CRMDAY ONE · LEGAL
Privacy Policy
This Privacy Policy explains how CRMDAY One ("CRMDAY One", "CRMDAY", "we", "us" or "our"), a platform made available through the domains crmday.net and one.crmday.net, collects, uses, stores, shares and protects personal data related to the use of its websites, applications, integrations, APIs and other services (collectively, the "Services").
Last updated: September 25, 2026
1. Introduction
By using the Services, you represent that you have read this Policy. When an organization uses CRMDAY One to manage its customers, contacts, communications, policies, tasks, documents and other records, that organization generally determines the purposes and means of processing that data. In that situation, it acts as the data controller and CRMDAY One acts as a processor or service provider, processing data according to the organization's instructions and the applicable contract.
This Policy should be read together with the Terms of Service and any specific notices presented at the time of collection or when activating an integration.
2. Data We May Process
Depending on the features used, we may process the following categories of data:
a) Account and registration data: name, email address, phone number, company, job title, language, time zone, protected credentials, preferences, organizations the user belongs to, and authentication records.
b) Business and CRM data: information about customers and contacts, deals, tasks, meetings, events, pipelines, notes, tags, documents, forms, service history, activities, owners and custom fields entered by the customer organization.
c) Insurance-related data: information about proposals, policies, coverage, household members, producers, commissions, supporting documents and other data required by the workflows configured by the organization. Depending on the content entered by the organization, these records may include sensitive personal data. The organization is responsible for having the appropriate legal basis and authorizations to enter and process this data.
d) Communications: email, SMS, WhatsApp, social media and other connected-channel messages; senders and recipients; subject; body; attachments; metadata; delivery status; and call recordings and transcripts, when the feature is enabled and the processing is permitted by applicable law.
e) Integration data: account identifiers, authorization tokens, settings, synced records and data provided by connected services, such as Google, Microsoft, Zoho, Meta, Stripe, Chatwoot, telephony services and other providers chosen by the organization.
f) Payment and subscription data: plan, number of licenses, subscription status, billing history, billing address and transaction identifiers. Full card data is generally processed directly by the payment provider and is not stored by CRMDAY One.
g) Technical and usage data: IP address, browser and device type, operating system, language, pages visited, dates and times, session identifiers, logs, security events, diagnostics, failures, performance and feature usage.
h) Support and relationship data: content of requests, communications with our team, files submitted, survey responses and records necessary to investigate and resolve issues.
3. How We Collect Data
We may collect data:
- directly from you, when you create an account, fill out forms, subscribe to a plan, request support or configure the Services;
- from the organization your account is linked to;
- from customers, contacts and other data subjects whose data is entered by the customer organization;
- from integrations and providers authorized by you or by the organization;
- automatically, through cookies, logs, application events and similar technologies;
- from public or licensed sources, where permitted by law and necessary for the requested functionality.
4. Purposes of Processing
We may use data to:
- create, authenticate, secure and manage accounts and organizations;
- provide the contracted CRM, service, automation, communication, calendar, forms, document, policy, commission, reporting and artificial intelligence features;
- sync data and perform actions requested in connected services;
- send, receive, organize, display and log authorized communications;
- process payments and manage subscriptions, licenses, free trials and billing;
- personalize language, time zone, formats and user experience;
- provide support, diagnose errors, and prevent abuse, fraud and security incidents;
- maintain audit records and the integrity, availability and continuity of the Services;
- comply with legal, regulatory and contractual obligations, and orders from competent authorities;
- produce aggregated or anonymized metrics for operating and improving the Services;
- communicate material changes, security notices and account information.
We do not sell personal data. We do not use data obtained from Google APIs for targeted advertising, ad profile creation, credit assessment, or resale to data brokers.
5. Legal Bases
Where the law requires a legal basis, processing may occur, depending on the case, to:
- perform a contract or pre-contractual steps requested by you;
- comply with a legal or regulatory obligation;
- pursue legitimate interests, after weighing the rights and expectations of data subjects;
- exercise rights in judicial, administrative or arbitration proceedings;
- protect life, safety and prevent fraud;
- rely on the consent provided by the data subject, when that is the appropriate basis;
- follow documented instructions from the controlling organization.
Consent may be withdrawn at any time, without affecting processing already carried out and without preventing processing based on another valid legal basis.
6. Google and Gmail Data
When a user connects a Google Account, CRMDAY One uses Google OAuth to request authorization. CRMDAY One does not receive the Google Account password.
Depending on the permissions granted, CRMDAY One may access:
- name, email address and basic profile information of the Google Account;
- Gmail messages and threads, including senders, recipients, subject, content, attachments, labels, folders and metadata;
- the features necessary to sync, display, search, organize, draft, reply to and send emails on the user's behalf within CRMDAY One.
This data is used only to provide the email and CRM features visible to the user. OAuth tokens and recoverable credentials are stored encrypted. Data is isolated by organization, and internal access is limited to situations authorized by the user, support expressly requested, security, abuse investigation or compliance with a legal obligation.
CRMDAY One does not transfer Google data to third parties, except when necessary to provide or improve a requested feature visible to the user, with the applicable authorization; for security purposes; to comply with the law; or in a permitted corporate transaction, subject to the required safeguards and authorizations.
CRMDAY One's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, available at: https://developers.google.com/terms/api-services-user-data-policy
Users can disconnect their Google Account in the CRMDAY One settings and also revoke access on their Google Account's permissions page: https://myaccount.google.com/permissions
Revocation prevents new access but does not automatically delete records that must be preserved to comply with user requests, contractual obligations, security, audits or legal requirements. Deletion requests can be made under the "Your rights" section.
7. Artificial Intelligence
Some features may use artificial intelligence to summarize, classify, suggest replies, extract information, support automations or assist the user's work. When these features are used, the necessary data may be sent to contracted technology providers under confidentiality, security and purpose-limitation obligations.
Responses produced by artificial intelligence may contain inaccuracies. The user and the organization are responsible for reviewing results before making decisions, sending communications or using them in regulated activities, especially in insurance, health, finance or legal matters.
8. Data Sharing
We may share data in the following situations:
- with authorized users of the same organization, according to configured roles and permissions;
- with infrastructure, hosting, storage, email, communication, payment, analytics, security, support and artificial intelligence providers necessary to deliver the Services;
- with integrations activated by the organization or the user;
- with professional advisors subject to confidentiality obligations;
- with public authorities or third parties when necessary to comply with the law, protect rights, investigate fraud or respond to security risks;
- in a corporate reorganization, merger, acquisition, financing or sale of assets, subject to applicable legal safeguards.
We do not authorize providers to use data for their own purposes incompatible with the contracted service.
9. International Transfers
The Services may use infrastructure and providers located in different countries. When personal data is transferred internationally, we adopt mechanisms and safeguards compatible with applicable law, such as contractual clauses, technical measures and provider assessments.
10. Retention and Deletion
We retain data for as long as necessary to provide the Services, comply with the contract, fulfill the purposes described in this Policy, and meet legal, regulatory, tax, audit, security and rights-defense obligations.
After account closure or a valid deletion request, data will be deleted or anonymized within a reasonable period, except where its retention is necessary or permitted by law. Residual copies may temporarily remain in protected backups until replaced by the normal retention cycle.
When CRMDAY One acts as a processor, requests concerning data controlled by an organization may be forwarded to that organization, which is responsible for deciding on and instructing the response.
11. Security
We adopt technical and organizational measures intended to protect data, including access controls, isolation by organization, encryption of credentials and tokens, audit logs, session protection, monitoring and incident-response procedures.
No system is entirely immune to risk. Users should use a strong password, protect their devices, restrict access, keep recovery information up to date and promptly report any suspected misuse of the account.
12. Cookies and Similar Technologies
We may use cookies and local storage that are strictly necessary for authentication, security, preferences and the operation of the Services. We may also use measurement tools to understand the performance and use of public pages. Where required, non-essential features will depend on the user's choice.
13. Your Rights
Subject to applicable law, data subjects may request:
- confirmation of whether processing exists;
- access to their data;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or unlawfully processed data;
- portability, where applicable;
- information about sharing;
- review or explanation of automated decisions, where applicable;
- objection to or restriction of processing;
- withdrawal of consent;
- deletion of data processed based on consent, subject to legal retention requirements;
- filing a complaint with the competent data protection authority.
To exercise your rights, send a request to info@crmday.net. We may request reasonable information to confirm your identity and protect data against unauthorized access. Users linked to an organization may also need to direct their request to the organization responsible for the data.
14. Children's Data
The Services are intended for organizations and professionals and are not directed at children. User accounts must be created by individuals with legal capacity to contract. If an organization enters data about minors in its records, it is responsible for having an appropriate legal basis, authorizations and safeguards for that processing.
15. Links and Third-Party Services
The Services may contain links to, or integrations with, third parties. The practices of those third parties are governed by their own policies and terms. We recommend that users review them before authorizing a connection or providing data.
16. Changes to This Policy
We may update this Policy to reflect legal, technical or operational changes. The current version will show the date of the last update. When a change is material, we will take reasonable steps to communicate it and, where required, request new consent before using data for a materially different purpose.
17. Contact
For questions, privacy requests or to exercise your rights, contact:
CRMDAY One
Email: info@crmday.net
Website: https://crmday.net/one