1. Who is responsible for what
When your organisation uses CubeCRM, you decide what data goes into it and what it is used for. You are the controller of that data, and Cube Systems Limited is your processor.
If you hold some of that data as a processor yourself, for example on behalf of one of your own customers, we act as your sub-processor for it, and the commitments on this page cover it in the same way.
Separately, we are a controller for the small amount of data we need to run our own business, such as the details of your account contacts and our billing records. That is covered by our privacy policy.
2. Our data processing agreement
Every customer agreement includes a data processing agreement that meets Article 28 of UK GDPR. Under it, we:
- process your data only on your documented instructions, which include using CubeCRM as designed with the configuration you choose, and tell you if we believe an instruction breaks the law;
- make sure everyone with access to it is bound by confidentiality;
- maintain the technical and organisational measures described below;
- use sub-processors only under written contracts with equivalent obligations, and give you notice before any change;
- help you answer requests from people exercising their rights, and with data protection impact assessments and any consultation with the ICO;
- notify you of a personal data breach affecting your data without undue delay;
- delete or return your data when the contract ends; and
- make available the information you need to demonstrate compliance, and allow for audits, including inspections, by you or an auditor you appoint.
To review the agreement before you sign, email hello@cubecrm.co.uk and we will send you a copy.
3. What CubeCRM holds
| Category | Examples |
|---|---|
| People | Your staff who use the system; the contacts at your customers and prospects; people who send you an enquiry through your website or by email; and anyone named in a note, activity, email or case logged against a record. |
| Contacts and accounts | Contacts and the companies they work for, with job titles, phone numbers, email and postal addresses, relationships between records, and the consent, lawful basis and marketing preferences you record for each contact. |
| Sales records | Leads and enquiries, deals and opportunities with their stage and value, quotes and proposals with every revision, price lists, forecasts and the notes filed against a record. |
| Activities and correspondence | Calls, meetings, visits, tasks and follow-ups; emails logged from Outlook or Gmail with their attachments; calendar entries; and photographs taken on visits. |
| Service cases | Customer queries, complaints and after-sales issues, with their history, owners, response targets and resolution. |
| Connected-service data | Invoices, balances and payment status, calendar entries, call logs and campaign results exchanged with services you connect, such as your accounting package, email platform or phone system. |
| Account and security records | Users, roles and permissions, sign-in history, API access tokens and call logs, and the audit log of every change. |
CubeCRM does not need special category data to work. Notes, logged emails and case descriptions are free text, and an email can contain anything its sender wrote, so please make sure your team does not record health or other sensitive information unless you have a lawful basis to do so.
4. Where it is held
Your data is stored in the United Kingdom:
- application servers, databases and backups in UK data centres operated by Crushed Ice, part of Crushed Ice Group; and
- uploaded files and attachments in Amazon S3, and system email sent through Amazon SES, both in the AWS London region.
None of our sub-processors stores or processes your CubeCRM data outside the UK. Email and calendars synced from Microsoft 365 or Google Workspace also stay in your own tenant, and services you connect hold data under their own terms.
5. How it is protected
Access and permissions
- Role-based permissions down to record and field level, and approval limits on discounts.
- Single sign-on through Microsoft Entra ID or Google Workspace, with your own multi-factor authentication and conditional access policies applied. When someone leaves and their account is disabled, their access to CubeCRM ends with it.
- Your data kept separate from other customers’ data, and access by our staff limited to the people who need it to run and support the service.
Audit and integrations
- An audit log of every change, recording who changed what and when, which cannot be edited.
- API access through tokens scoped to the endpoints and records an integration needs, revocable individually, with every call logged.
- A separate sandbox environment for integration work, so development never touches live records.
Encryption and resilience
- Encryption in transit and at rest.
- Encrypted off-site backups held in the UK, with a documented, tested recovery process.
- Continuous, versioned updates, so no customer is left on a release too old to support.
6. Services you connect
CubeCRM can connect to services your organisation already uses, including Microsoft 365, Google Workspace, Xero, Sage, QuickBooks, Mailchimp, Website Forms & Enquiries, Telephony & VoIP and Power BI & Reporting. You choose which to connect and what they can access, and you can disconnect them at any time.
Those services are not our sub-processors. You have your own agreement with each of them, and the data they hold is covered by their terms. What each connection is used for is listed on our sub-processors page.
7. Sub-processors
We use a small number of sub-processors, each named on our sub-processors page with what it does, what it processes and where. We give customers at least 30 days’ notice by email before adding or replacing one, and you can object during that period. If we cannot resolve a reasonable objection, you may terminate the affected part of the service.
8. Requests from individuals
When someone asks you to exercise their data protection rights, you can find, correct, export and delete the records relating to them in CubeCRM, and we will help you extract anything you cannot export yourself. If a request about your data comes to us directly, we will pass it to you without undue delay and will not answer it ourselves unless you ask us to.
9. Security incidents
If we become aware of a personal data breach affecting your data, we will notify your nominated contact without undue delay, and in any event within 48 hours, so that you can meet the 72-hour deadline for reporting to the ICO. We will tell you what happened, the data and people likely to be affected, the likely consequences and what we are doing about it, and keep you updated as we learn more.
10. When a contract ends
You can export your data in full at any time in open formats, not only at the end. When a contract ends:
- your system stays available for export for 30 days;
- we then delete your data from live systems within a further 60 days, including the audit log, and confirm in writing when we have; and
- copies in backups expire on their normal rotation within 90 days after that, and are not restored in the meantime.
We keep only what the law requires of us, such as invoices, which our privacy policy covers.
Contact
Questions about this document
Email us and a person will reply. For anything about data a business holds in its CubeCRM system, please contact that business first, as it decides how the data is used.
- Company
- Cube Systems Limited, trading as CubeCRM
- Company number
- 17220899, registered in England and Wales
- Registered office
- Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP
- hello@cubecrm.co.uk
- Telephone
- 01234 672 617
- ICO registration
- ZC216972