1Section 1
Scope and Purpose
This policy applies to all personal data processed by Franstorm CRM, whether it pertains to employees, customers, vendors, or any other individual. The purpose of this policy is to ensure compliance with the GDPR and to establish a framework for processing, storing, and handling personal data.
2Section 2
Definitions
Personal Data
Any information relating to an identified or identifiable natural person ("data subject") — names, identification numbers, location data, online identifiers, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.
Processing
Any operation performed on personal data — collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, restriction, erasure, or destruction.
Data Controller
The entity that determines the purposes and means of processing personal data.
Data Processor
The entity that processes personal data on behalf of the data controller.
Data Subject
The individual to whom the personal data relates.
3Section 3
Principles of Data Processing
Franstorm CRM adheres to the following principles when processing personal data:
- Lawfulness, Fairness, and Transparency — personal data is processed lawfully, fairly, and in a transparent manner.
- Purpose Limitation — data is collected for specified, explicit, and legitimate purposes and not further processed incompatibly with those purposes.
- Data Minimization — data collected is adequate, relevant, and limited to what is necessary.
- Accuracy — personal data is accurate and, where necessary, kept up to date.
- Storage Limitation — data is kept identifiable for no longer than necessary for its purposes.
- Integrity and Confidentiality — data is processed with appropriate security, protected against unauthorized processing and accidental loss, destruction, or damage.
- Accountability — Franstorm CRM is responsible for, and able to demonstrate, compliance with these principles.
4Section 4
Lawful Bases for Processing
Franstorm CRM processes personal data only when a lawful basis applies:
- Consent — the data subject has given explicit consent for one or more specific purposes.
- Contractual Necessity — processing is necessary to perform a contract with the data subject, or to take pre-contractual steps at their request.
- Legal Obligation — processing is necessary to comply with a legal obligation.
- Vital Interests — processing is necessary to protect the vital interests of the data subject or another person.
- Public Task — processing is necessary for a task carried out in the public interest or under official authority.
- Legitimate Interests — processing is necessary for legitimate interests pursued by the controller or a third party, except where overridden by the data subject's interests or rights.
5Section 5
Data Collection and Processing Activities
Franstorm CRM collects and processes personal data from users and customers for the following purposes:
- Customer Relationship Management — contact information, communication history, purchase history, and support tickets.
- Marketing and Communications — email marketing, newsletters, and product updates, where consent has been obtained.
- Analytics and Product Development — usage data, feedback, and surveys to improve services.
- Compliance with Legal Requirements — data necessary for compliance with laws and regulations.
6Section 6
Data Subject Rights
Under the GDPR, data subjects have the following rights regarding their personal data:
- Right to be Informed — about the collection and use of personal data.
- Right of Access — to access personal data and obtain a copy of it.
- Right to Rectification — to correct inaccurate or incomplete data.
- Right to Erasure — to request deletion of personal data in certain circumstances.
- Right to Restriction of Processing — to request restriction under specific conditions.
- Right to Data Portability — to receive data in a structured, machine-readable format and transmit it to another controller.
- Right to Object — to object to processing based on legitimate interests, direct marketing, or research/statistical purposes.
- Rights Related to Automated Decision-Making and Profiling — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
7Section 7
Data Security and Integrity
Franstorm CRM implements appropriate technical and organizational measures to protect personal data, including:
Data Encryption
Encryption of data at rest and in transit.
Access Controls
Role-based access control, password policies, and multi-factor authentication.
Regular Audits
Regular audits, security assessments, and vulnerability testing.
Anonymization & Pseudonymization
Techniques used to reduce identification risk of personal data where possible.
8Section 8
Data Retention Policy
Personal data is retained only as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. After this period, personal data is securely deleted, destroyed, or anonymized.
| Data Category | Retention Period |
|---|---|
| Customer Data | Duration of the customer relationship, plus a defined number of years thereafter |
| Marketing Data | Until the data subject withdraws consent or opts out |
| Employee Data | Duration of employment, plus a defined number of years thereafter |
9Section 9
Data Transfers
Franstorm CRM may transfer personal data to third parties or to countries outside the European Economic Area (EEA) only when appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission.
- Adequacy decisions where the European Commission has determined a third country ensures an adequate level of protection.
- Binding Corporate Rules (BCRs).
10Section 10
Third-Party Processors and Subprocessors
Franstorm CRM may engage third-party service providers (subprocessors) to support its operations. All third-party processors must comply with GDPR requirements and enter into data processing agreements (DPAs) to protect personal data. These processors are only permitted to process personal data as instructed by Franstorm CRM.
11Section 11
Data Breach Notification
12Section 12
Data Protection by Design and by Default
Franstorm CRM integrates data protection principles into its product development and business processes. This includes conducting Data Protection Impact Assessments (DPIAs) where processing activities are likely to result in a high risk to the rights and freedoms of data subjects.
13Section 13
Accountability and Governance
Franstorm CRM maintains documentation to demonstrate compliance with GDPR, including:
- Records of processing activities.
- Internal data protection policies and procedures.
- Training records.
- Data processing agreements.
14Section 14
Changes to This Policy
Franstorm CRM reserves the right to modify this policy at any time. Any changes will be communicated to data subjects where required by law. Data subjects are encouraged to review this policy periodically to stay informed about how Franstorm CRM protects their personal data.
Contact
Contact Information
Data Protection Officer (DPO)
Franstorm CRM
Email: contact@franstorm.com
Phone: +1 (704) 666-4910
Address: 2108 South Blvd #211, Charlotte, NC 28203, United States
For any questions or requests regarding this policy or data protection practices, please reach out, we investigate every request promptly.
