Privacy policy

Last updated: 9 August 2026

This privacy policy applies to the PuroCRM service and related marketing website operated by PuroCRM Oy. It has been drafted in accordance with the EU General Data Protection Regulation (GDPR, 2016/679), the Finnish Data Protection Act (1050/2018) and Section 205 of the Finnish Act on Electronic Communications Services (917/2014, "TSL").

PuroCRM Oy processes personal data in two distinct roles, which are kept separate throughout this policy:

  • Controller (Role A) - when we process data relating to marketing-site visitors, registered users, tenant administrators, and contract and billing data.
  • Processor (Role B) - when our customer companies (tenants) store personal data about their own customers and marketing targets in PuroCRM. In those cases the tenant is the controller and PuroCRM Oy acts as a processor on the tenant's behalf (GDPR Art. 28).

1. Controller and contact details

PuroCRM Oy

Business ID: 3640952-9

Mailing address: Viereläntie 4 A, 90630 Oulu (no visiting address)

Website: purocrm.fi

Privacy contact: Juha-Pekka Teirikangas

Email: juha-pekka@purocrm.fi

Data Protection Officer (DPO): Juha-Pekka Teirikangas

DPO email: juha-pekka@purocrm.fi

The competent supervisory authority in Finland is the Office of the Data Protection Ombudsman (P.O. Box 800, FI-00531 Helsinki, tietosuoja@om.fi).

2. Scope of the register

The register is called the PuroCRM user and marketing register. It covers visitors to the public marketing site, contact enquiries and any newsletter communication, as well as registered tenant administrators and end-users, access rights, contract and billing data, and logs related to the secure operation of the service. The policy covers both self-service sign-up and sales-led onboarding.

3. Personal data processed

3.1 Marketing-site visitors

IP address, user agent and server logs; contact-form and partner-application fields (name, company, email, phone, message); language and appearance preferences stored in cookies. On contact and partner forms we use Cloudflare Turnstile bot protection, which may transfer IP address and device identifiers to Cloudflare to prevent spam. We also collect anonymous, aggregated page-view statistics (page path, date, device category, referrer domain and country derived from IP address). The IP address is used only transiently to determine the country and is never stored. These statistics cannot be linked to any individual visitor.

3.2 Registered users and tenant administrators

Name, email, bcrypt-hashed password, user role, multi-factor authentication (MFA) settings, language preference, account expiry date, invitation metadata (inviter ID and invitation timestamp), last sign-in time, and IP address / browser metadata associated with sign-ins.

3.3 Billing and contract data (at tenant level)

Billing name, business ID, billing address, postal code, city, country, billing method, contract-specific pricing, credit balance and usage-metering data (e.g. emails sent, AI usage). Contact-person details are personal data where they relate to natural persons.

3.4 Security and administration logs

Audit logs of user actions, webhook delivery logs, and usage logs of public-API keys.

3.5 Electronic-signature event data

Signer IP address, user agent and timestamp. The e-signature in PuroCRM is a technical evidence mechanism - it is not a qualified electronic signature within the meaning of the eIDAS Regulation and does not rely on strong identification. Suitable for light-weight B2B agreements; for material legal transactions we recommend a service that supports strong authentication.

3.6 Social media platform connections

When a tenant administrator connects a LinkedIn Company Page, a Facebook Page / Instagram account, or a TikTok account to PuroCRM, the connection is made through PuroCRM's own LinkedIn, Meta or TikTok application. For X publishing, the tenant connects their own developer application (the "bring your own app" model). We store the resulting OAuth access and refresh tokens encrypted at rest, together with the connected page/account identifier, display name, granted scopes and token expiry. These tokens are used solely to publish content the tenant schedules through PuroCRM to that platform. The connection can be revoked from the administrator settings, after which the tokens and associated identifiers are removed.

3.7 Mailbox connections (email assistant)

When a user connects their own Gmail or Zoho Mail mailbox to the PuroCRM email assistant via OAuth, we store the connection's access and refresh tokens encrypted at rest, together with the connected email address, the provider, the granted scopes, the token expiry, the sync cursor and (for Zoho) the folder identifiers the user has selected. The Gmail scopes cover reading, sending and modifying messages and managing labels and filters, and the Zoho scopes cover managing messages, folders and filters; they are used to fetch incoming messages, send replies the user approves, sort messages into folders/labels and - only when the user explicitly requests it - create provider-side filter rules (for example to block spam at the mailbox before it reaches PuroCRM). AI-generated reply drafts are retained until the user sends or discards them. The connection can be revoked from settings, after which the tokens and all associated triage items are deleted. The processing of incoming email content is described in section 11 (processor role).

3.8 Personal file-storage integration (Dropbox)

When a user connects their own Dropbox account to PuroCRM, we store that connection's access and refresh tokens encrypted at rest, together with the connected account's identifier and label (typically an email address or account name). The tokens are used only to operate the Dropbox connection authorised by the user and to perform user-confirmed file actions within the permissions granted to the application. We request permission to read basic account information, to read folder and file metadata, and to write files; we do not request permission to read the contents of files already stored in the Dropbox account.

A user can save their own filing instructions (filing actions), on the basis of which AI proposes a destination folder and filename. When such an instruction is saved, the AI is given the names of the connected account's folders down to three levels, so that the instruction can be matched to the right folder. The attachment's contents are fetched through the mailbox connection and sent to Dropbox only after the user has confirmed that individual filing action; see sections 7 and 11.

The Dropbox connection is personal to the user who created it. It can be revoked from settings, whereupon we revoke the authorisation at Dropbox and delete the stored tokens, the account identifiers and the filing actions associated with the connection. Files already transferred to Dropbox thereafter remain subject to the retention, deletion and other terms applicable to that Dropbox account.

For transparency, we also describe below three categories of data we process in our processor role (Role B): campaign-email tracking events; meeting audio uploaded from the mobile app together with the resulting transcript and AI summary; and the incoming email content processed by the email assistant. Responsibilities are described in section 11.

4. Purposes of processing and legal bases

The same data may relate to more than one purpose. The storing of cookies on a user's terminal device is additionally governed by Section 205 TSL (see separate Cookie Policy).

Purpose Data Legal basis Retention
Technical operation and security of the websiteIP address, user agent, server logsLegitimate interest (GDPR 6(1)(f))90 days
Handling contact enquiries, partner applications and demo requestsName, company, email, phone, messagePre-contractual steps (GDPR 6(1)(b)) or legitimate interest (GDPR 6(1)(f))12 months from the last contact
Spam and bot protection (Turnstile)IP address, device identifiers (to Cloudflare)Legitimate interest: preventing misuse of forms (GDPR 6(1)(f))Cloudflare's own retention periods
Self-service sign-up and tenant creationAdministrator name and email, company details, tenant dataPerformance of a contract (GDPR 6(1)(b))Duration of contract + 30 days
Sales-led onboardingContact persons, tenant dataPerformance of a contract (GDPR 6(1)(b))Duration of contract + 30 days
User account management and access controlName, email, password hash, role, MFA, sign-in metadataContract (GDPR 6(1)(b)); security (GDPR 6(1)(f))Active account + 30 days
Billing, usage metering and accountingBilling name, business ID, address, metering data, invoicesContract (GDPR 6(1)(b)); legal obligation (GDPR 6(1)(c); Finnish Accounting Act 2:10)6 years from the end of the financial year
Audit, webhook and API-usage logsUser actions, timestamps, technical identifiersLegitimate interest: traceability and security (GDPR 6(1)(f))12 months
Mailbox connection management (email assistant)Encrypted OAuth tokens, email address, scopes, sync metadataPerformance of a contract (GDPR 6(1)(b)); legitimate interest (GDPR 6(1)(f))Until the user disconnects the mailbox
AI triage of incoming email (processor role)Sender, subject and message body (up to 8,000 characters) transmitted to Vertex AI; the AI-generated summary, intent, priority, suggested actions, folder sorting and any AI-drafted reply (until sent or discarded) are stored; additionally, to display the conversation, the message's basic details (sender, recipients, subject, an extract of up to 500 characters, message identifiers, folder, direction) for the other messages in the same conversation, including sent repliesProcessed on the tenant's instructions under the tenant's legitimate interest (GDPR 6(1)(f))Default 90 days (tenant-configurable 7–365 days), then automatic deletion
User-confirmed filing of email attachments to a connected Dropbox accountEncrypted Dropbox connection tokens and account identifier; the filing instruction written by the user; for the folder and name proposal, the email's sender, subject and body (up to 8,000 characters), the attachment's filename, MIME type and size, and the names of the connected account's folders down to three levels are transmitted to Vertex AI; the contents of the attachment selected by the user solely to carry out the confirmed transferPerformance of the contract (GDPR 6(1)(b)) for the connection and its tokens. For the tenant's Customer Data we process as a processor under the tenant's documented instructions and the data processing agreement (DPA) (GDPR Art. 28); the tenant, as controller, determines its own basis under Articles 6 and, where applicable, 9 GDPRThe connection, its tokens and its filing actions: until the user deletes the action or disconnects. The transferred attachment contents are not stored in PuroCRM's database. The proposed file path and the folder listing are held briefly in a technical cache in order to perform the operation.
Opt-in marketing communicationsEmail, consent recordConsent (GDPR 6(1)(a), 7)Until consent is withdrawn
Strictly necessary session and security cookiespurocrm-session, XSRF-TOKEN, remember_web_*No cookie consent required (strict-necessity exemption, Section 205 TSL)See cookie policy
Language, theme and UI preference storagelocale, appearance, sidebar:stateConsent for terminal-device storage (Section 205 TSL)Up to 12 months
Anonymous website visitor statisticsAggregated page-view counts by page, date, device type, referrer domain and countryLegitimate interest: understanding marketing-site usage to improve the service (GDPR 6(1)(f))24 months

5. Sources of data

Data is primarily obtained directly from the data subject (use of the website, contact enquiries, sign-up, accepting an invitation) and from our customer companies (e.g. when a tenant administrator creates accounts for other users). Public company-information sources and commercial business-data providers (such as ProFinder) may be used to enrich company and contact-person data to the extent permitted by applicable law. Technical data is collected from the user's browser and device as part of the secure operation of the service.

6. Disclosures and transfers outside the EU/EEA

Sub-processors used by PuroCRM. We use carefully selected sub-processors. We have a data processing agreement (GDPR Art. 28) with each of them. Where such processing involves a transfer of personal data outside the EU/EEA, we use an applicable transfer mechanism under Chapter V GDPR: primarily a European Commission adequacy decision (GDPR Art. 45), such as the EU–US Data Privacy Framework, and otherwise appropriate safeguards under Article 46, such as the Commission's Standard Contractual Clauses (SCCs, GDPR 46(2)(c)) together with any required supplementary measures.

External services selected by the user or tenant. PuroCRM may also, at the explicit request of a user or tenant, transmit data to an external service that the user has connected themselves and whose account they control themselves. Such a recipient does not automatically become a sub-processor of PuroCRM merely because we provide a technical integration to it. The recipient's data-protection role and any subsequent processing depend on the relevant service, the account type and the relationship between the user or tenant and that service. These recipients are listed separately in the table further below.

Provider Purpose Location Transfer mechanism
DigitalOceanHosting (server + database)Germany (Frankfurt)No transfer outside EU/EEA
Mailgun (Sinch Email)Transactional and campaign emailsEU (api.eu.mailgun.net)No transfer outside EU/EEA
QuriiriSMS deliveryFinland (EU)No transfer outside EU/EEA
Google LLC (Vertex AI - Gemini text and image; Gmail API; Calendar API; Pub/Sub; Firebase Cloud Messaging)AI text and image generation; email ingestion, classification and summarization; calendar sync; mobile-app push notification delivery (Android)EU multi-region (eu); some APIs globalGoogle Cloud DPA + SCC
Anthropic PBC (Claude models via Google Cloud Vertex AI)AI text generation for the premium tier, served through Google Vertex AIEU multi-region (via Google Cloud)Served via Google Vertex AI; Anthropic receives no customer content under the Vertex terms
Apple Distribution International Ltd.Mobile-app push notification delivery to iOS devices (Apple Push Notification service)Ireland (EU); also USA within the Apple groupDPA + SCC
Zoho Corporation B.V.Mailbox access for the email assistant (only when a user has connected a Zoho Mail account)Per the connected region (EU region mail.zoho.eu available)DPA + SCC
ElevenLabs Inc.Meeting-audio transcription (Scribe v2)United StatesDPA + SCC
Brave Software Inc.News monitoring (Brave Search API)United StatesSCC; searches are by company name, not personal data
Cloudflare Inc.Turnstile bot protection on marketing formsUnited States / globalDPA + SCC
ProFinderB2B company data lookupFinlandNo transfer outside EU/EEA
Vainu Finland OyB2B company data lookupFinland (EU)No transfer outside EU/EEA
LinkedIn Ireland Unlimited CompanySocial media publishing (only when the tenant has connected a LinkedIn Company Page)Ireland (EU); intra-group also United StatesLinkedIn DPA + SCC (PuroCRM's LinkedIn app; tenant acts as controller for published content)
Meta Platforms Ireland Ltd. (Facebook, Instagram)Social media publishing (only when the tenant has connected a Facebook Page / Instagram account)Ireland (EU); intra-group also United StatesMeta DPA + SCC (PuroCRM's Meta app; tenant acts as controller for published content)
X Corp.Social media publishing (only when the tenant has connected an X app)United StatesDPA + SCC (tenant's own app, tenant acts as controller)
TikTok Technology Limited / TikTok Inc.Social media publishing (only when the tenant has connected a TikTok account)Ireland (EU) / United StatesTikTok DPA + SCC (PuroCRM's TikTok app; tenant acts as controller for published content)

Recipients selected by the user or tenant

The service below is not used as a sub-processor of PuroCRM; the user connects their own account to it and decides on each individual transfer separately.

Recipient Purpose and data Role Location / international processing
DropboxTransfer of user-confirmed email attachments to the Dropbox account connected by the user, and the information necessary to operate the OAuth connection (only where the user has connected a Dropbox account)External recipient selected by the user. Dropbox is not used as PuroCRM's sub-processor for CRM file storage in this feature. Dropbox's role depends on the account type: Dropbox states that it acts as controller for personal accounts (Basic, Plus, Professional) and as processor for a Dropbox Team customer's data.Dropbox states that for users outside North America the contracting entity, and the controller of personal accounts, is Dropbox International Unlimited Company (Ireland). Dropbox states that it may also process and transfer data outside the EU/EEA and that it relies, as applicable, on mechanisms including adequacy decisions, the EU–US Data Privacy Framework and Standard Contractual Clauses.

The statements above about Dropbox's role and transfer mechanisms are based on Dropbox's own published terms and privacy policy and are not a guarantee given by PuroCRM. Once a file has been transferred to Dropbox, its storage and subsequent processing are governed by the terms applicable to that Dropbox account.

Google does not use customer data submitted through Vertex AI to train or fine-tune its models without the customer's explicit instruction. We run Vertex AI in the EU multi-region (eu) so that both storage and AI processing take place within the EU, and we do not enable features that would send data outside that boundary (we use no global endpoint and no web-search or Google Search grounding). Claude (Anthropic) models are served through Vertex AI under the same EU processing terms.

7. Retention periods

We retain personal data only for as long as is necessary for the purposes described in this policy, for fulfilling our contract, for defending legal claims, or for complying with statutory obligations.

  • Audit logs: 12 months (automated scheduled deletion).
  • Raw meeting audio uploaded from the mobile app: 30 days (automated deletion). The transcript and AI summary remain under tenant control.
  • Email-assistant triage items: default 90 days (tenant-configurable 7–365 days), automatically deleted; removed immediately when the mailbox is disconnected. Full message bodies and attachment contents are not persistently stored; the message's basic details and an extract of up to 500 characters are retained to display the conversation, under the same retention period. Where a user uses attachment filing to a connected external file-storage service (see section 3.8), PuroCRM transiently processes the contents of the selected attachment only for as long as it takes to carry out the transfer, and sends it to the selected service only after the user has confirmed the filing action; the file is not retained in PuroCRM afterwards.
  • Accounting records: at least 6 years from the end of the financial year (Finnish Accounting Act 2:10).
  • Active user accounts: for the duration of the customer relationship. After that, data is deleted or anonymised within 30 days unless a statutory retention obligation applies.
  • Cookies: no longer than stated in the cookie policy.

Tenant CRM data, campaign-tracking events, transcripts and AI summaries processed by us in our processor role are retained in accordance with the tenant's instructions and the data processing agreement (DPA).

8. Rights of the data subject

Under the GDPR, the data subject has the right to:

  • obtain confirmation of whether their data is being processed and access the data (GDPR Art. 15);
  • request rectification of inaccurate data (GDPR Art. 16);
  • request erasure in certain circumstances (GDPR Art. 17);
  • request restriction of processing (GDPR Art. 18);
  • data portability (GDPR Art. 20);
  • object to processing based on legitimate interest or to direct marketing (GDPR Art. 21);
  • withdraw consent at any time (GDPR Art. 7(3));
  • lodge a complaint with the Office of the Data Protection Ombudsman (GDPR Art. 77).

PuroCRM offers signed-in users a GDPR export feature to download their own data in one operation. Other rights requests can be sent to juha-pekka@purocrm.fi. We respond without undue delay, and at the latest within one month (GDPR Art. 12(3)). Manual deletion is performed within 30 days. Erasure may be restricted insofar as retention remains necessary under accounting law or other legal claim (GDPR Art. 17(3)).

8.1 Account and app data deletion (mobile app)

The PuroCRM mobile app (Google Play application ID fi.purocrm.app) does not offer self-service sign-up. User accounts are created by the administrator of the customer organisation (tenant) through the web application. The mobile app collects the following data from you as a user:

  • User profile: name and email address.
  • Authentication token (Sanctum API token) stored in the device's secure storage (Keychain / EncryptedSharedPreferences).
  • Push notification device token (Firebase FCM token), if you opt in to notifications after signing in.
  • Meeting audio recordings and the transcripts + AI summaries derived from them, when you use the meeting-recording feature.
  • Email-assistant and AI-assistant content (incoming sales-email details, AI summaries, suggestions and chats) shown in the app when your tenant has enabled these features. If you allow push notifications, a notification may include the subject and AI summary of a sales email; notifications are delivered to your device via Firebase Cloud Messaging (Android) and the Apple Push Notification service (iOS).
  • Crash reports and diagnostics via Firebase Crashlytics (release builds only).
  • Offline write-queue entries that the app has not yet synchronised to the server.

How to request account and data deletion:

  1. Send an email to juha-pekka@purocrm.fi with the subject "Deletion request (PuroCRM mobile app)".
  2. Include in your message:
    • the email address of your account (the same one you use to sign in to the app);
    • whether you want to delete the entire account or only specific data types (e.g. meeting audio, push token, or crash reports).
  3. We will acknowledge receipt by email. Where necessary, we may ask you to verify your identity by replying from the email address registered to the account (GDPR Art. 12(6)).
  4. We carry out the deletion within 30 days at the latest. GDPR Art. 12(3) requires a response within one month.

What is deleted in response to a request: the user account, name and email, the FCM push token on our servers, the Crashlytics user identifier, the meeting audio associated with the account (unless it has already been removed under the 30-day automated retention rule), transcripts and summaries created by the account itself (unless the tenant, acting as controller, requires their retention), and the session token and offline write-queue stored on the device.

What may be retained and why:

  • Accounting and invoicing records for at least 6 years under the Finnish Accounting Act (KPL 2:10).
  • Audit logs for 12 months for traceability and security (GDPR Art. 6(1)(f)).
  • Anonymised usage statistics from which an individual cannot be identified.
  • Tenant-owned CRM data (company and contact registries, sales pipeline, meeting contexts). If you use the app through your employer's tenant, the tenant is the controller for this data, and the deletion request must be addressed directly to the tenant. See section 11.

If you only want to stop push notifications without deleting your account, simply sign out of the app - the FCM token is automatically removed from our servers at sign-out. Uploaded meeting audio is automatically deleted under the 30-day retention rule without a separate request.

9. Automated decision-making and profiling

PuroCRM does not make decisions about data subjects that are based solely on automated processing and that produce legal or similarly significant effects within the meaning of GDPR Art. 22. AI features produce drafts, suggestions, transcripts and summaries; all final decisions and approvals are made by a human.

10. Security

We protect personal data with appropriate technical and organisational measures proportionate to the risk (GDPR Art. 32), including:

  • HTTPS/TLS encryption for all data in transit;
  • bcrypt password hashing;
  • session cookies configured with HttpOnly and SameSite, and HTTPS enforced in production;
  • multi-factor authentication (MFA) for users who have enabled it;
  • role-based access control and logical tenant isolation;
  • audit logging of critical actions;
  • regular backups and restore testing.

Any personal-data breaches are reported to the supervisory authority and, where required, to data subjects in accordance with GDPR Art. 33–34.

11. PuroCRM Oy as a processor (Role B)

When a customer company (tenant) stores personal data of its own customers, leads or marketing targets in PuroCRM, the tenant is the controller and PuroCRM Oy is the processor under GDPR Art. 28. This includes tenant customer and contact records, sales-pipeline data, campaign-email open/click tracking, and meeting audio uploaded from the mobile app together with the resulting transcript and summary.

In these situations we do not own the data and do not determine the purposes of processing. We process the data only on the tenant's documented instructions, under a separate data processing agreement (DPA) that forms part of the service agreement.

If you are a data subject in the register of one of PuroCRM's customer companies and wish to exercise your rights concerning that data, please contact that company (the controller) in the first instance. PuroCRM assists tenants with rights requests in accordance with the DPA.

Campaign emails sent through PuroCRM may include open- and click-tracking using signed first-party tokens - no third-party cookies are used. Technical data stored may include the recipient's IP address, user agent, event type and timestamp. The obligation to inform recipients lies with the tenant as controller.

The email assistant processes messages arriving in a mailbox connected by a tenant's user as a processor on the tenant's behalf (GDPR Art. 28). The sender, subject and up to 8,000 characters of the body are transmitted to Google Vertex AI for classification and summarization; full message bodies and attachment contents are not persistently stored. We retain the AI-generated summary, intent, priority and suggested actions, and - in order to display the conversation - the message's basic details: sender and recipient (including cc) addresses, subject, an extract of up to 500 characters, message identifiers and reply-chain headers, the folder, the direction (incoming or outgoing) and whether attachments are present. The same basic details are stored for a reply the user sends at the moment it is sent, and - when the user opens a conversation - for the other messages in that conversation, so that the history can be shown without repeatedly querying the mailbox. On the tenant's behalf the AI may also sort messages into mailbox folders/labels, prepare draft replies (retained until the user sends or discards them) and, at the user's request, create mailbox filter rules to block spam. All outgoing replies require the user's approval (see section 9, no automated decision-making). Triage items and reply drafts are deleted automatically when the retention period expires (default 90 days) and immediately when the connection is removed. The tenant acts as controller and is responsible for informing the senders.

Filing attachments to an external file-storage service. A tenant may allow its authorised users to connect a personal file-storage connection to PuroCRM (see section 3.8). When an authorised user confirms the filing of an individual attachment, PuroCRM transiently processes the attachment's contents and transmits it on the tenant's behalf in accordance with that documented instruction. No transfer is made before the user's confirmation, and the contents of the attachment are not sent to the AI model.

In this feature PuroCRM does not use Dropbox as its own sub-processor for CRM file storage; it transmits the user-confirmed material to the Dropbox account connected by the user. Subsequent processing by Dropbox is governed by the terms and privacy arrangements applicable to that Dropbox account (see section 6). As controller, the tenant is responsible for ensuring that its users are entitled to make the disclosure and to use the selected recipient, and for its own legal basis for the processing. PuroCRM remains responsible for the lawfulness and security of its own processing.

The social media publishing feature forwards tenant-authored post content (text and attached images) to the platforms the tenant has selected. LinkedIn, Meta (Facebook/Instagram) and TikTok posts go through PuroCRM's own applications; X posts go through the tenant's own OAuth application. Images are made available from our public file storage at publication time so that the social platform can fetch them. We perform these actions on the tenant's documented instructions as a processor; the tenant, as controller, is responsible for the lawfulness of the published content and for compliance with each social platform's terms of service and developer agreements.

12. Cookies

PuroCRM primarily uses strictly necessary and limited functional first-party cookies. We do not use analytics or marketing cookies. On contact and partner-application forms we use Cloudflare Turnstile bot protection, which may set Cloudflare cookies or similar identifiers on those form pages to prevent spam. Full details, categories and retention periods are described in the separate Cookie Policy.

13. Changes to this policy

We may update this privacy policy when the service, our processing practices, our sub-processors, or applicable law change. We will notify users clearly on the website or in the service before any material change takes effect - in particular changes that affect data-subject rights, processing purposes, or transfer mechanisms. The updated version is published on this page with its date.