Introduction
KudosCRM is committed to the EU and UK General Data Protection Regulation (GDPR). This page summarises how we support GDPR compliance for our customers and their users.
Our approach
- Roles: for the CRM data you upload, you're the controller and we're your processor; for your account data, we're the controller. See our Privacy Policy and Data Processing Agreement.
- Lawful processing: we process personal data on appropriate legal bases (such as contract, legitimate interests, and consent).
- DPA available: customers can enter into our GDPR Article 28 Data Processing Agreement — request a signed copy at [email protected].
- Sub-processor transparency: we publish our Sub-processors and give notice of changes.
- International transfers: where personal data is transferred outside the EEA/UK, we work to put appropriate safeguards (such as Standard Contractual Clauses) in place with our sub-processors.
- Breach notification: we are committed to notifying affected customers of personal-data breaches without undue delay, consistent with GDPR Articles 33–34.
- Security: appropriate technical and organisational measures — see our Security overview.
Your rights
Individuals can request access, rectification, erasure, restriction, portability, or object to processing. Email [email protected] and we'll respond within the timeframes the law requires. You also have the right to complain to your local supervisory authority.
Contact
Data Protection Officer: [email protected] · [email protected]