Legal
Privacy Policy
Effective September 7, 2026
This policy explains how VolaCRM handles information when you visit our websites, create an account, use a tenant or workspace, connect ChatGPT or another authorized client, or contact us.
1. Information we process
Depending on how you use VolaCRM, we process account details such as your name, email address, tenant membership and authentication identifiers; workspace content such as contacts, resources, activities, tags, workflows, custom fields, messages, files, application source and configuration; connection information such as approved scopes, workspace allow-lists, client identifiers, grant status and expiry; and operational information such as timestamps, request identifiers, audit events, device/browser information, network addresses and error diagnostics.
OAuth access tokens, authorization codes and similar credentials are handled only to provide authentication and authorization. VolaCRM does not intentionally expose them in application responses or logs.
2. Why we use information
We use information to provide and secure the service, authenticate users, enforce tenant and workspace boundaries, run customer-created applications and templates, process authorized integrations, maintain audit and recovery functions, prevent abuse, troubleshoot failures, communicate about the service, and comply with law.
3. Storage and service providers
VolaCRM stores and processes service data using secure AWS cloud infrastructure and uses appropriate technical and organizational safeguards. We may use AWS and other carefully selected providers for hosting, authentication, delivery, monitoring, support and related service operations. These providers process information only for the services they supply to us and under applicable contractual protections.
No online service can guarantee absolute security. Customers must configure permissions carefully, keep accounts secure, and review who can access each tenant and workspace.
4. Highly sensitive information
General-purpose custom fields, contacts, activities, conversation content, files and AI-created applications must not be treated as a password manager, payment vault, medical-record system or regulated-data store. Users and custom-application creators are responsible for choosing appropriate data and complying with applicable confidentiality, retention and legal requirements.
5. Tenant administrators and custom applications
Your tenant owner or administrator controls workspace membership, permissions, connected applications and much of the content stored in the tenant. Custom applications may collect or transform data according to the functionality their creators implement. Contact the relevant tenant administrator about a custom application's data practices. VolaCRM provides the underlying platform and official templates; it does not determine the purpose or content of independently created custom applications.
6. ChatGPT and connected services
When you authorize a connection, VolaCRM records the tenant, client, approved scopes, selected workspace allow-list, resource audience, issue time, expiry and revocation status needed to enforce that authorization. The connected service receives only information returned by tools you permit it to use. Publishing applications requires separate permission and explicit human action. You can revoke individual connections in VolaCRM and may also ask us to revoke account connections.
Connected third parties process information under their own terms and privacy policies. Review those policies before authorizing a connection.
7. Sharing and disclosure
We do not sell personal information. We disclose information to service providers as needed to operate VolaCRM; to tenant members and connected services according to authorized permissions; during a corporate transaction subject to appropriate safeguards; or when required to protect users, enforce our terms, respond to lawful process, or comply with law.
8. Retention
We retain information for as long as needed to provide the service, meet contractual and legal obligations, protect security, resolve disputes and maintain appropriate records. Retention periods vary by data type. Tenant content may remain until the tenant owner deletes it or closes the account, subject to backups, legal holds and technical deletion cycles. Revoked connection and audit metadata may be retained to demonstrate and enforce security events.
9. Your choices and rights
You may update account information, manage tenant data and permissions, revoke connected applications, and request access, correction, export or deletion where applicable. Some requests must be made through your tenant administrator. We may verify identity and retain information where law, security or legitimate recordkeeping requires it.
10. International processing
VolaCRM and its providers may process information in countries other than yours. Where required, we use appropriate safeguards for international transfers.
11. Children
VolaCRM is not directed to children acting independently. A parent, guardian, school or other responsible organization must authorize and manage any use involving a child and must avoid storing unnecessary information about minors.
12. Changes and contact
We may update this policy as the service changes. We will publish the revised policy here and update its effective date. Material changes may also be communicated through the service.
Questions and privacy requests: contact@volacrm.com.