Legal
Privacy Policy
Effective 3 August 2026 · Version 1.0
UptoCRM Limited · Company no. 17364287 · England and Wales
This Privacy Policy explains how UptoCRM Limited handles Personal Data in connection with the Site, Service and Apps. It also explains the separate role played by a business customer that uses UptoCRM to manage information about its own leads, contacts, partners, personnel and business relationships.
Important distinction: For most information entered into a customer's UptoCRM workspace, the customer decides why and how the information is used and is the controller. UptoCRM processes that Customer Data for the customer. Requests about Customer Data should normally be directed to the relevant customer first.
1. About this Policy and its scope
1.1 Scope. This Policy applies to https://uptocrm.com and other UptoCRM websites that link to it (the Site), the hosted UptoCRM platform and related services (the Service), UptoCRM mobile applications distributed through the Apple App Store, Google Play or another authorised marketplace (the Apps), and communications, support and commercial activities connected with them.
1.2 Personal Data. This Policy applies to Personal Data, meaning information relating to an identified or identifiable individual. It does not apply to anonymous information that cannot reasonably be linked to an individual.
1.3 Business service. The Service is intended for organisations and authorised business users. A customer's contract, order form, data processing addendum or other written agreement may contain additional data protection terms. If those terms conflict with this Policy in relation to Customer Data, the written customer agreement governs the parties' contractual responsibilities.
1.4 Third-party platforms. Apple, Google and other app marketplace providers process information for their own purposes under their own privacy notices. Their independent practices are not controlled by this Policy.
2. Who we are and the roles we perform
2.1 Identity. UptoCRM Limited is incorporated in England and Wales under company number 17364287. Its registered office is 275 New North Road, Unit 3051, London, N1 7AA, United Kingdom.
2.2 Controller activities. UptoCRM is a controller when it decides how and why Personal Data is processed, including for Site visitors, prospects, customer contracting and billing contacts, account administration, security, product analytics, support, and UptoCRM's own business operations.
2.3 Processor activities. UptoCRM is a processor when it handles Customer Data in a customer's workspace on that customer's documented instructions. The customer is normally the controller and is responsible for its own privacy notice, legal basis, rights handling and configuration of the Service.
2.4 Overlapping roles. A single record may be processed in different roles for different purposes. For example, a Company Member's work email is processed as controller for login security and account administration, and may also form part of operational Customer Data processed for the customer's business purposes.
3. Personal Data we collect
3.1 Site visitors, prospects and business contacts
Identity and contact details, including name, work email, telephone number, organisation, role and country or region.
Enquiry, demo-booking, event, survey and marketing-preference information, together with correspondence and call notes.
Technical and usage information, including IP address, browser and device type, operating system, language, referring page, pages viewed and cookie or similar identifiers.
3.2 Customer administrators, Company Members and authorised users
Profile and account details, including name, work email, telephone number, avatar or photograph, role, team or region, time zone, language preference and optional profile fields such as date of birth.
Authentication and security information, including password hashes or authentication tokens, login timestamps, session information, access rights, multi-factor authentication status and security events.
Subscription, contracting and billing information, including plan, order, renewal, billing contact, transaction status, tax information and limited payment-related information received from a payment processor or marketplace. UptoCRM does not store complete payment card numbers unless expressly stated at collection.
Support and feedback information, including tickets, chat records, diagnostic material, product feedback and any files voluntarily supplied for troubleshooting.
3.3 App, device and diagnostic information
App version, device model, operating-system version, locale, time zone, network and carrier information, IP address, device or installation identifiers, push-notification token and app configuration.
Product-interaction, performance, crash and diagnostic information used to operate, secure and improve the Apps and Service.
Information selected through device permissions, such as camera, photo library, files, contacts, calendar or notifications, only where the relevant feature is offered, the permission is enabled and the user chooses to use it.
3.4 Customer Data
Lead, opportunity and deal data, including contact details, budget, property or location preferences, request type, financing or mortgage information and customer-entered notes.
Contact and organisation records, including addresses, telephone numbers, email addresses, tax identifiers where entered, language preferences and configured relationships.
Partner, referral, source and portal records, including partner contact details, country, invitations, referral sources and related analytics.
Tasks, meetings, calendars, communications, pipeline stages, automation configurations, audit histories, notes and attachments.
Documents and other user content uploaded to the Service, which may include text, images, audio, video, spreadsheets, scanned material and metadata chosen by the customer or user.
Customers control the content placed in free-text fields and uploads. Customers should not submit special-category or highly sensitive Personal Data unless it is lawful, necessary for a documented purpose and appropriately protected.
4. Where Personal Data comes from
4.1 Direct collection. We collect Personal Data directly when a person visits the Site, requests a demo, communicates with us, signs an order, creates or uses an account, configures an integration, purchases a subscription, submits support material or uses an App feature.
4.2 Customer and partner sources. We receive Personal Data from the customer's administrators and other users, invited partners, referral sources and integrations that a customer enables. A customer may also obtain Personal Data from its own websites, forms, marketing channels, property portals, business partners and offline activities before adding it to the Service.
4.3 Service providers. We receive limited information from payment processors and app marketplaces, authentication providers, cloud and communications providers, analytics and diagnostic providers, public business sources and fraud or security services.
4.4 Automatic collection. We collect technical information automatically from browsers, Apps, servers, cookies, software development kits and similar technologies, subject to applicable consent and platform requirements.
5. How and why we use Personal Data
5.1 Contract and service delivery. We use controller Personal Data to take steps requested before a contract, provide and administer accounts, deliver the Service, authenticate users, process orders and payments, provide support and enforce the agreement. The usual legal basis is performance of a contract or steps requested before entering one.
5.2 Security and improvement. We use Personal Data to secure accounts and infrastructure, prevent fraud and abuse, investigate incidents, maintain audit trails, diagnose errors, plan capacity, improve usability, understand service adoption and develop features. The usual legal basis is our legitimate interests in operating a secure and effective business, balanced against individual rights.
5.3 Legal and compliance. We use Personal Data to meet tax, accounting, sanctions, export, law-enforcement, regulatory and other legal obligations, and to establish, exercise or defend legal claims. The legal basis is compliance with law, legitimate interests, or another basis available under applicable law.
5.4 Operational communications. We may send service, security, billing and administrative communications that are necessary for an account or customer relationship. These are not marketing messages and cannot always be opted out of while the account remains active.
5.5 Marketing. We may send product news, event invitations and other business marketing where permitted by law. We rely on consent where required and otherwise on legitimate interests or a permitted existing-customer relationship. Each electronic marketing message includes an unsubscribe method, and suppression data may be retained so that an opt-out continues to be honoured.
5.6 Legitimate interests. Where we rely on legitimate interests, we consider the purpose, necessity and effect of the processing, reasonable expectations, sensitivity of the information and available safeguards. A person may object as described in section 13.
6. Customer Data processed on a Customer's behalf
6.1 Instructions. We process Customer Data to host, organise, search, display, transmit, export, back up and otherwise operate the Service; apply the workflows, permissions, notifications, integrations and automation rules configured by the customer; secure and support the customer's workspace; and comply with the customer's documented instructions in the agreement and use of the Service.
6.2 Customer responsibility. The customer determines the purposes, legal basis, source, accuracy, categories, retention and permitted recipients of Customer Data. It must provide required privacy information, obtain any necessary consent, respond to individuals and ensure that its users and partners use the Service lawfully.
6.3 Individual requests. If a person believes that information about them was entered by a UptoCRM customer, the person should contact that customer. We will assist the customer as required by the applicable agreement and data protection law.
6.4 Restricted use. We do not sell Customer Data, use it for third-party behavioural advertising, or use it to train general-purpose artificial-intelligence or machine-learning models. We may use aggregated or de-identified service information that does not identify a customer or individual to operate, secure and improve the Service.
7. Mobile application and app marketplace disclosures
7.1 App data. The Apps collect only the information required for the selected account, device and product functions, together with appropriate security, crash and performance data. Optional device permissions are requested in context and can generally be changed in device settings, although disabling a permission may prevent the related feature from working.
7.2 Notifications. Push notifications may contain service or workflow information. Users can manage notification settings in the App or operating-system settings. A device push token is used to route notifications and is not used for cross-app advertising.
7.3 SDKs. The Apps may include third-party software development kits used for authentication, security, crash reporting, performance, communications or other stated App functions. We are responsible for assessing those providers and for reflecting their practices in our App Store privacy disclosures and Google Play Data safety declarations.
7.4 No cross-app tracking. We do not use App data to track individuals across apps or websites owned by other companies for targeted advertising, and we do not share App data with data brokers. If this practice changes, we will update this Policy, the relevant marketplace disclosure and any required consent before the change takes effect.
7.5 Marketplace labels. The privacy information shown on an App Store or Google Play listing is a platform summary. This Policy provides fuller context. Marketplace declarations, App behaviour and this Policy must be kept materially consistent; if a platform summary is more specific for a particular App version, that summary applies to that version in addition to this Policy.
8. Cookies, analytics and communications
8.1 Necessary technologies. We use strictly necessary cookies and similar storage or access technologies for login, security, load balancing, session continuity, preferences and core functionality.
8.2 Consent and exemptions. Analytics and other non-essential technologies are used only where permitted. Where UK or EEA law requires consent, we request it before using them. Limited statutory exemptions may apply to specific low-risk purposes, but only where the relevant conditions are met.
8.3 Controls. Cookie choices can be managed through the Site's consent tool, the relevant App or browser settings. Withdrawing consent does not affect processing that occurred before withdrawal. Blocking necessary technologies may affect login or functionality.
8.4 Advertising. We do not use third-party behavioural advertising cookies in the Service. Links or integrations chosen by a customer may lead to third-party services with their own cookie and privacy practices.
9. How we disclose Personal Data
9.1 Service providers. We disclose Personal Data to vetted processors and service providers for cloud hosting, storage and backup; authentication and security; email, SMS and push delivery; customer support; error and performance monitoring; analytics; payment processing; professional services and other functions needed to run the business. They may use Personal Data only for the contracted purpose and subject to appropriate confidentiality and data protection terms.
9.2 Marketplace providers. We disclose limited information to Apple, Google or another marketplace when needed for distribution, licensing, subscription administration, purchase verification, refunds, security, platform compliance or user-requested functionality. Each marketplace also acts independently for its own store operations.
9.3 Customer-directed recipients. A customer may enable integrations or direct exports to third parties. The customer is responsible for that instruction and the third party's use of exported or integrated data. We do not control an integration after data has been transferred to the third party as an independent recipient.
9.4 Corporate and professional recipients. We may disclose Personal Data to professional advisers, insurers, auditors, investors and transaction counterparties under appropriate confidentiality measures, including in connection with financing, reorganisation, merger, acquisition or sale of assets.
9.5 Legal and safety. We may disclose Personal Data where reasonably necessary to comply with law or binding process, respond to a regulator, protect rights or safety, investigate fraud or security, enforce agreements or establish, exercise or defend legal claims. Where lawful, we assess requests and disclose no more than reasonably necessary.
10. International transfers
10.1 Locations. We and our providers may process Personal Data in the United Kingdom, the European Economic Area and other countries where we or they operate. Those countries may have different data protection laws.
10.2 UK transfers. For a restricted transfer from the United Kingdom, we use UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the European Commission Standard Contractual Clauses, or another permitted safeguard or exception. Where a safeguard is used, we carry out any assessment and additional measures required by law.
10.3 EEA transfers. For a restricted transfer from the EEA, we use an adequacy decision, the European Commission Standard Contractual Clauses, binding corporate rules or another lawful mechanism, together with supplementary measures where required.
10.4 Further information. Information about the categories and locations of relevant subprocessors and applicable safeguards is available by contacting [email protected].
11. Retention and deletion
We retain Personal Data only for as long as reasonably necessary for the relevant purpose, including service delivery, security, legal compliance, dispute resolution and enforcement. We consider the amount, sensitivity, context and risk of the information, the customer's instructions and applicable limitation periods.
• Customer account and contract records — Subscription term, then normally six years for claims, audit and compliance.
• Customer Data — Subscription term plus at least 30 days for export; production copies are then deleted or anonymised and backup copies normally expire within 90 further days, unless law or a written agreement requires longer.
• Billing and tax records — Normally six years after the end of the relevant financial year, or longer if required by law.
• Security and audit logs — For the period reasonably required for security, fraud prevention, service integrity and investigation; retention varies with risk and log type.
• Sales enquiries and business contacts — While the relationship is active and afterwards for a reasonable business-development period, subject to objections and suppression requirements.
• Support records — For as long as needed to resolve the issue and maintain an appropriate service and legal record.
• Consent and suppression records — For as long as needed to demonstrate consent or ensure that an opt-out continues to be honoured.
Deletion from active systems does not always remove information immediately from immutable security records, legal holds or disaster-recovery backups. Access to retained copies is restricted and they are deleted, overwritten or anonymised according to the applicable cycle. We may retain de-identified information without time limit where it cannot reasonably be re-identified.
12. Security and incident response
12.1 Measures. We maintain technical and organisational measures appropriate to risk, including encryption in transit, access controls, role-based permissions, authentication safeguards, logging, monitoring, vulnerability and change management, secure development practices, provider diligence, backup controls and incident-response procedures.
12.2 Customer controls. Customers must configure roles and integrations appropriately, keep credentials confidential, apply device security, remove access promptly when no longer needed and notify us of suspected compromise. Security is a shared responsibility.
12.3 Limitations and response. No internet, mobile or storage system is completely secure. We cannot guarantee absolute security, but we investigate suspected incidents and make legally required notifications to affected customers, individuals and regulators.
12.4 Reporting. Security concerns should be reported promptly to [email protected] with enough information for investigation. Do not include unnecessary Personal Data or exploit a vulnerability beyond what is needed to demonstrate it.
13. Rights and privacy choices
13.1 Rights. Depending on location and applicable law, an individual may have rights to be informed; access Personal Data; correct inaccurate or incomplete data; request deletion; restrict processing; object to processing based on legitimate interests or direct marketing; receive portable data; withdraw consent; and obtain safeguards information for certain transfers.
13.2 How to exercise rights. For Personal Data controlled by UptoCRM, send a request to [email protected]. We may take reasonable steps to verify identity and authority, clarify scope, protect third-party rights and apply lawful exemptions. Authorised agents must provide evidence of authority where required.
13.3 Customer-controlled data. For Customer Data, direct the request to the UptoCRM customer that controls the workspace. If a request is sent to us, we may forward it to the customer and will assist as required.
13.4 Choices. A person may unsubscribe from marketing using the link in a message or by contacting us. Device permissions and notifications can be managed in device settings. Cookie preferences can be managed through the Site's consent tool.
13.5 Complaints. Individuals in the United Kingdom may complain to the Information Commissioner's Office at https://ico.org.uk. Individuals in the EEA may complain to their local supervisory authority. We encourage contacting us first so that we can try to resolve the issue.
14. Account and data deletion
Account deletion: Deleting or deactivating an account does not automatically cancel a subscription billed by Apple, Google or another marketplace. The subscription must be cancelled separately through the applicable marketplace account.
14.1 Request methods. Where account creation is available in an App, a user can initiate or request account deletion through the account settings or other deletion control made available in the App. A request can also be submitted outside the App by contacting [email protected] through the online version of this Policy.
14.2 Business accounts. A Company Member account is controlled by the customer's organisation. We may need to refer a deletion request to the customer's administrator, and the customer may retain business records for which it is the controller. UptoCRM will delete controller account data that it is not required to retain and will assist the customer with Customer Data.
14.3 Effect. On a valid deletion request, we delete or de-identify the account and associated UptoCRM-controlled data that is not required for law, security, fraud prevention, accounting, dispute resolution or protection of rights. Temporary deactivation is not treated as completed deletion. We will confirm completion or explain any lawful retention.
14.4 Third-party sign-in. If an account uses Sign in with Apple or another third-party login, we take the steps required by the relevant provider to revoke or disconnect the authentication token where applicable. The user may also need to manage the connection in the provider's settings.
15. Children
15.1 Age. The Site, Service and Apps are intended for organisations and business users aged 18 or over. They are not directed to children and are not designed for family or school use.
15.2 Notice. We do not knowingly collect Personal Data directly from a child as an account user. If such information has been supplied contrary to this Policy, contact [email protected]. Customer Data about a child remains the customer's responsibility, and the customer must have a lawful basis and appropriate safeguards.
16. Automation and artificial intelligence
16.1 Automation. The Service may apply customer-configured rules, timers, reminders, routing and template actions to records. The customer determines the configuration and is responsible for the content and effect of those actions.
16.2 Significant decisions. UptoCRM does not use controller Personal Data to make solely automated decisions that produce legal or similarly significant effects on individuals. If a customer configures processing that may have such an effect, the customer is responsible for meeting applicable transparency, lawful-basis, assessment and human-review requirements.
16.3 AI training. We do not use Customer Data to train general-purpose AI or machine-learning models. If a new AI-enabled feature materially changes processing, we will provide appropriate notice and update relevant contractual and marketplace disclosures before the feature processes Personal Data.
17. Additional regional disclosures
17.1 United Kingdom and European Economic Area
UK data protection law includes the UK GDPR, the Data Protection Act 2018 and relevant amendments made by the Data (Use and Access) Act 2025. EEA processing may also be subject to the EU GDPR and local law. Mandatory rights and protections apply notwithstanding any shorter description in this Policy.
17.2 United States state privacy laws
To the extent a United States state privacy law applies to UptoCRM, the categories collected in the preceding 12 months are those described in section 3; the sources are described in section 4; the business purposes are described in sections 5 to 8; and the recipient categories are described in section 9. We do not sell Personal Data for money and do not share Personal Data for cross-context behavioural advertising. We do not discriminate unlawfully against a person for exercising a privacy right.
Depending on the applicable state law, a resident may request access, correction, deletion or portability; opt out of sale, targeted advertising or qualifying profiling; appeal a decision; or use an authorised agent. Because we do not engage in sale or cross-context behavioural advertising, an opt-out may not change our current processing. Requests may be sent to the address in section 18.
17.3 Other jurisdictions
Where local law grants additional mandatory rights or requires a different legal basis, response period, consent standard or transfer mechanism, we apply that requirement to the relevant processing. Nothing in this Policy limits a non-waivable statutory right.
18. Changes and contact details
18.1 Changes. We may update this Policy to reflect changes in law, the Service, Apps, providers or processing practices. The online version will show the current effective date. We will provide additional notice of a material change where required, including by email, in-product message or marketplace update.
18.2 Privacy contact. Privacy questions and controller rights requests: [email protected].
18.3 Legal contact. Legal or security correspondence: [email protected].
18.4 Post. Postal address: UptoCRM Limited, 275 New North Road, Unit 3051, London, N1 7AA, United Kingdom.
18.5 Online. Website: https://uptocrm.com.