GDPR & Data Protection

Controller or processor?

It depends which data you mean, and the distinction matters.

For your account (the person who signed up, billing details, support conversations) we are the controller.

For the content inside your workspace (your leads, contacts, projects, invoices and the people named in them) you are the controller and we are the processor. We act on your instructions, and we do not decide what you collect or why.

Your rights

If you are in the UK, EU or another region with equivalent law, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to a particular use.

Requests go through one place: the data request form. We respond within 30 days.

If the data is inside someone else’s workspace (because your employer or a supplier put it there) we will pass your request to them, since they are the controller and only they can decide.

How we protect it

Every record belongs to exactly one workspace, and that boundary is enforced in the data layer on every request rather than filtered in the interface. Roles limit what each person can reach. Optional two-factor authentication and per-workspace IP rules are available, and significant changes are written to an audit log.

Transfers and sub-processors

We use a small number of vendors to run the service; they are listed on the sub-processors page and each is bound by contract.

A signed Data Processing Agreement is available on request.

Contact

Data-protection questions: privacy@example.com.

Give your team one place to work

Create a workspace, invite your team and import your first leads, all on the free plan.

No credit card required