone, job title and contact information;
  • company information, such as name, domain and logo;
  • organization, role, permissions and account preferences;
  • login, authentication and platform activity history.

3.2 Lead, contact and customer data

  • name, email, phone and other contact information;
  • behavioral data, conversions and interactions;
  • custom fields defined by the customer;
  • segments, classifications and qualification scores.

3.3 Campaign, integration and workflow data

  • performance metrics for ads, campaigns and channels;
  • audience, segmentation, cost, ROI and attribution data;
  • metadata for authorized accounts, properties and integrations;
  • payloads, outputs, errors and logs from customer-configured workflows;
  • encrypted OAuth/API credentials for authorized integrations.

3.4 Platform usage and diagnostic data

  • account identifier, name, email, organization and user role;
  • pages visited, actions taken and session metadata;
  • browser, device, operating system and approximate location information;
  • performance data, errors and session recordings with masking and redaction of sensitive content.

4. How we use your information

4.1 Providing the services

  • process and analyze digital marketing data;
  • generate reports, dashboards, widgets and segments;
  • support the management of leads, campaigns and integrations;
  • run webhooks, workflows and automations configured by the customer;
  • provide technical support and customer service.

4.2 Platform security, operation and improvement

  • maintain authentication, sessions, permissions and per-organization isolation;
  • monitor availability, performance, errors and abuse;
  • detect, prevent and investigate security incidents;
  • improve platform features and usability;
  • analyze feature adoption and platform usage journeys;
  • carry out aggregated or anonymized analysis where applicable.

4.3 Communication

  • send important notices about your account, security and the service;
  • respond to support, privacy and DPA requests;
  • share product updates and new features;
  • send marketing communications where permitted.

5. Third-party platform integrations

When authorized by the customer, Laiki may connect to platforms such as Google Ads, Google Analytics, Meta Ads, LinkedIn Ads, RD Station, Conta Azul, Pipedrive and other supported providers. These integrations may involve campaign metrics, account data, properties, leads, contacts, events and credentials authorized by the customer.

The customer may also configure webhooks, workflows, credentials and HTTP destinations. In those cases the customer defines which data is sent, received, transformed or shared with third parties.

6. Data sharing

We do not sell personal data. We may share personal data only where necessary to operate, protect, support or meet obligations relating to the services:

  • with infrastructure, hosting, database, email and payment providers;
  • with product analytics, performance and diagnostic providers, such as PostHog;
  • with providers of integrations authorized by the customer;
  • with destinations, webhooks or endpoints configured by the customer itself;
  • where required by law, a competent authority or legal process;
  • to protect the rights, security, integrity or availability of the platform;
  • with the consent, request or applicable instruction of the customer or data subject.

7. Security and data protection

Laiki applies technical and organizational measures proportionate to the risk, including:

  • encryption of data in transit via TLS/HTTPS;
  • encryption at rest provided by the database and hosting infrastructure;
  • passwordless authentication via OTP sent by email;
  • logical isolation per organization using Row Level Security;
  • access controls based on organization, role and permissions;
  • encryption of OAuth/API credentials at the application layer;
  • redaction of secrets and limitation of workflow logs;
  • backups and an incident response process.

8. Data retention

We retain personal data for as long as necessary to provide the services, fulfill the purposes described in this policy, follow customer instructions, comply with legal obligations, resolve disputes and protect the platform.

  • workflow execution logs are retained for up to 14 days;
  • widget caches may be retained for up to 4 hours;
  • pending invitations expire after 7 days;
  • financial records may be retained for the period required by law;
  • deleted data may remain in backups until the backup cycle expires.
  • product analytics events may be retained by PostHog for up to 7 years, depending on the applicable plan and configuration;
  • PostHog session recordings are retained for up to 30 days;
  • upon account deletion or a verified request, Laiki initiates deletion of the PostHog profile and its associated events and recordings; event removal is processed asynchronously by the provider.

9. Data subject rights

Under the LGPD, data subjects may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, objection and review where applicable.

For data where Laiki acts as controller, the request will be handled directly by Laiki. For data where a customer acts as controller, Laiki may forward the request to the customer or provide reasonable technical assistance.

10. Cookies and similar technologies

We use cookies and similar technologies to:

  • keep sessions authenticated;
  • remember preferences and settings;
  • analyze platform usage, performance and errors;
  • improve the user experience.

We use PostHog to analyze usage, performance and errors and to improve the platform. This processing may include the data described in section 3.4 and may take place on international infrastructure, subject to the applicable contractual safeguards. Laiki applies minimization controls, recording masking and redaction of URLs, tokens and unnecessary personal data.

11. Changes to this policy

We may update this policy from time to time. Material changes may be communicated by email, by notice on the platform or by publishing the updated version on this page.

12. Contact

If you have questions about this policy or about how we process personal data, contact us:

Privacy email: privacy@laiki.co
DPO: Juan Pujol, dpo@laiki.co
Address: Rod. José Carlos Daux, 4150 · 88032-005 · Florianópolis, SC · Brazil