CRM← Back to sign-in
⚠️ Courtesy translation — the French version is the only one that is binding This English version is provided for the convenience of non-French-speaking readers. In the event of any discrepancy of meaning or interpretation, the French version prevails. Like the French original, this document must be reviewed by a lawyer before final publication. It was written from the usual GDPR structure (record of processing activities, legal basis, retention periods, data subject rights) and from how the software actually behaves, as observed in its code.

Privacy policy

Last updated: 25/07/2026 — Version française

This policy describes how the CRM (the “Service”) processes personal data, under the General Data Protection Regulation (GDPR) and the French Data Protection Act. The Customer (your company) is the controller of the data of its own customers and prospects entered into the Service; the publisher acts as a processor within the meaning of article 28 of the GDPR — see the data processing agreement (DPA).

1. Data processed

CategoryExamplesPurpose
User accountsName, email, password (hashed), roleAuthentication and access control
Customers & contactsCompany name, company/establishment numbers, address, contacts (name, email, phone, job title)Managing the commercial relationship
Quotes & dealsAmounts, products, history of exchangesSales pipeline tracking
Telephony (optional module)Numbers called/calling, duration, audio recording, transcriptTracking commercial exchanges, service quality
Visit reportsNotes, transcribed voice dictationInternal sales reporting
Financial data (optional module)Financial health of customer companies (source: INSEE/Pappers)Assessing commercial risk
Technical logsIP address, timestamps of actionsSecurity, traceability (audit)

2. Legal basis

3. Retention periods

DataPeriod
Customer accounts / contactsDuration of the commercial relationship + 3 years (prospecting)
Quotes, dealsDuration of the subscription contract, then legal archiving (accounting obligations)
Call recordingsConfigurable by the Customer's administrator (Settings > Telephony > Governance), 90 days by default. Automatic daily purge, including at the telephony provider (Twilio).
Audit logsThe retention period configured for call recordings (Settings > Telephony)
User account after terminationSee Terms, termination section

4. Sub-processors (hosting and third-party services)

Depending on the modules enabled for your instance:

ProviderRoleLocation
Hostinger International Ltd (Cyprus)Hosting of the application and the databaseEuropean Union
Twilio Inc.Telephony (optional module) — calls, recordingsUnited States (standard contractual clauses)
OpenAI / AnthropicAI transcription and rewriting (optional modules)United States (standard contractual clauses)
Pappers / INSEEPublic company financial data (optional module)France

The exact list of active sub-processors depends on the modules subscribed to (Settings > Modules).

5. Telephony and call recordings

When the telephony module is enabled, calls may be recorded for sales follow-up purposes. Under the applicable regulations, informing the people being called (announcement message or prior contractual notice) is the Customer's responsibility. The publisher provides the technical means for automatic purging and for deleting an individual recording (including at the technical sub-processor), but cannot act in the Customer's place in informing the data subjects.

6. Rights of data subjects

Anyone whose data is processed in the Service has the rights of access, rectification, erasure, restriction, objection and portability. Such requests should be addressed first to the Customer (the controller) who uses the Service to manage its commercial relationship. Failing a response from the Customer, a request may be sent to the publisher: contact@indusiax.com.

Everyone also has the right to lodge a complaint with the French data protection authority (CNIL) — www.cnil.fr — or with the supervisory authority of their own country of residence.

7. Security

Technical measures in place: hashed passwords (never stored in clear text), encrypted connection (HTTPS), sign-in attempt throttling, data partitioning by user role, encrypted daily backups, automatic purging of data according to the retention policy defined.