Last Updated: September 20, 2026 • Version 2.4
1. Data Controller
Under global data protection standards including the EU General Data Protection Regulation (GDPR) and Law No. 6698 (KVKK), CRModular Technology Inc. (“CRModular”, “we”, “us”) acts as the Data Controller regarding your personal data.
2. Collected Data Categories
We process the following categories of data when you access or interact with CRModular:
- Contact & Identity: Full name, professional email, phone number, company name, and job title.
- System & Access Logs: IP address, device metadata, login audit logs, and session identifiers.
- Customer Data: Any CRM entities (leads, contacts, quotes) created within your workspace (Full ownership belongs to the customer).
- Billing Data: Processed directly via certified PCI-DSS Level 1 payment providers; raw payment details are never stored on our servers.
3. Purpose and Legal Basis for Processing
Your data is processed based on legitimate interests, contract fulfillment, and statutory obligations:
- Delivering SaaS services, authentication, and access control,
- Providing technical customer support and SLA guarantees,
- Preventing fraudulent activities and system abuse,
- Fulfilling statutory audit and tax reporting obligations.
4. Cryptographic Security & Isolation
CRModular employs robust security safeguards including end-to-end TLS 1.3 encryption in transit, AES-256 encryption at rest, strict multi-tenant data partitioning, and automated daily off-site backups.
5. Your Rights Under GDPR & Data Protection Laws
You have the right to access, rectify, restrict, or erase your personal data at any time. You may also request a structured, machine-readable export of your data.
6. Contact Information
For any questions or privacy inquiries, contact our Data Protection Team at: Email: [email protected]