Loza CRM
Loza CRM
Privacy

Privacy Policy

We respect your data. Without your permission — we do nothing.

Last updated: 26.06.2025
Only with consent
Any actions with your data — only with your explicit permission.
Secure storage
All data is encrypted and stored on secure servers.
Right to deletion
You can request complete deletion of all your data at any time.
Section 1
General provisions

Loza CRM (hereinafter "the Service", "we") is an online CRM system providing services for managing clients, campaigns and analytics. This Privacy Policy describes how we handle and protect user data.

By using Loza CRM, you confirm your agreement with this Policy. If you do not agree — please stop using the service and contact us for data deletion.

This Policy does not apply to users located in the Russian Federation. Separate terms determined by applicable RF legislation apply to users from Russia.
Section 2
Data status: Data Controller and Data Processor

Loza CRM operates under a data responsibility sharing model adopted in international practice (GDPR Article 28):

User — Data Controller. All data that the User enters into the Service (client base, leads, deals, campaigns) belongs exclusively to the User. The User determines the purposes and methods of processing this data.
Loza CRM — Data Processor. The Service acts as a technical storage ("safe") for the User's data. Loza CRM processes data solely according to the User's instructions and for the purpose of ensuring the Service's functionality.
Loza CRM does not use User data (leads, clients, deals) for its own purposes — does not analyze, sell, transfer or use for marketing
Loza CRM is not the owner of User data — all rights to the data belong to the User
The Data Controller / Data Processor model means: your data is your data. Loza CRM is the technical infrastructure that stores and processes it on your instructions, but does not own it.
Section 3
What data we collect

We collect only the data you explicitly provide during registration and use of the service:

Account data: email address, name, password (stored in hashed form)
Work data: client base, deal history, offers, funnels that you enter into the system
Technical data: IP address, browser type, device — for security purposes
Payment data: subscription information (card details are not stored — processed by payment systems)

We do not collect data about you from third-party sources and do not buy databases.

Section 4
Cookies

We use cookies — small text files saved in your browser. Types of cookies used:

Essential — for authorization and session maintenance. Without them the service does not work.
Functional — remember your interface settings (language, theme, filters).
Analytics — collect anonymous visit statistics to improve the service.

Analytics and functional cookies are used only with your consent. You can disable them in your browser settings at any time.

Section 5
How we use your data

As a Data Processor, we use data solely to ensure the technical operation of the Service:

Providing access to the CRM system and all its functionality
Running your client bases, deals, campaigns — exactly as you configure them
Processing payment transactions and subscription management (through Paddle.com Market Ltd.)
Technical support and responses to your inquiries
Ensuring account security and fraud protection
Improving service quality based on anonymous analytics

Loza CRM does not use your data (leads, clients, deals) for its own commercial purposes, does not analyze, sell or transfer it to third parties without your permission.

Section 6
Sharing data with third parties

We do not share your personal data with third parties, except in strictly limited cases:

Only with your consent — for example, when integrating with third-party services at your request
Payment systems — for processing transactions (without sharing passwords or unnecessary data)
Legal requirements — only when there is a lawful requirement from competent authorities

We do not cooperate with advertising networks and do not share data with marketing agencies.

Section 7
Data protection

To protect your data we apply:

Encryption of all transmitted data via TLS 1.3
Password hashing with salt (bcrypt / argon2)
Data isolation for each account at the database level
Regular encrypted backups
Restricted data access — only authorized technical personnel
Suspicious activity monitoring and automatic blocking on threats
Section 8
Data retention

Your account data is stored for the entire duration of service use.

After account deletion at your request — data is deleted within 30 days (backup recovery period). After this period, all data is permanently deleted.

Exception — data whose retention is required by law (e.g., financial records): stored strictly within legal timeframes.

Section 9
Your rights

You have the full right at any time to:

Request access to all data we hold about you
Correct inaccurate or outdated data
Request complete deletion of your account and all associated data
Export your data in a standard format
Withdraw consent for processing non-essential data (analytics, cookies)
Opt out of any communications except critical service notifications

To exercise any of these rights, write to support@loza-crm.com — we reply within 24 hours.

Section 10
Changes to the policy

We may update this Privacy Policy. You will be notified of significant changes:

by email provided during registration
via notification in your CRM dashboard

The last updated date is always shown at the beginning of the document. Continued use of the service after an update means acceptance of the new version of the Policy.

Questions about privacy?

If something is unclear or you have questions about data processing — write to us.