Legal Document

Privacy Policy

We are committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information.

365soft CRM Last updated: 7 July 2026
Introduction

Our Commitment to Privacy

365soft CRM ("we," "us," or "our") provides a customer relationship management platform (the "Software" or "Platform"). This Privacy Policy explains what personal data we process, why we process it, the legal grounds we rely on, how long we keep it, who we share it with, and the rights available to you under the EU/UK General Data Protection Regulation ("GDPR") and other applicable data protection laws.

This Policy applies to visitors of our website, prospective and registered customers who subscribe to the Platform ("Customers"), individual users that Customers invite to use the Platform ("End Users"), and, where relevant, the individuals whose personal data Customers store within the Platform ("Data Subjects").

If you are a contact, lead, or client whose details were entered into the Platform by a business that uses our CRM, please see the "Controller & Processor Roles" section below — your request should generally be directed to that business first.
Section 01

Controller & Processor Roles

Because 365soft CRM is a CRM platform, personal data flows through it in two distinct capacities, and our responsibilities differ depending on which applies:

Account, billing and platform-usage data. When you or your organization register for a subscription, we act as the data controller for account details, billing information, support communications, and technical/usage data generated by your use of the Platform.

Customer Data entered into the Platform. Our Customers use the Software to store and manage information about their own contacts, leads, and clients ("Customer Data"). For that data, the Customer is the data controller and 365soft CRM acts solely as a data processor, processing it only on the Customer's documented instructions, for no purpose other than providing the Software, and subject to a Data Processing Agreement ("DPA") consistent with Article 28 GDPR, available on request.

If your personal data has been entered into our Platform by one of our Customers, that Customer controls the purposes and means of processing and is the appropriate party to contact to exercise your rights. We assist our Customers in responding to such requests where required by law and will forward any request we receive directly from a Data Subject to the relevant Customer.

Section 02

Information We Collect

Account data: name, email address, phone number, company name, job title, password (stored hashed), and billing/invoicing details.

Customer Data: where you use the Platform to manage your own contacts, this may include names, email addresses, phone numbers, company details, deal and pipeline records, notes, attachments, appointments, and communication history that you or your team choose to store.

Usage & technical data: IP address, browser type, device and operating system, referring pages, log data, feature usage, and timestamps, collected automatically when you use the Platform.

Cookies and similar technologies: see the Cookies & Tracking section below.

Support communications: content of support tickets, emails, or chat messages you send us.

Payment data: processed on our behalf by PCI-DSS compliant third-party payment processors (e.g. Stripe / PayPal); we do not store full card numbers on our servers.

We only collect the information that is necessary to provide, secure, and improve the Platform.
Section 04

Use of Information

We use information we collect to provide, operate, secure, and maintain the Software; to authenticate users and process payments; to communicate service, billing, and security notices; to provide customer support; and to detect, investigate, and prevent fraud, abuse, or violations of our Terms of Use.

With your consent, we may send marketing communications such as product updates or newsletters; you can opt out at any time using the unsubscribe link in any such communication or via your account settings.

We may use aggregated or anonymized data — from which no individual can reasonably be identified — to analyze trends and improve the Platform. We do not use Customer Data to train external or third-party AI/machine-learning models, and we do not sell personal data.

Section 05

Cookies & Tracking Technologies

Strictly necessary cookies keep you securely signed in, remember session state, and balance load across our servers. These cannot be disabled without affecting core functionality.

Functional and analytics cookies help us understand how the Platform is used so we can improve it. Where required by applicable law (including the ePrivacy Directive), we only set these with your consent.

Marketing cookies, if used on our marketing website, are opt-in and can be managed through your cookie preferences or browser settings at any time. Most browsers also let you block or delete cookies directly; note that disabling essential cookies may prevent the Platform from working correctly.

Section 06

Sharing of Information & Sub-processors

We do not sell personal data. We share information only with third parties that need it to help us operate the Platform, acting as our sub-processors under contractual confidentiality and data-protection obligations, including:

Cloud hosting and storage providers, for application hosting and file storage; email delivery providers, for transactional and account-related email; payment processors (e.g. Stripe, PayPal), for billing; and customer support tooling providers, where used to manage support requests.

We may also disclose information where required to comply with applicable law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, property, or safety of 365soft CRM, our Customers, or others. In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to equivalent confidentiality protections.

An up-to-date list of sub-processors is available on request at [email protected].

Section 07

International Data Transfers

Personal data may be processed in countries other than the one in which you or your Customer are located, including countries outside the European Economic Area ("EEA") or United Kingdom. Where we transfer personal data outside the EEA/UK, we rely on recognized safeguards under GDPR, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or transfers to countries benefitting from an adequacy decision, in each case supplemented by appropriate technical and organizational measures.

Section 08

Data Retention

We retain personal data for as long as necessary to provide the Platform, fulfil the purposes described in this Policy, and comply with our legal, accounting, and reporting obligations. Account data is generally retained for the duration of your subscription and for a limited period afterward to allow for reactivation, dispute resolution, and legal compliance, after which it is deleted or anonymized.

Customer Data is retained in accordance with the Customer's instructions and our DPA; upon termination of a subscription, Customer Data is deleted or returned within a reasonable period, except where retention is required by law.

Section 09

Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, consistent with Article 32 GDPR. These include encryption of data in transit, access controls and authentication, role-based permissions, regular security testing, and staff confidentiality obligations.

No method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for enabling available security features such as two-factor authentication.

Section 10

Your Data Protection Rights

If you are located in the EEA, UK, or another jurisdiction with similar data protection laws, and personal data about you is processed by us as controller, you have the right to:

Access a copy of your personal data; rectify inaccurate or incomplete data; erase your data in certain circumstances ("right to be forgotten"); restrict processing; object to processing based on legitimate interests or for direct marketing; receive your data in a structured, commonly used, machine-readable format (data portability); and withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at [email protected]. We respond to verified requests within one month, as required by Article 12(3) GDPR, extendable by two further months for complex requests, in which case we will inform you of the extension and the reasons for it.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority, or with the supervisory authority in the EU/UK member state of your habitual residence, place of work, or the place of the alleged infringement.

Section 11

Automated Decision-Making & Profiling

The Platform includes optional features, such as lead scoring, that use automated logic to rank or prioritize records stored by a Customer. These features are configured and used by our Customers for their own internal business purposes and do not produce legal or similarly significant effects on individuals without human involvement. We do not use Customer Data to make automated decisions about individuals that produce legal or similarly significant effects, within the meaning of Article 22 GDPR. If a Customer configures the Platform to make such decisions, that Customer, as controller, is responsible for ensuring an appropriate legal basis and safeguards, including the right to obtain human intervention.

Section 12

Children's Privacy

The Software is a business tool not directed to, or intended for use by, children, and we do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have inadvertently collected personal data from a child under 16 without appropriate consent, we will promptly delete that information.

Section 13

Data Breach Notification

We maintain incident-response procedures to detect, contain, and investigate security incidents. Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where a breach is likely to result in a high risk to affected individuals, we will also notify those individuals, or, where we act as processor, promptly notify the affected Customer so that they can meet their own notification obligations.

Section 14

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the revised version on our website or within the Software and update the "Last updated" date above. Where changes are material, we will provide additional notice, such as by email or an in-app notice, before the changes take effect.

Section 15

Contact Us & Complaints

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us at [email protected].

You may also reach us through our contact page. We aim to acknowledge all privacy-related inquiries within 48 hours and to resolve them within the timeframes required by applicable law.