Privacy policy
How CRMcy handles personal data.
Last updated 2026-05-05
This is a placeholder privacy policy outlining the platform's data handling. Replace with counsel-reviewed text before public launch. CRMcy follows GDPR principles of data minimization, purpose limitation, and storage limitation; tenant administrators are the data controllers for the personal data they upload, and CRMcy operates as a data processor under a Data Processing Agreement (DPA) available on request.
The platform collects: (1) account data — email, name, hashed password, MFA secrets — for authentication; (2) tenant data — your customer records, invoices, etc. — strictly for the purpose of running the service; (3) operational data — request logs (90-day retention), error reports, performance metrics — for monitoring and incident response; and (4) cookie data — a session id only. We do not sell data, do not run third-party advertising trackers, and do not allow the OpenAI integration to train on your prompts (per OpenAI's API data policy).
Data subject rights
GDPR rights (access, rectification, erasure, portability, restriction, objection) are exercised in-app — see HR → GDPR — or by emailing [email protected].
Sub-processors
The current sub-processor list (Stripe, AWS, Cloudflare, OpenAI, Sentry) is published at https://crmcy.app/legal/subprocessors and updated 30 days before any addition.