Privacy Policy

We protect your data like it's our own.

Effective date: January 1, 2025

Data Processing Addendum (DPA)

If you are a controller under GDPR/UK-GDPR/DPDP, our DPA forms part of our agreement. Summary below; full signed DPA available on request.

Roles

Client = Data Controller. CleanupCRM = Data Processor.

Purpose

Processing limited to audit, deduplication, standardization, validation, reporting.

Sub-processors

Limited cloud infrastructure and tooling; list available on request; we'll notify of material changes.

Security

Administrative, technical, and physical controls; encryption in transit; restricted access; audit logs on request.

Data Subject Rights

We assist with access, rectification, deletion requests received by Client.

Breach Notice

We notify Client without undue delay after becoming aware of a personal data breach.

Retention/Return

Upon project end, return or delete data per Client instruction; default 30-day deletion.

Cross-border

Standard Contractual Clauses where applicable.

Contact

privacy@crmcleanup.co