Privacy Policy

In force from 18 September 2026

anyCRM is a business management system used by salons, shops and food outlets. This policy explains what data we collect, why we need it and what you can do about it. It is written in plain words — if anything is still unclear, write to us and we will explain.

Who is responsible for the data

The service belongs to KVLK Studio. For any question about personal data, write to us through the contact form.

Two roles are worth telling apart:

What we collect

DataWhyBasis
Email, name, phone, interface languageSigning in, event emails, supportPerformance of a contract
Company data: name, type, working hours, switched-on modules, balanceRunning the service and the monthly chargePerformance of a contract
What you enter: clients, bookings, orders, products, materials, financesThis is your work in the systemYour instructions
Technical records: request times, errors, IP addressSecurity, finding faultsLegitimate interest
Session token, language and theme in browser storageSo you are not signed out every time and the look does not resetNecessary for the service

What we do not collect

Who the data goes to

Only the services a feature you switched on cannot work without. A module that is off sends nothing.

WhereWhat exactly
monobank — paying for modules and topping up the balance; acquiring for your customersAmount, payment purpose, company name
Nova Poshta, Ukrposhta — deliveryRecipient's name, phone and address, description of the parcel
Prom.ua, Rozetka — marketplacesProducts, orders, buyer's contacts
LetsAds, TurboSMS, SMS Club, eSputnik, Twilio — messagingRecipient's phone or email and the message text
Telegram — notifications to you and your customersThe notification text
Checkbox — fiscal receiptsReceipt lines, total, payment method
PrivatBank, monobank, OpenDataBot — bank statements and sole trader tax dataThe account identifier or tax number you entered
Mail server — sign-in codes and notificationsRecipient's email and the message

Separately, data may be handed over on a lawful written demand from a state authority, and when the business passes to a new owner — of which we will warn you in advance.

How long it is kept

Your rights

Under the Ukrainian Personal Data Protection Act, and under the GDPR for residents of the EU, you can:

To use any of these rights, write to us through the contact form. We answer within 30 days.

Security

The connection to the server is always encrypted (HTTPS). There are no passwords in the usual sense: you sign in with a one-time code sent to your email, so there is no password to guess or steal. Only your company's own staff, with the rights you gave them, can see its data. Administrator access to the database is limited and used only to fix faults.

No system is perfectly safe. If a breach happens that puts your rights at risk, we will tell you and the supervisory authority within 72 hours of learning about it.

Children

The service is made for businesses and is not intended for anyone under 16. We do not knowingly collect their data.

Changes to this policy

If the policy changes, the new version appears on this page and the date above is updated. We will email you about any substantial change at least 14 days before it takes effect.

Questions about personal data — the contact form.

See also the Terms of Service.