Last updated: 23 September 2026.
Important residency notice: CRM Software Pro's standard production service is currently distributed across regions and is not an EU-only service. The primary application database and authentication service are hosted in the United States (North Virginia), and the production file bucket is presently located in the Asia-Pacific region. Connected AI, voice, email, payment, and channel providers may process data in other countries. See Data Processing and Subprocessors before enabling the service.
Our roles
For content that a business submits through its workspace—including customer chats, contact details, files, order references, and connected-channel messages—the business normally acts as the controller and CRM Software Pro acts as its processor. CRM Software Pro acts as controller for its own account, billing, security, support, and website data.
Customers must provide their own lawful privacy notice, choose a lawful basis, configure access, and ensure that they are permitted to send data to CRM Software Pro and the enabled integrations. A widget acknowledgment does not replace the controller's legal obligations.
What customers must not submit
- Passwords, authentication secrets, full payment-card data, or private cryptographic keys.
- Special-category or highly sensitive personal data unless a written agreement and suitable configuration explicitly permit it.
- Personal data that is unnecessary for the support, sales, scheduling, or CRM purpose.
- Data obtained without a lawful basis or shared with people who are not authorized to receive it.
Your Rights Under GDPR
Depending on the circumstances, people may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. If your data came through one of our customers, contact that customer first; it controls the purpose and can identify the relevant record. We assist customers with verified requests under our DPA.
How We Protect Your Data
- Encrypted HTTPS transport and managed-provider encryption at rest.
- Workspace, role, bot, and conversation access controls, including row-level authorization and signed file access.
- Short-lived capabilities for public widget sessions, rate limits, bot protection, and multi-factor authentication options.
- Logging, backup, incident-response, and access-revocation processes appropriate to the service.
Data Retention
Workspace content is retained while the account or workspace needs it, until an authorized user deletes it, or until a verified termination/deletion workflow applies. Security logs, billing records, provider logs, and backups may follow different legally or operationally required periods. Customers should set and document their own retention process. We do not promise that every copy disappears on a fixed timetable unless that timetable is stated in a signed DPA or order form.
International Data Transfers
Because the standard service is not EU-only, EEA/UK customers must assess international transfers. Depending on the provider and customer arrangement, safeguards may include adequacy decisions, the EU–US Data Privacy Framework, UK extensions, or Standard Contractual Clauses. Provider terms alone do not make a customer's deployment compliant; configuration, data minimization, and a signed DPA remain important.
DPA and subprocessors
Organizations using CRM Software Pro to process personal data should request and sign a Data Processing Addendum before production use, review our subprocessor list, and decide which optional AI, voice, avatar, payment, and messaging integrations to enable.
Privacy contact
Questions and verified rights requests: [email protected]. This address is our privacy contact; its publication does not by itself state that a statutory Data Protection Officer has been formally appointed.
Lodging a Complaint
You may contact your competent data-protection authority. We encourage you to contact the relevant controller and our privacy contact first so the request can be identified and addressed.