Lars CRM
Privacy Policy
What we collect, why we collect it, where it lives, how long we keep it, and who else can see it.
Effective 5 August 2026 · [LEGAL ENTITY — to be confirmed]
1. Who we are
Lars CRM is operated by [LEGAL ENTITY — to be confirmed], registered at [REGISTERED ADDRESS — to be confirmed]. For anything in this policy, write to admin@larscrm.com.
Two roles, and the difference matters. For the personal data of our own customers — the people who sign up, pay and administer an account — we are the controller. For the data our customers put into their CRM about their own leads and clients, we are the processor: we hold it and act on their instructions, and it is theirs. This policy covers the first role. The second is governed by the Data Processing Addendum.
2. What we collect
Account data. Name, email address, company name, and the answers to the questions asked during sign-up (your role, team size, industry, what you want the product to fix). We ask those because they configure the product; they are not resold and not used for advertising.
Billing data. The plan you are on, invoices, and payment status. Card details are handled by our payment provider and never reach our servers.
Usage data. Sign-in times, IP address, browser and device type, and which features were used. Kept to keep the service running, diagnose faults and detect abuse.
Support correspondence. What you write to us, and our replies.
Customer content. Everything you put into the CRM — leads, contacts, notes, files, call recordings and transcripts. We do not read it except when you ask us to in order to solve a problem, and processing it is described in the DPA.
3. Why we are allowed to
To perform the contract — account, billing and the service itself. Legitimate interests — keeping the service secure, preventing abuse, and improving it in aggregate. Legal obligation — tax and accounting records. Consent, where we ask for it, and which you can withdraw at any time without losing access to anything you have paid for.
4. Where it is stored
Data is held in managed cloud infrastructure in the [REGION — to be confirmed] region. Each customer has their own database, not a shared table with a customer column — see the Security page for what that buys you. Where a subprocessor is outside your country, transfers rely on Standard Contractual Clauses or an equivalent mechanism.
5. How long we keep it
Account and customer content: for as long as the account is open, and for 30 days after it closes, so that an account closed by mistake can be restored. After that it is deleted from live systems; backups age out within [BACKUP RETENTION — to be confirmed] days.
Billing records: as long as tax law requires, which is longer than we would otherwise keep them.
Usage logs: [LOG RETENTION — to be confirmed] days.
6. Who else touches it
Only the providers we need to run the service: hosting, the database cluster, file storage, email delivery, telephony, and the AI provider that analyses calls when that feature is switched on. Each is listed by name, purpose and location on the Subprocessors page, and each is bound by a contract no weaker than this policy.
We do not sell personal data, and we do not share it for advertising. There is no exception to that sentence.
7. Your rights
You may ask for a copy of your data, ask us to correct it, ask us to delete it, object to particular processing, or ask for it in a portable form. Write to admin@larscrm.com; we answer within 30 days. If you are in the EEA or the UK you may also complain to your data protection authority, and if you are in California you have the rights the CCPA gives you, including the right not to be treated differently for exercising them.
If your data is in a customer's CRM rather than in your own account with us, the customer decides — send your request to them, and we will help them meet it.
8. Cookies
The application sets a session cookie so you stay signed in, and a preference cookie for your language and theme. Neither is used for tracking, and there are no advertising cookies. [ANALYTICS — to be confirmed once a provider is chosen; see US-9.]
9. Children
The service is for businesses. It is not directed at anyone under 16, and we do not knowingly collect their data.
10. Changes
We will post any change here and update the effective date. If a change materially affects your rights, we will tell account holders by email before it takes effect.
The other documents
Questions about any of this go to admin@larscrm.com, and they reach a person.