Privacy Policy for The Bell CRM
Effective Date: May 20, 2026
ChangeSales Oy (Business ID: 3306591-9), located in Helsinki, Finland ("we", "us", "our") operates The Bell CRM ("Service"). This Privacy Policy explains how we collect, use, and protect personal data when you use our Service. We are committed to GDPR compliance as a SaaS data controller for platform user data.
1. Who We Are
- ChangeSales Oy
- Business ID: 3306591-9
- Email: info@thebellcrm.eu
- Address: Helsinki, Finland
2. Data Controller vs Processor Clarification
- WE are the DATA CONTROLLER for your account data (name, email, billing info) and platform usage data.
- YOU are the DATA CONTROLLER for your customer data (persons, companies, deals in your CRM).
- Your customers' personal data is processed on your instructions as a SaaS processor. You must have your own Privacy Policy compliant with GDPR Article 13/14.
3. Data We Collect
3.1 Account & Usage Data (Controller)
- Registration: name, email, password hash
- Billing: payment info (via Stripe, we don't store cards)
- Usage: IP address, browser, timestamps, feature usage
- Support: emails, chat transcripts
3.2 Your Customer Data (Processor)
- Persons/Companies/Deals/Activities you enter
- Processed only on your instructions
- Never used for our marketing or sold to third parties
4. How We Use Your Data
- Account data: provide Service, billing, support, analytics
- Usage data: improve Service, detect abuse, GDPR compliance
- Customer data: store/retrieve per your CRM operations only
5. Legal Basis (GDPR Article 6)
- Contract: provide Service (Art 6(1)(b))
- Legitimate interest: service improvement, security (Art 6(1)(f))
- Consent: marketing emails (Art 6(1)(a), opt-out anytime)
6. Data Retention
- Account data: retained for 30 days post-termination, then permanently deleted. During this period data is retained for recovery purposes only and is not actively processed.
- Customer data (CRM records): deleted immediately upon account termination
- Usage logs: 12 months (security and compliance purposes)
7. Your Rights (GDPR Chapter 3)
Contact us at info@thebellcrm.eu to exercise:
- Access: get copy of your personal data
- Rectification: correct inaccurate data
- Erasure ("right to be forgotten"): delete account data
- Restriction: limit processing during disputes
- Portability: export account data in structured format
- Object: stop marketing emails (immediate)
Response time: 30 days maximum.
8. International Transfers
- Hosted in EU (Supabase EU servers)
- Third parties: Stripe (EU), SendGrid (US with EU SCCs)
- GDPR Standard Contractual Clauses for any non-EU transfers
9. Third Party Processors
- Supabase (database hosting, EU)
- Vercel (hosting, EU)
- SendGrid (email delivery, EU SCCs)
- Stripe (payments, EU)
- Clerk (authentication, EU)
All processors GDPR compliant with DPAs signed.
10. Security Measures
- Data encryption at rest (Supabase)
- TLS 1.3 for transmission
- Row Level Security (RLS) on all tables
- Regular backups (7 days retention)
- Activity monitoring & audit logs
11. Beta Program Specifics
- Beta data may be used for product improvement (anonymized)
- Full GDPR data deletion rights apply during Beta. Account data is retained for 30 days post-termination; CRM customer data is deleted immediately upon termination.
12. Automated Decision-Making
We do not use automated decision-making or profiling as defined under Article 22 of the GDPR. No decisions are made about you solely on the basis of automated processing.
13. Post-Deletion Communication
Once your account data has been deleted, we will not send you any further emails or communications related to The Bell CRM, unless you have separately and explicitly consented to being contacted after deletion.
14. Children's Privacy
Service not directed at children under 16. No knowing collection.
15. Changes to Policy
30 days advance notice via email or in-app notification. Continued use = acceptance.
16. Contact Information
- Privacy Contact: info@thebellcrm.eu
- Supervisory Authority: Finnish Data Protection Ombudsman
Last Updated: May 20, 2026