Leap Privacy Policy

Last Updated: 6 September 2026

This Privacy Policy describes the current policies and practices of Anything is Possible Media Ltd (aip) with regard to Personal Data collected through the use of our software platform Leap. The term “Personal Data” refers to personally identifiable information about you, such as your name, email address, job title, or other contact details provided when using our platform.

1. Lawful Basis for Processing

We process your personal data based on the following lawful grounds under the UK GDPR:

  • 1.1. Contractual necessity: To provide you with access to the platform and fulfil our obligations under the contract. For example, processing your information to allow you to use the platform’s features.
  • 1.2. Legitimate interests: To keep the platform and your account secure, to maintain an accurate record of the changes made to information held in the platform, and to administer accounts. We do not rely on legitimate interests to build profiles of individual users or to carry out marketing analytics.
  • 1.3. Consent: For sending marketing communications or newsletters where you have explicitly opted in. You can withdraw consent at any time.

2. Data Subject Rights

Under the UK GDPR, you have several rights in relation to your Personal Data. These include:

  • 2.1. Right to Access: You can request information about the Personal Data we hold about you, including what data we have, how it is being used, and why.
  • 2.2. Right to Rectification: If any of the Personal Data we hold about you is inaccurate, you have the right to request corrections.
  • 2.3. Right to Erasure: You may request that we delete your Personal Data if it is no longer necessary for the purposes for which it was collected, or if you withdraw consent (where applicable).
  • 2.4. Right to Restrict Processing: You have the right to ask us to limit the processing of your Personal Data in certain circumstances, such as when the accuracy of the data is contested.
  • 2.5. Right to Data Portability: You can request a copy of the Personal Data you have provided to us in a commonly used, machine-readable format to transfer it to another service provider.
  • 2.6. Right to Object: You can object to the processing of your Personal Data, including for marketing purposes or based on our legitimate interests. Where we rely on legitimate interests, we will stop processing your Personal Data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, for example our need to keep the platform secure or to maintain an accurate record of the changes made to information held in it.
  • 2.7. Right not to be subject to automated decision-making: You have the right to not be subject to decisions based solely on automated processing that significantly affects you, including profiling. The platform makes no such decisions: section 7.5 explains how AI output is used.

To exercise any of these rights, please contact us at [email protected]. We will respond within one month of receiving your request.

3. Collection of Personal Data

We collect and store Personal Data that you provide when using our platform, including:

  • 3.1. Contact details (such as name, email, job title, and telephone number) submitted when creating an account
  • 3.2. Information related to your activity on the platform, such as uploaded briefs, interactions with features, and tracking data
  • 3.3. Content you put into the platform, including briefs, comments and requests, and any files you upload or links you add
  • 3.4. Where you choose to dictate rather than type, the words your browser turns your speech into. Section 7.6 explains what happens to the speech itself
  • 3.5. Any other data required for the use of the platform as specified by your agency or organisation

We do not collect personal data from individuals under the age of 16, and our platform is not intended for use by children.

4. Use of Personal Data

The purposes for which we process Personal Data include:

  • 4.1. Service provision: Enabling you to access and use the platform for briefing and tracking marketing campaigns.
  • 4.2. Security and accountability: Protecting accounts and the information held in the platform against unauthorised access and misuse, and keeping a reliable record of who changed what.
  • 4.3. Communications: Contacting you in relation to your account, including updates, security notifications, and support requests.
  • 4.4. Compliance: Ensuring compliance with legal requirements, regulatory obligations, or contractual commitments.
  • 4.5. Account administration: Understanding which accounts are in active use, so that access to the platform can be administered.
  • 4.6. Drafting and checking with AI: Producing summaries, drafts and suggestions for a person to review, as described in section 7.

5. Usage and Activity Records

We record limited information about how the platform is used. This information is linked to your named user account, which means the records below identify you personally rather than being anonymous statistics:

  • 5.1. The date and time you were last active on the platform, and the date and time the workspace for your organisation was last active.
  • 5.2. A record of the actions you take within the platform, such as creating, editing or deleting an item, including what was changed and when. These records are visible to other users who have access to the same information.
  • 5.3. Technical information recorded by our servers in the ordinary course of running the platform, such as your IP address, used for security, fault diagnosis and abuse prevention.
  • 5.4. Which version of our release notes you last read, and when. This is recorded for agency staff only, so that we can see who has caught up with changes to the platform and prompt anyone who has missed a significant one.

We do not use third-party analytics services, we do not track your activity across other websites, and we do not use any of this information for advertising or profiling. There is no analytics, advertising or session-recording technology in the platform at all.

The records described in this section are held in the platform's own database and are not sent anywhere else for analysis. Other parts of the platform do rely on service providers, and some of those providers receive Personal Data: section 10 names each of them and says what it receives.

We use these records to keep the platform secure, to maintain a reliable record of the changes made to information held in it, and to administer accounts. We do not use them for marketing, for advertising, or to make automated decisions about anyone. All Personal Data collected for these purposes is processed in compliance with the UK GDPR.

6. Cookies

We set one cookie, which records that you are signed in and which account you are using. It is necessary for the platform to work: without it you would be signed out on every page. It is removed when you sign out, and it expires on its own if you stop using the platform. We set no advertising cookies, no analytics cookies and no cookies that follow you to other websites, so there is nothing here to consent to or opt out of beyond signing out.

7. Artificial Intelligence in the Platform (Leap AI)

Parts of the platform use artificial intelligence. We call this Leap AI. This section explains what it does, what is sent where, and what it is not allowed to do.

  • 7.1. What it is used for: summarising a brief once it has been submitted; reading a brief you have written or pasted and setting out what it contains, what is missing and what is worth questioning; and answering questions about the work in your workspace for agency staff. Each of these produces a draft or a suggestion for a person to read.
  • 7.2. What is sent to a model provider: only what the feature you are using needs. That means the text you type or paste, any file you attach to a request, and the records in your own workspace that the feature is working from, such as a brief, a project, a task, a media plan or campaign performance figures. Those records can contain the names and email addresses of people using the platform, and anything written in a brief or a comment.
  • 7.3. Who processes it: we do not run the underlying models ourselves. Requests are sent to the model providers named in section 10, which are Amazon Web Services, Google and OpenAI. Which provider handles a given request depends on the feature and the model selected.
  • 7.4. What it is not used for: we do not train any model of our own on your data, we do not use it to build profiles of individuals, and we do not use it for advertising. The terms on which each provider may handle content sent to it are set out in our sub-processor list and in the Data Processing Agreement we hold with your organisation.
  • 7.5. A person always checks it: what Leap AI produces is a draft, shown as a draft, for someone to confirm, correct or discard. No decision about a person is made by a model, and nothing a model writes is sent to a client without a person deciding to send it.
  • 7.6. Dictating instead of typing: where you dictate into the platform, your speech is turned into text by your own web browser and not by us. On most browsers this means the browser sends the sound of your voice to the company that makes it, which is Google for Chrome and Edge and Apple for Safari, and returns the words. Where your browser is able to do this on your own device, the platform asks it to, and nothing leaves your computer. Either way, we never receive or store a recording: only the words you choose to keep reach the platform, and you can edit or delete them like anything else you have typed.
  • 7.7. Records of what was asked: conversations with Leap AI are stored so you can return to them, and can be deleted. We also keep a technical record of each request, which includes the content of the request, so that we can tell whether the feature is working and what it costs. That record is held by the provider named in section 10 and kept for a limited period.
  • 7.8. Where it does not apply: parts of the platform that do not use AI do not send anything to these providers. Nothing in the platform sends your data to a model provider unless you use one of the features described in 7.1.

8. Data Retention

We retain Personal Data for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The specific retention periods may vary depending on the type of data:

  • 8.1. Account-related information: Retained for the duration of your account usage and up to six months after account closure to meet legal or contractual obligations.
  • 8.2. Usage data: Retained for as long as your account remains open. The last active date described in section 5.1 is overwritten each time you use the platform, so only the most recent value is held. The records of actions described in section 5.2 are kept for the life of the account they relate to, because they form the audit trail your organisation relies on to see who changed what. Where we no longer need this information for that purpose, we delete it.
  • 8.3. Marketing data: Retained until you opt out or withdraw consent.

9. International Data Transfers

The platform itself is hosted in the United Kingdom and the European Union. Files you upload are stored in London, the platform's email is sent from Ireland, and the campaign performance data the reports are built from is held in London.

Some of the services listed in section 10 are outside the UK and the European Economic Area, or may handle a request outside it. These are the transfers that happen in the ordinary course of using the platform:

  • 9.1. Where you use a Leap AI feature, the content of that request may be processed outside the UK and EEA, depending on which provider handles it. Section 7.2 describes what a request contains.
  • 9.2. Where your organisation has chosen to receive notifications in a chat application, the notification is sent to that application, which may be outside the UK and EEA. A notification can include the name and email address of the person who submitted a brief or wrote a comment, and the text of what they wrote.
  • 9.3. Where you send us feedback about the platform, that message is posted into a chat application used by our team, which is outside the UK and EEA. It includes your name, your organisation and what you wrote.
  • 9.4. Where a dashboard is shown inside the platform, it is displayed by an external reporting service, so your device connects to that service directly and it sees your IP address.

Where Personal Data is transferred outside the UK or EEA, we rely on the following safeguards:

  • 9.5. Standard Contractual Clauses (SCCs), with the UK International Data Transfer Addendum where the transfer is from the UK: contracts that ensure your data receives an equivalent level of protection as required under UK/EEA law.
  • 9.6. Adequacy decisions: Where data is transferred to countries deemed by the UK Government or European Commission to offer an adequate level of data protection.

10. Data Sharing and Disclosure

We do not sell or distribute your Personal Data to unrelated third parties, except under the following circumstances:

  • 10.1. Service providers: Personal Data may be transferred to the third-party service providers acting on our behalf that are named in the table below, for further processing in accordance with the purposes for which the data was originally collected.
  • 10.2. Legal obligations: We may disclose your data to comply with legal requirements, to protect your vital interests, or to ensure the security of the platform.
  • 10.3. Business transfers: In the event of a business sale, merger, or reorganisation, your Personal Data may be transferred as part of the transaction.

The service providers we use, what each one is used for, and what each one may receive:

ProviderUsed forMay receiveLocation
Amazon Web ServicesHosting, file storage, the platform's email, and one of the Leap AI model routesEverything you upload, the emails we send you, and the content of a Leap AI requestUnited Kingdom and European Union
MongoDB AtlasThe platform's databaseEverything held in the platformUnited Kingdom and European Union
HerokuRunning the platform's website and interfaceEvery request you make to the platform, including your IP addressUnited Kingdom and European Union
Google CloudThe campaign performance data behind the reports, and storage for video submitted for analysisCampaign and spend figures, and any video you upload for analysisUnited Kingdom and European Union
GoogleOne of the Leap AI model routesThe content of a Leap AI requestDetermined by the provider
OpenAIOne of the Leap AI model routes, available to agency staffThe content of a Leap AI requestUnited States
Langfuse (ClickHouse, Inc.)The technical record of Leap AI requests described in section 7.7The content of a Leap AI request, and the identifier of the person who made itEuropean Union
Google ChatBrief and comment notifications, where your organisation has switched them onThe name and email address of the person who submitted or commented, and what they wroteDetermined by the provider
DiscordProduct feedback you send us, and alerts to our own teamYour name, your organisation, and the feedback you wroteUnited States
Google Looker StudioDashboards displayed inside the platformYour IP address and the name of the workspace you are viewingDetermined by the provider
MetaChecking that a campaign identifier entered in a media plan is validCampaign and advertising account identifiers only, and no Personal DataUnited States

We hold a written contract with each provider that handles Personal Data on our behalf. Section 9 sets out the safeguards we rely on where a transfer leaves the UK or the EEA. If we add or change a provider that handles Personal Data, we will update this list and tell you as described in section 15.

11. Data Breach Procedures

In the event of a data breach that may pose a risk to your rights and freedoms, we will notify you and the relevant supervisory authority (the ICO in the UK) within 72 hours, in line with GDPR requirements.

12. Data Integrity and Security

We are committed to maintaining the accuracy and security of your Personal Data. We use appropriate technical and organisational measures to protect your data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. We retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected or as required by law.

13. Data Protection Officer (DPO)

If you have any questions or concerns about how your data is processed, or if you wish to exercise any of your rights, please contact our Data Protection Officer (DPO) at [email protected].

14. Supervisory Authority

You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe that your data protection rights have been violated.

ICO Contact Information:
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time in line with legal or operational changes. Any significant updates will be communicated to you via the platform, and continued use of the platform constitutes acceptance of the updated policy.

16. Contact Information

If you have any questions or concerns regarding this Privacy Policy, or if you wish to exercise your data rights, please contact us at [email protected].