EzyCrm ← Back to the site

Privacy policy

Effective 22 August 2026 Last updated 22 August 2026 Applies to ezycrm.ca and the EzyCrm application

The short version

  • Your CRM records belong to you. We hold them to run the service and for no other purpose — we do not sell them, rent them, or train models on them.
  • Your CRM records are stored in Canada, in the ca-central-1 region. Email we send on your behalf passes through a provider in the United States — that is the one exception, and it is set out in full below.
  • There is no advertising, no tracking pixel and no analytics script on this website.
  • You can export everything you have put in, at any time, in one click.
  • If you ask us to delete your workspace, we delete it. Section 11 says exactly what happens to copies.

1. Who we are

This service is operated by Evan Korial, based in Saskatchewan, Canada (“EzyCrm”, “we”, “us”). For anything in this policy, write to evankorial7@gmail.com.

2. Two different kinds of data, two different roles

This distinction matters more than anything else in this document, so it comes first.

Account data — we decide what happens to it

The information you give us to have an account: your name, your email address, your company name, what plan you are on, what you have paid, and the technical records our servers keep while you use the product. We are the controller of this data. We decide why it exists and how long we keep it, within the limits set out below.

Customer data — you decide what happens to it

Everything you put into the CRM: your contacts, your companies, your deals, your notes, your emails, your files. This is your data about your customers. We are a service provider processing it on your instructions and nothing more. We do not decide what goes in it, we do not use it for our own purposes, and we do not look at it except in the narrow circumstances in section 6.

If you are subject to GDPR, read “controller” for you and “processor” for us in respect of customer data. Under Canadian law (PIPEDA) the same split applies: you are the organisation accountable to the individuals in your CRM, and we are your service provider.

3. What we collect, and why

WhatWhy we have itHow long we keep it
Email address and password (stored only as a one-way hash, never in readable form) To let you sign in and to recover your account Until you delete your account
Workspace name, plan, seat count, rate and payment records To run your subscription and meet our tax and bookkeeping obligations Seven years after the last payment, as required for financial records
An audit trail of changes made in your workspace — who changed what, and when Security, and so you can see and undo what happened For the life of the workspace
Server logs: IP address, timestamp, the request made, the response given To keep the service running and to investigate abuse Held only by our infrastructure providers, under their own schedules — between one and thirty days depending on the log. We keep no separate copy, and cannot extend it.
The CRM records you enter or import To provide the product to you. Nothing else. Until you delete them, or until your workspace is deleted
Emails we send on your behalf — booking confirmations, reminders, invitations To deliver the message and to show you whether it went out The record that it was sent stays on the contact's timeline in your workspace until you delete it. The copy held by our mail provider is subject to their retention schedule, not ours.

We do not collect special-category data (health, biometrics, political or religious views, and so on) about you. If you choose to put such information into your own CRM records, you remain responsible for having a lawful basis to hold it.

4. Our lawful basis

Where GDPR applies, we rely on: performance of a contract for everything needed to give you the service you signed up for; legitimate interests for security, abuse prevention and keeping the service working, weighed against your rights each time; and legal obligation for tax and accounting records. We do not rely on consent for anything except optional marketing email, which you can refuse without losing any part of the product.

5. Where your data lives

All application data is stored in Canada, in the ca-central-1 region, on infrastructure operated by our database provider (see section 7). Any backup copies stay in the same region.

Some of our sub-processors may access data from outside Canada in the course of providing support. Where that happens, transfers are covered by the safeguards in the contracts we hold with them, including Standard Contractual Clauses where the recipient is outside a jurisdiction recognised as adequate.

6. Who can see your CRM records

Access is enforced by the database itself, not only by the application. Each workspace's rows are restricted to members of that workspace by row-level security policies, so one customer cannot read another's data even if the application has a bug.

Our staff cannot read your CRM records in the ordinary course. A platform administrator can open a read-only summary of a workspace in order to answer a support question or investigate abuse. Two things constrain that:

  • There is no administrative write path anywhere in the system. It is not that we choose not to edit your records — the capability does not exist.
  • Every such view is written to an audit log, against the address of the person who did it, by the server. That record cannot be suppressed from the administration console.

We will tell you if we access your workspace for any reason other than a support request you raised yourself, unless we are legally prohibited from doing so.

7. Sub-processors

We use a small number of other companies to run the service. Each of them is bound by contract to process data only on our instructions and to protect it to a standard no lower than this policy. The current list is on the sub-processors page, which is the authoritative version and is updated when it changes.

8. What we do not do

  • We do not sell or rent personal information, and we never have.
  • We do not use your CRM records to train machine-learning models — ours or anyone else's.
  • We do not run advertising, ad networks or behavioural profiling.
  • We do not put an analytics script, tracking pixel or third-party tag on our website.

If you enable an AI feature and configure your own model provider, the text you send to that provider goes directly from your browser to them under your account and their terms. We do not proxy it and we do not keep a copy.

Calendar feeds work differently, and the difference matters. If you point EzyCrm at one of your calendars, our server fetches that feed on a schedule — your browser is not involved and may not even be open — and we store the busy blocks it returns, including event titles and times, so the scheduler can offer times you are actually free. That copy lives in your workspace under the same row-level security as the rest of it, is deleted when you remove the connection, and is not used for anything except showing your availability.

9. How we protect it

  • Encrypted in transit (TLS) and at rest.
  • Tenant isolation enforced in the database by row-level security, not only in the application.
  • Passwords are stored as one-way hashes by our authentication provider and are never visible to us. We do not currently screen new passwords against known breach lists. If you reuse a password that has appeared in a breach elsewhere, nothing here will stop you — use a password manager, and use a password you have not used anywhere else.
  • Backups — read this one carefully, because it is the weakest part of our setup. Our database is currently on a plan that does not include managed point-in-time backups. What protects your data today is redundancy of a different kind: the application is offline-first, so every signed-in device holds a complete working copy of your workspace, a full export is one click away at any time, and we take an encrypted off-site dump of the database on a schedule and keep it with a different provider. That is real protection against losing the database, and it is not the same as a managed backup with point-in-time recovery. We would rather write that down than claim a guarantee we cannot currently honour. When we move to a plan with managed backups, this paragraph changes and we will date the change.
  • An append-only audit trail of administrative actions.

No system is perfect and we will not pretend otherwise. If a breach affects your data and creates a real risk of significant harm, we will tell you without undue delay and in any case within 72 hours of becoming aware of it, together with what we know, what we are doing, and what we suggest you do. We will also report it to the relevant authority where the law requires it.

10. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to a particular use. You can also ask for it in a portable format — although you do not need to ask us for that one: a full export is built into the product and takes a single click.

Write to evankorial7@gmail.com. We will respond within 30 days. We do not charge for this. If we cannot do what you have asked, we will tell you why.

If one of your customers exercises a right against records held in your workspace, they should contact you, not us — the records are yours. If they contact us, we will point them to you and tell you that they did.

If you think we have handled your data badly, you are entitled to complain to the Office of the Privacy Commissioner of Canada, or to your local supervisory authority if you are in the EU or UK. We would rather you told us first, but it is your right either way.

11. Deleting your account

You can close your workspace at any time. When you do, we delete the live data within 30 days. Copies persist in our encrypted off-site dumps until those rotate out, which takes up to 30 days. Local copies held in your own browsers are yours and are not ours to delete — clear your site data, or use the sign-out option that wipes the local copy. We keep the minimum billing records the law requires us to keep, and nothing else.

12. Children

This is a business tool. It is not directed at children and we do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to us and we will remove it.

13. Changes to this policy

If we change something that materially affects you, we will email the account owner at least 30 days before it takes effect, and note it at the top of this page. Cosmetic corrections we will simply make. Every version is dated, and we keep the previous ones so you can see what changed.

14. Contact

Evan Korial
evankorial7@gmail.com

Written to be read. If any part of this is unclear, say so and we will rewrite it — that is a bug like any other.