Legal

Data processing

How CubeCRM handles the data your organisation puts into it, and what our data processing agreement commits us to.

  • Updated 25/09/2026
  • 7 min read
  • For customers

The short version

  • You are the controller

    We process your data only on your documented instructions, under a data processing agreement that is part of every customer contract.

  • Security in the base product

    Role-based permissions, single sign-on, an audit log that cannot be edited and encryption come with every subscription, not as an upgrade.

  • UK storage, named providers

    Databases, files and backups stay in the UK. The providers we use are named, and changes come with 30 days’ notice.

  • Your data leaves when you do

    Export it whenever you like, in open formats. When a contract ends, you have time to take it, and then it is deleted on a stated timetable.

A summary for convenience. The full text below is what applies.

1. Who is responsible for what

2. Our data processing agreement

3. What CubeCRM holds

4. Where it is held

5. How it is protected

6. Services you connect

7. Sub-processors

8. Requests from individuals

9. Security incidents

10. When a contract ends

Contact

Email us and a person will reply. For anything about data a business holds in its CubeCRM system, please contact that business first, as it decides how the data is used.

Email us
Company
Cube Systems Limited, trading as CubeCRM
Company number
17220899, registered in England and Wales
Registered office
Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP
Telephone
01234 672 617
ICO registration
ZC216972