Placeholder — not the final document.
The wording below is a working outline of what the Privacy & Data Protection notice will cover. It has not been drafted or reviewed by a solicitor, and it is not the agreement you are entering into. It will be replaced in full by the drafted notice before the service is offered to paying customers.
CollaborativeBD
CollaborativeBD provides this customer relationship management service. The final notice will name the operating company, its registered address, its ICO registration number, and a contact point for data protection questions.
For the account holder's own details — the person who signs up, their name, email address and billing information — we are the data controller.
For the records a customer puts into their CRM — their companies, contacts, deals, notes and activity history — the customer is the controller and we are the processor, acting on their instructions. The final notice will set out the processing terms in full, including the data processing agreement that forms part of the contract.
Account and profile information: name, email address, organisation name, role, and preferences such as timezone and language.
Customer records: whatever the customer chooses to store about their own companies, contacts and deals.
Technical and security information: sign-in events, IP address, browser type, and the audit trail of changes made inside an account.
To provide the service, to keep it secure, to support customers who ask for help, to bill for it, and to meet our legal obligations. The final notice will set out the lawful basis for each of these separately.
Only the suppliers needed to run the service — hosting, the database, email delivery and payment processing — each under a contract that limits them to acting on our instructions. The final notice will list them by name, with the country each operates in.
The final notice will state the hosting region, the safeguards used for any transfer outside the UK and EEA, and the retention period for each category of data. Two retention rules are already fixed by the product itself: deleted records sit in a recycle bin for 90 days before being purged, and the audit trail of who changed what is kept for the life of the account.
Access, correction, erasure, restriction, portability, and objection, together with the right to complain to the Information Commissioner's Office. Where we act as processor, a request about CRM records goes to the customer who controls them, and we support them in answering it.
Data is encrypted in transit and at rest, access is controlled per user and per object, every account's data is isolated from every other account at the database level, and two-factor authentication is available to every user. The final notice will describe our breach notification commitments.
We will tell account holders before any material change takes effect. The final notice will carry a version number and an effective date.