GDPR
Last updated: April 09, 2026
1. Introduction
PocketCRM ("we", "our", or "us") is committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) 2016/679 and the Finnish Data Protection Act (1050/2018). This page explains how we handle your data and your rights.
We process personal data only when necessary for providing our service, improving it, or when required by law. We do not sell your data to third parties.
If you are in the European Economic Area (EEA) or Finland, you have specific rights under GDPR. We describe these below.
2. Data Controller
The data controller responsible for your personal data is PocketCRM. We decide how and why your data is processed.
Contact
PocketCRM
Email: legal@pocketcrm.com
Data Protection Officer: dpo@pocketcrm.com
3. Legal Basis for Processing
We process your personal data only when we have a lawful basis under GDPR:
- Performance of a contract : To provide the service you signed up for (account, login, features).
- Consent : Where you have given clear consent (e.g. marketing, optional cookies).
- Legal obligation : When we must process data to comply with the law (e.g. tax, accounting).
- Legitimate interests : Where we have a legitimate interest that is not overridden by your rights (e.g. security, fraud prevention).
4. Data We Process
We may collect and process:
- Account data: name, email, password (hashed), and profile information you provide.
- Usage data: how you use the service (e.g. interactions, logs) to provide and improve the product.
- Technical data: IP address, browser type, device information for security and compatibility.
- Cookie data: as described in our cookie notice and data protection information.
Important: PocketCRM is designed so that you do not need to store your customers’ personal data in the system. Any data you choose to enter about your own customers remains your responsibility, and you must have a lawful basis for processing it under GDPR.
5. Your Rights Under GDPR
If you are in the EEA or Finland, you have the right to:
- Access : Request a copy of the personal data we hold about you.
- Rectification : Have inaccurate personal data corrected.
- Erasure : Request deletion of your personal data in certain circumstances.
- Restriction : Request that we limit how we use your data in certain cases.
- Data portability : Receive your data in a structured, machine readable format where applicable.
- Object : Object to processing based on legitimate interests or for direct marketing.
- Lodge a complaint : Complain to a supervisory authority (e.g. the Finnish Data Protection Ombudsman).
To exercise these rights, contact us at legal@pocketcrm.com or via the contact details below. We will respond within the time limits set by GDPR.
6. Data Retention
We retain your data only for as long as necessary to provide the service, comply with legal obligations, or resolve disputes. When you delete your account, we delete or anonymise your personal data in line with our retention policy and GDPR.
7. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse, in line with GDPR requirements.
8. International Transfers
Your data may be processed in the EU/EEA. If we use services outside the EEA, we ensure appropriate safeguards (e.g. adequacy decisions or standard contractual clauses) as required by GDPR.
9. Changes to This Information
We may update this GDPR information from time to time. We will indicate the last updated date at the top. Continued use of the service after changes constitutes acceptance of the updated information.
10. Contact and Supervisory Authority
For any request or question regarding your personal data or this page, please contact us:
PocketCRM
Email: legal@pocketcrm.com
Data Protection Officer: dpo@pocketcrm.com
You may also contact your local data protection supervisory authority. In Finland: Office of the Data Protection Ombudsman, tietosuoja.fi (Finland).