1. Who is responsible?
TorunICT is the provider of TorunICT CRM, available at crm.torunict.com. “We” and “us” refer to TorunICT. This statement applies to the CRM, platform administration, support and the features an organisation uses to process its business records and email.
TorunICT is the data controller for data relating to our own customer relationships, services and platform security. For personal data that a customer organisation enters or imports into its business records, that organisation is generally the data controller and TorunICT acts as a data processor under its instructions and the data processing agreements.
Are you a customer, supplier or employee of an organisation that uses the CRM? Please contact that organisation first with questions about its records. TorunICT supports it in handling privacy requests.
2. What personal data is processed?
The data depends on the features used and the information you or your organisation adds:
- Account and organisation: name, email address, user role, company details, settings, securely stored login credentials and subscription information.
- Contacts and business records: contact persons, addresses, telephone numbers, email addresses, quotes, invoices, work orders, appointments, notes, documents and attachments.
- Payments and bank data: account numbers, amounts, payment statuses and, when a bank connection or import is activated, account and transaction data including descriptions and counterparty details.
- Email connections: the connected email address, account identification, granted permissions, access tokens and the email data needed for sending messages and enabled invoice import.
- Support and usage: support requests, replies, attachments, administrative actions taken, usage times, IP addresses and technical error and security data.
This information comes from you, authorised users in your organisation, imported files, connected services and use of the platform. Information about third parties may, for example, appear in an invoice or an incoming email.
The CRM is intended for business administration. Do not add special categories of personal data, such as medical information, unless necessary for a lawful use.
3. For what purposes and on what legal bases?
We use personal data to manage accounts, provide the agreed CRM services, support organisations, invoice our own services and keep the platform secure and available.
- Contract: to the extent necessary to perform a contract with you or to take steps at your request before entering into one.
- Legitimate interests: for business contacts, appropriate support, business operations, limited usage insights and security. We balance these interests against your rights and limit processing to what is necessary.
- Legal obligation: for example, for our own tax records or a legally valid request for information.
- Consent: for processing that requires consent. You can withdraw it without affecting the lawfulness of earlier processing.
When we process data on behalf of a customer organisation, that organisation determines the purposes and valid legal basis. Permission to connect a mailbox technically is not, in itself, a legal basis for every subsequent use of third-party data.
An email address and necessary account information are required to use the CRM. Email and bank connections are optional; without the required access, the corresponding features are unavailable.
4. Google and Gmail connection
An authorised administrator can connect a Google account through Google's sign-in and consent screen. The Google password is entered there and is not provided to TorunICT. This connection supports email features within the CRM.
What access does the connection request?
- Account identification: account identification and email address, to connect the correct mailbox to the organisation.
- Sending email: the
gmail.sendpermission, to send messages and documents from the connected account as directed by the organisation. - Reading email, only when inbox import is enabled: the
gmail.readonlypermission, to retrieve relevant emails and PDF attachments for accounts payable.
The read permission technically provides access to more mailbox data than invoices alone. The application must limit that access to finding, displaying and processing relevant administrative messages. This may involve processing senders, subjects, dates, message identifiers, message content and attachments. Imported PDFs and the invoice details extracted from them become part of the business records.
Sending includes the recipients, any CC recipients, the subject, message text and selected attachments. Access tokens allow the connection to be used and renewed without signing in to Google each time. The inbox feature does not request permission to delete or modify messages.
Limited use of Google data
TorunICT will use and transfer information obtained through Google APIs in accordance with the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
This data may only be used for the visible, permitted features of the CRM. Sale, advertising, advertising profiling, credit assessment and the development, improvement or training of general-purpose AI or machine learning models are excluded. This also applies to derived data and transfers to service providers.
Transfers are permitted only for an authorised user-facing feature with consent, necessary security purposes, legal obligations or a business transfer with prior express consent. Access by our employees or service providers requires specific, documented consent, unless necessary for security or legal reasons, or where anonymised and aggregated data is used for internal business operations. These restrictions also apply to our contractors and legal successors.
5. Microsoft and Outlook connection
The Microsoft connection uses Microsoft's sign-in and consent screen. TorunICT does not receive the Microsoft password. Depending on your organisation, consent from a Microsoft administrator may be required.
The connection requests User.Read to identify the account, Mail.Send to send messages and offline_access to renew the connection. Mail.Read is requested only when inbox import is enabled.
When sending a message, the recipients, subject, message text and attachments are provided to Microsoft. For invoice import, message data and relevant PDF attachments are retrieved. When selecting invoices, data from other inbox messages may also be viewed. The data serves the same administrative purposes described above and may not be used for advertising, sale or training general-purpose AI models.
The inbox feature does not request write permissions for received messages. Storage of original and sent messages within your Microsoft account is also governed by your agreements with Microsoft.
6. Who may receive the data?
Data may be shared only for a specific purpose, with authorised recipients and to the extent necessary. Depending on the feature used, these may include:
- Your organisation and recipients: authorised CRM users and the recipients to whom your organisation sends documents or messages.
- Hosting, administration and backups: infrastructure and storage providers. Google Drive may be used for external backups; such backups must be encrypted before transfer.
- Google, Microsoft and other email providers: for the email connections configured by your organisation and for message delivery.
- Document recognition: when OCR is used, documents or images of document pages may be submitted to Amazon Web Services through Textract to recognise invoice fields. This is permitted only under agreements that allow processing for this feature and exclude use for general-purpose model training. Local document recognition is an alternative.
- Optional banking and payment features: for example, Synci and the bank concerned for a bank connection, or Mollie for a payment feature. The exchange must be limited to the necessary account, transaction or payment data.
- Address and routing features: PDOK for address data, OpenRouteService for route coordinates and Google Maps when a map or route is opened.
- Competent authorities and advisers: where necessary to comply with the law or handle a legal claim, subject to the additional restrictions on mailbox data.
Parties that process personal data on our behalf must be covered by data processing agreements, confidentiality obligations and appropriate security. Providers may also act as data controllers in their own right for their own accounts and services.
Processing outside the European Economic Area
International service providers may process data outside the EEA, including in the United States. This is permitted only with a valid legal basis for the transfer and the necessary safeguards, such as an applicable adequacy decision or the European standard contractual clauses with supplementary measures where needed. Consent to an email connection does not replace these safeguards. You can request information about the applicable safeguards, or a copy of them, through our privacy contact.
7. Security and access
TorunICT is responsible for appropriate technical and organisational measures tailored to the sensitivity of the data and the risks. Implementation of this policy is subject to requirements including:
- Secure connections, encrypted storage of OAuth tokens and protection of keys and other login credentials.
- Encryption of stored mailbox data and attachments covered by the email provider's requirements, and of external backups.
- Separation between customer organisations, role-based access and restriction of administrative access to authorised persons.
- Logging and review of relevant administrative and security actions, timely updates and procedures for incidents and recovery.
General email logging is intended for delivery status and error investigation. It must be limited to necessary data such as sender, recipient, subject, time and sending status; message text, attachments, passwords and access tokens do not belong in these logs. Human access to Google data is always subject to the additional restrictions in section 4.
8. How long may data be retained?
Data must not be retained longer than necessary for its purpose. The retention limits below apply to TorunICT CRM. A statutory retention obligation, specific dispute or legally valid retention instruction may require a targeted exception; this must not automatically result in retaining all account or mailbox data.
| Data | Retention limit or criterion |
|---|---|
| Account and customer records | For as long as the services or a valid instruction require. After termination, a maximum of 30 days for agreed export and deletion from the active environment, unless a specific exception applies. |
| Imported invoices and attachments | According to the necessary retention period for business records determined by the customer organisation. Disconnecting the mailbox does not end that retention period. |
| OAuth access tokens | Only for as long as the connection is necessary and permitted. On disconnection, stored access tokens must be removed from the active connection. |
| Connection and temporary import data | No longer than necessary for the connection or import; temporary document copies must be deleted after processing. Limited technical logs may be retained for a maximum of 90 days. |
| Email, security and usage logs | A maximum of 90 days. Only relevant data may be kept longer where demonstrably necessary for an ongoing incident, dispute or legal obligation. |
| Support requests and attachments | A maximum of 24 months after resolution, unless earlier deletion is possible or a specific exception applies. |
| Backups | A maximum of 90 days per backup. Deleted data may therefore remain temporarily in a restricted recovery copy, for no more than 90 days after deletion from the active environment. |
| Our own statutory records | Only the data subject to an applicable statutory retention period, for the duration of that period. |
Backups may be used only for recovery and continuity. After restoration, previously completed deletions and revoked connections must be reapplied. Manual and occasional backups are subject to the same retention policy.
9. Revoking access and deleting data
An authorised administrator can disconnect the email connection through the CRM's email settings. You can also revoke permission for TorunICT CRM through the connected apps or connections in your Google or Microsoft account. For business accounts, your organisation's administrator can help.
Disconnecting is different from deleting business records. Previously imported invoices, PDFs and necessary logs may still be held by your organisation. Disconnecting does not delete original messages held by the email provider.
Delete business data through an authorised user in your organisation or submit a request to info@torunict.com. Specify the organisation, account and data concerned. Do not send passwords, access tokens or the full contents of a mailbox. We assess the applicant's authority, TorunICT's role and any retention obligations.
11. Automated processing
Features such as invoice recognition and bank transaction matching can automatically select and extract data, make suggestions or create links between business records. They are intended to support administration. Authorised users must be able to check and correct the results.
This policy does not permit mailbox data to be used for creditworthiness assessments, advertising or general-purpose model training. Decisions producing legal effects or similarly significant effects on individuals must not be based solely on this administrative automation.
12. Your privacy rights
Depending on the processing and the legal conditions, you can request access to, rectification, erasure, restriction of processing or portability of your personal data. You can object to processing based on a legitimate interest and withdraw consent you have given.
Send your request to info@torunict.com. If it concerns a customer organisation's records, that organisation may need to handle the request. For identity verification, we ask only for the information necessary for that purpose.
In principle, you will receive a response within one month. If the law permits an extension because of the complexity or number of requests, you will receive an explanation of the reason and the additional time required within that first month. Rights are not unlimited: statutory retention obligations and the rights of others may be relevant.
You can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or another competent privacy supervisory authority. You do not have to complain to TorunICT first.
13. Changes and contact
We may amend this statement when our services, applicable rules or processing activities change. The version date at the top will then be updated. You must be informed in a timely manner about material changes affecting your data. If new processing requires consent, that consent must be requested before the processing begins.
Questions about this statement or your data? Email info@torunict.com and mention “Privacy TorunICT CRM”.