Effective 25 May 2026
Privacy Policy
How CRM Brain collects, uses, and protects your data.
1. Who We Are
CRM Brain is a product of Roveva Solutions, a sole trader (Einzelunternehmen) operating under German law. Roveva Solutions is the data controller for all personal data processed through crm-brain.com.
Data controller: Roveva Solutions
Sandstücken 9, 25421 Pinneberg, Germany
Email: hello@crm-brain.com
This policy applies to business customers and their authorised users. CRM Brain is a B2B service and is not directed at consumers.
2. What Data We Process
a. Account data
When you sign up, we collect your name, business email address, and team membership. Passwords are hashed by Supabase Auth and are never stored or accessible in plaintext.
b. CRM data
With your authorisation, CRM Brain reads pipeline data from your HubSpot account: contacts, deals, and companies. This integration is strictly read-only. CRM Brain never writes to, modifies, or deletes any record in your HubSpot account.
c. AI usage data
To generate insights and lead scores, we send deal and contact data to Claude (Anthropic). We log the prompts sent, AI responses received, and token counts for quality assurance and billing purposes. Anthropic does not use your data to train its models. See section 7 for transfer details.
d. Usage logs and session recordings
We collect technical logs including page visits, feature interactions, API response times, and error events. When you accept analytics cookies, PostHog records anonymised session replays that capture mouse movement, clicks, and page state. Recordings exclude passwords and payment fields. Neither the logs nor the recordings contain CRM record content. We use them to maintain service reliability and improve the product.
3. Why We Process It and the Legal Basis
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account; delivering the Service | Art. 6(1)(b) GDPR: performance of contract |
| Processing CRM data to generate AI insights | Art. 6(1)(b) GDPR: performance of contract |
| Server-side error monitoring, API logging, and performance measurement | Art. 6(1)(f) GDPR: legitimate interest (maintaining service reliability) |
| Client-side analytics and session recordings via PostHog | Art. 6(1)(a) GDPR: consent (granted via analytics cookie acceptance) |
| Transactional and product update emails to existing customers | Art. 6(1)(f) GDPR: legitimate interest (customer communication) |
| Storing cookies or accessing device storage | §25 TTDSG: consent where required; strictly necessary cookies are exempt |
4. Sub-Processors
We share data only with the following sub-processors. Each is bound by a data processing agreement.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase GmbH | Database storage, row-level security, and authentication | EU, Frankfurt (AWS eu-central-1) |
| Anthropic PBC | Claude AI: deal analysis and insight generation | United States (SCCs in place; no model training on your data) |
| Resend Inc | Transactional email delivery | United States (SCCs in place) |
| Vercel Inc | Application hosting and CDN | United States with EU edge nodes (SCCs in place) |
| Stripe Inc | Subscription billing and payment processing | United States (SCCs in place; CRM Brain never sees raw card data) |
| HubSpot Inc | CRM data source (read-only integration) | United States (SCCs in place) |
| PostHog, Inc. | Product analytics and session recording (consent-gated) | EU (EU Cloud, Frankfurt, AWS eu-central-1); company incorporated in US — SCCs in place; data does not leave EU |
5. Data Retention
| Data category | Retention period |
|---|---|
| Account data (name, email, team) | Duration of your active subscription, plus 30 days after cancellation |
| CRM data (contacts, deals, companies) | Refreshed on each sync; deleted within 30 days of account closure |
| AI usage logs (prompts, responses, token counts) | 90 days rolling |
| Billing records and invoices | 10 years (German commercial and tax law, §147 AO) |
| Technical logs (page visits, errors) | 30 days rolling |
6. Your Rights Under GDPR
As a data subject, you have the following rights under Articles 15 to 21 GDPR:
- Access (Art. 15): Request a copy of the personal data we hold about you.
- Rectification (Art. 16): Ask us to correct inaccurate or incomplete data.
- Erasure (Art. 17): Request deletion of your personal data where no legal obligation requires us to retain it.
- Restriction (Art. 18): Ask us to limit processing while a dispute is resolved.
- Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Objection (Art. 21): Object to processing carried out under legitimate interest, including direct marketing.
To exercise any of these rights, email us at hello@crm-brain.com. We will respond within one calendar month.
You also have the right to lodge a complaint with the competent supervisory authority. For Roveva Solutions, that authority is:
Hamburgischer Beauftragter für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany
www.datenschutz.hamburg.de
7. International Transfers
Some sub-processors are based in the United States. We transfer data to them only where an adequate transfer mechanism is in place:
- Anthropic PBC: Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c). Your data is not used to train Anthropic models per the Anthropic Data Processing Addendum.
- Vercel Inc: SCCs, with workloads served from EU edge nodes where possible.
- Stripe Inc: SCCs. Stripe holds card data; CRM Brain processes only subscription status and invoice metadata.
- Resend Inc: SCCs. Only email addresses and message content are transferred.
- HubSpot Inc: SCCs. Data is read from your existing HubSpot account.
- Supabase GmbH: EU-based; no international transfer for primary data storage.
8. Security
All data is stored in Supabase on AWS eu-central-1 (Frankfurt) with row-level security policies enforced at the database layer. Data in transit is encrypted with TLS 1.2 or higher. Passwords are hashed using bcrypt by Supabase Auth. Authentication uses JWTs with short expiry and secure, httpOnly cookie storage.
9. Changes to This Policy
We will notify you by email at least 14 days before making material changes to this policy. The effective date at the top of this page reflects the most recent version.
10. Contact
Questions, requests, or concerns about this policy: hello@crm-brain.com
Roveva Solutions, Sandstücken 9, 25421 Pinneberg, Germany