Privacy policy
This policy describes how [publisher's legal name, address, company number — to complete] ("the publisher") processes personal data related to SoliCRM.
Two distinct roles
- For the data our customers put in their CRM (their contacts, leads, customers), the customer is the controller and the publisher its processor: it processes that data only on the customer's instructions, under the data processing agreement.
- For user accounts, subscription billing and the website, the publisher is the controller.
Data the publisher processes as controller
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Provide the service, secure accounts | Name, email, password (Argon2id hash), sign-in logs | Contract | Contract term, logs 12 months |
| Bill the subscription | Billing details, invoices | Legal obligation | 10 years |
| Support | Exchanges with support | Legitimate interest | 3 years |
| Public demo | Nothing personal: fictitious accounts reset nightly | — | 24 h |
No data is sold or used for advertising. Passwords and integration secrets are encrypted; data is hosted in France (OVHcloud). Sub-processors are listed with their safeguards.
Your rights
Access, rectification, erasure, restriction, objection and portability: write to [GDPR contact address — to complete]. Answer within one month. You may complain to your data protection authority.
For data in a customer's CRM (for instance you are a prospect of a company using SoliCRM), contact that company: SoliCRM gives it export and erasure tools, and we help it answer.
Cookies
SoliCRM only uses necessary cookies (session, CSRF security, language). No analytics or advertising cookies.