Privacy Policy

Effective Date: 10 August 2026
Last Updated: 10 August 2026

1. Who We Are

CRMsynQ is a product of Logical Pure Minds SRL ("CRMsynQ", "we", "us", "our"), a company registered in Romania under company registration number RO43302770, with its registered office at:

Strada Lazăr Vicol, nr. 15, bl. E37, sc. A, ap. 47
Suceava 720245
Romania

You can reach us about anything in this policy at privacy@crmsynq.com.

This Privacy Policy explains what personal data we handle, why, and what rights you have. It applies to our website at crmsynq.com and to the CRMsynQ application at app.crmsynq.com (together, the "Service").

2. What CRMsynQ Does

CRMsynQ keeps CRM records up to date with information from LinkedIn profiles. In short:

  1. You connect your CRM (for example, HubSpot) to CRMsynQ.
  2. You tell us which CRM field holds the LinkedIn profile URL for your contacts.
  3. You create one or more sync schedules. Each schedule has its own filter (which contacts it covers) and its own frequency — for example, every 10 days, monthly, or annually.
  4. You define a field mapping: which profile fields are written into which CRM fields.
  5. On each run, we retrieve profile information for the contacts your filter selects and write the mapped fields back into your CRM.
  6. We keep a record of what changed so you can review before/after values in the Results section.

Understanding this flow matters, because it determines who is responsible for what under data protection law.

3. Our Two Roles: Controller and Processor

We handle two distinct categories of personal data, and our legal role differs for each.

3.1 Account Data — we are the controller

This is data about you, our customer: the person who signs up, pays, and configures the Service. We decide how this data is used, so we are the data controller for it.

3.2 Contact Data — we are the processor

This is data about the people in your CRM — your contacts, leads, candidates, and prospects. You decide which contacts are synced, which fields are updated, and how often. You are the data controller for this data; we act as your data processor and process it only on your documented instructions.

This means:

  • We do not use Contact Data for our own purposes.
  • We do not sell, rent, or license Contact Data.
  • We do not use Contact Data to train machine learning models.
  • We do not use Contact Data to build or enrich any independent database or data product.
  • We do not combine Contact Data across customers.

Our processing of Contact Data is governed by our Data Processing Agreement (DPA), available at https://crmsynq.com/dpa. If you are subject to the GDPR or UK GDPR, the DPA forms part of your agreement with us and takes precedence over this policy in respect of Contact Data.

If you are an individual whose data appears in a CRMsynQ customer's CRM, please read Section 8 — it is written for you.

4. Information We Collect

4.1 Information you give us

DataPurpose
Name, business email address, company nameCreating and administering your account
Billing name, billing address, VAT/tax IDInvoicing and tax compliance
Payment card detailsHandled entirely by Stripe — see 4.5. We never see or store full card numbers.
Support correspondenceAnswering your questions and improving the Service

4.2 CRM authorisation and data

When you connect your CRM, we use OAuth. We receive and store an access token and a refresh token. We never ask for, receive, or store your CRM password. You can revoke our access at any time from your CRM's connected-apps settings, and revocation takes effect immediately.

Once connected, we read from your CRM only what is needed to run your schedules:

  • The contact records matched by your schedule filters.
  • The CRM field you designated as holding the LinkedIn profile URL.
  • The destination fields you selected in your field mapping, so we can compare current values against new ones and avoid writing redundant updates.
  • Object and property metadata (field names and types), so we can present the field-mapping interface.

We write back only the fields you explicitly mapped. We do not write to unmapped fields, we do not create new contact records, and we do not delete contact records.

For performance and to make change history reviewable, we cache the values of the mapped fields and the LinkedIn URL. See Section 11 for how long.

4.3 Profile information from third-party data providers

For each contact you select, we retrieve information associated with the LinkedIn profile URL stored in your CRM. Depending on your field mapping, this may include name, current job title, current employer, location, industry, profile headline, profile photo URL, and other profile fields you choose to map.

How we obtain this data. We do not collect this information ourselves. We obtain it from specialist third-party data providers — Bright Data, Datagma, and Findymail — which supply publicly available professional profile information. Each provider is responsible for the lawfulness of its own collection practices and is engaged under a written agreement covering data protection. Which provider is used for a given lookup depends on availability and coverage.

Retrieved profile information is written into your CRM and, from that point, is subject to your CRM's own privacy practices and your own retention decisions.

4.4 Information collected automatically

When you use the Service, we collect IP address, approximate location derived from IP, device and browser type, operating system, referring page, timestamps, and records of actions you take in the application — for example, creating a schedule or changing a field mapping. We use this for security, abuse prevention, debugging, and understanding how the Service is used.

We also generate operational logs of sync runs: which schedule ran, when, how many records it covered, and whether it succeeded.

4.5 Payments

Payments are processed by Stripe Payments Europe, Ltd. Your card details go directly to Stripe and are never transmitted to or stored on our systems. We receive only what we need to reconcile your account: the last four digits, card brand, expiry, and transaction outcome. Stripe's privacy policy governs its handling of your payment data.

5. Legal Bases for Processing

If you are in the EEA, UK, or Switzerland, we rely on the following legal bases:

ProcessingLegal basis
Providing the Service, managing your account, billingPerformance of a contract (Art. 6(1)(b))
Security, fraud and abuse prevention, service improvement, product analyticsLegitimate interests (Art. 6(1)(f))
Non-essential cookies and marketing communicationsConsent (Art. 6(1)(a))
Tax and accounting records, responding to lawful requestsLegal obligation (Art. 6(1)(c))
Processing Contact Data on your behalfWe act as processor on your instructions; you are responsible for establishing the legal basis, typically your legitimate interests under Art. 6(1)(f)

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object at any time — see Section 12.

6. How We Use Information

We use Account Data and usage information to:

  • Create, authenticate, and administer your account.
  • Run the sync schedules you configure and show you the results.
  • Bill you and maintain financial records.
  • Provide customer support.
  • Monitor and improve reliability, performance, and security.
  • Detect, investigate, and prevent fraud, abuse, and violations of our terms.
  • Send service and account notifications — a failed sync, an expiring authorisation, a change to these terms. You cannot opt out of essential service notifications while you hold an account.
  • Send product news and marketing, where you have consented or where permitted by law. Every marketing message includes an unsubscribe link.
  • Comply with legal obligations and respond to lawful requests from authorities.

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes. We do not use Contact Data for any purpose other than delivering the Service to the customer it belongs to.

7. Sensitive and Special Category Data

CRMsynQ is designed to sync ordinary business contact information — names, job titles, employers, and locations.

We do not intentionally collect special categories of personal data as defined in Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation.

However, free-text profile fields such as headlines and summaries can incidentally contain such information — for example, a person describing voluntary work for a religious, political, or advocacy organisation. Because of this:

  • You choose which profile fields are mapped. Free-text fields such as headlines and summaries carry the greatest risk of incidental sensitive data, so consider them carefully before mapping them.
  • You must not configure CRMsynQ to write data into CRM fields designated for sensitive data, and you must not use the Service to deliberately collect special category data. Where your CRM provider imposes additional restrictions on sensitive data — such as HubSpot's Sensitive Data Terms — you remain responsible for compliance, and configuring CRMsynQ in a way that breaches them is also a breach of our terms.

CRMsynQ is not designed or approved for use with protected health information, financial account numbers, government identifiers, or any other regulated category of data.

8. Notice to Contacts (People Whose Data We Process on Behalf of a Customer)

If your details appear in the CRM of a business that uses CRMsynQ, we may process information about you even though you have never signed up with us. This section explains what that means.

What we do. At our customer's instruction and on their schedule, we retrieve information associated with the LinkedIn profile URL that our customer already holds for you, and write selected fields into their CRM record for you. We obtain that information from the third-party data providers named in Section 4.3. We do not contact you, market to you, or build a profile of you for our own purposes.

Who is responsible. The business whose CRM holds your record is the data controller. We act only as their processor. Decisions about whether to hold your data, how long to keep it, and what to do with it are theirs.

Your rights. Requests to access, correct, or delete your data, or to object to processing, should be directed to that business. If you contact us instead, we will pass your request to the relevant customer without undue delay and support them in responding, but we are generally not permitted to act on your data without their instruction.

If you don't know which business holds your data, write to privacy@crmsynq.com and we will help identify it where we reasonably can.

Suppression. If you would prefer that CRMsynQ not process your profile information for any customer, contact privacy@crmsynq.com and we will add you to our suppression list. This prevents future syncs but does not delete data already written into a customer's CRM — only that customer can do that.

You also have the right to lodge a complaint with a supervisory authority — see Section 12.

9. Sharing and Sub-processors

We share personal data only with service providers who help us operate the Service, and only to the extent needed. Each is bound by a written contract requiring confidentiality and appropriate safeguards, and each is prohibited from using the data for its own purposes.

Sub-processorPurposeEntity location
DigitalOcean, LLCApplication hosting, databases, and storageData hosted in the EU; company established in the United States
Stripe Payments Europe, Ltd.Payment and subscription processingIreland (with US affiliate)
Brevo (Sendinblue SAS)Transactional and service emailsFrance
Bright Data Ltd.Retrieval of publicly available professional profile informationIsrael
DatagmaRetrieval of publicly available professional profile informationFrance
FindymailRetrieval of publicly available professional profile informationFrance
Google Ireland Ltd.Website analytics and tag managementIreland (with US affiliate)

An up-to-date list is maintained at https://crmsynq.com/sub-processors. Customers may subscribe to notifications of changes to this list as described in our DPA. We will give at least 30 days' notice before adding a new sub-processor that processes Contact Data, during which you may object.

We may also disclose personal data:

  • To comply with the law — in response to a subpoena, court order, or other lawful request, or to establish, exercise, or defend legal claims. Where legally permitted, we will notify the affected customer first.
  • In a corporate transaction — if we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected customers, and any acquirer will remain bound by this policy or provide notice before materially changing it.

10. International Transfers

Our application, databases, and backups are hosted on DigitalOcean infrastructure located in the European Union. Contact Data is stored in the EU.

Some of our sub-processors are established outside the EEA:

  • Israel (Bright Data) — the European Commission has issued an adequacy decision for Israel, so no additional safeguards are required.
  • United States (DigitalOcean's parent entity, Stripe's and Google's US affiliates) — we rely on the European Commission's Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the recipient is certified, supported by technical measures including encryption in transit and at rest.

A copy of the relevant safeguards is available on request at privacy@crmsynq.com.

11. Data Retention

DataRetention period
Account data (name, email, settings)For the life of your account, then deleted within 30 days of account closure
OAuth tokensUntil you disconnect the CRM or close your account, then deleted immediately
Cached CRM field values30 days after the sync run that produced them
Sync change history (before/after values)12 months, or a shorter period you configure in your account settings
Operational and security logs12 months
Billing and invoice records10 years, as required by Romanian accounting and tax law
Support correspondence24 months after the ticket is closed

Deleting change history. You can delete change history for a schedule, or for individual contacts, from within the application at any time.

On account closure, we delete or irreversibly anonymise your data within 30 days, except where we are legally required to retain it — principally billing records.

12. Your Rights

Depending on where you live, you may have the following rights over your personal data:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct data that is inaccurate or incomplete.
  • Erasure — ask us to delete your data, where no legal ground requires us to keep it.
  • Restriction — ask us to limit how we use your data while a dispute is resolved.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
  • No automated decision-making — we do not make decisions producing legal or similarly significant effects about you by automated means alone.

How to exercise them. Most account information can be viewed and changed by signing in to CRMsynQ. Otherwise, email privacy@crmsynq.com. We will respond within 30 days; where a request is complex we may extend by a further two months and will tell you if we do. We may need to verify your identity first. We do not charge for these requests unless they are manifestly unfounded or excessive.

Complaints. If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data protection supervisory authority. Our lead supervisory authority is the Romanian Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania — www.dataprotection.ro. We would appreciate the chance to address your concern first.

California residents

If you are a California resident, you have rights under the CCPA/CPRA to know what personal information we collect, to request its deletion or correction, to opt out of sale or sharing, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA, and have not done so in the preceding twelve months. With respect to Contact Data, we act as a service provider and process personal information solely to perform the services specified in our contract with our customer. Requests can be made to privacy@crmsynq.com. Authorised agents may submit requests with proof of authorisation.

13. Security

We maintain administrative, technical, and physical safeguards designed to protect personal data against loss, misuse, and unauthorised access, disclosure, alteration, or destruction. These include:

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control and least-privilege access for staff, with access to production data limited to personnel who require it.
  • Audit logging of access to production systems.
  • Regular patching and dependency monitoring.
  • Confidentiality obligations for all personnel and contractors.

No system is completely secure. While we work to protect your information using commercially reasonable measures, we cannot guarantee absolute security.

Breach notification. If a personal data breach affecting your data occurs, we will notify you without undue delay and, where we act as processor, in time for you to meet your own notification obligations — in any event within 72 hours of becoming aware of it, as set out in our DPA.

14. Cookies and Tracking

We use cookies and similar technologies on crmsynq.com and app.crmsynq.com.

  • Strictly necessary cookies keep you signed in and maintain your session. These cannot be disabled and do not require consent.
  • Analytics and performance cookies help us understand how the Service is used.

Analytics cookies are set only after you consent via our cookie banner. You can change or withdraw your preferences at any time via the Cookie Settings link in our footer. Most browsers also allow you to block or delete cookies, though blocking strictly necessary cookies will prevent the Service from working.

Third parties that set cookies through our site do so under their own privacy policies, which we encourage you to review. A full list of the cookies we use is available at https://crmsynq.com/cookie-policy.

We do not currently respond to Do Not Track browser signals. We do honour Global Privacy Control signals where legally required.

15. Third-Party Sites and Features

Our website links to third-party sites and includes social media features. These are not covered by this policy. We do not control the cookies or data collection practices of those third parties, and we encourage you to read their privacy policies.

16. Testimonials

We publish customer testimonials on our website, which may include a name and company. We obtain consent before publishing. To have your testimonial removed, email privacy@crmsynq.com.

17. Children

The Service is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@crmsynq.com and we will delete it.

18. Changes to This Policy

We may update this policy from time to time. When we do, we will revise the "Last Updated" date above. If the changes are material, we will notify account holders by email or through an in-app notice at least 30 days before they take effect. Continuing to use the Service after that date constitutes acceptance.

Previous versions are available on request.

19. Contact Us

Questions, requests, or complaints about this policy or your personal data:

Logical Pure Minds SRL
Strada Lazăr Vicol, nr. 15, bl. E37, sc. A, ap. 47
Suceava 720245, Romania
Email: privacy@crmsynq.com

Related documents: Terms and Conditions · Data Processing Agreement · Sub-processors · Cookie Policy

Start your free trial

Get your first 50 automatic updates for free
Try CRMsynQ
No credit card required
Set it up in under one minute