Privacy Policy
Version 2026-08-23 · Last updated 23 August 2026
In plain English
We handle two different kinds of data. Your account data (name, email, company, billing, how you use the product) is ours to look after as controller. The CRM records you put into the product — your contacts, prospects, and deals — stay yours; we only process them on your instructions.
We don't sell personal data and we don't train AI models on your CRM data. Data is hosted in the EU. You can access, correct, export, or delete your data, and complain to the ICO if you're unhappy with how we respond.
This summary is for convenience only and is not part of the agreement.
1. Who we are and what this policy covers
iLLMSoft Ltd trading as ILLM CRM operates the ILLM CRM platform. This policy explains how we collect, use, share, and protect personal data across our marketing website (illmsoft.com), the CRM product, our APIs, and our support and billing operations.
We comply with the UK General Data Protection Regulation and the Data Protection Act 2018, and with the EU GDPR where it applies to our processing. For data protection enquiries and to exercise your rights, contact privacy@illmsoft.com.
2. Our two roles: controller and processor
This distinction determines who you should contact about a particular piece of data, so it is worth reading.
- We are the controller for data about our own customers and website visitors: account registration details, billing records, product usage and telemetry, support correspondence, marketing preferences, and website analytics. Sections 3, 4, and 12 apply.
- We are a processor for the CRM records our customers load into the platform — their contacts, prospects, deals, notes, emails, and attachments. The customer is the controller and decides why that data is held and for how long. Section 5 applies.
If you are a contact or prospect stored in a customer's CRM and want your data accessed, corrected, or deleted, please contact that organisation directly, as they control it. If you contact us instead, we will refer your request to them and assist them in responding.
3. Personal data we collect as controller
3.1 Information you give us
- Account and registration: full name, work email address, password (stored only as a salted hash), company name, and — for trial signups — job title, telephone number, company size, and industry.
- Acceptance records: the fact that you accepted our Terms of Service and Privacy Policy, the version accepted, the timestamp, and the originating IP address. We keep this to demonstrate a valid agreement.
- Billing: billing contact, billing address, invoice history, VAT details, and plan. Card details are entered directly with our payment processor and are never stored on our servers; we retain only a token, the card type, last four digits, and an anonymised fingerprint used to enforce one trial per card.
- Support and enquiries: the content of messages you send us through the contact form, email, or in-product support, plus any attachments.
- Marketing preferences: whether you opted in to product updates, and your cookie choices.
3.2 Information we collect automatically
- Device and connection: IP address, browser and operating system, language, timezone, and screen size class. Where we log IP addresses for security analytics we generally store them in hashed form.
- Usage and product telemetry: pages and features used, actions taken, timestamps, API call volumes, and error and performance diagnostics.
- Authentication and security events: sign-in attempts, session activity, approximate country derived from IP, and audit records of administrative actions.
- Cookies and local storage: see section 12 and our Cookie Policy.
4. Why we use it, and our legal bases
Under the UK GDPR we must have a lawful basis for each purpose. Ours are set out below.
- To provide the Service — create and administer your account, authenticate users, deliver the features of your plan, and provide support. Basis: performance of a contract.
- To take payment — invoicing, collections, tax and accounting records. Basis: performance of a contract, and legal obligation for statutory record keeping.
- To keep the Service secure — detect and prevent fraud, abuse, credential stuffing, and trial abuse; investigate incidents; maintain audit logs. Basis: legitimate interests in protecting our platform and our customers.
- To improve the product — analyse aggregate usage, diagnose faults, and prioritise development. Basis: legitimate interests in improving our service.
- Service communications — verification emails, security alerts, billing notices, trial expiry reminders, and material changes to terms. These are not marketing and cannot be unsubscribed from while you hold an account. Basis: performance of a contract, and legal obligation.
- Marketing — product updates, tips, and announcements. Basis: consent, or legitimate interests for business contacts under the soft opt-in for existing customers. You can withdraw at any time.
- Optional analytics and marketing cookies — Basis: consent.
- To comply with law and defend claims — respond to lawful requests, enforce our terms, and establish or defend legal claims. Basis: legal obligation, and legitimate interests.
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You may object to that processing — see section 11.
5. Customer Data we process on your behalf
When you use the CRM, you decide what to record about your own contacts, prospects, and deals. That may include names, business contact details, job titles, company information, notes, call and meeting records, email correspondence, documents, and any custom fields you configure.
- We process this data only to provide the Service to you, on your instructions, and as set out in our Terms of Service and any Data Processing Agreement between us.
- We do not use it for our own marketing, we do not sell it, and we do not use it to train generally available AI models.
- Tenants are logically isolated, with row-level security enforced in the database so one customer cannot read another's records.
- As controller, you are responsible for having a lawful basis to hold this data, for giving the required privacy information to the individuals concerned, and for honouring their rights. We will assist you with that.
- A Data Processing Agreement covering the Article 28 processor terms is available on request from privacy@illmsoft.com.
6. AI features
Some features use AI models to score leads, analyse sentiment, summarise activity, draft text, and answer questions about your CRM data.
- Where a feature uses a third-party model provider, the relevant content is transmitted to that provider as our sub-processor, under contractual terms that prohibit using it to train their models.
- We apply automated reduction of directly identifying personal data before transmission where technically feasible. This reduces but does not eliminate the possibility that free-text fields contain personal data, so avoid putting sensitive details in free-text notes.
- AI output is a suggestion, not a decision. It is presented to your users for review and does not by itself produce legal or similarly significant effects. See section 13.
- Administrators can disable AI features for their workspace.
7. Who we share data with
We do not sell personal data and we do not share it for third-party advertising. We use a small number of sub-processors to run the platform. Each is bound by a written contract containing data protection terms, and processes data only on our instructions.
- Hosting and infrastructure — IONOS, in the European Union. Hosts the application, database, and backups.
- Transactional email — Resend. Delivers verification, security, billing, and notification emails.
- AI model providers — Anthropic and OpenAI, for the AI features described in section 6, where enabled.
- Payments — Stripe, for card validation, subscriptions, and invoicing where card payment is enabled. Stripe acts as an independent controller for fraud prevention and regulatory purposes under its own privacy policy.
- Website chat — the chat on this marketing site answers common product questions in your browser. It does not use your microphone. If it cannot answer, the same window connects you to a person on our team. We store the messages so we can reply, and we email our support inbox that someone is waiting. We do not display a phone number. Please do not share payment card details in the chat.
We may also disclose data to professional advisers, auditors, or law enforcement where legally required, and to a successor entity in connection with a merger, acquisition, or sale of assets — in which case we will notify you and this policy will continue to apply until replaced. We will give notice of new sub-processors so you have an opportunity to object.
8. International transfers
Customer Data is hosted in the European Union (IONOS data centres). Some sub-processors, in particular AI model providers and payment infrastructure, may process data outside the UK and EEA. Where that happens we rely on an adequacy decision where one exists, or otherwise on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, together with a transfer risk assessment and supplementary technical measures such as encryption in transit. You may request details of the safeguards applying to a specific transfer from privacy@illmsoft.com.
9. How long we keep data
- Customer Data: for the life of your account, then deleted from active systems 30 days after termination, with backups expiring on our normal rotation. See clause 16 of the Terms.
- Account records: for the life of your account and up to 12 months afterwards, to handle reactivation and disputes.
- Billing, invoice, and tax records: 7 years, to meet UK accounting and tax obligations.
- Terms acceptance records: for the life of the account and 6 years afterwards, matching the limitation period for contractual claims.
- Security, audit, and sign-in logs: typically 12 months, longer where an investigation requires it.
- Support correspondence: up to 3 years from last contact.
- Cookie consent records: up to 2 years, to demonstrate accountability.
- Marketing contact records: until you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again.
10. How we protect data
- Encryption in transit using TLS 1.3, and encryption at rest using AES-256.
- Passwords stored only as salted bcrypt hashes; we can never retrieve your password.
- Multi-tenant isolation with database row-level security, plus role-based access control and per-tenant scoping on every API request.
- Least-privilege internal access, session invalidation controls, and audit logging of administrative actions.
- Encrypted, regularly tested backups held in the EU.
- Dependency and vulnerability monitoring, and a documented incident response process.
No system is completely secure. If a personal data breach is likely to result in a risk to individuals, we will notify the ICO within 72 hours where required, and notify affected customers without undue delay. Further detail is on our security page.
11. Your rights
Subject to conditions in the legislation, you have the right to:
- be informed about how your data is used — this policy;
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have data erased where there is no continuing lawful reason to keep it;
- restrict processing while a concern is investigated;
- receive your data in a portable, machine-readable format;
- object to processing based on legitimate interests, including profiling;
- withdraw consent at any time, where consent is the basis; and
- opt out of marketing at any time.
To exercise any of these, email privacy@illmsoft.com. We respond within one month and may extend by two further months for complex requests, telling you if we do. We may need to verify your identity. There is no fee unless the request is manifestly unfounded or excessive.
If you are unhappy with our response you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or to your local supervisory authority in the EEA. We would appreciate the chance to address your concern first.
12. Cookies and similar technologies
We use strictly necessary cookies to operate the site and product, and optional analytics and marketing cookies only with your consent. When you respond to our cookie banner we record your choice, the policy version, a random visitor identifier, and minimal technical information so we can demonstrate accountability. Full detail, including how to withdraw consent, is in our Cookie Policy.
13. Marketing and automated decision-making
Marketing emails always include an unsubscribe link, and you can also email privacy@illmsoft.com to opt out. Unsubscribing does not stop essential service messages such as billing and security notices.
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. AI lead scores and similar outputs are decision support for your own staff, who remain responsible for the outcome.
14. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact privacy@illmsoft.com and we will delete it.
15. Changes to this policy
We may update this policy as the product and the law develop. The version number and date at the top always reflect the current text. For material changes affecting how we use your personal data, we will notify account holders by email or by prominent notice in the Service before the change takes effect.
16. Contact us
Data protection and privacy: privacy@illmsoft.com
General support: support@illmsoft.com
Other enquiries: contact@illmsoft.com
Please include enough detail to identify your account or the data concerned so we can respond without unnecessary further requests.
Company details
- Legal entity
- iLLMSoft Ltd
- Trading as
- ILLM CRM
- Company number
- # Companies House number
- Registered office
- 9 Appold Street, London, EC2A 2AP, England, UK
- VAT number
- # omit if not VAT registered
- Governing law
- England and Wales