Privacy & data protection

How information is used in this CRM

Last updated: 11 August 2026

Who is responsible for your information?

The business or organisation that gave you access to this CRM is normally the data controller for the customer, employee, supplier, subcontractor, driver and other business records it enters into the service. CRM Platformprovides and operates the software and processes that information on the organisation's behalf.

For information used to operate the platform itself — such as account, authentication, security, service administration and support information — CRM Platform may act as a controller in its own right.

Questions about a business record should normally be directed to the organisation that collected it. Platform privacy contact details will be published before external production use.

Information the service may process

Depending on the modules an organisation enables, this may include:

  • names, contact details, addresses and business identifiers;
  • customer, supplier, job, quote, invoice, payment and accounting records;
  • employee, payroll, tax, National Insurance and bank information;
  • CIS subcontractor, driver, certification and operational records;
  • documents and files uploaded to business records;
  • conversation text and tenant record details deliberately submitted to optional AI-assisted features;
  • account, sign-in, security, audit and support information; and
  • technical information needed to provide and secure the service.

Why information is used

Information is processed to provide the CRM and the business functions selected by the organisation, administer user accounts, secure and audit access, maintain records, provide customer portal features, support financial and statutory workflows where enabled, provide optional AI-assisted receipt/invoice extraction and in-app assistance where enabled, prevent misuse and meet legal obligations.

The organisation using the CRM is responsible for identifying and documenting the appropriate lawful basis for the personal information it places in the system. Depending on the circumstances, this may include performance of a contract, compliance with a legal obligation, legitimate interests, consent or another lawful basis available under UK data-protection law.

Who information may be shared with

Information is available to authorised users of the organisation and may be processed by service providers used to host and operate the platform, including database/storage, application hosting, email delivery, payments, security/malware scanning, monitoring, rate-limiting and AI service providers where those optional features are enabled. The AI features can send uploaded receipt/invoice content, user conversation text and tenant-scoped CRM results needed to answer the user's request. Information may also be sent to external services such as HMRC or payment providers when an authorised user deliberately uses those features.

Access is limited by tenant, user role and enabled modules. The platform does not sell CRM records for advertising.

Retention

Records are retained for as long as the organisation needs them for its business, contractual, statutory and regulatory purposes. Some financial, payroll, tax, security and audit records may need to be kept after an account or business relationship ends. The organisation using the CRM controls its retention settings and responsibilities, subject to platform-level security and operational retention requirements.

Your rights

UK data-protection law gives individuals rights that can include access, rectification, erasure, restriction, objection and data portability, depending on the circumstances and lawful basis. Where the information is a record held by a business using this CRM, contact that business first. It can use the CRM's data-protection tools to help respond to your request.

You can also complain to the Information Commissioner's Office if you are unhappy with how your personal information has been handled.

Data protection complaints

If you think CRM Platform has handled personal information incorrectly in its role as platform operator or controller, you can raise a data protection complaint with us. Please explain what happened, the information involved, what you think went wrong and what outcome you are seeking.

A dedicated platform privacy contact will be published before external production use. We will acknowledge a data protection complaint within 30 days of receipt, investigate it without undue delay, keep you informed where appropriate and communicate the outcome when the investigation is complete.

If your complaint is about information entered or used by a business that uses this CRM, that business is normally the controller and should receive the complaint first. It is responsible for its own complaint process; the platform will provide reasonable processor assistance where required.

Cookies and similar technologies

The service uses storage or cookies that are necessary for authentication, security and operation of the CRM. These are required to provide the service requested by the user. The platform does not intentionally use advertising cookies. If non-essential analytics or tracking technologies are introduced, users will be given appropriate information and controls before they are used where consent is required.

Security

The platform uses measures including tenant isolation, role-based access controls, database row-level security, encryption for sensitive fields, audit logging, secure authentication, rate limiting, malware scanning and monitored deployment controls. No online service can guarantee absolute security, so controls are reviewed and improved as the platform develops.