Privacy policy
Last updated: 24 September 2026
This privacy policy applies to the PuroCRM service and related marketing website operated by PuroCRM Oy. It has been drafted in accordance with the EU General Data Protection Regulation (GDPR, 2016/679), the Finnish Data Protection Act (1050/2018) and Section 205 of the Finnish Act on Electronic Communications Services (917/2014, "TSL").
PuroCRM Oy processes personal data in two distinct roles, which are kept separate throughout this policy:
- Controller (Role A) - when we process data relating to marketing-site visitors, registered users, tenant administrators, and contract and billing data.
- Processor (Role B) - when our customer companies (tenants) store personal data about their own customers and marketing targets in PuroCRM. In those cases the tenant is the controller and PuroCRM Oy acts as a processor on the tenant's behalf (GDPR Art. 28).
1. Controller and contact details
PuroCRM Oy
Business ID: 3640952-9
Mailing address: Viereläntie 4 A, 90630 Oulu (no visiting address)
Website: purocrm.fi
Privacy contact: Juha-Pekka Teirikangas
Email: juha-pekka@purocrm.fi
Data Protection Officer (DPO): Juha-Pekka Teirikangas
DPO email: juha-pekka@purocrm.fi
The competent supervisory authority in Finland is the Office of the Data Protection Ombudsman (P.O. Box 800, FI-00531 Helsinki, tietosuoja@om.fi).
2. Scope of the register
The register is called the PuroCRM user and marketing register. It covers visitors to the public marketing site, contact enquiries and any newsletter communication, as well as registered tenant administrators and end-users, access rights, contract and billing data, and logs related to the secure operation of the service. The policy covers both self-service sign-up and sales-led onboarding.
3. Personal data processed
3.1 Marketing-site visitors
IP address, user agent and server logs; contact-form and partner-application fields (name, company, email, phone, message); language and appearance preferences stored in cookies. On contact and partner forms we use Cloudflare Turnstile bot protection, which may transfer IP address and device identifiers to Cloudflare to prevent spam. We also collect anonymous, aggregated page-view statistics (page path, date, device category, referrer domain and country derived from IP address). The IP address is used only transiently to determine the country and is never stored. These statistics cannot be linked to any individual visitor.
On our marketing site we additionally use Leadfeeder visitor identification (role A: we are the controller in this respect; Leadfeeder's contracting entity is the processor). Leadfeeder's script stores the cookie _lfa and the LocalStorage values _lfa and _lfa_expiry on the terminal device and infers, from that identifier and the IP address, which company is visiting the site; the information returned to us is at company level (company name, domain, pages visited, visit duration). The script is third-party tracking, so it is loaded only after consent has been given (see section 3.4 of the Cookie Policy). On its own side Leadfeeder also processes device-level identifiers and IP addresses in order to produce the identification.
3.2 Registered users and tenant administrators
Name, email, bcrypt-hashed password, user role, multi-factor authentication (MFA) settings, language preference, account expiry date, invitation metadata (inviter ID and invitation timestamp), last sign-in time, and IP address / browser metadata associated with sign-ins.
3.3 Billing and contract data (at tenant level)
Billing name, business ID, billing address, postal code, city, country, billing method, contract-specific pricing, credit balance and usage-metering data (e.g. emails sent, AI usage). Contact-person details are personal data where they relate to natural persons.
3.4 Security and administration logs
Audit logs of user actions, webhook delivery logs, and usage logs of public-API keys.
3.5 Electronic-signature event data
Signer IP address, user agent and timestamp. The e-signature in PuroCRM is a technical evidence mechanism - it is not a qualified electronic signature within the meaning of the eIDAS Regulation and does not rely on strong identification. Suitable for light-weight B2B agreements; for material legal transactions we recommend a service that supports strong authentication.
3.6 Social media platform connections
When a tenant administrator connects a LinkedIn Company Page, a Facebook Page / Instagram account, or a TikTok account to PuroCRM, the connection is made through PuroCRM's own LinkedIn, Meta or TikTok application. For X publishing, the tenant connects their own developer application (the "bring your own app" model). We store the resulting OAuth access and refresh tokens encrypted at rest, together with the connected page/account identifier, display name, granted scopes and token expiry. These tokens are used solely to publish content the tenant schedules through PuroCRM to that platform. The connection can be revoked from the administrator settings, after which the tokens and associated identifiers are removed.
3.7 Mailbox connections (email assistant)
When a user connects their own Gmail or Zoho Mail mailbox to the PuroCRM email assistant via OAuth, we store the connection's access and refresh tokens encrypted at rest, together with the connected email address, the provider, the granted scopes, the token expiry, the sync cursor and (for Zoho) the folder identifiers the user has selected. The Gmail scopes cover reading, sending and modifying messages and managing labels and filters, and the Zoho scopes cover managing messages, folders and filters; they are used to fetch incoming messages, send replies the user approves, sort messages into folders/labels and - only when the user explicitly requests it - create provider-side filter rules (for example to block spam at the mailbox before it reaches PuroCRM). AI-generated reply drafts are retained until the user sends or discards them. The connection can be revoked from settings, after which the tokens and all associated triage items are deleted. The processing of incoming email content is described in section 11 (processor role).
3.8 Personal file-storage integration (Dropbox)
When a user connects their own Dropbox account to PuroCRM, we store that connection's access and refresh tokens encrypted at rest, together with the connected account's identifier and label (typically an email address or account name). The tokens are used only to operate the Dropbox connection authorised by the user and to perform user-confirmed file actions within the permissions granted to the application. We request permission to read basic account information, to read folder and file metadata, and to write files; we do not request permission to read the contents of files already stored in the Dropbox account.
A user can save their own filing instructions (filing actions), on the basis of which AI proposes a destination folder and filename. When such an instruction is saved, the AI is given the names of the connected account's folders down to three levels, so that the instruction can be matched to the right folder. The attachment's contents are fetched through the mailbox connection and sent to Dropbox only after the user has confirmed that individual filing action; see sections 7 and 11.
The Dropbox connection is personal to the user who created it. It can be revoked from settings, whereupon we revoke the authorisation at Dropbox and delete the stored tokens, the account identifiers and the filing actions associated with the connection. Files already transferred to Dropbox thereafter remain subject to the retention, deletion and other terms applicable to that Dropbox account.
3.9 Quote requests received into PuroCRM's own mailbox
PuroCRM operates a mailbox of its own into which our customer companies' quote requests can be directed. An incoming message is turned into a quote request for the correct tenant, and the handling leaves a log entry: the sender's and recipient's email address, the subject, the time of receipt, the message identifier and the outcome of processing (which tenant the message was matched to, whether a quote request was created, and any error message). The message body is not stored in this log. The log is necessary to confirm that a message arrived and was handled, and to diagnose processing failures. The log entry is deleted automatically after the period stated in section 7, and the message itself is moved to the mailbox's Trash at the same time. Any quote request created from the message is the tenant's customer data, which we process as a processor (section 11).
For transparency, we also describe below three categories of data we process in our processor role (Role B): campaign-email tracking events; meeting audio uploaded from the mobile app together with the resulting transcript and AI summary; and the incoming email content processed by the email assistant. Responsibilities are described in section 11.
4. Purposes of processing and legal bases
The same data may relate to more than one purpose. The storing of cookies on a user's terminal device is additionally governed by Section 205 TSL (see separate Cookie Policy).
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Technical operation and security of the website | IP address, user agent, server logs | Legitimate interest (GDPR 6(1)(f)) | 90 days |
| Handling contact enquiries, partner applications and demo requests | Name, company, email, phone, message | Pre-contractual steps (GDPR 6(1)(b)) or legitimate interest (GDPR 6(1)(f)) | 12 months from the last contact |
| Company-level visitor identification on the marketing site (Leadfeeder, role A) | The _lfa visitor id (cookie and LocalStorage) and the LocalStorage value _lfa_expiry set by Leadfeeder, and the IP address; the company-level information returned to us (name, domain, pages visited, visit duration) | Consent (Section 205 TSL; GDPR Art. 6(1)(a)). Not loaded before consent; withdrawal deletes the identifiers from the device and stops it loading | Leadfeeder retains visit data for as long as it is necessary for the purpose; on termination of the agreement the data is returned or deleted on our instructions (DPA). Leadfeeder does not publish a fixed period. The lifetimes of the terminal-device identifiers are listed in the Cookie Policy; the consent choice for 12 months |
| Spam and bot protection (Turnstile) | IP address, device identifiers (to Cloudflare) | Legitimate interest: preventing misuse of forms (GDPR 6(1)(f)) | Cloudflare's own retention periods |
| Self-service sign-up and tenant creation | Administrator name and email, company details, tenant data | Performance of a contract (GDPR 6(1)(b)) | Duration of contract + 30 days |
| Sales-led onboarding | Contact persons, tenant data | Performance of a contract (GDPR 6(1)(b)) | Duration of contract + 30 days |
| User account management and access control | Name, email, password hash, role, MFA, sign-in metadata | Contract (GDPR 6(1)(b)); security (GDPR 6(1)(f)) | Active account + 30 days |
| Billing, usage metering and accounting | Billing name, business ID, address, metering data, invoices | Contract (GDPR 6(1)(b)); legal obligation (GDPR 6(1)(c); Finnish Accounting Act 2:10) | 6 years from the end of the financial year |
| Audit, webhook and API-usage logs | User actions, timestamps, technical identifiers | Legitimate interest: traceability and security (GDPR 6(1)(f)) | 12 months |
| Mailbox connection management (email assistant) | Encrypted OAuth tokens, email address, scopes, sync metadata | Performance of a contract (GDPR 6(1)(b)); legitimate interest (GDPR 6(1)(f)) | Until the user disconnects the mailbox |
| AI triage of incoming email (processor role) | Sender, subject and message body (up to 8,000 characters) transmitted to Vertex AI; the AI-generated summary, intent, priority, suggested actions, folder sorting and any AI-drafted reply (until sent or discarded) are stored; additionally, to display the conversation, the message's basic details (sender, recipients, subject, an extract of up to 500 characters, message identifiers, folder, direction) for the other messages in the same conversation, including sent replies | Processed on the tenant's instructions under the tenant's legitimate interest (GDPR 6(1)(f)) | Default 180 days (tenant-configurable from 7 days to 5 years), then automatic deletion |
| Receiving quote requests into PuroCRM's own mailbox, and the log of how they were handled | The message's sender and recipient email address, subject, time of receipt, message identifier and the outcome of processing (which tenant the message was matched to, whether a quote request was created, and any error message). The message body is not stored in this log | Legitimate interest: confirming that messages arrived and diagnosing processing failures (GDPR 6(1)(f)) | 90 days, after which it is deleted automatically; the message itself is moved to the Trash of PuroCRM's mailbox at the same time, which Google empties within 30 days |
| User-confirmed filing of email attachments to a connected Dropbox account | Encrypted Dropbox connection tokens and account identifier; the filing instruction written by the user; for the folder and name proposal, the email's sender, subject and body (up to 8,000 characters), the attachment's filename, MIME type and size, and the names of the connected account's folders down to three levels are transmitted to Vertex AI; the contents of the attachment selected by the user solely to carry out the confirmed transfer | Performance of the contract (GDPR 6(1)(b)) for the connection and its tokens. For the tenant's Customer Data we process as a processor under the tenant's documented instructions and the data processing agreement (DPA) (GDPR Art. 28); the tenant, as controller, determines its own basis under Articles 6 and, where applicable, 9 GDPR | The connection, its tokens and its filing actions: until the user deletes the action or disconnects. The transferred attachment contents are not stored in PuroCRM's database. The proposed file path and the folder listing are held briefly in a technical cache in order to perform the operation. |
| Opt-in marketing communications | Email, consent record | Consent (GDPR 6(1)(a), 7) | Until consent is withdrawn |
| Strictly necessary session and security cookies | purocrm-session, XSRF-TOKEN, remember_web_* | No cookie consent required (strict-necessity exemption, Section 205 TSL) | See cookie policy |
| Language, theme and UI preference storage | locale, appearance, sidebar_state, ui_scale | No separate consent required (Section 205 TSL: a service the user has explicitly requested) | Up to 12 months |
| Anonymous website visitor statistics | Aggregated page-view counts by page, date, device type, referrer domain and country | Legitimate interest: understanding marketing-site usage to improve the service (GDPR 6(1)(f)) | 24 months |
| Application usage statistics | Aggregated view and action counts per customer organisation, day and device type (e.g. "sales pipeline opened 12 times"). No user identifier is stored, so the statistics cannot be linked to an individual user | Legitimate interest: understanding how the service is used in order to improve it (GDPR 6(1)(f)) | 24 months |
5. Sources of data
Data is primarily obtained directly from the data subject (use of the website, contact enquiries, sign-up, accepting an invitation) and from our customer companies (e.g. when a tenant administrator creates accounts for other users). Public company-information sources and commercial business-data providers (such as ProFinder) may be used to enrich company and contact-person data to the extent permitted by applicable law. Technical data is collected from the user's browser and device as part of the secure operation of the service.
6. Disclosures and transfers outside the EU/EEA
Sub-processors used by PuroCRM. We use carefully selected sub-processors. We have a data processing agreement (GDPR Art. 28) with each of them. Where such processing involves a transfer of personal data outside the EU/EEA, we use an applicable transfer mechanism under Chapter V GDPR: primarily a European Commission adequacy decision (GDPR Art. 45), such as the EU–US Data Privacy Framework, and otherwise appropriate safeguards under Article 46, such as the Commission's Standard Contractual Clauses (SCCs, GDPR 46(2)(c)) together with any required supplementary measures.
External services selected by the user or tenant. PuroCRM may also, at the explicit request of a user or tenant, transmit data to an external service that the user has connected themselves and whose account they control themselves. Such a recipient does not automatically become a sub-processor of PuroCRM merely because we provide a technical integration to it. The recipient's data-protection role and any subsequent processing depend on the relevant service, the account type and the relationship between the user or tenant and that service. These recipients are listed separately in the table further below.
| Provider | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| DigitalOcean | Hosting (server + database) | Germany (Frankfurt) | No transfer outside EU/EEA |
| Mailgun (Sinch Email) | Transactional and campaign emails | EU (api.eu.mailgun.net) | No transfer outside EU/EEA |
| Quriiri | SMS delivery | Finland (EU) | No transfer outside EU/EEA |
| Google LLC (Vertex AI - Gemini text and image; Gmail API; Calendar API; Pub/Sub; Firebase Cloud Messaging) | AI text and image generation; email ingestion, classification and summarization; calendar sync; mobile-app push notification delivery (Android) | EU multi-region (eu); some APIs global | Google Cloud DPA + SCC |
| Anthropic PBC (Claude models via Google Cloud Vertex AI) | AI text generation for the premium tier, served through Google Vertex AI | EU multi-region (via Google Cloud) | Served via Google Vertex AI; Anthropic receives no customer content under the Vertex terms |
| Apple Distribution International Ltd. | Mobile-app push notification delivery to iOS devices (Apple Push Notification service) | Ireland (EU); also USA within the Apple group | DPA + SCC |
| Zoho Corporation B.V. | Mailbox access for the email assistant (only when a user has connected a Zoho Mail account) | Per the connected region (EU region mail.zoho.eu available) | DPA + SCC |
| ElevenLabs Inc. | Meeting-audio transcription (Scribe v2) | United States | DPA + SCC |
| Spoke SAS (Meeting BaaS) | Meeting assistant: a bot participant joins a remote meeting (Google Meet or Microsoft Teams) and records the audio – only when a tenant user has invited the assistant. No video. The recording is deleted from the provider as soon as PuroCRM has fetched it | France (EU) | DPA; no transfer outside EU/EEA |
| Brave Software Inc. | News monitoring (Brave Search API) | United States | SCC; searches are by company name, not personal data |
| Cloudflare Inc. | Turnstile bot protection on marketing forms | United States / global | DPA + SCC |
| Leadfeeder (contracting entity as named in the Order) | Company-level visitor identification on our own marketing site (role A). We are the controller; Leadfeeder's contracting entity is the processor. Not used inside the PuroCRM service and not used in processing tenants' data | The processing agreement is Leadfeeder's Inside-EEA Data Processing Agreement (February 2026 version, GDPR Art. 28), which expressly covers the controller's website visitors and website traffic and metadata. Under that agreement processing takes place primarily in Germany, in an EU member state or in another EEA state. Leadfeeder's sub-processors (list dated 14 November 2025): Amazon Web Services (hosting, EU/EEA), Dealfront Finland Oy (Finland), Dealfront Germany GmbH (EU/EEA), and Google Cloud EMEA, OpenAI Ireland and Perplexity AI (USA) | The DPA also permits processing in third countries for certain features, subject to the requirements of Art. 44 et seq. GDPR, and obliges the processor to ensure a lawful transfer mechanism. Leadfeeder states that it uses the EU Standard Contractual Clauses or, where applicable, an adequacy decision (GDPR Art. 46); the US sub-processors named above are listed as covered by Standard Contractual Clauses (controller to processor). We have not yet received a breakdown from Leadfeeder of which sub-processors take part in visitor identification specifically. You can request further information about the safeguards from our privacy contact |
| ProFinder | B2B company data lookup | Finland | No transfer outside EU/EEA |
| Vainu Finland Oy | B2B company data lookup | Finland (EU) | No transfer outside EU/EEA |
| LinkedIn Ireland Unlimited Company | Social media publishing (only when the tenant has connected a LinkedIn Company Page) | Ireland (EU); intra-group also United States | LinkedIn DPA + SCC (PuroCRM's LinkedIn app; tenant acts as controller for published content) |
| Meta Platforms Ireland Ltd. (Facebook, Instagram) | Social media publishing (only when the tenant has connected a Facebook Page / Instagram account) | Ireland (EU); intra-group also United States | Meta DPA + SCC (PuroCRM's Meta app; tenant acts as controller for published content) |
| X Corp. | Social media publishing (only when the tenant has connected an X app) | United States | DPA + SCC (tenant's own app, tenant acts as controller) |
| TikTok Technology Limited / TikTok Inc. | Social media publishing (only when the tenant has connected a TikTok account) | Ireland (EU) / United States | TikTok DPA + SCC (PuroCRM's TikTok app; tenant acts as controller for published content) |
Recipients selected by the user or tenant
The services below are not used as sub-processors of PuroCRM; the user or the tenant connects their own account to them and controls it themselves.
| Recipient | Purpose and data | Role | Location / international processing |
|---|---|---|---|
| Leadfeeder (the tenant's own account) | Company-level visitor identification on the tenant's own website (role B). The tenant obtains its own Leadfeeder account and agreement, connects its own API key to PuroCRM and embeds the script on its own site. Using that key, PuroCRM fetches company-level visit data into the tenant's CRM; person-level fields are not imported (see section 11) | External service selected by the tenant. Leadfeeder is not used as a sub-processor of PuroCRM in this feature. The tenant is the controller both for visitor identification on its own site and for its Leadfeeder account, and is responsible for arranging its own cookie consent and transparency information | As determined by the agreement between the tenant and Leadfeeder; PuroCRM is not a party to that agreement |
| Dropbox | Transfer of user-confirmed email attachments to the Dropbox account connected by the user, and the information necessary to operate the OAuth connection (only where the user has connected a Dropbox account) | External recipient selected by the user. Dropbox is not used as PuroCRM's sub-processor for CRM file storage in this feature. Dropbox's role depends on the account type: Dropbox states that it acts as controller for personal accounts (Basic, Plus, Professional) and as processor for a Dropbox Team customer's data. | Dropbox states that for users outside North America the contracting entity, and the controller of personal accounts, is Dropbox International Unlimited Company (Ireland). Dropbox states that it may also process and transfer data outside the EU/EEA and that it relies, as applicable, on mechanisms including adequacy decisions, the EU–US Data Privacy Framework and Standard Contractual Clauses. |
| AI assistant over an MCP connection (e.g. ChatGPT, Claude; the user's own account) | Once the tenant has enabled the connection, a user can connect their own AI assistant to PuroCRM. The connection is read-only: at the user's request the assistant looks up companies, contacts and sales summaries, and the data retrieved passes to the assistant's provider through the user's account | External recipient selected by the user. The assistant's provider is not used as a sub-processor of PuroCRM; its role and terms are set by the agreement between the user or tenant and that provider. The tenant can disconnect the connection at any time, including for an individual user | As determined by the agreement between the user or tenant and the assistant's provider; PuroCRM is not a party to that agreement |
| Moontalk (the tenant's own phone system) | Once the tenant has connected the Moontalk integration, PuroCRM returns the caller's name and company for the number of an incoming call, and the phone system sends PuroCRM the state of the call and a summary made of it | External service selected by the tenant. Moontalk is not used as a sub-processor of PuroCRM in this feature; the tenant is the controller and is responsible for its own agreement with the provider | As determined by the agreement between the tenant and the provider; PuroCRM is not a party to that agreement |
The statements above about Dropbox's role and transfer mechanisms are based on Dropbox's own published terms and privacy policy and are not a guarantee given by PuroCRM. Once a file has been transferred to Dropbox, its storage and subsequent processing are governed by the terms applicable to that Dropbox account.
Google does not use customer data submitted through Vertex AI to train or fine-tune its models without the customer's explicit instruction. We run Vertex AI in the EU multi-region (eu) so that both storage and AI processing take place within the EU, and we do not enable features that would send data outside that boundary (we use no global endpoint and no web-search or Google Search grounding). Claude (Anthropic) models are served through Vertex AI under the same EU processing terms. For semantic search we compute text embeddings of reply-memory patterns and knowledge-base articles with Vertex AI's text-embedding model in an EU region (europe-west1); an embedding is a numeric vector from which the original text cannot be recovered, and it is stored in PuroCRM's own database under the same retention period and the same scoping as the record it describes.
7. Retention periods
We retain personal data only for as long as is necessary for the purposes described in this policy, for fulfilling our contract, for defending legal claims, or for complying with statutory obligations.
- Audit logs: 12 months (automated scheduled deletion).
- Raw meeting audio uploaded from the mobile app: 30 days (automated deletion). The transcript and AI summary remain under tenant control.
- Email-assistant triage items: default 180 days (tenant-configurable from 7 days to 5 years), automatically deleted; removed immediately when the mailbox is disconnected. Full message bodies and attachment contents are not persistently stored; the message's basic details and an extract of up to 500 characters are retained to display the conversation, under the same retention period. Reply-memory patterns and drafting guidelines (section 11): default 730 days from last use (tenant-configurable from 30 days to 5 years); the user can clear them at any time. Where a user uses attachment filing to a connected external file-storage service (see section 3.8), PuroCRM transiently processes the contents of the selected attachment only for as long as it takes to carry out the transfer, and sends it to the selected service only after the user has confirmed the filing action; the file is not retained in PuroCRM afterwards.
- Log of quote requests handled by PuroCRM's own mailbox: 90 days (automated deletion). The log holds the message's sender and recipient address, subject and processing outcome, not the message body. When the log entry is deleted, the message itself is moved to the Trash of PuroCRM's mailbox, which Google empties within 30 days. Any quote request created from the message is the tenant's CRM data and is retained under the tenant's own retention practice.
- Accounting records: at least 6 years from the end of the financial year (Finnish Accounting Act 2:10).
- Active user accounts: for the duration of the customer relationship. After that, data is deleted or anonymised within 30 days unless a statutory retention obligation applies.
- Cookies: no longer than stated in the cookie policy.
- Web events in a tenant's register: unidentified visits are deleted automatically after the retention period set by the tenant. Visits attributed to a company are the tenant's customer history and are retained as part of the tenant's CRM data until the tenant deletes them or the agreement ends - the automatic purge cycle does not touch them. They are also deleted when the company or the tenant in question is deleted.
Tenant CRM data, campaign-tracking events, transcripts and AI summaries processed by us in our processor role are retained in accordance with the tenant's instructions and the data processing agreement (DPA).
8. Rights of the data subject
Under the GDPR, the data subject has the right to:
- obtain confirmation of whether their data is being processed and access the data (GDPR Art. 15);
- request rectification of inaccurate data (GDPR Art. 16);
- request erasure in certain circumstances (GDPR Art. 17);
- request restriction of processing (GDPR Art. 18);
- data portability (GDPR Art. 20);
- object to processing based on legitimate interest or to direct marketing (GDPR Art. 21);
- withdraw consent at any time (GDPR Art. 7(3));
- lodge a complaint with the Office of the Data Protection Ombudsman (GDPR Art. 77).
PuroCRM offers signed-in users a GDPR export feature to download their own data in one operation. Other rights requests can be sent to juha-pekka@purocrm.fi. We respond without undue delay, and at the latest within one month (GDPR Art. 12(3)). Manual deletion is performed within 30 days. Erasure may be restricted insofar as retention remains necessary under accounting law or other legal claim (GDPR Art. 17(3)).
8.1 Account and app data deletion (mobile app)
The PuroCRM mobile app (Google Play application ID fi.purocrm.app) does not offer self-service sign-up. User accounts are created by the administrator of the customer organisation (tenant) through the web application. The mobile app collects the following data from you as a user:
- User profile: name and email address.
- Authentication token (Sanctum API token) stored in the device's secure storage (Keychain / EncryptedSharedPreferences).
- Push notification device token (Firebase FCM token), if you opt in to notifications after signing in.
- Meeting audio recordings and the transcripts + AI summaries derived from them, when you use the meeting-recording feature.
- Email-assistant and AI-assistant content (incoming sales-email details, AI summaries, suggestions and chats) shown in the app when your tenant has enabled these features. If you allow push notifications, a notification may include the subject and AI summary of a sales email; notifications are delivered to your device via Firebase Cloud Messaging (Android) and the Apple Push Notification service (iOS).
- Crash reports and diagnostics via Firebase Crashlytics (release builds only).
- Offline write-queue entries that the app has not yet synchronised to the server.
How to request account and data deletion:
- Send an email to juha-pekka@purocrm.fi with the subject "Deletion request (PuroCRM mobile app)".
- Include in your message:
- the email address of your account (the same one you use to sign in to the app);
- whether you want to delete the entire account or only specific data types (e.g. meeting audio, push token, or crash reports).
- We will acknowledge receipt by email. Where necessary, we may ask you to verify your identity by replying from the email address registered to the account (GDPR Art. 12(6)).
- We carry out the deletion within 30 days at the latest. GDPR Art. 12(3) requires a response within one month.
What is deleted in response to a request: the user account, name and email, the FCM push token on our servers, the Crashlytics user identifier, the meeting audio associated with the account (unless it has already been removed under the 30-day automated retention rule), transcripts and summaries created by the account itself (unless the tenant, acting as controller, requires their retention), and the session token and offline write-queue stored on the device.
What may be retained and why:
- Accounting and invoicing records for at least 6 years under the Finnish Accounting Act (KPL 2:10).
- Audit logs for 12 months for traceability and security (GDPR Art. 6(1)(f)).
- Anonymised usage statistics from which an individual cannot be identified.
- Tenant-owned CRM data (company and contact registries, sales pipeline, meeting contexts). If you use the app through your employer's tenant, the tenant is the controller for this data, and the deletion request must be addressed directly to the tenant. See section 11.
If you only want to stop push notifications without deleting your account, simply sign out of the app - the FCM token is automatically removed from our servers at sign-out. Uploaded meeting audio is automatically deleted under the 30-day retention rule without a separate request.
9. Automated decision-making and profiling
PuroCRM does not make decisions about data subjects that are based solely on automated processing and that produce legal or similarly significant effects within the meaning of GDPR Art. 22. AI features produce drafts, suggestions, transcripts and summaries; all final decisions and approvals are made by a human.
10. Security
We protect personal data with appropriate technical and organisational measures proportionate to the risk (GDPR Art. 32), including:
- HTTPS/TLS encryption for all data in transit;
- bcrypt password hashing;
- session cookies configured with
HttpOnlyandSameSite, and HTTPS enforced in production; - multi-factor authentication (MFA) for users who have enabled it;
- role-based access control and logical tenant isolation;
- audit logging of critical actions;
- regular backups and restore testing.
Any personal-data breaches are reported to the supervisory authority and, where required, to data subjects in accordance with GDPR Art. 33–34.
11. PuroCRM Oy as a processor (Role B)
When a customer company (tenant) stores personal data of its own customers, leads or marketing targets in PuroCRM, the tenant is the controller and PuroCRM Oy is the processor under GDPR Art. 28. This includes tenant customer and contact records, sales-pipeline data, campaign-email open/click tracking, and meeting audio uploaded from the mobile app together with the resulting transcript and summary.
In these situations we do not own the data and do not determine the purposes of processing. We process the data only on the tenant's documented instructions, under a separate data processing agreement (DPA) that forms part of the service agreement.
If you are a data subject in the register of one of PuroCRM's customer companies and wish to exercise your rights concerning that data, please contact that company (the controller) in the first instance. PuroCRM assists tenants with rights requests in accordance with the DPA.
Campaign emails sent through PuroCRM may include open- and click-tracking using signed first-party tokens - no third-party cookies are used. Technical data stored may include the recipient's IP address, user agent, event type and timestamp. The obligation to inform recipients lies with the tenant as controller.
The email assistant processes messages arriving in a mailbox connected by a tenant's user as a processor on the tenant's behalf (GDPR Art. 28). The sender, subject and up to 8,000 characters of the body are transmitted to Google Vertex AI for classification and summarization; full message bodies and attachment contents are not persistently stored. We retain the AI-generated summary, intent, priority and suggested actions, and - in order to display the conversation - the message's basic details: sender and recipient (including cc) addresses, subject, an extract of up to 500 characters, message identifiers and reply-chain headers, the folder, the direction (incoming or outgoing) and whether attachments are present. The same basic details are stored for a reply the user sends at the moment it is sent, and - when the user opens a conversation - for the other messages in that conversation, so that the history can be shown without repeatedly querying the mailbox. On the tenant's behalf the AI may also sort messages into mailbox folders/labels, prepare draft replies (retained until the user sends or discards them) and, at the user's request, create mailbox filter rules to block spam. All outgoing replies require the user's approval (see section 9, no automated decision-making). Triage items and reply drafts are deleted automatically when the retention period expires (default 180 days) and immediately when the connection is removed. Where the tenant enables reply memory, a reply the user wrote or edited themselves is distilled by AI into a generalised question–answer pattern (at most 600 + 1,500 characters) from which e-mail addresses, phone numbers, identifiers and names are removed before storage; the reply itself is not stored. Likewise, a short generalised drafting guideline (at most 120 + 400 characters) is formed when the user says why they rejected an AI-written draft or sends a draft after editing it: the draft, the user's reason or edited reply and the difference between them are passed to the AI de-identified but not stored – only the guideline is. The user can switch off either way of learning separately. The pattern is personal and never shown to other users; the user can switch the feature off and clear their memory at any time. Patterns are deleted once unused for the retention period (default 730 days, tenant-configurable from 30 days to 5 years) and when the user is deleted. The tenant acts as controller and is responsible for informing the senders.
Filing attachments to an external file-storage service. A tenant may allow its authorised users to connect a personal file-storage connection to PuroCRM (see section 3.8). When an authorised user confirms the filing of an individual attachment, PuroCRM transiently processes the attachment's contents and transmits it on the tenant's behalf in accordance with that documented instruction. No transfer is made before the user's confirmation, and the contents of the attachment are not sent to the AI model.
In this feature PuroCRM does not use Dropbox as its own sub-processor for CRM file storage; it transmits the user-confirmed material to the Dropbox account connected by the user. Subsequent processing by Dropbox is governed by the terms and privacy arrangements applicable to that Dropbox account (see section 6). As controller, the tenant is responsible for ensuring that its users are entitled to make the disclosure and to use the selected recipient, and for its own legal basis for the processing. PuroCRM remains responsible for the lawfulness and security of its own processing.
Website visits (visitor identification on the tenant's own site). A tenant may connect its own Leadfeeder account to PuroCRM and receive sales signals about the companies visiting its own website. The tenant is then the controller both for the tracking on its own site and for its own Leadfeeder account; PuroCRM processes the retrieved data as a processor under the tenant's instructions. The tenant is responsible for classifying the script correctly in the cookie consent of its own site so that it does not load before consent, and for informing that site's visitors.
The imported signal is at company level. We do not import person-level fields from Leadfeeder's response - a visitor's email address, name, cookie identifier and other analytics identifiers are not stored in PuroCRM at all; they are dropped as the API response is read. We store the company's name and domain, the pages visited, the time and duration of the visit, and the campaign source. If a visiting domain has no counterpart in the tenant's company register, it goes onto a separate worklist where a user of the tenant decides for themselves whether to link it, create a new company, or ignore it; adding a sole trader to the register is likewise the user's own decision there, for which the tenant is responsible as controller.
The social media publishing feature forwards tenant-authored post content (text and attached images) to the platforms the tenant has selected. LinkedIn, Meta (Facebook/Instagram) and TikTok posts go through PuroCRM's own applications; X posts go through the tenant's own OAuth application. Images are made available from our public file storage at publication time so that the social platform can fetch them. We perform these actions on the tenant's documented instructions as a processor; the tenant, as controller, is responsible for the lawfulness of the published content and for compliance with each social platform's terms of service and developer agreements.
12. Cookies
PuroCRM primarily uses strictly necessary and limited functional first-party cookies. Our site statistics are collected server-side without cookies. The marketing site additionally carries one consent-based third-party tracking technology, Leadfeeder visitor identification, which is not loaded before consent (section 3.1). On contact and partner-application forms we use Cloudflare Turnstile bot protection, which sets no cookies on our site but does disclose the visitor's IP address to Cloudflare to prevent spam. Full details, categories and retention periods are described in the separate Cookie Policy.
13. Changes to this policy
We may update this privacy policy when the service, our processing practices, our sub-processors, or applicable law change. We will notify users clearly on the website or in the service before any material change takes effect - in particular changes that affect data-subject rights, processing purposes, or transfer mechanisms. The updated version is published on this page with its date.