Ontoor CRM Back
Last updated & effective: January 1, 2025

Privacy Policy

At Ontoor, your privacy is not a compliance checkbox — it is a core part of how we build software. We will never sell your data. We will always be transparent about what we collect and why.

We never sell your data End-to-end encryption Tenant data isolation GDPR-aligned You own your data
No data selling — ever
No third-party advertising
Your data, your ownership
30-day data export on cancellation
72-hour breach notification

Overview

Plain-language summary Ontoor CRM is a B2B SaaS product. We collect the minimum data needed to run the service. We have never sold your personal information to anyone, and we never will. Your business data — the leads, customers, deals, and invoices you store in Ontoor — belongs entirely to you. We are its custodian, not its owner.

This Privacy Policy explains how Ontoor Solutions Pvt. Ltd. ("Ontoor", "we", "us", "our") collects, uses, discloses, and protects personal information in connection with Ontoor CRM — our cloud-based Customer Relationship Management platform — and related websites, applications, and services (collectively, the "Services").

Please read this policy carefully. By using our Services, you acknowledge you have read and understood it. If you are using Ontoor CRM on behalf of an organisation, you represent that you have the authority to bind that organisation to this policy.

Who We Are

Ontoor Solutions Pvt. Ltd. is a private limited company providing cloud-based business software to organisations worldwide. We operate Ontoor CRM as a software-as-a-service (SaaS) product.

Legal EntityOntoor Solutions Pvt. Ltd.
ProductOntoor CRM
Service TypeB2B SaaS — Customer Relationship Management
Data Controller RoleController for account and usage data; Processor for subscriber business data
Privacy Contactprivacy@ontoorsolutions.com
Websitewww.ontoorsolutions.com

Scope & Application

This policy applies to:

  • Subscribers (Organisations): Companies and teams that have signed up for an Ontoor CRM account (referred to as "tenants")
  • Users: Individual people who access the platform on behalf of a subscribing organisation (admins, sales reps, managers, etc.)
  • Customer Portal Users: Customers of our subscribers who access the self-service portal
  • Visitors: Anyone who visits our marketing website or public pages
  • Contacts: Individuals whose data is entered into the CRM by our subscribers (leads, customers, contacts)
Note for contacts entered by subscribers If your information has been entered into Ontoor CRM by a business using our service, that business is the data controller for your information. You should contact them directly to exercise your rights regarding that data. Ontoor acts only as a data processor on their behalf.
Part I

Information Ontoor Collects & Controls

Data we collect about subscribers, users, and visitors to operate, secure, and improve our Services.

What We Collect

Information You Provide to Us

Account & Registration

  • Organisation name, size, and industry
  • Administrator's name, work email address, and phone number
  • Billing contact name, address, and country
  • Payment method details — processed and tokenised by our payment provider. We do not store full card numbers.
  • Subscription plan, contract duration, and pricing tier

User Profiles

  • Full name, work email address, and phone number
  • Profile photo (optional, uploaded by the user)
  • Job title and department
  • Hashed password (we use bcrypt — plaintext passwords are never stored)
  • Role assignments and permission settings within the platform

Support & Communications

  • Content of support tickets, chat messages, and email correspondence with our team
  • Survey responses and feature feedback
  • Onboarding call recordings (only with prior consent)

Information Collected Automatically

When you use our Services, we automatically collect certain technical information:

  • Log data: IP address, login timestamps, pages accessed, actions taken, features used
  • Device information: Browser type and version, operating system, screen resolution, language setting
  • Session data: Duration of sessions, navigation paths, error events
  • Performance data: Response times and API call logs (used for debugging and improvement)
No third-party tracking within the app Inside the authenticated Ontoor CRM application, we do not load Google Analytics, Facebook Pixel, or any cross-site advertising trackers. The automatic collection above is first-party only, purely for operating and securing the service.

Information We Do NOT Collect

  • Biometric data of any kind
  • Full payment card numbers (handled exclusively by our payment processor)
  • Social media profile data without explicit consent
  • Sensitive personal categories (health, religion, political opinions, racial origin) — unless your organisation voluntarily enters such data into the system
  • Data about children under 18 (our service is B2B only)

How We Use Your Information

Purpose Data Used Legal Basis
Provision and operation of the CRM service Account data, user profiles, usage logs Contract performance
User authentication, session management, and access control Email, password hash, role assignments Contract performance
Transactional emails — password resets, assignment notifications, invoice alerts Name, email address Contract performance
Subscription billing and payment processing Billing contact data, payment token Contract performance
Customer support, troubleshooting, and onboarding Account data, support ticket content, usage logs Legitimate interest
Security monitoring, fraud detection, and abuse prevention IP addresses, login logs, activity patterns Legitimate interest
Product improvement, bug fixing, and feature development (using anonymised/aggregated data) Anonymised usage telemetry Legitimate interest
Product update announcements and release notes Name, work email Legitimate interest (opt-out available)
Compliance with legal obligations (tax records, court orders) Billing records, activity logs Legal obligation
Enforcing our Terms of Service and resolving disputes Account data, communications Legitimate interest / Legal obligation
What we will never do with your information: Sell or rent it to third parties · Use it for advertising or retargeting · Share it with data brokers · Use your business data to train AI or machine learning models · Permit Ontoor employees to access it for their personal benefit.
Part II

Information Ontoor Processes on Your Behalf

The business data your organisation stores in Ontoor CRM — leads, customers, deals, invoices, and more. You own this data. We are its custodian.

Your Business Data (Service Data)

As part of using Ontoor CRM, your organisation stores and manages business data within the platform. This includes but is not limited to:

  • Lead records — names, contact details, source, status, notes, activities
  • Customer and contact records — company profiles, billing addresses, primary contacts
  • Sales opportunities — deal values, stages, expected close dates, probability
  • Quotations and invoices — line items, amounts, payment records
  • Email communications — sent emails, campaign content, email logs
  • Documents — uploaded files linked to records
  • Internal notes and activity logs
  • Any other information entered by your users into the platform

We refer to this collectively as "Service Data."

Data Ownership

You own your Service Data — completely and unconditionally. Ontoor claims no intellectual property rights over the data you store in our platform. We do not use your Service Data for any purpose other than providing the Services to you.

As the data controller for your Service Data, your organisation is responsible for:

  • Ensuring you have the legal right to store any personal data you enter into the system
  • Providing appropriate privacy notices to the individuals whose data you store (your leads, customers, and contacts)
  • Responding to requests from those individuals to access, correct, or delete their data
  • Complying with applicable data protection laws in your jurisdiction

Ontoor acts as a data processor for Service Data, processing it only on your documented instructions. We provide a Data Processing Addendum (DPA) for enterprise customers — contact privacy@ontoorsolutions.com to request one.

Data Export & Portability

You can export your Service Data at any time while your subscription is active, in standard formats (CSV, Excel, PDF). Upon cancellation of your subscription, we provide a 30-day grace period during which you may export all your data before it is permanently deleted from our systems.

After the 30-day period, all Service Data associated with your account is permanently and irreversibly deleted from production databases and from backups within a further 30-day window.

Our Access Policy

Access to your Service Data by Ontoor personnel is strictly controlled and limited to specific circumstances:

Circumstance Who Can Access Logged?
Resolving a support ticket where you have granted access Authorised support engineers only Yes
Investigating a security incident or data breach Security team only Yes
Legal obligation (court order, regulatory request) Legal team + management Yes
Technical maintenance causing unavoidable data exposure (extremely rare) Senior engineering only, under strict controls Yes

Ontoor employees are contractually bound by confidentiality obligations and receive data privacy training. Access to production systems is granted on a least-privilege basis and reviewed periodically.

We will notify you If we receive a government or law enforcement request for your Service Data, we will promptly notify you (unless legally prohibited from doing so) so that you may seek appropriate legal protection.

Data Sharing & Third Parties

Ontoor has never sold your personal information to any third party. We never will. We do not share data for advertising, data broker, or any commercial purpose beyond what is strictly necessary to deliver the Services.

Sub-processors

We use a limited number of trusted third-party service providers ("sub-processors") to help operate the platform. Each is bound by a Data Processing Agreement, is prohibited from using your data for their own purposes, and is required to maintain security standards equivalent to or greater than our own.

Category Purpose Data Involved
Cloud infrastructure & hosting Server hosting, database storage, file storage All platform data — encrypted at rest and in transit
Transactional email delivery (SMTP provider) Sending password resets, notifications, invoices, campaign emails Recipient email addresses, sender name, email content
Payment processor Subscription billing and invoicing Billing contact name, email, amount — card data handled entirely by provider

We do not share data with advertising networks, social media platforms, or analytics companies.

Legal Disclosures

We may disclose personal data where required by law, court order, or legitimate government authority. Before doing so, we will:

  • Verify the legal validity of the request
  • Notify you where legally permissible
  • Disclose only the minimum data required

Business Transfers

If Ontoor undergoes a merger, acquisition, or sale of all or part of its assets, your data may be transferred to the successor entity. We will provide at least 30 days' notice via email and within the application, and will ensure the receiving entity provides equivalent privacy protections. You will retain the right to delete your data if you do not wish for it to be transferred.

Data Security

We take data security seriously at every layer of the platform. Below are the technical and organisational measures we have in place.

TLS Encryption in Transit
All data between your browser and our servers is encrypted using TLS 1.2 or higher. Unencrypted HTTP connections are rejected.
Encryption at Rest
Database storage and file uploads are encrypted at rest. Passwords are hashed using bcrypt — never stored in readable form.
Tenant Data Isolation
Every organisation's data is logically segregated using tenant-scoped queries. No tenant can ever view another tenant's data.
Role-Based Access Control
Granular module-level permissions ensure users access only what their role authorises. Admins can configure permissions per role.
Audit Trails
All logins, data changes, and administrative actions are logged with timestamp, user identity, and IP address for full accountability.
Session Security
Sessions expire after inactivity, are invalidated on logout, and are protected against CSRF using per-request tokens.
Automated Backups
Database backups are taken daily and retained for 30 days, enabling recovery in the event of data loss or corruption.
Least-Privilege Access
Internal system access for Ontoor staff is granted on a need-to-know basis, reviewed quarterly, and fully audited.
Vulnerability Management
We monitor for known vulnerabilities in our dependencies, apply security patches promptly, and conduct periodic code reviews.
Breach Response
We maintain an incident response plan. In the event of a breach affecting your data, we will notify you within 72 hours of discovery.
Security is a shared responsibility While Ontoor secures the infrastructure and application layer, you are responsible for securing access credentials, managing user permissions appropriately, and ensuring your users follow sound password practices. We strongly recommend enabling all available access controls within the platform.

Data Retention

We retain personal data for as long as necessary to fulfil the purpose for which it was collected, or as required by law.

Data Category Retention Period Reason
Active account and user data Duration of active subscription Service delivery
Service Data (leads, customers, invoices, etc.) Duration of subscription + 30-day post-cancellation export window Data portability; then permanently deleted
Billing records and payment history 7 years from transaction date Legal / tax / accounting obligation
Security and access audit logs 12 months rolling Security monitoring and incident investigation
Support communications 3 years from resolution Service quality assurance and dispute resolution
Email communication logs (sent via platform) 12 months Deliverability troubleshooting
Anonymised, aggregated usage analytics Indefinite Product improvement — no personal identifiers retained

After the applicable retention period, data is securely and permanently deleted or anonymised such that it can no longer be attributed to an individual.

You may request earlier deletion of your personal data by contacting us at privacy@ontoorsolutions.com, subject to any legal retention obligations.

Your Rights

You have the following rights over your personal data. We honour these rights regardless of your location or jurisdiction.

Access
Request a copy of the personal data we hold about you, and information about how we process it.
Rectification
Ask us to correct any inaccurate or incomplete personal data we hold. Users can update most information directly in their profile.
Erasure
Request deletion of your personal data ("right to be forgotten") where we have no overriding legal obligation to retain it.
Portability
Receive a copy of your data in a structured, machine-readable format (CSV/Excel) for transfer to another service.
Restriction
Request that we pause processing your data in certain circumstances, such as while you contest its accuracy.
Objection
Object to processing based on legitimate interest, including unsolicited product communications. We will stop unless we have compelling grounds.
Withdraw Consent
Where processing is based on consent (e.g., newsletters), withdraw it at any time. This does not affect the lawfulness of prior processing.
Automated Decisions
Not to be subject to solely automated decisions that produce significant legal effects. We do not make such decisions about individuals.

How to Exercise Your Rights

Email us at privacy@ontoorsolutions.com with the subject line "Privacy Request — [Right Type]". We will acknowledge your request within 3 business days and fulfil it within 30 days (or inform you if more time is needed under applicable law, up to a maximum of 60 days).

We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests.

If you are unsatisfied with our response, you have the right to lodge a complaint with your relevant data protection supervisory authority.

Cookies & Tracking Technologies

Ontoor CRM uses a minimal, functional-only set of cookies. We do not use cookies for advertising, cross-site tracking, or third-party analytics inside the application.

Name Type Purpose Duration
ontoor_session Essential Maintains your authenticated session across page loads. Without this, you would need to log in on every click. Session — expires on logout or browser close
XSRF-TOKEN Essential (Security) Cross-Site Request Forgery (CSRF) protection token. Validates that form submissions and API requests originate from our application. Session
sidebarCollapsed Functional (localStorage) Remembers whether you have collapsed the navigation sidebar. Stored in your browser's localStorage — not transmitted to our servers. Persistent until manually cleared

The first two cookies are strictly necessary for the application to function and cannot be disabled while using the service. The localStorage preference is entirely local to your browser.

Our marketing website (separate from the application) may use analytics cookies to understand visitor behaviour. These are subject to your browser's cookie consent mechanism and can be declined.

International Data Transfers

Ontoor is headquartered in India and primarily stores data on servers in the region selected during account setup. If your organisation is based in the European Economic Area (EEA), UK, or another jurisdiction with cross-border transfer restrictions, data may be transferred outside your region.

In all such cases, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) — the European Commission's approved clauses for lawful data transfer
  • Data Processing Agreements (DPAs) — binding agreements with all sub-processors covering GDPR-equivalent obligations
  • Adequacy decisions — relying on jurisdictions recognised as providing equivalent protection where available

Enterprise and mid-market customers may request a signed Data Processing Addendum (DPA) by contacting privacy@ontoorsolutions.com. This is available at no charge.

AI & Automation

Ontoor CRM includes workflow automation and rule-based features (such as lead assignment rules and scheduled campaign sending). These are deterministic, rule-based automations configured by you — not AI systems making independent decisions about individuals.

We do not train AI models using your data. Your Service Data — including leads, customer records, emails, and business information — is never used to train, fine-tune, or improve any artificial intelligence or machine learning model, whether operated by Ontoor or any third party.

If we introduce AI-powered features in the future (such as predictive lead scoring or smart suggestions), we will:

  • Update this privacy policy in advance with 30 days' notice
  • Make any AI features opt-in, not opt-out
  • Clearly disclose which data is used and how
  • Never use data from one customer to benefit another

Changes to This Policy

We may update this Privacy Policy from time to time as our practices evolve, as our product grows, or to comply with legal requirements.

When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify all active subscribers by email at least 30 days before the changes take effect
  • Display a notice within the application
  • For significant changes affecting data rights, require acknowledgement before continued use of the platform

For minor changes (grammar, clarifications, non-substantive edits), we will update the page without individual notice.

Previous versions of this policy are available upon request.

Contact Us & Data Processing Addendum

For any questions, concerns, or requests relating to this Privacy Policy or how we handle your data, please reach out through the channels below. We take privacy enquiries seriously and commit to a substantive response.

Privacy Requests
Data access, erasure, portability, correction
privacy@ontoorsolutions.com
General Support
Platform issues, billing, account help
support@ontoorsolutions.com
DPA Requests
Data Processing Addendum for enterprise
privacy@ontoorsolutions.com
CompanyOntoor Solutions Pvt. Ltd.
Websitewww.ontoorsolutions.com
Privacy emailprivacy@ontoorsolutions.com
Response timeAcknowledgement within 3 business days; resolution within 30 days
DPA availableYes — available on request at no charge