Privacy Policy
Last updated: 26 September 2026
This policy explains how Kasba CRM handles personal data.
1. Two roles
For our customers' account and billing information (name, email, phone, company, billing address, VAT number), we act as data controller. For the data our customers store in their CRM (their clients, agents, partner agencies and documents), our customer is the controller and we process it only on their instructions to provide the Service.
2. Data we collect about customers
- Account data: name, work email, phone, password (stored encrypted).
- Company and billing data: company name, address, country, VAT/TRN number, subscription and invoice history.
- Payment data: handled directly by our payment provider; we do not store full card numbers.
- Usage data: sign-in times and technical logs used for security.
3. Why we use it
To create and run your account, bill the subscription, provide support, keep the Service secure, and meet legal and accounting obligations. We do not sell personal data.
4. Sharing
We share data only with service providers that help us run the Service (hosting, email delivery, payment processing, AI document reading), under confidentiality and data-protection commitments, or when required by law.
5. Retention
Account data is kept while the subscription is active and then for the period required by accounting law. CRM data is deleted within 30 days after cancellation, after an export if requested.
6. Security
Data is encrypted in transit, access is restricted per role, and each developer's data is isolated from other customers.
7. Your rights
You may request access, correction, deletion or export of your personal data, or object to its processing, by contacting us through our website.
8. Changes
We may update this policy and will notify material changes by email or in the Service.