1. Who We Are
Lion Sales Funnel LLC ("LSF", "we", "us") is a Florida limited liability company with a registered office at 7901 4th St N STE 300, St. Petersburg, FL 33702, United States.
We provide CRM integration, data engineering, attribution, reporting, and marketing automation services to businesses. Our work involves connecting systems that do not natively communicate, and building the data infrastructure that sits underneath them.
This policy explains what we do with personal information. It applies to lionsalesfunnels.com and to our services generally.
2. Our Two Roles
We handle personal information in two distinct capacities, and it matters which one applies to you.
2.1 As a controller
When you visit our website, submit our consultation form, email us, or engage us as a client, we decide what to do with your information. In that relationship we are the controller, and sections 3 to 5 describe what we collect and why.
2.2 As a processor
When we deliver services to a client business, we process information belonging to that client, including information about their customers, patients, or end users. In that relationship the client decides the purposes and means, and we act on their documented instructions. We are the processor, or service provider, and they are the controller.
If you are a customer or patient of a business that uses our services, and you want to know how your information is handled or want to exercise a right over it, contact that business directly. They control the data. We will support them in responding, but we cannot act on your request without their instruction, and we generally have no direct relationship with you.
3. Information We Collect Directly
3.1 Information you give us
- Consultation enquiries. Name, email address, company name, and the message you write when you submit our form.
- Correspondence. Anything you send us by email, phone, or messaging, together with our record of the exchange.
- Client relationship records. For clients, the contact details of your nominated personnel, billing and payment details, contractual documents, and the operational records of the engagement, including tickets, project notes, and meeting records.
- Meeting recordings and transcripts. Where a call is recorded or transcribed, the recording and transcript, subject to notice and consent as required by law. We will tell you when a call is being recorded.
- Recruitment information. Where you apply to work with us, the information in your application and any assessment or trial output.
3.2 Information collected automatically
Our website is a static page. It does not set analytics cookies, run advertising trackers, or build a profile of you.
Our hosting infrastructure and content delivery network process technical information necessary to serve the page and protect it from attack, including IP address, browser type, request time, and requested resource. This is standard server logging and is used for security, abuse prevention, and reliability, not for marketing.
The page embeds video from Loom and a map from Google. When those load, the respective provider may receive your IP address and set its own cookies. See section 14.
3.3 Information we do not want
Please do not send us sensitive personal information, health information, payment card numbers, or credentials through our consultation form or by unencrypted email. If you need to share something sensitive, contact us first and we will arrange a secure method.
4. How We Use That Information
| Purpose | What this involves |
|---|---|
| Responding to enquiries | Reading your message, replying, and arranging a fit call |
| Providing services | Delivering the work described in your Order and communicating about it |
| Billing and administration | Issuing invoices, taking payment, and maintaining financial records |
| Service improvement | Understanding what works, refining our methods, improving our documentation |
| Security and abuse prevention | Detecting spam submissions, blocking attacks, investigating incidents |
| Legal and compliance | Meeting tax, accounting, and regulatory obligations, and establishing or defending legal claims |
| Recruitment | Assessing applications and managing trials |
We do not sell personal information. We do not share it with third parties for their own marketing. We do not engage in cross-context behavioural advertising on our own website.
5. Legal Bases for Processing
Where the UK GDPR, EU GDPR, or a similar regime applies, we rely on the following bases.
- Contract. Processing necessary to enter into or perform a contract with you, including delivering services and handling billing.
- Legitimate interests. Responding to enquiries, securing our systems, preventing abuse, improving our services, and pursuing or defending legal claims. We balance these against your interests and rights.
- Legal obligation. Retaining financial records and responding to lawful requests from authorities.
- Consent. Where we ask for it specifically, such as for a testimonial or a recorded call in a jurisdiction requiring consent. You may withdraw consent at any time, without affecting processing already carried out.
6. Client Data We Process on Instruction
Delivering our services involves connecting to and extracting data from our clients' systems. Depending on the engagement, that can include:
- contact records from CRM platforms, including names, email addresses, phone numbers, and correspondence history;
- call records and call tracking data, including recordings and transcripts where the client captures them;
- form submissions and lead records;
- appointment and scheduling records;
- advertising and campaign performance data, including identifiers used for attribution;
- billing, invoicing, and transaction records; and
- in some engagements, clinical or treatment records held in practice management systems.
We process this only to deliver the services the client has engaged us for. We do not use it for our own purposes, do not sell it, do not use it to build products for other clients, and do not use it to train machine learning models for our own benefit.
Where we build a data warehouse or reporting layer, it is provisioned for that client, holds that client's data, and remains the client's property. Our access is operational and ends with the engagement.
If you are an individual whose information is held by one of our clients, that client is the controller and is the right party to contact. We can only act on their instruction.
7. Health Information and HIPAA
Some of our clients are healthcare providers, and some engagements involve protected health information as defined under the Health Insurance Portability and Accountability Act.
Where that is the case, we act as a business associate. We execute a Business Associate Agreement with the covered entity before processing protected health information, and that agreement governs our handling of it. Where its terms conflict with this policy in respect of protected health information, the agreement prevails.
We apply the minimum necessary standard, restricting access to personnel who need it for the engagement, and we impose equivalent obligations on any subcontractor that may encounter such information.
A valid business associate relationship has to exist across every vendor that touches protected health information, not only between the provider and us. Where we identify a gap in that chain during an engagement, we raise it with the client. Raising it is an operational observation, not a legal opinion or a warranty that no other gap exists, and the client should take its own advice on its compliance position.
8. When We Share Information
We share personal information only in these circumstances.
- With service providers and subprocessors who help us operate, as described in section 9.
- With our personnel and contractors who need it to deliver the engagement, subject to confidentiality obligations.
- With professional advisers such as lawyers, accountants, and auditors, where necessary and subject to confidentiality.
- Where required by law or in response to a valid request from a competent authority. Where we are permitted to notify the affected party, we will.
- To establish or defend legal claims, or to protect the rights, property, or safety of LSF, our clients, or others.
- In a corporate transaction, such as a merger, acquisition, or sale of assets, in which case the recipient is bound to treat the information consistently with this policy.
We do not sell personal information, and we have not done so in the preceding twelve months.
9. Service Providers and Subprocessors
We use third parties to run our business and deliver our services. The categories are:
- cloud hosting and infrastructure providers;
- content delivery, DNS, and security providers;
- communication and collaboration tools, including email, messaging, and video;
- project management and documentation systems;
- meeting transcription services, where used with notice;
- accounting, invoicing, and payment processing providers; and
- contracted personnel engaged to deliver services.
We impose contractual obligations on subprocessors that are materially equivalent to our own, restrict them to processing on our instructions, and remain responsible to our clients for their performance. Clients may request a current list of subprocessors used in their engagement.
10. International Transfers
We operate internationally. Our personnel and contractors work from multiple countries, and our infrastructure providers operate globally. Personal information may therefore be accessed from, processed in, or stored in countries other than the one where it was collected, including the United States, countries in Europe, and countries in Asia.
Data protection laws differ between countries. Where we transfer personal information out of a jurisdiction that restricts such transfers, we put in place an appropriate safeguard, such as standard contractual clauses, or rely on another lawful transfer mechanism.
Clients with specific data residency requirements should raise them before an engagement begins, so the architecture can be designed accordingly. Retrofitting residency constraints after a system is built is substantially more difficult.
11. How Long We Keep Information
| Category | Retention |
|---|---|
| Enquiries that do not become engagements | Up to 24 months from last contact |
| Client relationship and project records | Duration of engagement, then up to 7 years |
| Financial and tax records | As required by law, generally 7 years |
| Client Data in systems we operate | Per the client's instruction and the Order |
| Protected health information | Per the Business Associate Agreement |
| Server and security logs | Typically 30 to 90 days |
| Recruitment records for unsuccessful applicants | Up to 12 months |
On termination of an engagement, and subject to the client's instructions and any legal retention requirement, we return or delete Client Data. Copies may persist in routine backups for a limited period before being overwritten in the ordinary cycle, and remain protected by our confidentiality and security obligations until then.
12. How We Protect Information
We maintain technical and organisational measures appropriate to the risk, including:
- role-based access control and least-privilege access to production systems;
- single sign-on and multi-factor authentication for internal systems;
- encryption of data in transit;
- credential management practices that avoid sharing secrets in plain text;
- separation of client environments, with dedicated databases rather than shared tables;
- documented procedures governing access, change control, and incident handling; and
- confidentiality obligations on all personnel and contractors.
No system is completely secure, and we cannot guarantee absolute security. Where we become aware of a breach affecting personal information in our custody, we will notify affected clients without undue delay and cooperate in investigation and remediation, and will make any notification required of us by law.
13. Your Rights
Depending on where you are, you may have some or all of the following rights over personal information we hold about you as a controller.
- Access. To know what we hold and obtain a copy.
- Correction. To have inaccurate information corrected.
- Deletion. To have information erased, where no overriding basis for retention applies.
- Restriction. To limit how we use information in certain circumstances.
- Objection. To object to processing based on legitimate interests.
- Portability. To receive information in a portable format, where applicable.
- Withdraw consent. Where processing is based on consent.
- Non-discrimination. To exercise these rights without receiving worse service.
To exercise a right, email info@lionsalesfunnels.com. We will verify your identity before responding, which may require additional information. We respond within the period the applicable law requires, generally thirty (30) days, and will tell you if we need longer.
You may use an authorised agent where the applicable law permits, subject to verification.
If you are in the European Economic Area or the United Kingdom, you may lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
Where the information relates to a business that uses our services rather than to your relationship with us, see section 2.2. Direct the request to that business.
14. Cookies and Analytics
Our website does not set analytics or advertising cookies, and does not use tracking pixels for marketing.
Two categories of third party content are embedded in our pages:
- Loom, which hosts the framework walkthrough videos. When a video loads, Loom may receive your IP address and set cookies under its own privacy policy.
- Google Maps, which renders the map of our registered office. When the map loads, Google may receive your IP address and set cookies under its own privacy policy.
We do not control those providers' cookies. You can block third party cookies in your browser, or use a content blocker, and the rest of the page will continue to function.
Our infrastructure provider may set a strictly necessary cookie for security and abuse prevention. This is not used for tracking or advertising.
We do not currently respond to browser Do Not Track signals, as no common standard for them has been settled.
15. Children
Our services are directed at businesses, not to children. We do not knowingly collect personal information from anyone under sixteen (16) through our website. If you believe a child has provided information through our site, contact us and we will delete it.
Where a client engagement involves records of minors, such as a healthcare practice treating paediatric patients, that information is handled as Client Data under section 6 and under the applicable Business Associate Agreement or data processing terms.
16. Automated Decision Making
We do not make decisions producing legal or similarly significant effects about individuals through automated processing alone.
Our services may build lead prioritisation, scoring, or ranking systems for clients. Those systems operate under the client's control and instruction, the client determines how their output is used, and the client is responsible for the resulting decisions and for any disclosure obligations to affected individuals.
17. Changes to This Policy
We may update this policy as our practices or the law changes. The version number and effective date at the top of this page indicate the current version.
Where a change is material, we will take reasonable steps to notify affected clients in advance. Continuing to use our website or services after a change takes effect indicates acceptance of the updated policy.
18. How to Contact Us
For privacy questions, requests, or complaints:
LION SALES FUNNEL LLC
7901 4TH ST N STE 300
ST PETERSBURG FL 33702
United States
info@lionsalesfunnels.com
917-997-1133
See also our Terms of Service.