BodiCRM

Legal

Privacy Policy

Effective date: June 20, 2026 · Last updated: July 11, 2026

BodiCRM is an enterprise business-to-business platform that organizations license to manage their customer relationships and operations. This Privacy Policy explains how information is handled in connection with the BodiCRM platform and our mobile applications, including the iOS app on the Apple App Store (collectively, the "Service").

The business information in the Service belongs to and is controlled by the organization that licenses it — not by BodiCRM. We process that information only as a service provider, on the organization's behalf and instructions. We never sell it and never use it for advertising.

Contents
  1. Who controls the information
  2. Information your organization controls
  3. Information we collect to run the Service
  4. How information is used
  5. Service providers
  6. Caller ID & device contacts
  7. Data location & retention
  8. Security
  9. Your rights & choices
  10. Children's privacy
  11. Changes
  12. Contact

1. Who controls the information

BodiCRM is provided to businesses, not to the general public. If you use the Service, you do so as an authorized user of an organization — typically your employer or a partner that invited you (the "Customer"). The Customer decides what information is put into the Service and how it is used.

For the business information processed in the Service, the Customer is the data controller and BodiCRM is a data processor acting on the Customer's behalf and under its instructions. BodiCRM does not own this information, does not sell it, and does not use it for its own purposes (such as marketing, profiling, or training third-party AI models). The Customer's own privacy policy and internal policies govern how it collects and uses information, and questions about that information should be directed to the Customer's administrator. BodiCRM is the controller only for the limited account and operational data described in Section 3.

2. Information your organization controls

The Customer and its authorized users enter, import, and access business records through the Service — for example accounts and contacts, communications, sales records such as quotes and orders, notes, tasks, and documents. Optional integrations the Customer enables (such as email/calendar or an ERP system) bring additional business data into the Service.

BodiCRM hosts and processes this information solely to provide the Service to the Customer. The Customer determines what is collected, who may access it, and how long it is kept (subject to the agreement between the Customer and BodiCRM).

3. Information we collect to run the Service

To operate, secure, and support the Service, BodiCRM collects a limited set of information as a controller:

Some features may process relevant record content with a trusted AI provider to generate suggestions you can review and edit. That content is used only to provide the feature and is not used to train third-party foundation models.

4. How information is used

We do not use a Customer's business information for our own commercial purposes, and we do not sell personal information or use it for cross-context behavioral advertising.

5. Service providers

We use a limited set of service providers (sub-processors) to deliver the Service, each bound by confidentiality and data-protection obligations and permitted to use information only to provide services to us:

CategoryPurpose
Cloud infrastructureHosting, database, storage, and email delivery
Productivity integrationEmail/calendar connectivity — only if the Customer enables it
ERP integrationOrder and pricing synchronization — only if the Customer enables it
AI processingAssistive features such as drafting and summaries
Mobile servicesPush-notification delivery and app updates

A current list of named sub-processors is available to Customers on request. We may also disclose information to comply with applicable law or lawful requests, to protect rights, safety, and security, and in connection with a corporate transaction (with notice where required).

6. Caller ID & device contacts

The BodiCRM mobile app offers optional phone and contact-related features to help authorized users connect calls and contacts with their organization's CRM records.

Caller ID

BodiCRM may sync contact names and phone numbers from the organization's CRM to the device's call-directory system so the operating system can label matching incoming calls. This matching happens on the device. BodiCRM does not receive the user's personal call history or details of who calls them through this caller ID matching feature. Caller ID can be turned off at any time in the device settings.

Device contact import

The BodiCRM mobile app may also allow users to select contacts from their device address book to add or link those contacts to CRM records. BodiCRM does not upload all device contacts automatically.

When a user chooses a specific device contact and confirms the upload in the app, BodiCRM may upload selected contact details, such as the contact's name, phone number, and email address, to the user's company BodiCRM server.

Selected device contact information is used only to:

BodiCRM does not sell device contact information and does not use it for advertising. Once imported, a contact becomes part of the organization's business records (see Section 2) and is controlled by the organization. Users can decline or revoke the app's access to device contacts at any time in their device settings; the rest of the app continues to work without it.

7. Data location & retention

Information is hosted on cloud infrastructure located in Canada. Business information is retained for as long as the Customer's account is active and as instructed by the Customer, and is returned or deleted on termination in accordance with the Customer agreement. Account and operational data we hold as a controller is retained only as long as needed for the purposes above and to meet legal obligations.

8. Security

We use industry-standard safeguards, including encryption in transit (TLS) and at rest, role-based and least-privilege access controls, network isolation, and audit logging of changes to data. No method of transmission or storage is completely secure, but we work to protect information and to promptly address issues that arise.

9. Your rights & choices

Depending on where you live, you may have rights to access, correct, delete, export, or restrict the processing of your personal information. Because the business information in the Service is controlled by your organization, requests about that information are generally fulfilled by — or routed to — your organization, and we assist the organization in responding. You can also:

We do not discriminate against you for exercising your privacy rights.

10. Children's privacy

The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us information, please contact us and we will take appropriate steps to delete it.

11. Changes

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date above and, where appropriate, provide additional notice.

12. Contact

BodiCRM is developed and operated by LUYALING CONSULTING LTD.

If you have questions about this Privacy Policy, contact us at [email protected]. For product support, email [email protected] or visit www.bodicrm.ca/#contact. If you use the Service through an organization, you may also contact that organization's administrator regarding your information.