Privacy Policy
1. Introduction
Closina ("Closina," "we," "us," or "our") is committed to protecting the privacy of our users and the individuals whose data is managed through our platform. This Privacy Policy ("Policy") describes how we collect, use, store, share, and protect personal information when you use the Closina CRM platform and related services (the "Service").
This Policy applies to all users of the Service, including account holders, team members, and administrators. It also describes the rights of individuals whose personal data is stored within the Service by our users.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Full name and professional title;
- Email address;
- Phone number;
- Organization or business name;
- Business address and jurisdiction;
- Professional license information (when voluntarily provided);
- Billing and payment information (processed and stored by Stripe; we do not store full credit card numbers).
2.2 Contact Data You Manage
As a CRM platform, you may store information about your customers and business contacts, including:
- Names, email addresses, phone numbers, and mailing addresses;
- Communication history (emails, SMS messages, call transcripts);
- Appointment records and calendar events;
- Custom fields and notes you create;
- Transaction and deal records;
- Social media profiles and interaction history.
You are the data controller for this contact data. We act as a data processor on your behalf and process this data solely as instructed by you and as necessary to provide the Service.
2.3 Usage Data
We automatically collect certain information when you use the Service:
- IP addresses and approximate geolocation;
- Browser type and version;
- Device type, operating system, and screen resolution;
- Pages visited, features used, and time spent on the platform;
- Click patterns and navigation paths;
- Error logs and performance metrics;
- Authentication events and security logs.
2.4 AI-Processed Data
When you use our AI features (voice copilot, transcription, content generation, analytics), we process:
- Audio recordings of voice calls (when transcription or AI copilot features are enabled);
- Text inputs provided to AI content generation tools;
- Communication patterns analyzed for campaign optimization;
- Voice interaction metadata (call duration, sentiment indicators).
2.5 Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Maintain your session and authentication state;
- Remember your preferences and settings;
- Analyze usage patterns to improve the Service;
- Ensure security and detect fraudulent activity.
For more details, see Section 8 (Cookie Policy) below.
3. How We Use Your Information
3.1 Providing the Service
We use your information to:
- Create and maintain your account;
- Deliver the CRM features you have subscribed to;
- Process communications (email, SMS, voice, social media) on your behalf;
- Generate AI-powered insights, transcriptions, and content;
- Manage subscriptions, billing, and payments;
- Provide customer support and respond to inquiries.
3.2 Improving the Service
We use aggregated and anonymized data to:
- Analyze platform usage patterns and feature adoption;
- Identify and fix technical issues;
- Develop new features and improve existing ones;
- Optimize performance and reliability.
This section does not apply to data Closina receives from Google Workspace APIs. That data - whether raw, aggregated, anonymized, or otherwise derived from it - is used only to provide the features you asked for, and Google Workspace APIs are not used to develop, improve, or train non-personalized AI and/or ML models. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Our Google API data-use disclosure sets out, permission by permission, exactly what we receive, what we do with it, who it reaches, and how to revoke it.
3.3 Security and Compliance
We use your information to:
- Detect, prevent, and respond to fraud, abuse, and security incidents;
- Enforce our Terms of Service and Acceptable Use Policy;
- Comply with legal obligations, including lawful requests from governmental authorities;
- Maintain audit trails for regulatory compliance.
3.4 Communications
We may send you:
- Service-related notices (maintenance windows, security alerts, account changes);
- Billing and subscription communications;
- Product updates and feature announcements (you may opt out);
- Responses to your support requests.
We will never sell your contact information to third parties for their marketing purposes.
4. Data Sharing and Disclosure
4.1 We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information or the contact data you manage through the Service. This applies to all categories of data described in this Policy.
4.2 Service Providers
We share data with trusted third-party service providers who assist in operating the Service, including:
| Provider | Purpose | Data Shared |
|---|---|---|
| Cloud infrastructure providers | Hosting and storage | All Service data (encrypted) |
| Stripe | Payment processing | Billing and payment data |
| Email delivery providers | Transactional email | Email addresses, message content |
| Twilio | Telephony and messaging carriage | Phone numbers, message content, call audio |
| AI voice-agent provider | Places and answers calls on your behalf | Contact name, email address and phone number; the free appointment times your calendar shows; call audio and transcripts |
| Its speech-to-text, text-to-speech and language-model sub-processors | Components of the AI voice agent, engaged by that provider rather than by Closina | Call audio and transcripts passed on by it |
| OpenAI | Transcription, content generation, AI coach and copilot | Text inputs, call recordings and transcripts for transcription and post-call analysis |
| Microsoft Azure AI Speech | Speech-to-text and text-to-speech in the mobile app | Spoken input and the assistant's spoken replies |
| Analytics providers | Usage analytics | Anonymized usage data |
| Security services | Threat detection | Security logs, IP addresses |
We require our service providers to protect your data and to use it only for the purposes described above, and we hold data processing agreements with the providers that handle personal data on our behalf.
4.3 Legal Requirements
We may disclose your information when required by law, regulation, legal process, or governmental request, including:
- Court orders and subpoenas;
- Requests from law enforcement agencies;
- Regulatory compliance requirements;
- Protection of our rights, property, or safety, or the rights, property, or safety of others.
When legally permitted, we will notify you of such requests before disclosure.
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity. We will notify you before your information becomes subject to a different privacy policy.
4.5 With Your Consent
We may share your information with third parties when you have given explicit consent.
5. Data Retention
5.1 Active Accounts
We retain your data for as long as your account is active and as necessary to provide the Service. Specific retention periods:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days post-deletion |
| Contact data you manage | Duration of account + 30 days post-deletion |
| Communication history | Duration of account + 30 days post-deletion |
| Voice recordings and transcripts | As configured in your settings (default: 90 days) |
| Usage logs and analytics | 24 months (rolling) |
| Security and audit logs | 36 months (for compliance) |
| Billing records | 7 years (legal requirement) |
5.2 After Account Termination
When you terminate your account:
- You may request a full data export within thirty (30) days;
- Your data will be deleted within thirty (30) days of the export period (or termination, whichever is later);
- Certain data may be retained longer as required by law (e.g., billing records, legal hold data);
- Backups containing your data are purged within ninety (90) days.
5.3 Data Minimization
We regularly review the data we hold and delete data that is no longer necessary for the purposes for which it was collected.
6. Security Measures
We implement comprehensive security measures to protect your data, including:
6.1 Technical Safeguards
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher;
- Encryption at rest: All stored data is encrypted using AES-256 encryption;
- Access controls: Role-based access control (RBAC) with principle of least privilege;
- Multi-factor authentication: Available for all accounts, required for administrative access;
- Network security: Firewalls, intrusion detection systems, and DDoS protection;
- Vulnerability management: Regular security scanning and penetration testing.
6.2 Organizational Safeguards
- Employee background checks and security training;
- Incident response procedures and disaster recovery plans;
- Regular security audits and compliance assessments;
- Data access logging and monitoring;
- Vendor security assessments for all third-party service providers.
6.3 Breach Notification
In the event of a data breach that affects your personal data, we will:
- Notify affected users within seventy-two (72) hours of becoming aware of the breach;
- Notify relevant supervisory authorities as required by applicable law;
- Provide details of the breach, including the nature of the data affected, the likely consequences, and the measures taken or proposed to address the breach.
7. Your Rights
7.1 General Rights (All Users)
Regardless of your location, you have the right to:
- Access: Request a copy of the personal data we hold about you;
- Correction: Request correction of inaccurate or incomplete personal data;
- Deletion: Request deletion of your personal data ("Right to be Forgotten");
- Data Portability: Receive your data in a structured, commonly used, machine-readable format (JSON, CSV);
- Opt-out: Unsubscribe from marketing communications at any time;
- Withdraw Consent: Withdraw previously granted consent for specific data processing purposes.
7.2 GDPR Rights (EU/EEA Residents)
If you are located in the European Economic Area, you additionally have the right to:
- Restriction: Request restriction of processing in certain circumstances;
- Object: Object to processing based on legitimate interests;
- Automated Decision-Making: Not be subject to decisions based solely on automated processing;
- Lodge Complaint: File a complaint with your local data protection authority.
Our legal bases for processing under GDPR are:
- Contract: Processing necessary to perform our agreement with you;
- Legitimate Interest: Processing necessary for our legitimate business interests (analytics, security);
- Consent: Processing based on your explicit consent (marketing, optional AI features);
- Legal Obligation: Processing required by law.
7.3 CCPA/CPRA Rights (California Residents)
If you are a California resident, you additionally have the right to:
- Know: Know what personal information is collected, used, shared, and sold;
- Delete: Request deletion of personal information;
- Opt-Out of Sale: Opt out of the sale of personal information (we do not sell your data);
- Non-Discrimination: Not be discriminated against for exercising your privacy rights;
- Correct: Request correction of inaccurate personal information;
- Limit Use of Sensitive Personal Information: Limit the use and disclosure of sensitive personal information.
Categories of personal information we collect (per CCPA): Identifiers, professional information, internet/network activity, geolocation data, and commercial information.
7.4 Canadian Privacy Rights (PIPEDA / Quebec Law 25)
If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Quebec's Law 25 (An Act to modernize legislative provisions as regards the protection of personal information):
- Consent: We collect, use, and disclose your personal information only with your consent or as permitted by law;
- Access and Correction: You may request access to and correction of your personal information;
- Withdrawal: You may withdraw consent for non-essential data processing;
- Granular Consent: For Quebec residents, we provide granular consent options for specific data collection purposes;
- Complaint: You may file a complaint with the Office of the Privacy Commissioner of Canada or the Commission d'acces a l'information du Quebec.
7.5 Exercising Your Rights
To exercise any of these rights:
- Use the Privacy Settings in your account dashboard;
- Email our Data Protection Officer at dpo@closina.com;
- Contact support at privacy@closina.com.
We will respond to verified requests within thirty (30) days (or within the timeframe required by applicable law). We may ask you to verify your identity before processing requests.
8. Cookie Policy
8.1 Types of Cookies We Use
| Cookie Type | Purpose | Duration | Required? |
|---|---|---|---|
| Essential | Authentication, security, session management | Session | Yes |
| Functional | Preferences, settings, language | 1 year | No |
| Analytics | Usage patterns, feature adoption | 2 years | No |
| Performance | Load times, error tracking | 1 year | No |
8.2 Managing Cookies
You can manage cookie preferences through:
- Your browser settings (to block or delete cookies);
- Our in-app cookie preference center;
- Your account privacy settings.
Note that disabling essential cookies will prevent you from using the Service.
8.3 Third-Party Cookies
We may use third-party analytics tools that set their own cookies. These are governed by the respective third parties' privacy policies.
9. International Data Transfers
9.1 Data Location
The Service is hosted on cloud infrastructure in North America. Your data may be processed in the United States and Canada.
9.2 Transfer Safeguards
For transfers of personal data from the EU/EEA, UK, or other jurisdictions with data transfer restrictions, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Data Processing Agreements with the sub-processors we engage directly, and the flow-down obligations those agreements impose on any sub-processor those providers in turn engage;
- Supplementary technical and organizational measures as needed.
9.3 Data Localization
If you require data to remain within a specific geographic region, please contact us to discuss available options.
10. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly.
If you believe that a child under 16 has provided us with personal information, please contact us at privacy@closina.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Post the updated Policy on our website and within the Service;
- Notify you via email or in-app notification at least thirty (30) days before the changes take effect;
- Update the version number and effective date;
- Require re-acceptance if the changes are substantive.
We encourage you to review this Policy periodically to stay informed about our data practices.
12. Contact Information
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
- Data Protection Officer: dpo@closina.com
- Privacy Inquiries: privacy@closina.com
- General Support: support@closina.com
- Mailing Address: Closina Inc, Privacy Team, 18 King Street East, Suite 1400, Toronto, Ontario M5C 1C4, Canada
- Website: https://closina.com
For unresolved privacy concerns, you may also contact the applicable data protection authority in your jurisdiction.