Privacy Policy
Version 2026-08-08, last updated 8 August 2026
Scope of This Policy
This Privacy Policy applies only to the official Customermates website and the managed cloud service operated by Benjamin Wagner, including where that service is made available through another domain or brand operated by him. It does not describe processing performed by an independent self-host operator.
An independent self-host operator determines its own purposes, infrastructure, providers, recipients, retention, and legal bases and must provide its own privacy information. Benjamin Wagner does not receive CRM content merely because an independent operator installs or updates the software. If this policy is displayed inside a self-hosted build, it is an upstream reference and does not replace the operator's own notice.
1. Privacy at a Glance
General Notes
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can personally identify you. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.
Data Collection on this Website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Note on the controller" in this privacy policy.
How do we collect your data?
Your data is collected when you communicate it to us. This can be, for example, data that you enter in a contact form. Other data is collected automatically or after your consent when you visit the website by our IT systems. These are mainly technical data (e.g., internet browser, operating system, or time of page view). The collection of this data occurs automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the website is provided without errors. Other data is recorded in aggregated form in order to measure the use of the website. If contracts are concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other requests.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipient, and purpose of your stored personal data at any time, free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have the right to request the restriction of the processing of your personal data under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority. You can contact us at any time regarding this and other questions about data protection. Analysis and third-party tools: website use is measured in aggregated form, and the affiliate tracking described in section 5 processes pseudonymous browser and attribution data. Details are set out below.
2. Hosting and Infrastructure Providers
We host and operate our website and our application with the following providers:
Vercel
The provider is Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (hereinafter referred to as Vercel). When you visit our website, Vercel processes request and log data, including IP addresses, to host and secure the website and web application. Vercel Web Analytics is described separately in section 4 and, according to Vercel, does not use cookies. Cookies required for account authentication and application functions are set by Customermates, not attributed to Vercel Web Analytics. For details, please refer to Vercel's privacy policy: https://vercel.com/legal/privacy-policy.
For personal data that Customermates processes as controller, hosting through Vercel is based on Art. 6 para. 1 lit. f GDPR because we have a legitimate interest in the reliable and secure provision of our website and, insofar as necessary to provide our contractual service, on Art. 6 para. 1 lit. b GDPR. For customer-controlled content, the customer determines the legal basis and Customermates processes the data on documented instructions under the Data Processing Agreement. Storage of or access to information on a user's device is addressed separately under "Cookies" below.
The transfer of personal data to the USA is based on the standard contractual clauses of the EU Commission of 2021 (Implementing Decision (EU) 2021/914) pursuant to Art. 46 GDPR, which form Schedule 3 of Vercel’s data processing addendum. That addendum is available at https://vercel.com/legal/dpa.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service, in the form of Vercel's data processing addendum, which applies on our Pro plan. It is a contract required by data protection law, providing that Vercel processes the personal data of our website visitors according to our instructions and in compliance with the GDPR. Under section 4 of that addendum, Vercel is an independent controller for service-generated data and contact data, and processes that data on its own responsibility under its own privacy policy.
Neon
For the provision and management of our database, we use the Neon managed PostgreSQL service under a contract with Databricks, Inc., the parent company of Neon, LLC (hereinafter "Neon"). Neon provides the managed PostgreSQL database in which the data of our application is stored.
Customermates has configured its primary production database in the AWS Frankfurt region (eu-central-1). This is a selected product setting, not a contractually guaranteed data-residency commitment. Databricks, its affiliates, and applicable subprocessors may process or access data from other countries as described below.
For personal data that Customermates processes as controller, processing through Neon is based on Art. 6 para. 1 lit. b GDPR insofar as necessary to provide our contractual services and on Art. 6 para. 1 lit. f GDPR for our legitimate interest in reliable and secure application operation. For customer-controlled content, the customer determines the legal basis and Customermates processes the data on documented instructions. Neon processes both categories on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Our counterparty is Databricks, Inc., United States. The agreement consists of the Neon Platform Services Product Specific Schedule (https://neon.com/platform-terms), which places the service under the Databricks Master Cloud Services Agreement (https://www.databricks.com/legal/mcsa) and the Databricks Data Processing Addendum (https://www.databricks.com/legal/dpa), and is accepted by using the service.
Databricks, Inc. and its affiliate Neon, LLC are established in the United States, so access from the United States for administration, maintenance, and support cannot be ruled out. The Neon Platform Services Product Specific Schedule dated 5 August 2026 states that the service uses Grafana Labs in the United States in addition to the subprocessors on Databricks' current list at https://www.databricks.com/legal/databricks-subprocessors. That list covers cloud infrastructure, support, communications, and technical or operational affiliates in the countries stated there, and identifies some cloud and AI providers as customer-selected. Customermates uses Neon only as a managed PostgreSQL database in the selected AWS Frankfurt region and has not selected an AI-backed Databricks service for this processing. For restricted transfers to Databricks, the Databricks Data Processing Addendum incorporates the standard contractual clauses of the EU Commission of 2021 (Implementing Decision (EU) 2021/914) pursuant to Art. 46 GDPR.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that Neon processes both the personal data for which we are the controller and the connected-account content that we process on our customers' behalf under section 6, and for which Neon is a subprocessor, only according to our instructions and in compliance with the GDPR.
Forward Email (business email hosting)
For incoming email to our own business addresses under @customermates.com, we use Forward Email, LLC, 16192 Coastal Hwy, Lewes, DE 19958, United States of America (https://forwardemail.net) as our final hosted operator mailbox. Messages are received and stored by Forward Email; no separate downstream mailbox provider is used. The service is not used to connect customer mailboxes, messaging accounts, or calendars and does not ordinarily receive CRM records.
Forward Email may process sender and recipient addresses, message content, attachments, headers, delivery and security metadata, and related account, domain, and alias data. This is ordinarily controller-side business correspondence. If a customer includes personal data governed by our Data Processing Agreement in a support or feedback request, Forward Email also processes that limited fragment as a subprocessor. For controller-side correspondence, our legal basis is Art. 6(1)(f) GDPR (our legitimate interest in secure and reliable business email) and, where necessary for a contractual relationship, Art. 6(1)(b) GDPR. For a fragment covered by our Data Processing Agreement, the customer determines the legal basis and we process it on the customer's documented instructions.
Forward Email's standard data processing agreement is accepted electronically through its service Terms and incorporates the EU Standard Contractual Clauses for applicable transfers. Forward Email is established in the USA, so personal data may be processed in a third country. Further information is available in Forward Email's Terms, data processing agreement, and privacy policy.
Resend
For sending transactional and account emails, we use the service Resend, offered by Plus Five Five, Inc. (operating as Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA (hereinafter "Resend").
We use Resend exclusively for service emails that are necessary to operate your account and to perform our contract with you. These are, in particular, the confirmation of your email address, emails for resetting your password, invitations to a company account, notices concerning the trial period and the status of your account and your connected accounts, notices about updated Terms, the Data Processing Agreement, the Privacy Policy or subprocessors, and internal notifications to us, for example about a new registration, an inquiry submitted through the contact form, feedback, or a support request. The data processed for this purpose comprises the recipient's email address, the name and account data contained in the respective message, the message content, and the technical dispatch and delivery metadata.
The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the email is necessary for the performance of our contract with you or for pre-contractual measures, and Art. 6 para. 1 lit. f GDPR for the notifications sent internally to us and for our legitimate interest in a reliable and secure email infrastructure. Where an email answers an inquiry you addressed to us, our legitimate interest in the effective handling of that inquiry applies (Art. 6 para. 1 lit. f GDPR). These emails are service messages and not advertising. They are therefore not based on consent within the meaning of Art. 6 para. 1 lit. a GDPR and cannot be unsubscribed from separately for as long as your account exists. We do not use Resend for advertising or marketing mailings.
Resend processes the content and the recipient data of the emails we send on our behalf and according to our instructions within the framework of a data processing agreement pursuant to Art. 28 GDPR. For the account, billing and service usage data of our own Resend account, Resend acts as an independent controller under its own terms. Since Resend processes data on servers in the USA, personal data is transferred to a third country. The transfer is based on the standard contractual clauses of the EU Commission pursuant to Art. 46 GDPR, which form part of Resend's data processing addendum, and on Resend's certification under the "EU-US Data Privacy Framework" (DPF).
Further information on data protection at Resend can be found at: https://resend.com/legal/privacy-policy
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This contract covers the recipient data, message content, and delivery metadata that Resend processes on our behalf according to our instructions and in compliance with the GDPR.
Sentry
For error and performance monitoring across our application (browser, server, and background workers), we use the service Sentry, offered by Functional Software, Inc. (d/b/a Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Within the European Union, Sentry is represented by Sentry Software Netherlands B.V., Schiphol Boulevard 359, 1118 BJ, Amsterdam Schiphol, Netherlands. Sentry processes IP addresses, user identifiers (where set), session IDs, stack traces, breadcrumbs, request URLs, and other event metadata from errors captured in our browser, server, and worker runtimes, for the purpose of error monitoring and diagnostics.
We operate Sentry on its European region (Frankfurt, Germany). Error event data is stored within the European Union. However, account, authentication, integration, audit-log, and support data are stored by Sentry on infrastructure in the United States regardless of the region selected. The processing is based on Art. 6 para. 1 lit. f GDPR (legitimate interest in operational reliability and incident response) and, where necessary to provide our contractual services, Art. 6 para. 1 lit. b GDPR. Sentry processes error-event and other Service Data on our behalf under a data processing agreement pursuant to Art. 28 GDPR; it acts as an independent controller for its own account, profile, device, usage, and support data under its privacy policy.
For the transfer of personal data to the United States, Sentry is certified under the EU-US Data Privacy Framework (DPF). Details and the participant record are available at: https://www.dataprivacyframework.gov/list. In addition, Schedule 3 of Sentry's data processing agreement provides for the EU Standard Contractual Clauses pursuant to Art. 46 GDPR as a fallback: they apply if the Data Privacy Framework is invalidated or does not apply to the transfer. For more information about data protection at Sentry, please visit: https://sentry.io/privacy/. Sentry's list of subprocessors is available at: https://sentry.io/legal/subprocessors/. The data processing agreement is available at: https://sentry.io/legal/dpa/.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This contract covers the error-event and other Service Data that Sentry processes on our behalf according to our instructions and in compliance with the GDPR.
3. General Notes and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. When you use this website, various personal data is collected. Personal data is data that can personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens. We would like to point out that data transmission on the Internet (e.g., when communicating by e-mail) can have security gaps. A complete protection of data against access by third parties is not possible.
Note on the controller
The controller for data processing on this website is:
Benjamin Wagner
An den Kasernen 25
68167 Mannheim
Germany
E-Mail: mail@customermates.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names or e-mail addresses).
Storage duration
Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons no longer apply.
General notes on the legal basis of data processing on this website
If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, insofar as special categories of data pursuant to Art. 9 para. 1 GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also carried out on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or to the access to information in your terminal device (e.g., via device fingerprinting), the data processing is additionally carried out on the basis of § 25 para. 1 TDDDG. The consent can be revoked at any time. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if this is necessary to fulfill a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR. The data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.
Recipients of personal data
As part of our business activities, we work with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only pass on personal data if this is necessary for the performance of a contract, if we are legally obliged to do so (e.g., disclosure to tax authorities), if we have a legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in the disclosure, or if another legal basis permits it. Where an external party acts as our processor, Art. 28 GDPR requires a data processing agreement; the contract status, including any unresolved gap, is described in the relevant provider section and in our subprocessor information. In the case of joint controllership, an arrangement under Art. 26 GDPR is concluded.
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke consent that you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
IF THE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR THE PROCESSING IS FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR). IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, their place of work, or the place of the alleged infringement. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
Automated decision-making and profiling
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22(1) and (4) GDPR. Automated steps that merely carry out the agreed terms of your contract, such as the expiry of a trial period or the automatic deactivation of connected accounts after a prolonged period of inactivity, do not constitute such a decision.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
Information, correction, and deletion
Within the framework of the applicable legal provisions, you have the right to free information about your stored personal data, its origin and recipient, and the purpose of data processing at any time, and if applicable, a right to correction or deletion of this data. For this purpose and for further questions on the subject of personal data, you can contact us at any time.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time.
The right to restriction of processing exists in the following cases
If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data. If the processing of your personal data is unlawful, you can request the restriction of data processing instead of deletion. If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balance must be struck between your and our interests. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data. If you have restricted the processing of your personal data, this data may - apart from being stored - only be processed with your consent or for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or a member state.
SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Payment processing and encrypted transmission
Payments for self-service subscriptions are processed through Sold through Link, LLC (formerly Lemon Squeezy LLC); see section 5. Enterprise subscriptions and customers introduced by a distribution partner are billed by invoice from Customermates or the relevant partner. For a self-service purchase, you enter card or account details on the payment provider's own pages; we do not collect those details on this website or receive access to complete payment data. Transmission is encrypted using SSL or TLS.
Objection to advertising e-mails
The use of contact data published within the framework of the imprint obligation for the transmission of advertising and information materials not expressly requested is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.
4. Data Collection on this Website
Cookies
Our Internet pages use so-called "cookies". Cookies are small data packets and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them yourself or an automatic deletion is carried out by your web browser. Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services of third-party companies within websites (e.g., cookies for handling payment services). Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes.
Cookies or comparable technologies that are strictly necessary to transmit a communication or provide a digital service expressly requested by you are stored or accessed under § 25 para. 2 TDDDG. Any subsequent processing of personal data is based on Art. 6 para. 1 lit. b GDPR where necessary to provide the requested contractual function and otherwise on Art. 6 para. 1 lit. f GDPR unless our legitimate interest in secure operation is overridden by the interests or fundamental rights and freedoms of data subjects. Non-essential storage or access requires consent under § 25 para. 1 TDDDG; related personal-data processing is based on Art. 6 para. 1 lit. a GDPR. Consent may be withdrawn at any time. The affiliate technology described in Section 5 is non-essential, and the managed service does not currently implement the consent mechanism required before its device access.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited. Which cookies and services are used on this website can be found in this privacy policy.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
A merge of this data with other data sources will not be done. The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of his website - for this purpose, the server log files must be collected.
Externally Hosted Flags and Directory Badges
The language selector and country fields can load flag images directly from flagcdn.com. The footer can load directory badges directly from uneed.best, b.sf-syn.com (SourceForge), twelve.tools, wired.business, startupfa.me, and open-launch.com. When such an image is displayed, your browser connects directly to the relevant domain. The operator of that domain can receive the IP address, the requested image URL, the time of the request, browser and device request headers, and, depending on the browser's referrer policy, the referring page. We do not intentionally send CRM content or account identifiers with these image requests and do not receive visitor-level response data from the image hosts.
We initiate these requests on the basis of Art. 6 para. 1 lit. f GDPR, based on our legitimate interest in making language and country choices recognizable and in displaying factual references to directories that list Customermates. The image hosts process the request data under their own terms; they are listed as other recipients, not as subprocessors for customer-controlled CRM content. Their infrastructure may involve processing outside the EEA, and the location and transfer safeguards depend on the operator concerned. The current domains and their roles are also listed at Subprocessors and Other Recipients.
Vercel Web Analytics
We use Vercel Web Analytics, a usage measurement service of Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (hereinafter "Vercel"). Vercel Web Analytics is active on all pages of our website and of the web application, including the pages available after login.
Vercel Web Analytics records page views and the associated usage measurement data, in particular the page called up, the referrer, and technical information derived from the request such as the browser and device type and an approximate geographic origin, and makes this available to us in aggregated form. We use this data to understand how our offering is used and to improve it.
The use of Vercel Web Analytics is based on our legitimate interest in the needs-based design and improvement of our offering (Art. 6 para. 1 lit. f GDPR). According to Vercel, this analytics service does not use cookies or store data on or access data from your device for analytics purposes.
The transfer of personal data to the USA is based on the standard contractual clauses of the EU Commission of 2021 pursuant to Art. 46 GDPR, as set out in Vercel's data processing addendum. Further details can be found in Vercel's privacy policy: https://vercel.com/legal/privacy-policy.
Contact form
If you send us inquiries via the contact form, your information from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. In processing the inquiry, these data are transmitted to the infrastructure and e-mail providers described in section 2; we otherwise disclose them only where a legal basis permits it.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR, if your request is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the requests addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; the consent can be revoked at any time.
The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.
Request by e-mail
If you contact us by e-mail, your request, including all resulting personal data (name and content of the request), will be stored and processed by us for the purpose of handling it. These data pass through the e-mail providers described in section 2; we otherwise disclose them only where a legal basis permits it. The processing is based on Art. 6 para. 1 lit. b GDPR if your request relates to a contract or pre-contractual measures. In all other cases, it is based on our legitimate interest in handling requests effectively (Art. 6 para. 1 lit. f GDPR) or, where requested, on your consent (Art. 6 para. 1 lit. a GDPR), which you may revoke at any time.
The data you send to us by email will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions - in particular legal retention periods - remain unaffected.
Data Processing Agreement
Incoming email to our own @customermates.com business addresses is received and stored in our hosted operator mailbox at Forward Email. Resend sends the automated transactional and account messages generated by the application; ordinary human replies are sent from the Forward Email mailbox. No separate downstream mailbox provider is used. Resend's processing is governed by a data processing agreement pursuant to Art. 28 GDPR. Forward Email's standard data processing agreement is accepted electronically through its service Terms and incorporates the EU Standard Contractual Clauses for applicable transfers.
Registration on this website
You can register on this website to use additional functions on the site. We use the data entered for this purpose only for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration. Providing this data is not required by statute; it is required in order to conclude and perform the contract with us. Without the information marked as mandatory we cannot create an account for you and cannot provide the service. Beyond that you are not obliged to provide us with personal data, and apart from being unable to use the function concerned there are no consequences if you do not.
For important changes, such as the scope of the offer or technically necessary changes, we use the e-mail address provided during registration to inform you in this way. The processing of the data entered during registration is based on the purpose of carrying out the user relationship established by the registration and, if applicable, for the initiation of further contracts (Art. 6 para. 1 lit. b GDPR). The data collected during registration will be stored by us as long as you are registered on this website and will then be deleted. Legal retention periods remain unaffected.
Legal-document notices and acceptance records
For the managed cloud service, we record legal-document notices and electronic acceptances in the existing company audit log. Every record includes the company and user identifiers, event type, and audit-record creation time. A notice record also contains the current document versions, the exact documents included in the email, a snapshot of the recipient's email address, and any applicable effective or objection date. An acceptance record also contains the current document versions, a snapshot of the accepting user's email address, and whether acceptance occurred during initial onboarding or after a later update. The audit-record creation time is the notice or acceptance time.
We use these records to avoid duplicate notices, identify notices that remain to be sent, calculate a consistent company deadline, present or enforce the legal-update flow in the managed-service user interface, and prove which identified documents were notified or accepted. The processing is based on Art. 6(1)(b) GDPR where it is necessary to form, administer, or amend the business-customer contract and on Art. 6(1)(f) GDPR for our legitimate interests in reliable delivery, access control, and legal evidence. The records currently follow the audit log's existing retention relationships: they remain while the related company and user records exist and are deleted automatically if either related record is deleted. This is the audit system's existing cascade-deletion behavior and must be reassessed before a production user- or company-deletion feature is introduced. No separate immutable legal archive is maintained in the application.
Registration with Google
Instead of registering directly on this website, you can register with Google. The provider of this service is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Your browser redirects you to Google's sign-in page, where you enter your Google credentials; Customermates does not receive or store your password. Google authenticates you and returns the account information covered by the authorization screen so that we can create or complete your profile. You can review connected access in your Google settings at https://myaccount.google.com/security and https://myaccount.google.com/permissions. The processing associated with Google registration is based on our legitimate interest in offering a simple registration process (Art. 6 para. 1 lit. f GDPR). The function is voluntary.
For transfers to the United States, Google LLC is an active participant in the EU-US Data Privacy Framework (DPF). The participant record is available at: https://www.dataprivacyframework.gov/participant/5780.
Registration with Microsoft
Instead of registering directly on this website, you can register with Microsoft. The provider of this service is Microsoft Ireland Operations Limited ("Microsoft"), One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. Your browser redirects you to Microsoft's sign-in page, where you enter your Microsoft credentials; Customermates does not receive or store your password. Microsoft authenticates you and returns the account information covered by the authorization screen so that we can create or complete your profile. You can review your security and privacy settings at https://account.microsoft.com/security and https://account.microsoft.com/privacy.
The data processing associated with Microsoft registration is based on our legitimate interest in making the registration process as simple as possible for our users (Art. 6 para. 1 lit. f GDPR). Since the use of the registration function is voluntary and users can decide for themselves about the respective access options, no opposing overriding rights of the data subjects are apparent.
For transfers to the United States, Microsoft Corporation is an active participant in the EU-US Data Privacy Framework (DPF). The participant record is available at: https://www.dataprivacyframework.gov/participant/6474.
5. Digital Platform and Payment Provider
Processing of Customer and Contract Data
We collect, process, and use personal customer and contract data for the establishment, content design, execution, and modification of our contractual relationships. Personal data relating to the use of this website (usage data) is collected, processed, and used only insofar as this is necessary to enable the use of the service or for billing purposes.
The legal basis for this data processing is Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures).
The collected customer data will be deleted after termination of the business relationship and expiry of any applicable statutory retention periods. Statutory retention obligations remain unaffected.
We disclose personal data to the recipients identified in this privacy policy where this is necessary to perform a contract, to comply with a legal obligation, to pursue a legitimate interest after balancing the affected interests, or where another legal basis permits the disclosure. We do not sell personal data or disclose it to third parties for their own advertising purposes.
Payment Services (Lemon Squeezy)
For self-service payment processing, we use the external payment service provider Sold through Link, LLC (formerly Lemon Squeezy LLC), 222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA (hereinafter “Lemon Squeezy”).
When you make a self-service purchase, your payment data (e.g. name, billing address, email address, payment amount, and, where applicable, payment information such as credit card or bank details) is processed directly by Lemon Squeezy. We do not receive access to full payment details.
For a self-service purchase, Lemon Squeezy acts as the Merchant of Record and is responsible for payment processing and, where applicable, the calculation, collection, and remittance of statutory sales taxes. It does not act on our behalf for that purchase but as an independent controller under its own terms; there is no data processing agreement pursuant to Art. 28 GDPR for that processing.
Data processing is carried out on the basis of:
- Art. 6(1)(b) GDPR (performance of a contract),
- Art. 6(1)(f) GDPR (legitimate interest in secure and efficient payment processing).
As Lemon Squeezy is based in the USA, personal data may be transferred to a third country. For a self-service purchase, Lemon Squeezy acts as merchant of record under its own terms and as an independent controller, so its own privacy policy governs that processing. Its published data processing agreement provides that the parties rely on the EU Standard Contractual Clauses; we have archived that text but have not concluded a separate agreement with the provider.
Affiliate Tracking (Lemon Squeezy)
As part of our affiliate program, we use a tracking system provided by the payment and affiliate service provider Sold through Link, LLC (formerly Lemon Squeezy LLC),
222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA.
Affiliate tracking is used for the attribution of concluded contracts to referring partners and the settlement of affiliate commissions. The affiliate script is scheduled by the root layout on managed Customermates routes. When the browser fetches it as part of a full document load, the request discloses ordinary request metadata, including the browser's IP address, to Lemon Squeezy. When its affiliate tracker initialises, it reads document.cookie to look for an existing ls_aff_ref cookie. The current root layout does not suppress the script solely because APP_MODE=self-hosted is set. An independent self-host operator controls its own deployment and is responsible for its own disclosures and consent choices.
If neither an existing ls_aff_ref cookie nor an aff parameter in the page URL is found, the script exits without executing its bundled fingerprinting routine or sending an affiliate tracking POST. Otherwise it executes that routine and reads browser and device signals including canvas, audio, fonts, plugins, storage availability, screen, platform, and hardware characteristics; where the trigger is an aff parameter, it can set the ls_aff_ref cookie. The cookie duration is controlled by the affiliate-program setting and has not yet been verified for our store.
When affiliate identification is triggered, the script sends the page URL, referrer, affiliate or click reference, and a pseudonymous visitor identifier to Lemon Squeezy's affiliate endpoint. For the ordinary request metadata disclosed by the unconditional script load and for subsequent personal-data processing for affiliate attribution, we currently rely on Art. 6(1)(f) GDPR (legitimate interest in administering the affiliate program and settling commissions). Storage of device information or access to it requires a separate basis under § 25 TDDDG; Art. 6 GDPR does not replace it. Affiliate attribution is not strictly necessary to provide the digital service requested by the visitor, so consent under § 25(1) TDDDG and a corresponding technical mechanism are required before the non-essential device access. That consent mechanism is not currently implemented.
As Lemon Squeezy is based in the USA, personal data may be transferred to a third country. Lemon Squeezy's contractual role and the applicable transfer mechanism for affiliate tracking have not yet been established for our account; both issues remain unresolved for the current processing.
Further information on data processing by Lemon Squeezy can be found in their privacy policy:
https://www.lemonsqueezy.com/privacy
and their terms of service:
https://www.lemonsqueezy.com/terms
6. Connected Accounts (Email, Messaging, and Calendar)
Our CRM system offers an optional connected-account feature that lets you connect your own email mailboxes (Gmail/Google, Microsoft/Outlook, and IMAP), messaging accounts (LinkedIn, including its Sales Navigator and Recruiter variants, as well as WhatsApp, Instagram, and Telegram), and calendars. Depending on the connected provider, the feature can send, receive, and manage business communications and appointments; retrieve and display social posts, comments, reactions, and person or company profiles; list, send, accept, withdraw, or decline relationship requests; run Sales Navigator lead and company searches; and view existing lead or account lists and add entries to them. The use of this feature is optional and only takes effect if you actively choose to connect an account.
The technical transport of connected-account data is provided by our service provider UNIPILE SAS, RCS Roanne 885265595, 168 rue de la Rotonde, 42153 Riorges, France (hereinafter "Unipile").
Authentication takes place via a Unipile-hosted flow in which you enter provider credentials or complete the provider's OAuth login. Those credentials or OAuth authorization are processed within that flow; Customermates receives neither provider passwords nor OAuth tokens and stores only an opaque account identifier together with non-secret account metadata.
Processed Data
When you use the connected-account feature, the following personal data may be processed, depending on the accounts you connect:
- connected-account metadata (e.g., the connected address or handle, display name, and connection status);
- email content, including subject, body, sender and recipient addresses, and attachments;
- chat and direct-message content across the connected messaging channels;
- contact and participant profile data (name, avatar, LinkedIn headline/occupation, profile URL, and the relevant email address, phone number, or handle);
- social posts and engagement data (post or comment text, authors, reactors, timestamps, reaction types, and counters);
- person and company profile and relationship data (provider identifiers, names, profile URLs and images, descriptions, employment, location, industry, network distance, connection status, and request messages);
- Sales Navigator search inputs, results, and list data (search URLs and filters, lead and company profiles, list names and membership, and saved status);
- calendar events, including attendee email addresses and RSVP status;
- message and account metadata.
Attachment files are transmitted on demand and are not stored by Customermates; only attachment metadata is stored. In addition to the processing at Unipile, Customermates stores a copy of the synchronized connected-account content in its own database (see section 2, "Neon"), in particular message bodies (text and HTML), subjects, sender and recipient identifiers, thread participant profiles, calendar events with attendee email addresses, and the raw inbound data received from the providers. Social posts and engagement, profile lookups, relationship requests, and Sales Navigator search, result, and list data are retrieved or transmitted through Unipile when a customer requests the relevant operation and are returned to the requesting user or a customer-authorized API or MCP client. Customermates does not store that operation data as connected-account content unless the customer separately saves information as a CRM record. Relationship-request and list actions modify the underlying platform on the customer's instruction.
The data processed via the connected-account feature includes personal data of your own users as well as third parties, including correspondents, post and comment authors, reactors, profile subjects, parties to relationship requests, Sales Navigator leads, and company representatives.
Please note that connecting an account also ingests the content of conversations with people who are not users of our service. This content is determined by you and your correspondents and may contain special categories of personal data within the meaning of Art. 9 GDPR. As controller for this content, you are responsible for having a legal basis for its processing and for fulfilling your information duties toward the people concerned.
Roles and Data Processing on Behalf
For connected-account content and operations (including mailboxes, messages, contacts, calendars, social content and engagement data, profiles, relationship requests, and Sales Navigator search and list data), you are the controller within the meaning of Art. 4 no. 7 GDPR. Customermates processes this data exclusively on your behalf and according to your instructions as a processor pursuant to Art. 28 GDPR. Customermates engages Unipile as a subprocessor for this purpose. The underlying communication platforms (Google, Microsoft, LinkedIn, Meta/WhatsApp/Instagram, and Telegram) act as independent controllers for their own respective services.
A list of the subprocessors we engage is available at Subprocessors, and further information on the data processing agreement is available at Data Processing Agreement.
Legal Basis
For account and feature metadata that Customermates processes as controller, processing is necessary to perform our contract with you (Art. 6 para. 1 lit. b GDPR). For connected-account content processed on your behalf, you determine the applicable legal basis and instruct us under the data processing agreement pursuant to Art. 28 GDPR; those instructions are not an independent legal basis under Art. 6 GDPR. This processing by Customermates is not based on consent under Art. 6 para. 1 lit. a GDPR.
Storage and Transfer to Third Countries
Connected-account data is processed at Unipile and is additionally stored in Customermates' own database (see section 2). Unipile states that connected-account data is stored in the EU (France). Its data processing agreement nevertheless permits transfers outside the European Union where Chapter V GDPR safeguards apply, and its subprocessor list names a payment provider in the USA and five proxy providers whose location is not stated. We therefore do not represent that connected-account data never leaves the European Union.
Further information can be found in Unipile's privacy policy at https://www.unipile.com/privacy-policy/, its terms of use at https://www.unipile.com/terms-of-use/, and its security and compliance information at https://www.unipile.com/security-compliance/.
Retention and Deletion
A connected account can be removed in two ways, and the two paths currently have different consequences for the content already stored.
If you disconnect a connected account yourself, we delete the threads, messages, participant profiles, calendar entries, and account activity records stored for that account from our database, and we request Unipile to remove the account.
A connected account is also removed automatically, in particular if a payment fails, if a trial period expires, if the owner of the account has been inactive for a prolonged period, or if after a change of plan more accounts are connected than the plan includes. In these cases we likewise request Unipile to remove the account, but in our own database it is currently only deactivated and marked as deleted. The content already stored for that account, that is the threads, messages, participant profiles, calendar entries, and account activity records, is retained.
Content retained in this way is deleted when the connected account is disconnected, when your user account or your company account is deleted, or through the post-contract return and deletion process described below. You can request deletion at any time, and we will then delete the content.
CRM records that were created or supplemented from connected-account data, in particular contacts and the communication identifiers assigned to them, form part of your CRM data. They are not deleted when a connected account is removed, and they remain until you delete them yourself, your company account is deleted, or the post-contract return and deletion process applies.
We also store technical records of the inbound data received from the providers. Records assigned to a connected account are deleted together with that account. Records that could not be assigned to a connected account are retained for error analysis without a fixed period and cannot currently be attributed to a customer for per-account export or deletion.
Deletion takes effect in our production systems immediately. Copies contained in backups are removed as those backups expire.
We do not apply a fixed retention period to stored connected-account content while the contract remains in force. After the contract ends, data available in our systems and attributable to your company is retained during the 30-day election period under section 11 of the Data Processing Agreement. It is then deleted, or returned and then deleted, in accordance with that section. Statutory retention obligations and the limitations for unassigned raw inbound records described above remain unaffected.
Information for people whose data reaches us through a customer (Art. 14 GDPR)
If you are not a customer of ours but your personal data reaches our systems because one of our customers communicates with you or stores your data in its CRM, that customer and not Customermates is the controller for this data. We process it exclusively on that customer's documented instructions as a processor pursuant to Art. 28 GDPR.
The categories of data concerned are those set out in section 6, in particular contact and profile data; message and calendar content; social-post and engagement data; relationship-request data; and Sales Navigator search, result, and list data. They reach us from the customer directly or, for connected accounts, from the email, messaging, social-network, and calendar providers the customer has connected.
Because we act as a processor, we cannot decide on your rights ourselves. Please address requests for information, rectification, erasure, restriction or objection to the customer who is the controller. If you contact us and we can identify the customer concerned, we forward your request to them without undue delay and inform you that we have done so. Our own contact details are set out in section 3.
Data Subject Requests
Requests from data subjects concerning connected-account content that are addressed to Customermates are forwarded to you as the controller; within the scope of its role as processor, Customermates supports you in responding to such requests. Where you process the personal data of third parties within the CRM, you remain responsible for that processing under data protection law.
7. Planned AI Assistant (OpenAI)
We are developing an optional AI assistant for our CRM system. As at the date of this privacy policy, the assistant is not yet available and is not processing any data. We describe it here so that you know in advance how it is intended to work. We will update this section before the assistant becomes available.
The assistant is planned as an optional feature for registered users within the CRM. It is intended to answer questions, to analyse and summarise content, and to support the use of the CRM, for example by preparing new entries from the content of a conversation. For customers in the EEA or Switzerland, the planned API counterparty is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (https://openai.com).
Notice on the use of an AI system
When the assistant becomes available, you will be interacting with an artificial intelligence system and not with a human being, and we will point this out in the interface of the feature. This notice is given pursuant to Art. 50 para. 1 of Regulation (EU) 2024/1689 (AI Act). The outputs of the assistant are generated automatically, may be inaccurate or incomplete, and should be checked before you rely on them. The assistant does not take any decision that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
Data to be processed
Once the assistant is available, the following data may be processed when it is used:
- the content of the inputs you make in the assistant,
- data from your company account that you or the assistant include in the request on your instruction,
- technical metadata such as timestamps and session information.
The assistant will be limited to the data of the company account from which it is used.
Legal basis and roles
The assistant will process two different categories of data, and the same allocation of roles applies as for the rest of the CRM.
For the content that you store in the CRM or that reaches the CRM through connected accounts, including the personal data of your contacts and correspondents, you are the controller and we process that content exclusively on your documented instructions as a processor pursuant to Art. 28 GDPR (see section 6). OpenAI will be engaged as a subprocessor for this purpose. Enabling and using the assistant is a decision you take as controller and constitutes an instruction to us; it is not a consent within the meaning of Art. 6 para. 1 lit. a GDPR.
For the operation of your user account and for making the feature available to you as our customer, the processing is based on Art. 6 para. 1 lit. b GDPR (performance of our contract with you) and, insofar as we process technical metadata for the secure and reliable operation of the feature, on Art. 6 para. 1 lit. f GDPR.
The assistant will be an optional feature that has to be activated for a company account. Deactivating it ends its availability and any further processing through it. This is a contractual and technical control and does not alter the legal basis described above.
Processing on our behalf and processing by OpenAI
Before the assistant is made available, we will conclude a data processing agreement with OpenAI pursuant to Art. 28 GDPR. OpenAI is already listed in advance at Subprocessors under the notice procedure set out in our Data Processing Agreement, marked as planned and not yet in use. According to OpenAI, data transmitted through its API is not used to train its own models. Further information:
- OpenAI Data Processing Addendum: https://openai.com/policies/data-processing-addendum
- OpenAI Privacy Policy: https://openai.com/policies/privacy-policy
Transfer to third countries
Use of the assistant may involve transfers of personal data to the USA. Before the feature is made available, any such transfer will be governed by the transfer terms and Standard Contractual Clauses in OpenAI's data processing addendum pursuant to Art. 46 GDPR.
Storage duration
It is intended that the content of conversations with the assistant is processed only for the duration of the respective session and is not stored permanently by us. We will confirm the actual behaviour in this section before the assistant becomes available.
Responsibility
Insofar as we act as controller, we are responsible for the data processing involved in providing and technically operating the CRM system, including the AI assistant. Insofar as you process personal data of third parties within the CRM, you are the controller and we act as processor as described above.