This is a starting template. It describes how the platform actually works, but it has not been reviewed by a lawyer for your jurisdiction. Have it checked before you rely on it.
Controller or processor?
It depends which data you mean, and the distinction matters.
For your account (the person who signed up, billing details, support conversations) we are the controller.
For the content inside your workspace (your leads, contacts, projects, invoices and the people named in them) you are the controller and we are the processor. We act on your instructions, and we do not decide what you collect or why.
Your rights
If you are in the UK, EU or another region with equivalent law, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to a particular use.
Requests go through one place: the data request form. We respond within 30 days.
If the data is inside someone else’s workspace (because your employer or a supplier put it there) we will pass your request to them, since they are the controller and only they can decide.
How we protect it
Every record belongs to exactly one workspace, and that boundary is enforced in the data layer on every request rather than filtered in the interface. Roles limit what each person can reach. Optional two-factor authentication and per-workspace IP rules are available, and significant changes are written to an audit log.
Transfers and sub-processors
We use a small number of vendors to run the service; they are listed on the sub-processors page and each is bound by contract.
A signed Data Processing Agreement is available on request.
Contact
Data-protection questions: privacy@example.com.