- [Home](/)
- [Legal](/legal)
- Privacy policy

Legal

# Privacy policy

How Cube Systems Limited collects, uses and protects personal data when you visit this website, get in touch, or use CubeCRM.

- Updated 25/09/2026
- 12 min read
- For everyone

## The short version

- Analytics only if you allow it

Google Analytics sets cookies only after you choose “Allow analytics”. There are no advertising or social media tags on this website.

- Your business data stays yours

Inside CubeCRM, your organisation is the controller. We act as its processor, only on its instructions and under a written agreement.

- Held in the UK

CubeCRM databases, files and backups are in UK data centres, and system email is sent from the AWS London region.

- Nothing sold, nothing passed on

We do not sell personal data or share it for anyone else’s marketing. Asking us a question does not put you on a mailing list.

A summary for convenience. The full text below is what applies.

On this page

- [1Who we are](#who-we-are)
- [2When this policy applies](#when-this-applies)
- [3What we collect](#what-we-collect)
- [4How we use it, and why](#how-we-use-it)
- [5Who we share it with](#who-we-share-it-with)
- [6Where it is held](#where-it-is-held)
- [7How long we keep it](#how-long-we-keep-it)
- [8How we protect it](#how-we-protect-it)
- [9Your rights](#your-rights)
- [10Complaints](#complaints)
- [11Cookies](#cookies)
- [12Changes to this policy](#changes)

On this page12 sections
- [1Who we are](#who-we-are)
- [2When this policy applies](#when-this-applies)
- [3What we collect](#what-we-collect)
- [4How we use it, and why](#how-we-use-it)
- [5Who we share it with](#who-we-share-it-with)
- [6Where it is held](#where-it-is-held)
- [7How long we keep it](#how-long-we-keep-it)
- [8How we protect it](#how-we-protect-it)
- [9Your rights](#your-rights)
- [10Complaints](#complaints)
- [11Cookies](#cookies)
- [12Changes to this policy](#changes)

Print or save as PDF[Ask us a question](mailto:hello@cubecrm.co.uk)[All legal documents](/legal)
## 1. Who we are

This policy is issued by **Cube Systems Limited**, a company registered in England and Wales under number 17220899, with its registered office at Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP. CubeCRM is a trading name of Cube Systems Limited, which is part of Crushed Ice Group. In this policy, “we”, “us” and “our” mean Cube Systems Limited.

For the processing this policy describes we are the controller. That means we decide how and why the data is used, and we are responsible for it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We are registered with the Information Commissioner’s Office under registration number [ZC216972](https://ico.org.uk/ESDWebPages/Entry/ZC216972).

We are not required to appoint a data protection officer. Questions about this policy or your personal data go to [hello@cubecrm.co.uk](mailto:hello@cubecrm.co.uk), by telephone on [01234 672 617](tel:+441234672617), or by post to the address above, marked for the attention of the data protection lead.

## 2. When this policy applies

We handle personal data in two different capacities, and it matters which one applies to you.

### Where we are the controller

This policy covers personal data we collect for our own purposes, about:

- people who visit this website;
- people who contact us, book a walkthrough or ask for a quote;
- contacts at our customers, prospective customers and suppliers; and
- people who sign in to CubeCRM, in respect of their account, sign-in and security records, and any support request they raise with us.

### Where we are a processor

Businesses use CubeCRM to manage their customer relationships: contacts, accounts, enquiries, deals, quotes, activities, logged emails and service cases. The personal data in those records, such as their customers’ and prospects’ contacts, the people who send them enquiries, and their own staff, belongs to that business. The business is its controller and its own privacy notice applies. We process the data only on its instructions, under a data processing agreement, as set out in our [data processing](/legal/data-processing) terms.

If you deal with a business that uses CubeCRM, for example as its customer or because you sent it an enquiry, please contact that business about your data first. If you contact us instead, we will tell you who to approach and pass your request on to them.

## 3. What we collect

### When you visit this website

Pages, fonts, icons and images are served from our own servers. The website sets no cookies unless you allow analytics, and it carries no advertising or social media tags.

Like any web server, ours keeps a log of each request: your IP address, the date and time, the page requested, the page that linked to it, and the browser and operating system your device reports. We use these logs only to keep the site secure and working.

Your browser also keeps a short note of your visit in its session storage, under the name visit_journey: the page you arrived on and when, the site that sent you, any campaign tags or ad click IDs in that first link, the previous page, and how many pages you have viewed. It stays in that browser tab, is deleted when you close it, and only reaches us if you send the enquiry form.

### If you allow analytics

When analytics is in use, a banner asks whether you allow it. If you choose “Allow analytics”, Google Analytics 4 sets its _ga and _ga_<container-id> cookies and records which pages you view, how you arrived, the type of device, browser and screen you use, your approximate location (such as the country and city, worked out by Google from your IP address), and interactions such as scrolling, following a link to another website, clicking a phone number or email address, and sending the enquiry form. GA4 does not log or store IP addresses. We see the results as reports about visits in general, and we do not use them to identify anyone. Advertising features are switched off.

The Google Analytics script only loads after you allow analytics, so if you choose “Essential only” nothing is sent to Google. If you withdraw your consent through Cookie settings, Google Analytics stops and its _ga cookies are removed.

### When you get in touch

If you use the contact form we collect your name and email address, your company name and telephone number if you give them, the type of enquiry, your message, and the page or form you sent it from.

With the form, your browser also sends details about your visit. They help us route your enquiry to the right person, spot misuse of the form, and understand which pages lead people to get in touch. They are:

- your IP address;
- your browser and operating system, read from the user agent your browser reports, and the type of device;
- your language, time zone and local time, your screen and window size, whether your device has a touch screen, and whether cookies are enabled;
- the note of your visit described above: the page you arrived on and when, the site that sent you, campaign tags and ad click IDs, the previous page and the number of pages viewed; and
- if you allowed analytics, your Google Analytics client ID, which lets us match the enquiry to the analytics for that visit.

The enquiry is sent by email through Amazon Simple Email Service (Amazon SES), in the AWS London region, to the Cube Systems enquiries mailbox. If you email or call us, we keep what you tell us and the details you contact us from.

Please do not send passwords, API keys or personal data about your own customers through the contact form. If we need sample data to scope a migration, we will agree a secure way to exchange it first.

### When you become a customer

We hold names, job titles and business contact details for the people we deal with at your organisation, including account, billing and technical contacts, together with contract and order records, invoices, payment history, and the history of our support and account conversations. We do not take card payments through this website.

### When you use CubeCRM

- **Account details:** your name, email address, role and permissions in your organisation’s CubeCRM system.
- **Sign-in data:** the details needed to sign you in. If your organisation uses single sign-on through Microsoft Entra ID or Google Workspace, you sign in with that account and we receive the account identifier it provides.
- **Security records:** sign-in times and the IP address and browser used, which we use to protect accounts and investigate misuse.
- **Audit records:** which user created, changed or deleted a record, and when. Your organisation can see these in the CubeCRM audit log.
- **Support requests:** anything you send us when you ask for help.

We do not ask for special category data, such as health information, and CubeCRM is built for businesses, so we do not knowingly collect information about children.

## 4. How we use it, and why

Data protection law requires a lawful basis for every use of personal data. These are ours.

Purposes and lawful basesPurposeLawful basisReplying to enquiries, arranging walkthroughs and preparing quotesLegitimate interests in responding to people who contact us, and steps you have asked us to take before entering into a contract.Recording the visitor details sent with an enquiry, to route it to the right person, prevent abuse of the form and understand which pages lead to enquiriesLegitimate interests in answering enquiries promptly, protecting the form from misuse and improving the website.Measuring how the website is used with Google AnalyticsConsent, given in the cookie banner. You can withdraw it at any time through Cookie settings in the footer.Providing CubeCRM, managing customer accounts and giving supportPerformance of our contract with the customer, and legitimate interests in supporting the people who use it.Keeping the website and platform secure, preventing abuse and investigating incidentsLegitimate interests in protecting our systems, our customers and their data.Invoicing, accounting and taxLegal obligation, and performance of the contract.Service messages: security notices, planned maintenance, and changes to our terms or sub-processorsPerformance of the contract, and legitimate interests in keeping customers informed.Occasional product news to contacts at existing customersLegitimate interests. Every message has a way to opt out, and opting out never stops service messages.Establishing, exercising or defending legal claims, and answering lawful requests from regulatorsLegal obligation, and legitimate interests.Where we rely on legitimate interests, we have weighed them against your rights and you can ask us for that assessment. You can object at any time, as explained under [your rights](#your-rights).

We do not make decisions about anyone based solely on automated processing that have legal or similarly significant effects.

## 5. Who we share it with

We do not sell personal data, and we do not share it with anyone for their own marketing. We share it only with:

- **Crushed Ice Group companies**, chiefly Crushed Ice, which operates the UK data centres CubeCRM runs in and may deliver part of a project for you, such as bespoke development.
- **Service providers** who process data for us under written contracts: Amazon Web Services, for email delivery and CubeCRM file storage in its London region; Google, for website analytics if you allow it; and our business email and accounting providers. Those used within CubeCRM itself are named on our [sub-processors](/legal/sub-processors) page.
- **Services a customer connects.** If a customer connects CubeCRM to Microsoft 365 or Google Workspace, an accounting package, Mailchimp or a phone system, data passes between them at the customer’s direction and under that provider’s own terms.
- **Professional advisers**, such as lawyers, accountants and insurers, who owe us a duty of confidentiality.
- **Authorities**, such as the police, HMRC or a regulator, where the law requires it. We check that a request is lawful before acting on it and, where the data belongs to a customer, we tell the customer unless the law forbids us to.
- **A buyer or successor**, if all or part of our business is sold or reorganised, on condition that they honour this policy.

## 6. Where it is held

We hold personal data in the United Kingdom. CubeCRM databases, file storage and backups are in UK data centres, and the email and storage services we use from Amazon Web Services run in its London region.

The exception is Google Analytics, which runs only if you allow it. It is provided by Google Ireland Limited, with Google LLC, and the data may be processed in the United States under the UK Extension to the EU-US Data Privacy Framework.

If any other provider can access personal data from outside the UK, for example to give technical support, it does so under UK adequacy regulations or the International Data Transfer Addendum to the European Commission’s standard contractual clauses. You can ask us for a copy of the relevant safeguards.

## 7. How long we keep it

We keep personal data only for as long as we need it for the purpose it was collected for, then delete or anonymise it.

Retention periodsRecordHow longEnquiries that do not lead to a customer relationship24 months from our last contactWeb server logs90 daysGoogle Analytics data, if you allowed analyticsUp to 14 months, then deleted by GoogleCustomer account, contract and support recordsThe life of the contract, then six yearsInvoices and financial recordsSix years from the end of the financial year they relate toCubeCRM user accounts and sign-in historyWhile the account is active. Removed when the user is deleted or the contract ends, except where it forms part of the audit logData your organisation holds in CubeCRMDecided by your organisation, and deleted at the end of the contract as set out in our data processing termsThe note of your visit kept in your browser is deleted when you close the tab, unless you send it to us with an enquiry. Where a legal claim or investigation is under way, we may keep the relevant records until it is resolved.

## 8. How we protect it

Security features are part of the base CubeCRM product rather than an upgrade. The measures that protect personal data include:

- encryption in transit and at rest, and encrypted off-site backups with a documented, tested recovery process;
- role-based permissions down to record and field level, approval limits on discounts, and single sign-on through your organisation’s Microsoft or Google account;
- an audit log of every change, recording who changed what and when, which cannot be edited;
- API access through tokens scoped to what each integration needs, revocable individually, with every call logged; and
- staff access limited to the people who need it to run and support the service.

If a personal data breach is likely to put people’s rights at risk, we will report it to the ICO within 72 hours of becoming aware of it and, where the risk is high, tell the people affected without undue delay. Customers are notified as set out in our [data processing](/legal/data-processing#security-incidents) terms.

## 9. Your rights

Under UK GDPR you have the right to:

- **be informed** about how your data is used, which is what this policy is for;
- **access** a copy of the personal data we hold about you;
- **rectification** of data that is inaccurate or incomplete;
- **erasure** of your data where there is no good reason for us to keep it;
- **restrict** how we use it, for example while a question about its accuracy is resolved;
- **object** to processing based on legitimate interests, and to direct marketing at any time;
- **data portability**, receiving data you gave us in a machine-readable format; and
- **withdraw consent**, where we rely on it, without affecting anything done before. For analytics, use Cookie settings in the footer of any page.

To use any of these rights, email [hello@cubecrm.co.uk](mailto:hello@cubecrm.co.uk). You do not need a form or any particular wording. We may ask you to confirm your identity before we act, so that we never hand your data to someone else. We respond within one month, and there is normally no charge. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month.

If your request concerns data a business holds in its CubeCRM system, we will pass it to that business, which is responsible for answering it, and help it do so.

## 10. Complaints

If you are unhappy with how we have handled your data, please tell us first at [hello@cubecrm.co.uk](mailto:hello@cubecrm.co.uk) and we will try to put it right.

You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection, with whom we are registered under number ZC216972:

- online at [ico.org.uk/make-a-complaint](https://ico.org.uk/make-a-complaint/);
- by telephone on 0303 123 1113; or
- by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

## 11. Cookies

This website sets no cookies unless you allow Google Analytics, which then sets two. CubeCRM itself uses one cookie to keep you signed in. Everything is listed in our [cookie policy](/legal/cookies), and you can change your analytics choice at any time using Cookie settings in the footer.

## 12. Changes to this policy

We review this policy at least once a year, and whenever the way we handle personal data changes. The date at the top shows when it was last updated. If a change materially affects customers, we will email their nominated contacts before it takes effect. Previous versions are available on request.

Contact

## Questions about this document

Email us and a person will reply. For anything about data a business holds in its CubeCRM system, please contact that business first, as it decides how the data is used.

[Email us](mailto:hello@cubecrm.co.uk)CompanyCube Systems Limited, trading as CubeCRMCompany number[17220899](https://find-and-update.company-information.service.gov.uk/company/17220899), registered in England and WalesRegistered officeUnit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FPEmail[hello@cubecrm.co.uk](mailto:hello@cubecrm.co.uk)Telephone[01234 672 617](tel:+441234672617)ICO registration[ZC216972](https://ico.org.uk/ESDWebPages/Entry/ZC216972)
## Other legal documents

[Legal overview](/legal)
-
### [Cookie policy](/legal/cookies)

This website sets no cookies unless you allow Google Analytics. The CubeCRM application uses one to keep you signed in. The full list, and how to change your mind.

Updated 25/09/2026

-
### [Terms of use](/legal/terms-of-use)

The rules for using this website, including automated and AI access. Subscriptions to CubeCRM are covered by your customer agreement instead.

Updated 25/09/2026

-
### [Data processing](/legal/data-processing)

How CubeCRM processes the data your organisation puts into it: roles, security, sub-processors, deletion, and what our data processing agreement commits us to.

Updated 25/09/2026

-
### [Sub-processors](/legal/sub-processors)

The third parties that process customer data on our behalf, what each one does, where it does it, and how we tell you about changes.

Updated 25/09/2026

---

**URL:** https://cubecrm.co.uk/legal/privacy-policy
