SoarSCRM Legal Center

Privacy Policy

This policy explains how SoarSCRM collects, uses, shares, retains, and protects information about visitors, customer users, and business contacts.

Version: 1.0Effective: August 31, 2026

1. Scope and roles

SoarSCRM generally acts as an independent controller for registration, subscription, support, security, and business relationship data. For personal data submitted by business customers through conversations, contacts, materials, translation, automation, and backup features, we generally act as a processor following customer instructions. Customers must give required notices and ensure lawful processing.

2. Information we collect

Information may include account and contact details, organization and subscription data, support communications, device and log data, security events, usage records, and conversations, contacts, files, and customer labels that you submit or make available through connected platforms. We do not ask for data unrelated to the features you use.

3. Purposes and legal bases

We use information to create and administer accounts, perform orders, provide and secure the services, process payments and support, troubleshoot, comply with law, prevent fraud, and improve products where permitted. The legal basis may be contract, legitimate interests, legal obligation, or consent, depending on the data and applicable law.

4. Sharing, subprocessors, and transfers

We disclose information to contractually bound providers only as needed for cloud hosting, content delivery, payments, email, monitoring, support, translation, or AI features, and when required by law, a corporate transaction, or user safety. Selling contact lists is not our business.

International transfers use contractual or other safeguards recognized by applicable law. Actual providers, data regions, and transfer mechanisms must match the subprocessor list and order in effect at publication.

5. Retention and security

We retain information as needed to provide services, perform contracts, resolve disputes, and meet legal duties, then delete or de-identify it under product settings, orders, and backup rotation. We use risk-appropriate access controls, transmission protection, logging, backups, and incident response, but no system can promise absolute security.

6. Your rights and choices

Depending on local law, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or complain to a regulator. Requests involving data controlled by a business customer should normally be sent to that customer first; we will reasonably assist the customer.

The services are not directed to children below the age set by applicable law. Contact us if you believe child data was collected without proper authorization.

7. Updates and contact

We will explain material changes through the page, product notice, or another reasonable method and update the version and effective date. Send privacy or deletion requests to [email protected].