Privacy Policy
We are committed to protecting the personal data of prospects, clients, and visitors to our website. This policy explains what we collect, why we collect it, how long we keep it, and the rights you have over it.
Last updated: 10 August 2026
In short
- →We only collect the information you voluntarily submit through our contact form (name, email, phone, company, message).
- →We use it solely to respond to your inquiry and discuss a potential business relationship. We do not sell or rent your data — ever.
- →We retain inquiries for up to 24 months, then permanently delete them.
- →You can request access, correction, or deletion of your data at any time by emailing Info@leaderpreform-sd.com.
1. Data Controller
LEADER PERFORM is the data controller for personal data submitted through this website. We operate from two locations:
- Khartoum, Sudan — primary office, GMT+2
- United Arab Emirates — secondary office, GMT+4
For any privacy-related question, including requests to access, correct, or delete your personal data, contact us at Info@leaderpreform-sd.com or write to us at our Sudan office.
2. What We Collect
We collect only the minimum personal data needed to respond to your inquiry and evaluate a potential business relationship. All data is provided voluntarily by you.
Data you submit (via our contact form)
- Full name — to address you correctly.
- Email address — to reply to your inquiry.
- Phone number (optional) — for follow-up calls if you request them.
- Company name (optional) — for context about your business.
- Service of interest — to route your inquiry to the right team.
- Message — the details of your inquiry.
Data collected automatically
- IP address — collected server-side for security, abuse prevention, and rate-limiting. Truncated to 64 characters before storage.
- User agent — the browser identifier sent with your request. Truncated to 400 characters before storage. Used for diagnostics only.
- Server logs — standard request logs (timestamp, URL, status code) retained for 14 days for security and debugging.
We do not use third-party analytics, advertising cookies, tracking pixels, or fingerprinting on this website. We do not use Google Analytics, Facebook Pixel, or any equivalent service.
3. Legal Basis for Processing
Where the EU General Data Protection Regulation (GDPR) applies, our legal basis for processing your personal data is:
- →Legitimate interests (Art. 6(1)(f)) — to respond to your inquiry and evaluate a potential business relationship with you.
- →Consent (Art. 6(1)(a)) — for any optional follow-up marketing communication, which we will only send if you explicitly opt in.
- →Legal obligation (Art. 6(1)(c)) — where we are required to retain records for accounting or tax purposes.
You may withdraw consent for optional communications at any time by replying to any email from us with the word “unsubscribe” in the subject line, or by emailing us at Info@leaderpreform-sd.com.
4. How We Use Your Data
We use the personal data you submit for the following purposes:
- →To respond to your inquiry and discuss your needs.
- →To prepare a proposal, scope of work, or quote if you request one.
- →To maintain records of pre-contract communications for up to 24 months.
- →To protect our systems against abuse, spam, and unauthorized access (IP and user agent only).
- →To comply with legal, accounting, or tax obligations where applicable.
We do not use your data for automated decision-making, profiling, or training AI models. We do not share your data with third parties for their own marketing purposes.
6. Data Retention
We retain personal data only as long as necessary:
- →Inquiries (no contract signed): 24 months from submission, then permanently deleted.
- →Active clients: retained for the duration of the contract + 7 years for legal/accounting compliance, then deleted.
- →Server logs: 14 days, then automatically rotated.
- →IP / User Agent: stored alongside the inquiry and deleted with it.
When the retention period expires, we delete the data permanently from our primary database and from any backups within 30 days.
7. Security Measures
We implement industry-standard technical and organisational measures to protect your personal data:
- →HTTPS everywhere — all traffic encrypted via TLS 1.3, with HTTP Strict Transport Security (HSTS) enabled.
- →Content Security Policy — strict CSP with per-request nonces blocks cross-site scripting (XSS) attacks.
- →Server-side validation — every form field is validated with Zod schemas before storage.
- →Rate limiting — API endpoints are rate-limited to prevent abuse and DoS.
- →Access controls — database access is restricted to authenticated staff; production secrets are never committed to version control.
- →Honeypot anti-spam — bot submissions are silently dropped without storing any data.
Despite these measures, no system can be 100% secure. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours, as required by Article 34 of the GDPR.
Found a security vulnerability? See our responsible disclosure policy at /.well-known/security.txt.
8. Your Rights
Under the GDPR and similar regulations (UK GDPR, CCPA, PIPL), you have the following rights over your personal data:
- →Access — request a copy of the data we hold about you.
- →Rectification — correct inaccurate or incomplete data.
- →Erasure — request deletion of your data (“right to be forgotten”).
- →Restriction — limit how we process your data.
- →Data portability — receive your data in a machine-readable format.
- →Objection — object to processing based on legitimate interests.
- →Withdraw consent — at any time, for processing based on consent.
To exercise any of these rights, email us at Info@leaderpreform-sd.com with the subject line “Data Subject Request”. We will respond within 30 days. We may request identity verification before acting on your request.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. For reference, the supervisory authority in Sudan is the National Information Centre, and in the UAE the UAE Data Office (DIFC / ADGM) handles relevant complaints.
10. Children's Privacy
Our services are intended exclusively for businesses and professionals. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has submitted personal data to us, please contact us immediately at Info@leaderpreform-sd.com and we will delete it.
11. International Transfers
Your personal data is primarily stored and processed in Sudan and the United Arab Emirates. Where data is transferred to a third country (e.g. via a hosting provider), we ensure an adequate level of protection through:
- →The European Commission's adequacy decision for the receiving country, or
- →Standard Contractual Clauses (SCCs) signed with the receiving party, or
- →Binding Corporate Rules for intra-group transfers.
12. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we do, we will update the “Last updated” date at the top of this page. For material changes (e.g. new purposes of processing, new data categories), we will also display a prominent notice on the homepage for at least 30 days.
We encourage you to review this policy periodically. Continued use of our website after any change constitutes acceptance of the updated policy.
13. Contact Us
For any question, concern, or request related to this privacy policy or your personal data, contact us: