Privacy Policy
Effective July 12, 2026
This Privacy Policy explains how eClients CRM (“eClients CRM”, “we”, “us”) collects, uses, stores, and protects information when you or your organization use our customer relationship management (CRM) platform (the “Service”). It applies to every user of the Service — administrators, team members, and anyone whose data is processed on their behalf.
1. Information We Collect
1.1 Account & Organization Information
When you or your organization sign up, we collect your name, email address, phone number, job title, password (stored as a salted hash, never in plain text), and organization/company details (name, address, billing information). If two-factor authentication is enabled, we store an encrypted authentication secret and recovery codes.
1.2 Customer Relationship Data You Enter
The core of the Service is data your organization enters to manage its own customers and operations: leads, contacts, opportunities/deals, quotes, invoices, purchase orders, RFQs, delivery challans, inventory/item records, tasks, calendar events, internal notes, tags, and uploaded documents. This data belongs to your organization — see Section 2 (“How We Use Your Information”) and our Terms of Service for how it is handled.
1.3 Communications Data
If you connect a Google account, WhatsApp Business number, or send email through the Service, we process the content and metadata of those communications (see Section 1.4 for Google-specific detail) so they can be logged to the relevant contact’s timeline, displayed in your inbox/chat views, and — where you use AI features — summarized or drafted with assistance from our AI provider (Section 3).
1.4 Google User Data (Gmail & Calendar)
If you choose to connect Gmail and/or Google Calendar, we request the following Google OAuth scopes and use them only for the purposes stated:
- Gmail (read, send, modify) — to display your inbox inside the Service, send email on your behalf when you compose a message, and mark messages as read. We log a copy of message metadata (sender, subject, timestamp) and, where relevant, message content to the matching contact’s activity timeline, so your team has a shared record of customer communication.
- Google Calendar (events) — to two-way sync your organization’s calendar events between Google Calendar and the Service.
- Basic profile/email — to identify which Google account is connected.
Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not use Gmail or Calendar data to serve advertisements, and we do not sell, rent, or otherwise transfer this data to third parties, except as strictly necessary to provide or improve the Service’s features described above, to comply with law, or as part of a merger/acquisition (in which case the acquiring entity must honor this policy).
- We do not allow any human to read your Gmail or Calendar data except: (a) with your explicit, affirmative consent for a specific support request; (b) where necessary for security purposes such as investigating abuse; or (c) to comply with applicable law.
- You can disconnect Google access at any time from Settings, which immediately revokes our stored token; you can also revoke access directly from your Google Account permissions page.
1.5 WhatsApp Messages
If your organization connects a WhatsApp Business number, we process inbound and outbound message content through Meta’s WhatsApp Business API in order to display a unified chat inbox, allow your team to reply, and — if enabled — allow an AI auto-responder to draft or send replies using your organization’s configured knowledge base.
1.6 Usage, Device & Security Data
We automatically collect login timestamps, IP address, approximate location derived from IP address, device/browser information, and session identifiers, in order to secure accounts (audit logs, security event alerts, session management, optional IP allow-listing) and maintain an immutable change-history/audit trail as part of the Service’s compliance features.
1.7 Cookies & Similar Technologies
We use a session token to keep you signed in and, if you enable them, browser push notification subscriptions to deliver alerts. We do not use third-party advertising or cross-site tracking cookies.
2. How We Use Your Information
We use the information described above to:
- Provide, operate, and maintain the Service and its features (pipeline management, quoting/invoicing, document lifecycle, communications, calendar, analytics, automations).
- Authenticate you, secure your account, and detect/prevent fraud or abuse.
- Send transactional notifications (e.g. lead assignment, invoice reminders, document expiry alerts, calendar reminders) by email and/or in-app/push notification.
- Provide AI-assisted features (drafting, summarization) when you choose to use them.
- Analyze aggregated, non-identifying usage patterns to improve the Service.
- Comply with legal obligations and enforce our Terms of Service.
Your organization’s customer relationship data (Section 1.2) is used solely to provide the Service to your organization — we do not access, analyze, or repurpose it for our own separate purposes, and we do not sell any user or customer data to third parties.
3. Third-Party Service Providers (Subprocessors)
We rely on the following categories of third-party providers to operate the Service. Each only receives the data necessary to perform its function, under its own privacy/security terms:
- Database & hosting — our managed PostgreSQL database provider and our application hosting providers (separate backend API and frontend services) store the Service’s data at rest.
- Google — Gmail API and Google Calendar API, only when you explicitly connect a Google account (Section 1.4).
- Meta Platforms, Inc. — WhatsApp Business API, only when your organization connects a WhatsApp number.
- OpenAI — powers optional AI features (assistant, email/reply drafting, summarization, document extraction). Content you submit to an AI feature is sent to OpenAI’s API to generate a response; we do not send data to OpenAI unless you actively invoke an AI feature.
- Email delivery provider — sends transactional email (invitations, quotes, invoices, notifications, password resets) on our behalf.
- Cloud file storage — stores uploaded documents when configured for production use.
4. Data Retention
We retain your information for as long as your account or organization remains active, plus a reasonable period afterward to comply with legal, tax, or accounting obligations, resolve disputes, and enforce our agreements. When an organization’s account is deleted, we delete or anonymize its data within a commercially reasonable time, except where retention is required by law.
5. Your Rights & Choices
Depending on your location, you may have the right to:
- Access, correct, or export a copy of your personal information.
- Request deletion of your personal information, subject to legal retention requirements.
- Disconnect any connected third-party account (Google, WhatsApp) at any time from Settings.
- Object to or restrict certain processing, where applicable law provides that right.
To exercise any of these rights, contact us at support@nextek.com.pk.
6. Data Security
We use industry-standard safeguards including encryption in transit (TLS), password hashing, role-based access control, optional two-factor authentication, optional IP allow-listing, and audit logging of security-sensitive actions. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. International Data Transfers
Our service providers may process and store data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.
8. Children’s Privacy
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email, and the “Effective” date above will be updated accordingly.
10. Contact Us
Questions about this Privacy Policy or our data practices can be sent to support@nextek.com.pk.