Official Policy Documentation

BrainStorm™ CRM - Privacy Policy

This policy explains what data is collected in BrainStorm™ CRM, how it is used, how it is protected, and how you can request action on your data.

1) Overview

Last updated:

This Privacy Policy applies to BrainStorm™ CRM provided by ROSH™ Company Labs. It covers collection, processing, storage, and protection of operational data used in the platform.

By using the service, you acknowledge this policy and related documents: Terms and Cookies.

2) Data We Collect

Account Data
Operator identity fields such as email and basic authentication metadata.
Client and Order Data
Phone, name, product, payment fields, debt data, scheduling dates, and workflow notes.
System Data
Session and technical logs required for security, stability, and support.
Generated Files
PDF outputs created through the app workflows on operator action.

3) How We Use Data

  • Operate client and order workflows in BrainStorm™ CRM.
  • Support debt management, reminders, and risk controls.
  • Generate delivery and financial communications selected by the operator.
  • Improve reliability, security, and troubleshooting quality.
  • Comply with legal obligations where applicable.

4) Legal Basis

Where required by law, processing is based on contractual necessity, legitimate interests (including security and operations), consent where collected, and legal compliance requirements.

5) Cookies

Cookie details are governed by the dedicated Cookies Policy. This Privacy page keeps only the high-level rule:

  • Essential cookies support secure login and core platform operation.
  • Non-essential cookies (preferences/analytics) are managed by consent and browser settings.

Open full Cookies Policy

6) WhatsApp and Email

  • Communication templates are generated from operator-triggered actions.
  • The operator remains responsible for recipient validation before sending.
  • Risk controls in the app can block or require approval before continuation.
Gone orders are restricted by policy and cannot be used for delivery/product outreach flows.

7) Data Retention

Data is retained for operational continuity, auditing, and legal obligations. Retention can vary by record type and business process.

8) Data Sharing

Category Purpose Policy Position
Infrastructure providers Hosting, authentication, storage, delivery Used under standard safeguards
Legal and safety requests Compliance, rights protection, abuse prevention Disclosed only when legally required
Commercial resale Personal data sale Not performed

9) International Transfers

Where processing occurs across jurisdictions, appropriate technical and contractual safeguards are applied in line with applicable law.

10) Security Measures

  • Access control and authentication enforcement.
  • Encrypted transport and managed storage controls.
  • Operational guardrails for high-risk actions.
  • Audit-friendly note and event workflows.

11) Your Rights

Depending on jurisdiction, you may request access, correction, deletion, export, objection, or restriction of certain processing activities. Contact official support to submit requests.

12) Children

The service is not intended for children under the applicable legal age in your jurisdiction.

13) Policy Changes

This policy may be updated. The published version on this page is the effective version. Continued use after updates indicates acceptance.