GDPR Compliance and Data Privacy

Your CRM platform is committed to safeguarding the privacy of your data and the data of your customers. We are proud to participate in frameworks that demonstrate our dedication to data security and compliance with international privacy standards. This article outlines key principles of the General Data Protection Regulation (GDPR) and explains the respective roles and responsibilities when you use our platform.

It is essential to review this information alongside our official Privacy Policy. For specific legal advice regarding your obligations, we recommend consulting with a qualified legal professional.

Understanding GDPR

The General Data Protection Regulation (GDPR) is a European Union regulation designed to standardize data privacy laws and enhance individuals' control over their personal data. Its rules apply to any organization handling the personal data of individuals in the EU. The principles of GDPR have also been adopted into UK law.

Your Role: The Data Controller

Under GDPR, a data controller is the entity that determines the purposes and means of processing personal data. When you use the CRM to manage your contacts and campaigns, you act as a data controller.

This means you are responsible for:

  • Establishing a valid legal basis for collecting and processing personal data.
  • Ensuring you do not retain data longer than necessary.
  • Handling requests from individuals regarding their data rights.

You should ensure your own business practices and policies are updated to lawfully transfer data to the CRM platform.

Our Role: The Data Processor

The CRM platform acts as a data processor. This means we store and manage the data you upload strictly according to your instructions. We do not use your data for our own independent purposes.

You must have a valid legal basis, as defined by GDPR, for processing personal data. It is your responsibility as the controller to select the appropriate basis (such as consent or legitimate interest) and implement the necessary notices and consent mechanisms for your customers. Choose your legal basis carefully at the outset of data collection.

Data Subject Rights

GDPR grants individuals (your customers) rights over their data, including the right to access, correct, or delete it. The CRM provides systems to help you manage these requests. If we receive a request directly from an individual, we will notify you so you can provide instructions for handling it promptly.

International Data Transfers

Transferring personal data outside the European Economic Area (EEA) is restricted. To facilitate lawful transfers, our Data Processing Agreement incorporates Standard Contractual Clauses approved for this purpose.

Our Commitment to Data Security

We implement robust security measures to protect the data you entrust to us. This includes regular testing for vulnerabilities, maintaining reliable backup systems, and employing processes to ensure data integrity and recovery, minimizing the risk of data loss or corruption.

If you have further questions about data privacy or your specific compliance needs, please contact our support team.