Legal

Privacy Policy

What we hold, why, on what legal basis, who else can see it, how long it stays, and how to make us act on it. Written to be checkable rather than reassuring.

Updated October 2026info@agadigitaltech.com

01

Who we are, and which hat we are wearing

AGA CRM provides a customer-support CRM to businesses. This policy covers both this website and the application. We are established in the United Kingdom, your workspace is hosted in Manchester, United Kingdom, and you can reach us about anything in this policy at info@agadigitaltech.com.

Almost every complaint about a privacy policy comes from one confusion, so it is worth settling first: we hold two different kinds of data, and we are a different thing in law for each.

  • We are the controller of account and billing data — the staff accounts in a workspace, sign-in records, the subscription and the payments. We decide what is needed to run and bill the service, and this policy governs it.
  • We are a processor of support data — the tickets, emails, chat messages, attachments, customer profiles, call recordings and notes a business handles in the CRM. The business is the controller: it decides what it collects and why, and we act on its instructions. Our Data Processing Agreement governs that, not this policy.
  • So if you are a customer of a business that uses AGA CRM, we almost certainly hold data about you — but we are not the ones who decided to, and we cannot lawfully act on your request without that business. Section 8 explains what to do, and it does not end with us ignoring you.

For completeness: this notice identifies us by our trading name, AGA CRM, because the registered legal name and a postal address for notices are not yet published here. Ask at info@agadigitaltech.com and we will confirm them in writing.

02

Our representative in the EU

We are established in the United Kingdom, which is outside the European Union, and we offer the service to people inside it. That means Article 27 of the EU GDPR requires us to designate a representative inside the Union, and we have not yet done so — so this paragraph says that rather than implying otherwise.

Until one is in place, EU data subjects and supervisory authorities should write to us directly at info@agadigitaltech.com, and we answer in the same time limits we would be held to anyway: one month for a rights request, 72 hours for a breach. Nothing about the gap reduces what you are entitled to, and nobody has to go through an intermediary to get it.

  • In the United Kingdom: no representative is needed. We are established in the United Kingdom, so there is nothing for a UK representative to bridge. Write to us directly.
  • In Nigeria: the Nigeria Data Protection Act 2023 asks something different again — registration with the Commission and a designated data protection officer, but only of a controller or processor "of major importance", which turns on the volume of Nigerian data subjects involved. Ask us and we will tell you whether we cross that threshold today.

This is an open item, stated rather than dressed up: an EU representative is required of us and none has been appointed. It is a written mandate with a firm in the Union, not a setting we can switch on. If you are an EU buyer whose procurement needs it in place first, ask at info@agadigitaltech.com and we will tell you where it stands.

03

What we hold, why, and on what legal basis

Every category we process as controller, with the ground we rely on under Article 6. Where the ground is legitimate interests, the interest is named, because an unnamed one cannot be weighed against yours.

DataWhat it isWhy we have itLegal basis
Staff account dataName, work email address, role, department, language, and a bcrypt hash of the password. Two-factor seeds where enabled.To create the account your administrator asked for and to let you sign in.Performance of our contract with your employer.
Sign-in and session recordsTimes, IP address, browser, and the active sessions you can see and revoke in your own security settings.To keep the account secure, to show you where you are signed in, and to detect a stolen session.Legitimate interests — securing the service and your account against unauthorised access.
Audit trailWho did what in the workspace and when. Sign-ins, permission changes and views of a customer’s contact details sit in a protected tier.So a workspace can hold its own staff accountable, and so an incident can be reconstructed.Legitimate interests — accountability and security. It is also how we meet our own obligations as a processor.
Presence and activityOnline, idle or on-break status while you are signed in, and the heartbeat that maintains it.To route work to agents who are actually available.Legitimate interests — operating the service your employer subscribed to.
Subscription and billingPlan, seat count, invoices, payment status, and the billing contact. The card itself is held by the payment processor, never by us.To charge for the service and to keep the records tax law requires.Performance of our contract, and legal obligation for the accounting records.
Website enquiriesThe name, email address, company and message you type into the contact or demo form.To answer you.Legitimate interests, or steps towards a contract where you are asking to buy.
Server and security logsRequest lines and errors — IP address, time, path, response, and a stack trace when something breaks.To keep the service running, to debug a fault, and to investigate abuse.Legitimate interests — availability and security.
Support dataEverything a workspace processes about its own customers.Only to provide the product, on that workspace’s instructions.Not ours to choose. The controller is the business using the CRM; see our DPA.

04

Where it comes from

Staff account data comes from the workspace administrator who created the account, or from you when you edit your own profile. Billing data comes from the person who subscribed, and the payment status comes back from the payment processor.

Support data arrives through the channels a workspace connects: an email it receives, a WhatsApp or Telegram message, an on-site chat, an inbound call, an import, or an agent typing it in. If you are a customer of such a business, your data reached us because you contacted them — we did not collect it from you, and we did not buy it from anyone. We do not enrich, purchase or scrape personal data, full stop.

05

AI features, and what they are not

A workspace can switch on an assistant that drafts summaries, suggested replies and category guesses. When it is on, the content of the relevant ticket conversation is sent to Anthropic’s Claude API to produce that draft.

Nothing is sent to a model for training — not by us, and not by Anthropic under the terms we use. Nothing is sent automatically to your customer: a suggestion is a draft that an agent reads, edits and chooses to send, and the product has no path that sends model output to anyone without a human doing it.

There is no automated decision-making that produces a legal effect or anything similar: no profiling, no scoring that decides an outcome, no automated refusal of anything. A workspace administrator can disable AI entirely in settings, and when it is off no ticket content leaves our servers for a model.

06

Google Workspace data

When an administrator connects a Gmail or Google Workspace mailbox, AGA CRM reaches it through the official Gmail API using OAuth, with the narrowest scopes that do the job. We read incoming support messages to create tickets, and send the replies your agents write. OAuth tokens are encrypted at rest with AES-256-GCM, and the connection can be revoked at any time from the CRM or from your Google account.

AGA CRM’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not transfer it to others except as needed to provide the service or where the law requires, and do not allow humans to read it except with your permission, to resolve a fault or security issue, or to comply with law.

07

Who else sees it

We do not sell personal data, do not rent it, and do not use it to advertise anything.

Beyond that, the honest answer is a list rather than a sentence, and it is published in full as the annex to our Data Processing Agreement: every provider that can ever receive data, the contracting entity, what it does, where it does it, and the condition that has to be true before it receives anything at all. Most entries never activate — they wait on a workspace connecting that feature. The payment processors sit on the billing path only and never see a ticket, a customer record or an attachment.

Each is bound by written terms no weaker than our own, and we give workspace administrators at least 30 days’ notice by email before a new one starts processing support data. We also disclose data where the law compels us, and will tell the affected customer unless we are forbidden from saying.

08

Leaving the country

Your workspace lives in Manchester, United Kingdom. The United Kingdom has an EU adequacy decision, which is the basis on which data reaches us from the EEA.

Some providers in that annex process outside the UK and the EEA — the United States, and Nigeria for one payment route. For those we rely on the European Commission’s Standard Contractual Clauses with the UK International Data Transfer Addendum, or on an adequacy decision where one covers the destination, and we assess the transfer risk for each. Copies are available on request.

09

How long we keep it

Specific periods, because "as long as necessary" is not an answer.

  • Staff accounts: while the account exists. Deleting it removes the profile; the audit trail keeps the record that the account acted, which is the point of an audit trail.
  • Audit trail: 90 days for ordinary activity and 30 days for machine chatter by default, both adjustable by your administrator. Sign-ins, permission changes and customer-contact views are kept for 365 days on a floor that workspace settings cannot shorten — an evidentiary trail that can be turned down is not one.
  • Support data: as long as the workspace wants it, unless its administrator sets a retention period. Once set, resolved and closed tickets older than it are deleted nightly along with their messages, internal notes and attachment files. It is off by default and has a 30-day floor.
  • An erased customer: gone immediately. Profile, every ticket, every message, call records, notes, and the attachment files on the server — not just the database rows. What survives is an audit entry recording that an erasure happened and the counts of what it removed, holding none of the erased data.
  • A workspace that ends: 30 days of read and export access after cancellation or an expired 14-day trial, then deletion. Encrypted backups run on a 30-day rolling window, so the last copy leaves the backup set within 30 days of the deletion. We delete sooner on an administrator’s written instruction, and confirm in writing when it is done.
  • Billing records: six years from the end of the financial year, because tax law requires it.
  • Website enquiries: 12 months if they do not become an account, then deleted.
  • Server and security logs: 30 days, longer only for a specific log being used in an active investigation.

10

Your rights, and how to actually use them

You can ask for access to your data, a copy in portable form, correction, erasure, restriction of processing, or to object to processing we base on legitimate interests. Where processing rests on consent you can withdraw it at any time. We never charge for this and we answer within one month, extendable by two for a genuinely complex request, in which case we will tell you before the first month is up.

Which door to knock on depends on the hat in section 1, so: if the data is your staff account, your sign-in history or your billing, write to us. If it is data a business holds about you as its customer, write to that business — it decides, and we are not permitted to overrule it. Workspace administrators have the tools to answer you directly without waiting for us: one button downloads everything held about a person — profile, tickets, every message, notes, calls and attachments — as a single machine-readable file, and another erases it, files on disk included.

If a request about customer data reaches us by mistake, we will not sit on it or quietly drop it: we will tell you to contact the business, and tell the business that you tried, so the clock starts on their side. Send anything to info@agadigitaltech.com; we may ask for enough information to be sure who you are, and nothing more.

If we get it wrong you can complain to a regulator, and you do not have to go through us first. In the UK that is the Information Commissioner’s Office at ico.org.uk; in Nigeria the Nigeria Data Protection Commission at ndpc.gov.ng; in the EEA your own national authority. We would rather you raised it with us so we can fix it, but that is your choice and not a precondition.

11

How it is protected

TLS on every connection; AES-256-GCM for secrets at rest; passwords only ever as salted bcrypt hashes; per-workspace isolation on every query; role-based permissions; two-factor authentication available on every account; sessions that expire on inactivity and refresh tokens that rotate on use, where a reused token is treated as theft; AES-256 encrypted database backups taken nightly and before every deployment, each verified by decrypting and reading it back; and deletion that removes files from the disk rather than only rows from a table.

Our security page sets each of these out in detail, including the things we do not have — there is no SOC 2 or ISO 27001 report today, and we would rather say so than imply otherwise.

If we suffer a breach affecting personal data we hold as controller, and it is likely to be a risk to you, we will tell the relevant regulator within 72 hours and tell you without undue delay. Where the data belongs to a workspace, we notify its administrators within 72 hours of becoming aware and give them what they need to notify their own regulator and customers on time.

12

Cookies

One cookie, which keeps you signed in, plus two short-lived session-storage entries. No analytics, no advertising pixels, no third-party scripts, and web fonts served from our own domain so that loading a page tells nobody that you were here.

Our Cookie Notice prints the complete list with the purpose and lifetime of each, and explains why there is no consent banner: everything in it is strictly necessary, so there is no second option to offer you. If that changes, the banner arrives before the tracking does.

13

Children

AGA CRM is a business tool, sold to businesses and used by their staff. It is not directed at children and we do not knowingly create accounts for anyone under 18.

A business using the CRM may of course end up handling a message from a child who contacted it. That is the business’s call as controller, and its own notice and lawful basis have to cover it — but it is a good reason for that business to set a short retention period in settings.

14

Changes

The date at the top of this page is the version in force. We post changes here and, where they are material, email workspace administrators before the change takes effect rather than after.

Questions about this policy?

We answer data and security questions directly, no ticket queue, no sales call.