Privacy Policy
In force from 18 September 2026
anyCRM is a business management system used by salons, shops and food outlets. This policy explains what data we collect, why we need it and what you can do about it. It is written in plain words — if anything is still unclear, write to us and we will explain.
Who is responsible for the data
The service belongs to KVLK Studio. For any question about personal data, write to us through the contact form.
Two roles are worth telling apart:
- For your own account we are the controller: we decide what has to be kept for the service to work.
- For your customers' data, which you enter into the system, we are only the processor: we store and process it on your instructions. You are the controller of that data, and it is you who must have a lawful basis for entering it and for telling your customers about it.
What we collect
| Data | Why | Basis |
|---|---|---|
| Email, name, phone, interface language | Signing in, event emails, support | Performance of a contract |
| Company data: name, type, working hours, switched-on modules, balance | Running the service and the monthly charge | Performance of a contract |
| What you enter: clients, bookings, orders, products, materials, finances | This is your work in the system | Your instructions |
| Technical records: request times, errors, IP address | Security, finding faults | Legitimate interest |
| Session token, language and theme in browser storage | So you are not signed out every time and the look does not reset | Necessary for the service |
What we do not collect
- Card numbers. Payment happens on the bank's own page. If you let the bank keep the card for automatic top-ups, it stays with the bank, and we receive only an opaque token and the masked last digits — neither can be turned back into a number or used to pay anywhere else.
- Advertising profiles. There are no trackers, advertising pixels or third-party analytics on the site or in the app. We do not sell or hand data to ad networks.
Who the data goes to
Only the services a feature you switched on cannot work without. A module that is off sends nothing.
| Where | What exactly |
|---|---|
| monobank — paying for modules and topping up the balance; acquiring for your customers | Amount, payment purpose, company name |
| Nova Poshta, Ukrposhta — delivery | Recipient's name, phone and address, description of the parcel |
| Prom.ua, Rozetka — marketplaces | Products, orders, buyer's contacts |
| LetsAds, TurboSMS, SMS Club, eSputnik, Twilio — messaging | Recipient's phone or email and the message text |
| Telegram — notifications to you and your customers | The notification text |
| Checkbox — fiscal receipts | Receipt lines, total, payment method |
| PrivatBank, monobank, OpenDataBot — bank statements and sole trader tax data | The account identifier or tax number you entered |
| Mail server — sign-in codes and notifications | Recipient's email and the message |
Separately, data may be handed over on a lawful written demand from a state authority, and when the business passes to a new owner — of which we will warn you in advance.
How long it is kept
- As long as you use the service — everything you entered.
- After an account is deleted, the company's data is removed within 30 days. That window exists so a deletion made by mistake can be undone.
- Records of payments and charges are kept longer — accounting and tax law require it.
- Technical records are kept for up to 90 days.
Your rights
Under the Ukrainian Personal Data Protection Act, and under the GDPR for residents of the EU, you can:
- find out what data we hold about you and get a copy of it;
- correct inaccurate data — most fields are editable in the app itself;
- delete the account along with its data;
- object to processing or have it restricted;
- complain to the Ukrainian Parliament Commissioner for Human Rights or to the supervisory authority of your country.
To use any of these rights, write to us through the contact form. We answer within 30 days.
Security
The connection to the server is always encrypted (HTTPS). There are no passwords in the usual sense: you sign in with a one-time code sent to your email, so there is no password to guess or steal. Only your company's own staff, with the rights you gave them, can see its data. Administrator access to the database is limited and used only to fix faults.
No system is perfectly safe. If a breach happens that puts your rights at risk, we will tell you and the supervisory authority within 72 hours of learning about it.
Children
The service is made for businesses and is not intended for anyone under 16. We do not knowingly collect their data.
Changes to this policy
If the policy changes, the new version appears on this page and the date above is updated. We will email you about any substantial change at least 14 days before it takes effect.
Questions about personal data — the contact form.
See also the Terms of Service.