Privacy Policy

Effective from: July 29, 2025, until further notice

1. Purpose of this Policy

This Privacy Policy informs users ("User") of the CoreCRM online platform ("Service") about how their personal data is collected, used, and protected by the service provider ("Provider").

The processing of www.corecrm.hu website visitors' data (e.g. via the contact form) is covered by a separate policy: Privacy Policy (website).

The Provider is committed to protecting your personal data and handles all data in accordance with applicable data protection laws, particularly the General Data Protection Regulation (EU) 2016/679 – GDPR.

2. Data Controller

Company Name: Lionheart ec.
Registered Address: 1044 Budapest, Bezerédj köz 4.
Email: info@corecrm.hu
Website: www.corecrm.hu

3. Types of Data We Collect

During your use of the system, we may collect and process the following personal data:

  • Full name
  • Email address
  • Password (stored in encrypted form)
  • Company name
  • Login logs
  • User activity within the system (e.g., actions performed and timestamps)

4. Purpose of Data Processing

We process personal data for the following purposes:

  • To operate and improve the system (including during the testing phase)
  • To create and manage user accounts
  • To communicate with users
  • To detect errors and ensure system security
  • To fulfill legal obligations

5. Legal Basis for Processing

The legal basis for data processing may include:

  • User consent (Article 6(1)(a) GDPR) – e.g., during registration
  • Performance of a contract (Article 6(1)(b) GDPR)
  • Legitimate interests (Article 6(1)(f) GDPR) – e.g., system security, fraud prevention

6. Data Sharing and Processors

We do not share personal data with third parties for marketing purposes. However, we may use trusted data processors to support the operation of our service, such as:

  • Hosting providers
  • Email delivery services (e.g., SendGrid, Mailgun)

All data processors are bound by strict data protection agreements.

7. Gmail Integration (Google User Data)

The application allows Users to integrate their Gmail account via Google services. During this integration, the User must explicitly grant the required permissions (e.g., to view and send emails within the application). The Provider declares that any data accessed through the Gmail integration (including email content, metadata, and contact information) is not permanently stored, processed, or shared by the Provider. Data remains accessible only via the direct connection between the User and Google, displayed within the application interface.

Security Measures

To safeguard Google User Data beyond Google’s secure environment, the Provider has implemented the following measures:

  • Encrypted Connections: All communication between the application and Google services is secured using HTTPS/TLS encryption.
  • No Permanent Storage: Google User Data is never written to databases, servers, or logs. Data is only accessible in memory during the User’s active session.
  • Session Security: Access to Google User Data is limited to the User’s authenticated session, secured by Google’s OAuth 2.0 standard. Once the session ends, all temporary data is deleted.
  • Access Control: Only the authenticated User who granted permissions can access their Gmail data within the application. No employee, contractor, or third party has access.
  • Monitoring and Logging: Unauthorized access attempts are monitored. Security logs are maintained without storing personal email content.
  • Data Minimization: The application requests only the minimum scopes and permissions required for its intended functionality. The Provider is committed to transparency and user control: Google User Data is never used for advertising, profiling, or shared with third parties.

8. Data Retention

Personal data is retained until the user account is deleted or for a maximum of 2 years after the last activity. Certain data may be retained longer if required by law (e.g., for invoicing).

9. Your Rights

As a data subject, you have the right to:

  • Access your personal data
  • Request correction or deletion
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time
  • You may exercise your rights by contacting us at the details above.

If you believe your data protection rights have been violated, you may file a complaint with your local data protection authority. In Hungary, this is the National Authority for Data Protection and Freedom of Information (NAIH): Website: www.naih.hu

10. Use of Cookies

Our Service uses cookies to improve user experience, enhance security, and for statistical purposes. More information about cookie usage can be found on our website.

11. Changes to this Policy

The Provider reserves the right to modify this Privacy Policy at any time. Users will be notified of changes in advance via email and/or on the website.

This website uses cookies to provide personalized content, analyze traffic, and improve site functionality. By clicking the "Accept" button, you consent to the use of cookies.