BSC
Big Simple CRM

Privacy Policy

Version 2 · Updated 2026-08-04
Big Simple CRM Privacy Policy Last updated: August 2025 1. Who We Are Big Simple CRM ("BSC", "we", "us") provides an intelligence-led customer relationship management platform for real-estate brokerages. This Privacy Policy explains how we collect, use, protect and share information when you use the platform. 2. Our Role: Processor and Controller For the lead, client and communication data you and your team enter into your workspace, BSC acts as a data PROCESSOR — you (the brokerage) are the data CONTROLLER. For account, billing and product-usage data, BSC acts as a controller. We process workspace data strictly on your documented instructions. 3. Information We Process • Account data — names, work emails, roles, and authentication credentials of your team members. • Workspace data — leads, contacts, communications, notes, pipeline stages, documents and activity you create inside your workspace. • Usage & device data — log data, IP address, browser type and feature usage, used to secure and improve the service. • Billing data — plan, subscription status and payment references. Full card details are handled by our PCI-compliant payment providers, never stored by BSC. 4. How We Use Information • To provide, operate and secure the platform. • To generate workspace intelligence (health, performance and pipeline analytics). • To deliver transactional and lifecycle emails you have configured. • To provide support and to comply with legal obligations. We do NOT sell personal data. We do NOT use your workspace client data to train third-party AI models. 5. Role-Based Access & Client Privacy Access to personal data is enforced server-side by role: • Admins, Managers and Brokers may access full client contact information within their permitted scope. • Strategy (intelligence-only) roles receive analytics WITHOUT access to raw client contact details — names, phone numbers and emails are masked, and communication content is withheld. • Integration credentials, API keys and secrets are restricted to Company Admins and are ALWAYS masked in the interface. 6. Artificial Intelligence (Aiden) Aiden, our AI assistant, operates strictly within the permissions of the logged-in user. Aiden can never reveal data or perform actions the user could not perform manually, and never exposes secrets or credentials. 7. Sub-Processors We use vetted sub-processors for hosting, email delivery, payment processing and AI services. Each is bound by contractual data-protection obligations. A current list is available on request via privacy@bigsimplecrm.com. 8. Data Retention Workspace records are retained for the life of your workspace unless you request deletion. Queued emails are retained for delivery and audit. On workspace closure, data is deleted or anonymised within a commercially reasonable period. 9. Security We apply defence-in-depth: encrypted transport (TLS), role-based access control, secret masking, signed webhooks, and least-privilege service design. No method is 100% secure, but we continuously harden the platform. 10. International Transfers Where data is processed outside your region, we rely on appropriate safeguards consistent with applicable data-protection law. 11. Your Rights Subject to applicable law, individuals may request access, correction, deletion or export of their personal data. As BSC is a processor for workspace data, such requests should be directed to the relevant brokerage (controller); we will assist. 12. Contact Questions about this policy or your data: privacy@bigsimplecrm.com.

← Back to Trust Center·Home