Compliance
GDPR & Data Protection
How Beagle CRM helps you meet your obligations under the UK GDPR and the Data Protection Act 2018.
Beagle CRM is built and operated by Beagle Software Limited in the United Kingdom. Data protection is not a bolt-on for us — the tools you need to respond to your own customers' requests are built into the product. This page summarises how we handle personal data and support your compliance. The binding detail lives in our Privacy Policy and Data Processing Agreement.
Controller and processor: who does what
For the personal data your organisation loads into Beagle CRM about its own contacts, leads, and customers, you are the data controller and we are the data processor — we process it only to run the service and only on your instructions. For your own account and billing details, we act as controller. This split is set out in full in our DPA.
Your data rights
Under the UK GDPR, data subjects have the right to access, rectify, erase, restrict, and port their personal data, and to object to certain processing. Beagle gives you the tools to act on these on your customers' behalf:
- Access & portability — an administrator can export your organisation's data (customers, contacts, leads, invoices, quotations, sales orders, and tasks) as a set of CSV files, delivered as a secure, time-limited download link.
- Rectification — records are editable throughout the app, so keeping personal data accurate and up to date is straightforward.
- Erasure ("right to be forgotten") — you can anonymise a customer, which removes their personal details (name, business name, company/VAT/DUNS numbers, email, address, phone numbers, and website) and deletes their contacts and activity history.
- Restriction & objection — marketing consent is recorded per recipient, and every marketing email carries a one-click unsubscribe that suppresses further contact.
Where a customer has invoices or other financial records, the details we're legally required to keep for accounting purposes are preserved on those documents (a billing snapshot), as permitted under UK GDPR Article 17(3)(b).
Data retention
We don't keep personal data longer than we need it. In summary:
- A deleted account is held for a short grace period (14 days) before it is permanently purged, so accidental deletions can be reversed.
- For paid subscriptions, account data is retained until the end of the billing period plus 30 days, then permanently deleted.
- Raw website analytics are pruned after 90 days; only anonymous, aggregated statistics are kept beyond that.
- Data-export files are available on a short-lived link and are removed shortly after they expire.
Full detail is in our Privacy Policy.
Consent and marketing
Marketing consent and unsubscribe requests are tracked in a per-recipient consent record, with optional double opt-in confirmation. Our website uses only strictly necessary cookies by default — no advertising or tracking cookies are set unless you opt in. See our Cookie Policy.
Sub-processors
To run the service we rely on a small number of vetted sub-processors — for hosting, payments, email delivery, and file storage — each bound by data protection terms. The current list, with each provider's purpose and location, is maintained in our Data Processing Agreement. We give reasonable notice of any change so you can object on reasonable grounds.
How we protect your data
We apply technical and organisational measures appropriate to the risk, including encryption of sensitive data at rest (such as connected mailbox credentials and one-time-password secrets), encryption in transit (enforced HTTPS with HSTS), tenant isolation between organisations, optional two-factor authentication, and encrypted backups with point-in-time recovery. Our primary data store is hosted in the United Kingdom.
Data breaches
If a personal data breach affecting your data occurs, we will notify you without undue delay — and, where the UK GDPR requires it, within 72 hours of becoming aware — with the information you need to meet your own obligations.
Talk to us
Have a data protection question, or need a countersigned DPA? We're happy to help — get in touch. For independent guidance you can also consult the Information Commissioner's Office (ICO).