Privacy policy

This policy describes how [publisher's legal name, address, company number — to complete] ("the publisher") processes personal data related to SoliCRM.

Two distinct roles

  • For the data our customers put in their CRM (their contacts, leads, customers), the customer is the controller and the publisher its processor: it processes that data only on the customer's instructions, under the data processing agreement.
  • For user accounts, subscription billing and the website, the publisher is the controller.

Data the publisher processes as controller

PurposeDataLegal basisRetention
Provide the service, secure accountsName, email, password (Argon2id hash), sign-in logsContractContract term, logs 12 months
Bill the subscriptionBilling details, invoicesLegal obligation10 years
SupportExchanges with supportLegitimate interest3 years
Public demoNothing personal: fictitious accounts reset nightly—24 h

No data is sold or used for advertising. Passwords and integration secrets are encrypted; data is hosted in France (OVHcloud). Sub-processors are listed with their safeguards.

Your rights

Access, rectification, erasure, restriction, objection and portability: write to [GDPR contact address — to complete]. Answer within one month. You may complain to your data protection authority.

For data in a customer's CRM (for instance you are a prospect of a company using SoliCRM), contact that company: SoliCRM gives it export and erasure tools, and we help it answer.

Cookies

SoliCRM only uses necessary cookies (session, CSRF security, language). No analytics or advertising cookies.