Legal

GDPR Compliance

Last updated: July 25, 2026

MrGeeksCRM is committed to the General Data Protection Regulation (GDPR) and equivalent laws such as the UK GDPR. This page explains how we meet those obligations — both for the data we control and the customer data we process on your behalf — and how you can exercise your rights. It supplements our Privacy Policy.

1. Controller and Processor Roles

  • MrGeeksCRM as controller — for your account details, billing records, and usage data, we decide how and why the data is processed.
  • MrGeeksCRM as processor — for the content your workspace stores in the platform (customer contacts, chat conversations, deals, and documents), the workspace owner is the controller. We process that data only on documented instructions, as set out in our Data Processing Agreement.

2. Data Processing Agreement (DPA)

We offer a DPA incorporating the GDPR's Article 28 processor terms and, where relevant, Standard Contractual Clauses. Customers who need a countersigned copy can request one at legal@mrgeekscrm.com.

4. Data Subject Rights

Under the GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you;
  • Rectification — correct inaccurate or incomplete data;
  • Erasure— request deletion ("right to be forgotten") where there is no overriding reason to keep it;
  • Restriction — limit how we process your data in certain circumstances;
  • Portability — receive your data in a structured, machine-readable format;
  • Objection — object to processing based on legitimate interests or used for direct marketing;
  • Withdraw consent — at any time, without affecting prior processing;
  • Complain — lodge a complaint with your local supervisory authority.

How to exercise your rights

Email privacy@mrgeekscrm.com and we will respond within one month. Many requests can also be handled directly from your account settings (profile edits, data export, account deletion). If your data was entered into MrGeeksCRM by one of our customers, direct your request to that business — as their processor we will assist them in fulfilling it.

5. Sub-Processors

We use a limited set of vetted sub-processors for hosting, payment processing, email delivery, error monitoring, and messaging-channel connectivity (including Meta for WhatsApp, Instagram, and Messenger). Each is bound by a written agreement imposing data protection obligations no less protective than our DPA. A current list is available on request at legal@mrgeekscrm.com, and customers are notified in advance of material changes.

6. International Transfers

Where personal data is transferred outside the EEA, the UK, or Switzerland, we use recognised safeguards — primarily the European Commission's Standard Contractual Clauses and the UK Addendum — together with supplementary technical measures such as encryption in transit.

7. Security Measures

  • Encryption of data in transit (TLS);
  • Role-based access control and workspace-level permissions;
  • Audit logging of administrative actions;
  • Least-privilege access for our personnel, under confidentiality obligations;
  • Continuous monitoring, error tracking, and regular backups;
  • Vendor due diligence and data processing agreements.

8. Data Breach Notification

We maintain an incident response process. Where a personal data breach is likely to result in a risk to individuals, we will notify affected customers without undue delay after becoming aware of it, and in any event within the timeframes the GDPR requires, providing the information controllers need for their own notification obligations.

9. Data Retention and Deletion

Workspace data is retained while the subscription is active. On termination, controllers can export their data for a limited period, after which it is deleted from production systems and expires from backups on a rolling schedule. Account and billing records are retained as required by tax and accounting law.

10. Contact

For GDPR matters, contact our privacy team at privacy@mrgeekscrm.com or our legal team at legal@mrgeekscrm.com. You also have the right to contact the supervisory authority in your country of residence or place of work.