Legal
Privacy Policy
Last updated: 12 June 2026
This policy explains how Beagle CRM collects, uses, and protects personal data, and the rights you have under UK data protection law (the UK GDPR and the Data Protection Act 2018).
Who we are
Beagle CRM is operated by Beagle Software Limited (company number 15815186), registered in England and Wales. For anything in this policy you can contact us at hello@beaglecrm.uk.
Controller and processor
For the personal data of the people who run a Beagle CRM account (our customers' staff), we are the data controller. For the personal data your organisation loads into the CRM about its own contacts, leads, and customers, your organisation is the controller and Beagle Software Limited acts as a data processor on your instructions. Business customers can request a Data Processing Agreement (DPA) at hello@beaglecrm.uk.
What we collect
- Account data — name, email address, and authentication details of the people who sign in.
- Customer records you enter — contacts, leads, companies, notes, tasks, invoices, and related business data.
- Billing data — subscription and payment status (card details are handled by Stripe, not stored by us).
- Usage and technical data — log data, IP address, and device/browser information needed to run and secure the service.
- Analytics data (consent-based) — if you opt in to statistics cookies, our own in-house analytics records the pages you view, an anonymous first-party visitor identifier, the referring site, and coarse browser/device information. This data stays in our systems and is not shared with any third party. We never store your IP address, and raw analytics records are deleted after 90 days (anonymous aggregate counts are kept longer).
Why we use it (lawful basis)
- Contract — to provide the CRM you have signed up for.
- Legitimate interests — to secure the service, prevent abuse, and improve the product.
- Legal obligation — to meet accounting, tax, and other legal duties.
- Consent — for any non-essential cookies and optional marketing, which you can withdraw at any time.
Subprocessors
We use a small number of trusted providers to run the service. Each is bound by a data processing agreement:
- Stripe — subscription billing and card processing.
- SendGrid (Twilio) — transactional and campaign email delivery.
- Cloudflare — content delivery, DNS, and encrypted backup storage (R2).
- Our hosting provider — UK/EU-based application and database hosting.
Where your data is stored
Your data is hosted on servers in the UK/EU and backed up to encrypted Cloudflare R2 storage. Where any provider processes data outside the UK, that transfer is covered by an appropriate safeguard (such as the UK International Data Transfer Addendum).
How long we keep it
We keep account and customer data for as long as your account is active. After an account is closed, data is held for a short grace period and then deleted, except where we must keep records (for example, invoices) to meet legal obligations.
Your rights
Under UK data protection law you have the right to access, correct, erase, restrict, and port your personal data, and to object to certain processing. To exercise any of these, contact hello@beaglecrm.uk. If your data was entered by an organisation using Beagle CRM, we will pass your request to that organisation as the controller.
Cookies
We only set essential cookies by default. See our Cookie Policy for details and to manage your preferences.
Complaints
If you have a concern we have not resolved, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Changes to this policy
We may update this policy from time to time. Material changes will be notified to account holders by email or in-app before they take effect.