1. Who we are
ArabyCRM ("we", "us", "our") provides a multi-tenant CRM and invoicing service for small businesses. We act as the data controller for the account, marketing, billing, and security data we collect about you directly. We act as a data processor for the customer records, documents, and files you and your team add to your workspace (your "Customer Data").
2. Information we collect
We collect only the information we need to run the service:
- Account data: your name, work email, password hash (never stored in plaintext), profile photo, language preference, time zone, MFA enrollment status.
- Workspace settings and Customer Data your team adds: clients, contacts, deals, quotes, invoices, projects, tasks, notes, files, and signed documents.
- Billing metadata: chosen plan, subscription state, invoices we issue you, and the masked card or PayPal account identifiers our payment processor returns. We never see or store full payment-card numbers.
- Operational data: sign-in events, IP address and user agent for security review, audit log entries, queue job records, transactional email delivery receipts.
- Support data: messages you send to info@, security@, billing@ aliases and any attachments you include.
3. How we use this information
We use the data above to: (a) deliver the product features you and your team chose to use; (b) keep tenants isolated; (c) process signup, billing, plan changes, and dunning; (d) send operational emails (account verification, password reset, billing, security alerts) and customer-facing notifications you configure (reminders, invoices, quote follow-ups, document signing); (e) provide support; (f) detect and prevent abuse, fraud, and security incidents; and (g) improve reliability and performance through aggregated metrics and error logs.
4. Lawful bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on: (a) performance of a contract — to provide the service you signed up for; (b) legitimate interests — to keep the service secure, prevent abuse, and improve reliability, after balancing against your rights; (c) legal obligation — to keep records we are required to keep (for example, tax invoices); and (d) consent — for any optional non-essential cookies and for marketing email you explicitly opt in to.
5. Subprocessors and data sharing
We use a short list of trusted subprocessors to run ArabyCRM: Microsoft Azure (application hosting, managed PostgreSQL), Cloudflare R2 (file vault object storage), PayPal (subscription payments), Microsoft 365 SMTP via Office 365 (transactional email), Google OAuth and GitHub OAuth (optional social sign-in identity verification). A current list with each provider's role and processing region is published at /subprocessors. We do not sell personal data and we do not share Customer Data with third parties except (i) with the subprocessors listed above to operate the service, (ii) when you direct us to (for example, by configuring your own SMTP), or (iii) when required by law and we have validated the request.
6. Where data is stored
Production application servers, queues, and the primary database run on Microsoft Azure (West Europe region today). File Vault object storage runs on Cloudflare R2 with EU-located buckets where available. Transactional email is sent through Microsoft 365 SMTP infrastructure. Operational backups are stored in the same primary region with encryption at rest. We will update this section in advance if the primary region changes.
7. International transfers
Some of our subprocessors (for example PayPal, Cloudflare, Microsoft) operate global networks and may transfer data outside the country where your workspace is provisioned. Where the GDPR or UK GDPR applies, we rely on Standard Contractual Clauses (SCCs) and equivalent UK transfer mechanisms with each subprocessor, plus encryption in transit (TLS) and at rest.
8. Retention windows
We keep different categories of data for different periods:
- Active workspace data: kept while your account is active. You can edit, export, or delete records inside the product.
- Account audit logs: kept for 365 days by default (configurable per workspace between 30 and 3,650 days).
- Transactional email delivery logs: kept for 90 days by default (configurable per workspace between 7 and 3,650 days).
- Signed signup-intent records: discarded 1 day after completion.
- Billing and tax records: kept for at least 7 years where required by tax law, even after account closure.
- Operational backups: rolling 30 days, encrypted, then permanently overwritten.
- Workspace deletion: requested deletions are completed within 30 days across the live database, file storage, queues, and search indexes; backup copies are purged on the rolling backup schedule above.
9. Security
We protect data with TLS in transit, encryption at rest on managed Azure and Cloudflare storage, per-tenant authorisation checks on every request, audit logging of privileged actions, hashed passwords with modern KDFs, optional MFA on user accounts, and routine dependency and infrastructure updates. No system is perfectly secure; you remain responsible for choosing strong passwords, enabling MFA, and removing former teammates promptly.
10. Your rights
Depending on where you live you may have rights to access, rectify, port, restrict processing of, or delete personal data we hold about you. Workspace owners can perform most of these tasks directly from the product. For anything you cannot do in the UI, write to info@arabycrm.com (or privacy@arabycrm.com once that alias is provisioned) and we will respond within 30 days. You also have the right to lodge a complaint with the data protection authority in your country.
11. Cookies and similar technologies
ArabyCRM uses strictly necessary cookies for sign-in, session management, security (CSRF protection), and your language and theme preference. We do not use third-party advertising or cross-site tracking cookies, and we do not embed third-party analytics scripts on the marketing site or in the app. A cookie notice on first visit lets you acknowledge this; you can reset your choice from the footer link.
12. Breach notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected customers without undue delay and within 72 hours of becoming aware of it, where required under the GDPR or UK GDPR. The notice will describe what happened, the data categories affected, the steps we are taking, and what you can do.
13. Children
ArabyCRM is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided personal data to us, contact info@arabycrm.com and we will delete it.
14. Changes and contact
We will update this policy when the product, our subprocessors, or applicable law change. The "last updated" date at the top of the page reflects the most recent revision. Material changes are announced in-app or by email. Questions or requests? Write to info@arabycrm.com. A Data Processing Agreement (DPA) is available on request.