D3CRM LEGAL · VERSION 2026-10-08
Privacy Policy
This policy covers d3CRM’s public site and account service, and explains how we process website enquiries for the businesses that use our CRM.
Last updated: 8 October 2026. Effective when published; contractual terms require acceptance.
New account registration is not yet open. The operator’s identity, contact details, and processing locations will be published before registration opens.
Who decides how data is used
For account administration, service security, billing, and our own support, the operator named below decides the purposes of processing (a controller or, under Indian law, Data Fiduciary). For enquiries, notes, templates, and other workspace content, the customer business decides the purposes; we process its data under its instructions and the Data Processing Agreement. Agencies must have authority to act for their clients.
A connected website’s privacy notice governs its collection and use of your enquiry. Our notice does not replace that business’s notice or provide consent on its behalf.
What we collect and why
- Account and team details: name, email, password hash, email-verification status, workspace name, membership and role, invitation details, recovery tokens, and timestamps. These let us authenticate users, recover accounts, and control workspace access. See the separate Account Data Notice.
- Workspace content: form definitions and historical schema snapshots; submitted fields such as name, email, telephone, and message as chosen by the customer; a normalized contact email; notes, assignments, status, follow-up dates, reply templates, and saved views including saved search text. We store and display these to manage enquiries, generate customer-requested reports, and export CSV files.
- Enquiry context: sending website origin, browser user-agent, a hashed IP address, and, if supplied, landing page/referrer and campaign tags. We use these for abuse prevention and customer enquiry attribution. Stored context URLs omit query strings and fragments; paths and campaign values may still contain information, so customers must avoid personal data there.
- Service records: activity with actor/record IDs and change metadata, endpoint tests, hashed rate-limit identifiers, delivery jobs/status/errors, and request information handled by hosting or security providers. These support security, troubleshooting, and accountable workspace changes. Hashes and IDs can still be personal data.
- Billing and support: if billing is enabled, owner email, workspace name, Stripe customer/subscription/checkout identifiers and subscription status; if you contact us, your correspondence and necessary account context. We use these to administer the requested subscription and resolve requests. Payment-card entry is handled by Stripe; d3CRM does not store full card details.
We receive information from you, authorized workspace teammates, connected websites, billing events, and service providers. Avoid passwords, payment-card data, government IDs, health/biometric data, or other sensitive information in enquiry fields, notes, URLs, templates, or saved searches.
Purposes and legal grounds
Where Indian consent rules apply, we obtain specific consent for account details through the separate notice. Other processing must have an applicable lawful ground, including permitted voluntary provision or a legal requirement. Workspace customers are responsible for their own collection grounds and consent records.
Where the EU/EEA or UK rules apply, necessary account/service and billing processing is based on performing our agreement with you, or our legitimate interest in administering business accounts where the agreement is with your employer. Proportionate security, abuse prevention, and troubleshooting serve our legitimate interests in protecting the service and its users. Mandatory records and disclosures rely on legal obligations. Consent applies to processing for which we specifically request it. We do not replace consent with another ground simply because you withdraw it.
We do not sell personal data, share it for cross-context behavioural advertising, run targeted advertising, or use workspace content to train AI models. The app’s AI form workflow involves the agent you choose; we do not call an AI provider. Only copy information you are authorized to share into external tools. Assignment routing and same-email warnings assist work; d3CRM does not make legally significant automated decisions about individuals.
Who receives data and where
Authorized workspace members can access workspace records according to their roles; viewers can read and export. Owners can change access, and an agency that remains a member can access its client workspace. The operator may access necessary records for support, security, and legal duties under confidentiality controls.
- Hosting, database, and backup services: The actual providers will be disclosed before new registration opens.
- Resend, when email is enabled: recipient addresses and account/invitation links or notification messages. Enquiry alerts contain a form name and a dashboard link rather than the submitted answers. Read Resend’s privacy notice.
- Stripe, when billing is enabled: billing contact/workspace details and payment/subscription information. Stripe also has its own legal responsibilities. Read Stripe’s privacy notice.
- Customer-selected services: webhooks receive enquiry answers, attribution, and assignment metadata; downloaded CSVs and drafts opened in your email application leave d3CRM. The customer chooses and is responsible for those destinations.
Processing and authorized support locations: Locations will be disclosed before new registration opens. Providers may also process data in countries identified in their agreements. We disclose the relevant provider and transfer details on request.
Where a transfer needs specific safeguards, we must agree and implement them before the transfer, such as applicable EU Standard Contractual Clauses or a UK transfer instrument with the necessary assessment. This policy itself creates no transfer mechanism. Contact us before importing regulated data that requires these arrangements. We may disclose necessary records to comply with lawful requests, protect rights and security, or complete a business transfer subject to appropriate confidentiality and notice.
Cookies and public tools
d3CRM uses necessary authentication, CSRF protection, and callback cookies to sign you in securely. Login sessions last up to 30 days; the selected-workspace cookie can last up to one year. Blocking necessary cookies can prevent account access. You can clear cookies in your browser or sign out.
The app does not install advertising or optional analytics cookies. Its form snippets read current-page campaign parameters without persistent tracking cookies or browser storage. Demo interactions, campaign-link building, and checklist selections stay in page memory and reset on reload; normal requests to load these pages still reach the hosting provider. Connected customer websites and external billing/email tools have their own practices and notices.
Retention and deletion
We keep account details while needed to provide the account, then handle closure and erasure requests through the privacy contact. Customers must review and delete enquiries when no longer needed. Archiving a form, marking an enquiry as spam, cancelling billing, or removing a teammate does not erase the workspace’s stored records.
Owners/admins can delete an enquiry in the app. This removes its stored answers, notes, and linked delivery records; detached activity metadata remains. Activity, saved views, templates, and other workspace records have no automatic expiry in the current service. Workspace deletion and account closure require operator assistance. Expired invitation/recovery and rate-limit records may remain pending cleanup; an expiry time is an access limit, not an erasure date.
We assess retained metadata and provider/backup copies when handling erasure, stop using data no longer needed, and arrange deletion subject to narrow legal obligations. Retention depends on the active service purpose, the customer’s lawful instructions, security needs, backup lifecycle, and mandatory legal/accounting periods. We explain any exception and expected deletion timing. Successfully sent or skipped email-job bodies are cleared; webhook delivery payloads may remain until the enquiry or workspace is deleted. Copies already exported, emailed, or delivered to customer integrations require deletion at those destinations.
Security and incidents
The app hashes passwords, checks current membership, validates inputs, rate-limits requests, hashes configured IP identifiers, and encrypts queued email bodies and webhook secrets. These controls do not mean all stored fields are encrypted or that any system is risk-free. Infrastructure access, backups, encryption settings, monitoring, and incident response must also be maintained by the operator.
We investigate personal-data breaches, take containment measures, and notify affected customers, people, and authorities as applicable law requires. A service incident does not remove anyone’s statutory rights.
Your rights and complaint routes
Use the contact below to request access or a copy, correction, erasure, account closure, or withdrawal of consent. Tell us the account or connected website/form involved and the request; do not send unnecessary identity documents or other people’s records. We respond within applicable deadlines, explain refusals or lawful extensions, and do not penalize you for exercising rights. Authorized representatives can contact us with evidence of authority. For customer-controlled enquiries, we help the responsible business handle your request.
- India: DPDP access, correction/erasure, grievance, and nomination rights apply when their provisions commence. Contact our grievance contact first; if unresolved, use the Data Protection Board’s complaint process when available under the applicable provisions. Current applicable Indian remedies remain available. Official status and notices: MeitY’s DPDP publications.
- EU/EEA and UK: where applicable, you may also request restriction and portability, withdraw consent, and object to processing based on legitimate interests. You have the right to object to that processing, and an unconditional right to object to direct marketing. You can complain to your local EU/EEA supervisory authority or the UK ICO.
- California and other US states: where the relevant law covers the business and processing, you may have rights to know/access, correct, delete, obtain a portable copy, opt out of sale, sharing, targeted advertising or qualifying profiling, and limit certain sensitive-data uses. Our service does not carry out sale, advertising sharing, or targeted advertising, so there is no such activity to opt out of. Where required, we honor recognized preference signals for activities they cover. If your state provides an appeal, reply to a refusal with “Privacy appeal”; you can also contact the competent state regulator. See California’s regulator guidance.
- Other locations: mandatory local rights apply where the law covers our processing. Contact us to identify the applicable procedure; location alone does not establish that every privacy law applies.
Children and changes
d3CRM accounts are for adults aged 18 or older. The service is not intended to collect children’s data; customers must not knowingly use it for that purpose without a separately agreed lawful arrangement. Tell us if such data reaches the service so we can help restrict and remove it.
We publish a dated revision when practices change, notify account holders of material changes, and request new consent where required before new consent-dependent processing. A policy update does not silently expand a previous consent or waive mandatory rights.
Operator and privacy contact
The operator’s public contact details are pending. New registrations remain closed until these details are available.
If your enquiry was submitted on another business’s website, contact that business first: it decides how to use your enquiry. You can also contact the d3CRM operator for help identifying the responsible workspace. We verify identity and authority proportionately before disclosing, changing, or deleting records.