Privacy Policy
Our formal commitments regarding customer data protection, tenant isolation, ephemeral AI processing, and GDPR Article 17 hard-delete standards.
Customer records and conversations are processed ephemerally in-memory and never used to train foundation models.
Enforced database-level partition scoping (company_id) and AES-256-CBC encrypted integration vaults.
Payment credentials are never stored on our servers. Processed entirely via Lemon Squeezy Merchant of Record.
Complete data sovereignty. Download standardized .ZIP archives of all workspace records anytime before deletion.
1. Information We Collect
We collect only operational data required to deliver core CRM functionality: user account credentials (name, verified email), organization profiles, customer CRM entities (contacts, deals, custom products, currencies), multimodal business card OCR scans, and inbound lead payloads dispatched via connected advertising webhooks (Meta, Google, TikTok Ads).
2. Multi-Tenant Architecture & Data Isolation
STRIV CRM enforces strict database-level tenancy locks via global TenantScope applied to every relational query (company_id). Organizations operate in cryptographically and logically isolated partitions. Inbound webhook signing secrets and third-party API integration keys are encrypted at rest using AES-256-CBC vaults.
3. EU AI Act (Art. 50) & Ephemeral Model Processing
In accordance with EU AI Act (Regulation (EU) 2024/1689, Art. 50), all automated deal proposals and drafts produced by our AI Swarm are explicitly marked as synthetic drafts. AI prompts execute in volatile RAM with zero retention. Customer records and pipeline conversations are strictly never retained or used to train public foundation models.
4. Payment Processing & PCI-DSS Compliance
STRIV CRM does not handle, ingest, or store raw cardholder data or CVV codes. All subscription transactions, currency conversions, and global tax compliances are tokenized and processed via Lemon Squeezy as our PCI-DSS Level 1 Compliant Merchant of Record.
5. GDPR (Art. 17/20) & Immediate Hard Erasure
We enforce unconditional Direct Hard Erasure under GDPR Article 17. When an authorized tenant owner initiates account deletion via Profile Danger Zone, our system executes an atomic database transaction that permanently force-deletes all associated tenant records (users, clients, deals, products, activities, ai_sessions, and API credentials). Zero soft-delete holding tanks or shadow recovery bins exist. Under GDPR Article 20, tenant owners may download a comprehensive .ZIP archive of their workspace data at any time prior to erasure. We do not sell or monetize personal data under CCPA/CPRA.
6. Data Retention Lifecycle & DPO Contact
User-initiated deletion takes effect instantly with zero retention lag. For abandoned or lapsed subscriptions without an explicit erasure request, workspace partitions enter a 90-day read-only grace period before automated scheduled database purging. For Data Processing Agreements (DPA) or security inquiries, reach our Data Protection Officer at [email protected].
