Privacy
Privacy Policy (concept) β Pomio CRM
CONCEPT β not legal advice, not live until Stefan GO.
Pending approval by Stefan Simon. Do not publish as final law.
Controller / contracting party below is Pomio only.
Last updated: [INVULLEN β date on Stefan GO]
Language: English (default)
1. Who we are
Pomio is the provider of the Pomio SaaS multi-tenant CRM (EU / Made in Europe positioning). Pomio is the sole controller and contracting party for this Privacy Policy.
Privacy contact: via Pomio support or the contact form on this site.
2. Roles under GDPR / AVG
| Context | Who is controller? |
|---|---|
| Pomio marketing website, trial/demo/contact intake, account administration, billing metadata, support about the product | Pomio (controller) |
| Personal data that you (the customer) store or process inside the Pomio CRM on behalf of your own organisation or clients | You (the customer) are controller; Pomio acts as processor under the data processing agreement (DPA / verwerkersovereenkomst) included by default with the Pomio subscription |
This Privacy Policy mainly covers processing where Pomio is controller. CRM customer-content processing is governed by the Terms and the DPA (included by default with the subscription).
3. What we process and why
3.1 Account & subscription
- Data: name, email, organisation, seat count, plan, payment status / billing references
- Purpose: create and manage your Pomio subscription, authenticate users, invoice
- Legal basis: performance of contract (Art. 6(1)(b) GDPR)
3.2 CRM service delivery (as processor)
- Data: whatever you enter into Pomio (contacts, notes, activities, etc.)
- Purpose: host and operate the CRM for you
- Legal basis (your side): determined by you as controller; our processing is on your documented instructions (Art. 28 GDPR) under the DPA included with the subscription
3.3 Support
- Data: contact details, ticket content, technical logs needed to diagnose issues
- Purpose: respond to support requests
- Legal basis: contract and/or legitimate interest in assisting customers (Art. 6(1)(b)/(f))
3.4 Trial / demo / contact / support intake (Typeform)
- Data: fields you submit via Typeform (typically name, email, company, message, request type)
- Purpose: handle trial, demo, contact, and support intake
- Legal basis: pre-contractual steps / contract (Art. 6(1)(b)) or legitimate interest in responding to enquiries (Art. 6(1)(f)); consent where we ask for marketing follow-up
- Note: Typeform is a named subprocessor of Pomio for lead / intake forms
3.5 Cookies & similar technologies (first-party)
We use first-party cookies / local storage for essential functions. Optional Google Analytics 4 loads only after analytics consent.
| Type | Examples | Purpose | Consent |
|---|---|---|---|
| Necessary | session, security, load balancing | operate the site/app | No consent required (strictly necessary) |
| Analytics (Google Analytics 4, after consent) | usage aggregates, feature adoption | improve Pomio and the site | Consent for non-essential analytics |
Non-essential cookies/analytics are only set after consent. You can withdraw consent via the cookie controls on the site. Details of cookie names/durations: [INVULLEN β cookie table when lighter solution is live].
3.6 Marketing (if any)
- Only with consent or soft-opt-in where Dutch/EU law allows for existing customers β [INVULLEN β confirm marketing practice]
- Legal basis: consent (Art. 6(1)(a)) and/or legitimate interest with opt-out where applicable
4. Categories of data (summary)
- Identity & contact data
- Organisation / role data
- Account & subscription data
- Support communications
- Typeform intake data
- Technical / log data (IP, user agent, timestamps β as needed for security and operations)
- Cookie/analytics identifiers (Google Analytics 4 when consented; otherwise first-party essential only)
- CRM content: processed as your data under your controllership (see Β§2)
We do not intentionally collect special categories of personal data for our own purposes as controller. Do not submit such data via marketing forms unless necessary and lawful on your side.
5. Retention
| Data | Retention (draft) |
|---|---|
| Account & billing | For the subscription term + period required for tax/accounting (NL: typically up to 7 years for fiscal records) β [BEVESTIG] |
| Support tickets | For the duration needed to resolve + reasonable archive period β [INVULLEN] |
| Typeform leads | Until handled + short follow-up window, or until deletion request β [INVULLEN] |
| Logs / security | As long as needed for security and abuse prevention β [INVULLEN] |
| Cookies | Per cookie duration in cookie table β [INVULLEN] |
| CRM customer content | Until you delete it or your account ends, subject to Terms/DPA |
Exact retention schedules to be confirmed before go-live.
6. Recipients and subprocessors
Pomio may share data with providers engaged by Pomio:
- Hosting / infrastructure provider(s) (engaged by Pomio): [INVULLEN β name, region]
- Payment provider (engaged by Pomio): [INVULLEN]
- Typeform (lead / intake forms; named subprocessor of Pomio)
- Professional advisers (accountant, lawyer) under confidentiality where needed
- Authorities where legally required
A current subprocessors list will be published or attached to the DPA: [INVULLEN].
We do not sell personal data.
7. International transfers
Pomio is positioned for EU / Made in Europe use. Prefer processing in the EEA.
If a recipient is outside the EEA/UK adequacy area, we use appropriate safeguards (e.g. EU Standard Contractual Clauses) and assess transfer risk β [INVULLEN β confirm hosting region & any non-EEA tools].
8. Your rights (GDPR / AVG)
Where Pomio is controller, you may request:
- Access, rectification, erasure
- Restriction of processing
- Data portability (where applicable)
- Objection to processing based on legitimate interest
- Withdrawal of consent (without affecting prior lawful processing)
- Complaint to the Dutch Autoriteit Persoonsgegevens (or your local EU supervisory authority)
For data inside your CRM tenant, contact your organisation (the controller) first; we assist as processor per the DPA/Terms.
9. Security
We apply appropriate technical and organisational measures for a multi-tenant SaaS CRM (access control, encryption in transit, tenant isolation measures, backups as configured) β [INVULLEN β high-level security statement if desired]. No measure is perfect; report suspected incidents to the privacy contact.
10. Children
Pomio is a B2B CRM. We do not knowingly offer the service to children. Marketing forms are not directed at minors.
11. Changes
We may update this policy. Material changes will be announced on the site and/or by email where appropriate. The βLast updatedβ date will change on Stefan GO and subsequent revisions.
12. Contact
Pomio
Contact: via Pomio support or the contact form on this site.
End of CONCEPT Privacy Policy (EN). Not legal advice. Not live until Stefan GO.