Skip to content

Privacy policy

Last updated 29 July 2026

Who we are

atomcrm.ai operates this service. This policy explains what personal data we handle, why we handle it, and what rights you have over it.

Two different roles, and the difference matters

For data about you as our customer — your name, work email, billing details and how you use the product — we are the data controller.

For data you put into your workspace — your own customers’ names, phone numbers and conversation history — we are a data processor. You decide what goes in and why; we hold it on your behalf and act on your instructions. Concretely: we do not mine it, sell it, or train models on it.

What we collect

Account data: name, work email, phone, company name, role, and your password stored only as a one-way hash.

Billing data: billing address, GSTIN where you supply one, and payment records. Card details are handled entirely by Razorpay and never reach our servers.

Usage data: pages visited, features used, session times, IP address, browser and device type. This is what drives both our product analytics and the audit trail your own administrators depend on.

Support data: whatever you send us in a ticket or tell us on a call.

Website data: form submissions and the campaign parameters that show how you found us.

Why we use it

To provide the service, bill you for it, support you, keep the platform secure, meet our legal obligations, and — only where you have opted in — tell you about product changes.

We do not sell personal data to anyone. We do not use the contents of your workspace for advertising, and we do not share it with other customers under any circumstances.

Where it is stored

In our Mumbai (ap-south-1) region, so Indian customer data stays in India. Data is encrypted in transit with TLS 1.2 or higher and encrypted at rest. Backups are encrypted and retained for 30 days. Enterprise customers may request dedicated infrastructure.

How long we keep it

Workspace data for as long as your subscription is active, and for 90 days afterwards so you can recover or export it. Billing records for eight years, as Indian tax law requires. Audit logs for up to 24 months. Website inquiries for 24 months.

Who else sees it

Only the sub-processors necessary to run the service: our cloud host, Razorpay for payments, our transactional email provider, and — where you switch them on — WhatsApp Business, Meta and Google for those integrations. Each is bound by contract to equivalent protections.

We will publish any change to this set here before it takes effect.

Your rights

You may request access to, correction of, or deletion of your personal data, and a machine-readable export of it. Workspace administrators can export their own data at any time from inside the product without asking us.

Email privacy@atomcrm.ai and we will respond within 30 days.

Changes to this policy

We will post any material change on this page and email account administrators at least 14 days before it takes effect.