Legal & Data Protection

Privacy Policy & GDPR / CCPA Compliance

Last Updated: September 30, 2026 · Effective Date: January 1, 2026

1. Overview and System Boundaries

Glady CRM (“Glady”, “we”, “our”, or “the Platform”) respects your privacy and is committed to protecting your personal data and the data of your audience contacts. This Privacy Policy explains how we collect, process, store, and safeguard information when you use Glady CRM.

Data Ownership: You (the creator or brand workspace owner) maintain 100% legal ownership of your contacts, customer lists, notes, and deal history. Glady acts strictly as a Data Processor regarding your audience contacts, while acting as a Data Controller regarding your platform account credentials and billing records.

2. Categories of Data Collected

We process information categorized into distinct data classifications:

  • Account Credentials: Name, email address, password hashes (salted SHA-256 / bcrypt), workspace slugs, and billing customer references.
  • Audience Contacts: First name, last name, email addresses, phone numbers, social handles (Instagram, YouTube, Skool), and explicit consent preferences.
  • Commerce Data: Store order numbers, purchased items, total minor unit spend, and webhook reference IDs from connected commerce systems. Cardholder payment details are processed directly by PCI-DSS compliant providers (Stripe, PayPal) and are never stored in CRM databases.
  • Telemetry & Audit Logs: Cryptographic session tokens, IP addresses, browser user agents, and mutation timestamps.

3. Lawful Basis for Processing (GDPR Article 6)

We process personal data under the following lawful bases:

  • Contract Performance: Providing core CRM, workflow automations, and brand deal tracking services.
  • Consent: Sending email campaigns, SMS alerts, and marketing broadcasts only when contacts have granted explicit opt-in consent (consentEmail: true).
  • Legitimate Interests: Enforcing platform fraud detection, preventing abusive message velocities, and protecting system security.

4. Data Subject Rights (Portability & Erasure)

In accordance with GDPR (Articles 15–22) and the California Consumer Privacy Act (CCPA), you and your contacts possess guaranteed data rights:

Right to Data Portability

Export complete structured JSON archives of your contacts, timeline events, and brand deals via Privacy Settings or POST /api/v1/privacy/export.

Right to be Forgotten

Trigger irreversible cryptographic anonymization of contact PII across all databases via POST /api/v1/privacy/erase while preserving immutable financial audit requirements.

5. Security Operations & Encryption

All integration credentials (OAuth tokens, API secrets) are encrypted at rest using industry-standard AES-256-GCM. Outbound webhooks are cryptographically signed using HMAC-SHA256 signatures (X-Glady-Signature) to ensure data authenticity and tamper prevention.

6. Contact Data Protection Officer (DPO)

For legal inquiries, privacy concerns, or verification audits, contact our Data Protection Office at:

Glady CRM Privacy Office
Email: privacy@gladycrm.com
Address: Sellersalt Global Technologies, Contabo Infrastructure Zone