Privacy Policy
Version 2026-09-02; editorially corrected 4 September 2026
Scope of This Policy
This Privacy Policy applies only to the official Customermates website and the managed cloud service operated by Benjamin Wagner, including where that service is made available through another domain or brand operated by him. It does not describe processing performed by an independent self-host operator.
An independent self-host operator determines its own purposes, infrastructure, providers, recipients, retention, and legal bases and must provide its own privacy information. Benjamin Wagner does not receive CRM content merely because an independent operator installs or updates the software. If this policy is displayed inside a self-hosted build, it is an upstream reference and does not replace the operator's own notice.
1. Privacy at a Glance
General Notes
The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can personally identify you. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.
Data Collection on this Website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find the operator's contact details in the section "Note on the controller" in this privacy policy.
How do we collect your data?
Your data is collected when you communicate it to us. This can be, for example, data that you enter in a contact form. Other data is collected automatically or after your consent when you visit the website by our IT systems. These are mainly technical data (e.g., internet browser, operating system, or time of page view). The collection of this data occurs automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the website is provided without errors. Other data is recorded in aggregated form in order to measure the use of the website. If contracts are concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other requests.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipient, and purpose of your stored personal data at any time, free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. Furthermore, you have the right to request the restriction of the processing of your personal data under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority. You can contact us at any time regarding this and other questions about data protection. Analysis and third-party tools: use of the managed public website is measured in aggregated form. On managed-cloud public content pages, affiliate referrals are attributed using Lemon Squeezy's standard script. Google advertising and analytics tags remain disabled; after consent, Customermates can retain one advertising click identifier per advertising platform for first-party attribution and report results back to that platform. Such a report would carry that click identifier, which is itself personal data, and beyond it no directly identifying data: no name, no email address and no device identifier. Details are set out below.
2. Hosting and Infrastructure Providers
We host and operate our website and our application with the following providers:
Vercel
The provider is Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (hereinafter referred to as Vercel). When you visit our website, Vercel processes request and log data, including IP addresses, to host and secure the website and web application. Vercel Web Analytics is described separately in section 4 and, according to Vercel, does not use cookies. Cookies required for account authentication and application functions are set by Customermates, not attributed to Vercel Web Analytics. For details, please refer to Vercel's privacy policy: https://vercel.com/legal/privacy-policy.
For personal data that Customermates processes as controller, hosting through Vercel is based on Art. 6 para. 1 lit. f GDPR because we have a legitimate interest in the reliable and secure provision of our website and, insofar as necessary to provide our contractual service, on Art. 6 para. 1 lit. b GDPR. For customer-controlled content, the customer determines the legal basis and Customermates processes the data on documented instructions under the Data Processing Agreement. Storage of or access to information on a user's device is addressed separately under "Cookies" below.
The transfer of personal data to the USA is based on the standard contractual clauses of the EU Commission of 2021 (Implementing Decision (EU) 2021/914) pursuant to Art. 46 GDPR, which form Schedule 3 of Vercel’s data processing addendum. That addendum is available at https://vercel.com/legal/dpa.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service, in the form of Vercel's data processing addendum, which applies on our Pro plan. It is a contract required by data protection law, providing that Vercel processes the personal data of our website visitors according to our instructions and in compliance with the GDPR. Under section 4 of that addendum, Vercel is an independent controller for service-generated data and contact data, and processes that data on its own responsibility under its own privacy policy.
Neon
For the provision and management of our database, we use the Neon managed PostgreSQL service under a contract with Databricks, Inc., the parent company of Neon, LLC (hereinafter "Neon"). Neon provides the managed PostgreSQL database in which the data of our application is stored.
Customermates has configured its primary production database in the AWS Frankfurt region (eu-central-1). This is a selected product setting, not a contractually guaranteed data-residency commitment. Databricks, its affiliates, and applicable subprocessors may process or access data from other countries as described below.
For personal data that Customermates processes as controller, processing through Neon is based on Art. 6 para. 1 lit. b GDPR insofar as necessary to provide our contractual services and on Art. 6 para. 1 lit. f GDPR for our legitimate interest in reliable and secure application operation. For customer-controlled content, the customer determines the legal basis and Customermates processes the data on documented instructions. Neon processes both categories on our behalf under a data processing agreement pursuant to Art. 28 GDPR. Our counterparty is Databricks, Inc., United States. The agreement consists of the Neon Platform Services Product Specific Schedule (https://neon.com/platform-terms), which places the service under the Databricks Master Cloud Services Agreement (https://www.databricks.com/legal/mcsa) and the Databricks Data Processing Addendum (https://www.databricks.com/legal/dpa), and is accepted by using the service.
Databricks, Inc. and its affiliate Neon, LLC are established in the United States, so access from the United States for administration, maintenance, and support cannot be ruled out. The Neon Platform Services Product Specific Schedule dated 5 August 2026 states that the service uses Grafana Labs in the United States in addition to the subprocessors on Databricks' current list at https://www.databricks.com/legal/databricks-subprocessors. That list covers cloud infrastructure, support, communications, and technical or operational affiliates in the countries stated there, and identifies some cloud and AI providers as customer-selected. Customermates uses Neon only as a managed PostgreSQL database in the selected AWS Frankfurt region and has not selected an AI-backed Databricks service for this processing. For restricted transfers to Databricks, the Databricks Data Processing Addendum incorporates the standard contractual clauses of the EU Commission of 2021 (Implementing Decision (EU) 2021/914) pursuant to Art. 46 GDPR.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that Neon processes both the personal data for which we are the controller and the connected-account content that we process on our customers' behalf under section 6, and for which Neon is a subprocessor, only according to our instructions and in compliance with the GDPR.
Forward Email (business email hosting)
For incoming email to our own business addresses under @customermates.com, we use Forward Email, LLC, 16192 Coastal Hwy, Lewes, DE 19958, United States of America (https://forwardemail.net) as our final hosted operator mailbox. Messages are received and stored by Forward Email; no separate downstream mailbox provider is used. The service is not used to connect customer mailboxes, messaging accounts, or calendars and does not ordinarily receive CRM records.
Forward Email may process sender and recipient addresses, message content, attachments, headers, delivery and security metadata, and related account, domain, and alias data. This is ordinarily controller-side business correspondence. If a customer includes personal data governed by our Data Processing Agreement in a support or feedback request, Forward Email also processes that limited fragment as a subprocessor. For controller-side correspondence, our legal basis is Art. 6(1)(f) GDPR (our legitimate interest in secure and reliable business email) and, where necessary for a contractual relationship, Art. 6(1)(b) GDPR. For a fragment covered by our Data Processing Agreement, the customer determines the legal basis and we process it on the customer's documented instructions.
Forward Email's standard data processing agreement is accepted electronically through its service Terms and incorporates the EU Standard Contractual Clauses for applicable transfers. Forward Email is established in the USA, so personal data may be processed in a third country. Further information is available in Forward Email's Terms, data processing agreement, and privacy policy.
Resend
For sending transactional and account emails, we use the service Resend, offered by Plus Five Five, Inc. (operating as Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA (hereinafter "Resend").
We use Resend exclusively for service emails that are necessary to operate your account and to perform our contract with you. These are, in particular, the confirmation of your email address, emails for resetting your password, invitations to a company account, notices concerning the trial period and the status of your account and your connected accounts, notices about updated Terms, the Data Processing Agreement, the Privacy Policy or subprocessors, and internal notifications to us, for example about a new registration, an inquiry submitted through the contact form, feedback, or a support request. The data processed for this purpose comprises the recipient's email address, the name and account data contained in the respective message, the message content, and the technical dispatch and delivery metadata.
The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the email is necessary for the performance of our contract with you or for pre-contractual measures, and Art. 6 para. 1 lit. f GDPR for the notifications sent internally to us and for our legitimate interest in a reliable and secure email infrastructure. Where an email answers an inquiry you addressed to us, our legitimate interest in the effective handling of that inquiry applies (Art. 6 para. 1 lit. f GDPR). These emails are service messages and not advertising. They are therefore not based on consent within the meaning of Art. 6 para. 1 lit. a GDPR and cannot be unsubscribed from separately for as long as your account exists. We do not use Resend for advertising or marketing mailings.
Resend processes the content and the recipient data of the emails we send on our behalf and according to our instructions within the framework of a data processing agreement pursuant to Art. 28 GDPR. For the account, billing and service usage data of our own Resend account, Resend acts as an independent controller under its own terms. Since Resend processes data on servers in the USA, personal data is transferred to a third country. The transfer is based on the standard contractual clauses of the EU Commission pursuant to Art. 46 GDPR, which form part of Resend's data processing addendum, and on Resend's certification under the "EU-US Data Privacy Framework" (DPF).
Further information on data protection at Resend can be found at: https://resend.com/legal/privacy-policy
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This contract covers the recipient data, message content, and delivery metadata that Resend processes on our behalf according to our instructions and in compliance with the GDPR.
Sentry
For error and performance monitoring across our application (browser, server, and background workers), we use the service Sentry, offered by Functional Software, Inc. (d/b/a Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Within the European Union, Sentry is represented by Sentry Software Netherlands B.V., Schiphol Boulevard 359, 1118 BJ, Amsterdam Schiphol, Netherlands. Sentry processes IP addresses, user identifiers (where set), session IDs, stack traces, breadcrumbs, request URLs, and other event metadata from errors captured in our browser, server, and worker runtimes, for the purpose of error monitoring and diagnostics.
We operate Sentry on its European region (Frankfurt, Germany). Error event data is stored within the European Union. However, account, authentication, integration, audit-log, and support data are stored by Sentry on infrastructure in the United States regardless of the region selected. The processing is based on Art. 6 para. 1 lit. f GDPR (legitimate interest in operational reliability and incident response) and, where necessary to provide our contractual services, Art. 6 para. 1 lit. b GDPR. Sentry processes error-event and other Service Data on our behalf under a data processing agreement pursuant to Art. 28 GDPR; it acts as an independent controller for its own account, profile, device, usage, and support data under its privacy policy.
For the transfer of personal data to the United States, Sentry is certified under the EU-US Data Privacy Framework (DPF). Details and the participant record are available at: https://www.dataprivacyframework.gov/list. In addition, Schedule 3 of Sentry's data processing agreement provides for the EU Standard Contractual Clauses pursuant to Art. 46 GDPR as a fallback: they apply if the Data Privacy Framework is invalidated or does not apply to the transfer. For more information about data protection at Sentry, please visit: https://sentry.io/privacy/. Sentry's list of subprocessors is available at: https://sentry.io/legal/subprocessors/. The data processing agreement is available at: https://sentry.io/legal/dpa/.
Data Processing Agreement
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This contract covers the error-event and other Service Data that Sentry processes on our behalf according to our instructions and in compliance with the GDPR.
3. General Notes and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. When you use this website, various personal data is collected. Personal data is data that can personally identify you. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens. We would like to point out that data transmission on the Internet (e.g., when communicating by e-mail) can have security gaps. A complete protection of data against access by third parties is not possible.
Note on the controller
The controller for data processing on this website is:
Benjamin Wagner
An den Kasernen 25
68167 Mannheim
Germany
E-Mail: mail@customermates.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names or e-mail addresses).
Storage duration
Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons no longer apply.
General notes on the legal basis of data processing on this website
If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, insofar as special categories of data pursuant to Art. 9 para. 1 GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, the data processing is also carried out on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or to the access to information in your terminal device (e.g., via device fingerprinting), the data processing is additionally carried out on the basis of § 25 para. 1 TDDDG. The consent can be revoked at any time. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if this is necessary to fulfill a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR. The data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.
Recipients of personal data
As part of our business activities, we work with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only pass on personal data if this is necessary for the performance of a contract, if we are legally obliged to do so (e.g., disclosure to tax authorities), if we have a legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in the disclosure, or if another legal basis permits it. Where an external party acts as our processor, Art. 28 GDPR requires a data processing agreement; the contract status, including any unresolved gap, is described in the relevant provider section and in our subprocessor information. In the case of joint controllership, we conclude an arrangement under Art. 26 GDPR where the other party makes one available.
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke consent that you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
IF THE DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR THE PROCESSING IS FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR). IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, their place of work, or the place of the alleged infringement. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
Automated decision-making and profiling
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22(1) and (4) GDPR. Automated steps that merely carry out the agreed terms of your contract, such as the expiry of a trial period or the automatic deactivation of connected accounts after a prolonged period of inactivity, do not constitute such a decision.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
Information, correction, and deletion
Within the framework of the applicable legal provisions, you have the right to free information about your stored personal data, its origin and recipient, and the purpose of data processing at any time, and if applicable, a right to correction or deletion of this data. For this purpose and for further questions on the subject of personal data, you can contact us at any time.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time.
The right to restriction of processing exists in the following cases
If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data. If the processing of your personal data is unlawful, you can request the restriction of data processing instead of deletion. If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balance must be struck between your and our interests. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data. If you have restricted the processing of your personal data, this data may - apart from being stored - only be processed with your consent or for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or a member state.
SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or requests that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Payment processing and encrypted transmission
Payments for self-service subscriptions are processed through Sold through Link, LLC (formerly Lemon Squeezy LLC); see section 5. Enterprise subscriptions and customers introduced by a distribution partner are billed by invoice from Customermates or the relevant partner. For a self-service purchase, you enter card or account details on the payment provider's own pages; we do not collect those details on this website or receive access to complete payment data. Transmission is encrypted using SSL or TLS.
Objection to advertising e-mails
The use of contact data published within the framework of the imprint obligation for the transmission of advertising and information materials not expressly requested is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.
4. Data Collection on this Website
Cookies
Our Internet pages use so-called "cookies". Cookies are small data packets and do not cause any damage to your device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them yourself or an automatic deletion is carried out by your web browser. Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services of third-party companies within websites (e.g., cookies for handling payment services). Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes.
Cookies or comparable technologies that are strictly necessary to transmit a communication or provide a digital service expressly requested by you are stored or accessed under § 25 para. 2 TDDDG. Any subsequent processing of personal data is based on Art. 6 para. 1 lit. b GDPR where necessary to provide the requested contractual function and otherwise on Art. 6 para. 1 lit. f GDPR unless our legitimate interest in secure operation is overridden by the interests or fundamental rights and freedoms of data subjects. Non-essential storage or access requires consent under § 25 para. 1 TDDDG; related personal-data processing is based on Art. 6 para. 1 lit. a GDPR. Consent may be withdrawn at any time. Vercel Web Analytics is described below and, according to Vercel, does not use cookies and stores anonymized analytics data. The first-party advertising attribution cookie remains disabled until consent is granted; the choice can be changed through “Privacy choices” in the footer. The standard Lemon Squeezy affiliate script described below uses the ls_aff_ref referral cookie for visitors who arrive through an affiliate link or return with an existing referral cookie. The Customermates choice does not switch Vercel Web Analytics or this unchanged Lemon Squeezy script. Google advertising and analytics tags are disabled.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited. Which cookies and services are used on this website can be found in this privacy policy.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Requested URL, including any query parameters
- Hostname of the accessing computer
- Time of the server request
- IP address
A merge of this data with other data sources will not be done. The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of his website - for this purpose, the server log files must be collected.
Externally Hosted Flags and Directory Badges
The language selector and country fields can load flag images directly from flagcdn.com. The footer can load directory badges directly from uneed.best, b.sf-syn.com (SourceForge), twelve.tools, wired.business, startupfa.me, and open-launch.com. When such an image is displayed, your browser connects directly to the relevant domain. The operator of that domain can receive the IP address, the requested image URL, the time of the request, browser and device request headers, and, depending on the browser's referrer policy, the referring page. We do not intentionally send CRM content or account identifiers with these image requests and do not receive visitor-level response data from the image hosts.
We initiate these requests on the basis of Art. 6 para. 1 lit. f GDPR, based on our legitimate interest in making language and country choices recognizable and in displaying factual references to directories that list Customermates. The image hosts process the request data under their own terms; they are listed as other recipients, not as subprocessors for customer-controlled CRM content. Their infrastructure may involve processing outside the EEA, and the location and transfer safeguards depend on the operator concerned. The current domains and their roles are also listed at Subprocessors and Other Recipients.
Vercel Web Analytics
We use Vercel Web Analytics, a usage measurement service of Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (hereinafter "Vercel"). The analytics component runs only on public content pages in the managed cloud service. It does not run inside the authenticated application, on authentication or invitation routes, or in the upstream self-hosted application.
Vercel Web Analytics records page views and the associated usage measurement data, in particular the page called up, the referrer, and technical information derived from the request such as the browser and device type and an approximate geographic origin, and makes this available to us in aggregated form. We use this data to understand how our offering is used and to improve it.
The use of Vercel Web Analytics is based on our legitimate interest in understanding and improving our public offering (Art. 6 para. 1 lit. f GDPR). According to Vercel, this analytics service does not use cookies and stores anonymized analytics data.
The transfer of personal data to the USA is based on the standard contractual clauses of the EU Commission of 2021 pursuant to Art. 46 GDPR, as set out in Vercel's data processing addendum. Further details can be found in Vercel's privacy policy: https://vercel.com/legal/privacy-policy.
First-party advertising attribution
In short. If you arrive through a Customermates advertisement, you can choose whether to help us learn what works. With Allow, we retain the advertising platform's click identifier for up to 90 days and, if you create a new managed-cloud workspace, associate it with that workspace. We may use it to report a Customermates signup or paid subscription to the platform that issued the identifier. Beyond that identifier, we do not send your name, email address, telephone number, IP address, user-agent string or purchase amount, and we do not use this data for profiling or personalised advertising. You can decline or withdraw at any time.
Customermates may advertise through Google Ads, ChatGPT Ads, Reddit Ads and LinkedIn Ads. Each of those platforms can append its own click identifier to the address of the page you land on: gclid, gbraid or wbraid for Google, oppref for ChatGPT, rdt_cid for Reddit and li_fat_id for LinkedIn. Customermates does not load any advertising platform's pixel, tag or SDK, and none of them sets a cookie on this website or otherwise accesses your device: only Customermates does.
When a managed-cloud public content page or the contact page is opened with exactly one valid identifier and no attribution decision is stored, Customermates offers an optional attribution choice. A page carrying more than one recognised identifier is ignored entirely. If you consent, a signed first-party cookie named cm_ad_attribution, which JavaScript cannot read (HttpOnly) and which is sent only over an encrypted connection (Secure), stores at most one identifier per advertising platform, each with its identifier kind, click time, capture time and expiry, alongside your decision, the decision time and the version of this notice. It does not store UTM parameters, referrers, landing paths, form contents or CRM records. Raw identifiers expire 89 days after the click for Google and LinkedIn and 30 days after the click for ChatGPT and Reddit, and never later than 90 days after your decision. The cookie itself lasts 90 days from your decision. No advertising company can read it.
While the choice remains open, the identifier and a technical pending marker are carried in the address of Customermates pages you navigate to so the choice survives navigation and reloads. The application recognises this marked pending state for 24 hours, with up to five minutes of device-clock tolerance. This does not create a Customermates attribution cookie or user record before you choose Allow. The notice does not block the page: you can read and use the site while the choice is open, and no cookie, no browser storage entry and no database record is created unless you choose Allow. While the choice is open the identifier is part of the web address, so it reaches the server log files described above. Browser history may retain an earlier marked address until it is revisited; after a decision, expiry, or an invalid marker, the application removes both values from the current address and from an earlier such history entry when you revisit it.
An unexpired Allow choice remains valid until you withdraw it or until we change what this notice asks your permission for, and a later eligible visit is stored without presenting the choice again. If we change what your Allow covers, your earlier decision is treated as if it had not been given: the stored identifiers are no longer used and you are asked again. An editorial or factual correction that does not change the data, purpose, retention, potential recipients, legal basis, your rights or what your Allow covers leaves your decision in place. Because each advertising platform matches a conversion only against the click it issued, a later click from the same platform replaces the earlier one for that platform; identifiers held for other platforms are unaffected.
If you create a new managed-cloud workspace before expiry, the retained identifiers and those timestamps are copied once, as part of the same registration transaction, to that workspace and you as its initial owner. They are not copied to invited users or users joining an existing workspace and are not overwritten on later sign-ins. Customermates also records that the workspace was created, and later that it became a paying subscription. The purpose of all of this is to learn which of our advertisements bring people to Customermates, so that we can decide where to spend our advertising budget. We do not build usage profiles, do not combine this data with data from other websites, and do not use it to target advertising at you.
Reporting is not automatic. An authorised Customermates operator decides whether to submit a conversion report before the identifier expires, and only the advertising platform that issued the identifier may receive it. Your Allow covers the report described here to the four platforms named below. If we want to report to another advertising platform or send a broader report, we ask for your decision again first.
A report may contain the identifier the platform itself issued, the result name ("Customermates signup" or "Customermates paid"), the time of that result, a one-way deduplication reference and, where required, consent-status fields. The deduplication reference lets the platform ignore a repeated report without revealing your workspace or linking the signup and paid result to each other. The click identifier is itself personal data because the platform can link it to the advertisement it served you. Beyond that identifier, no directly identifying data is transmitted: no name, no email address, no hashed email address, no telephone number, no IP address, no user agent and no monetary amount. Personalised advertising remains denied.
Potential recipients of such a report are Google LLC for Google Ads, OpenAI for ChatGPT Ads, Reddit, Inc. for Reddit Ads and LinkedIn Corporation for LinkedIn Ads. Each acts as an independent controller for its own advertising services, not as a processor for Customermates, and decides for itself how it handles a conversion it receives. Transfers outside the EEA rely on the EU-US Data Privacy Framework where the recipient is certified under it, which covers Google, Reddit and LinkedIn, and on standard contractual clauses together with a transfer impact assessment for OpenAI, which is not certified under that framework. We keep standard contractual clauses as a fallback for the certified recipients as well.
Choosing Allow gives two separate consents in one action: one under § 25 para. 1 TDDDG to storing the cookie described above on your device, and one under Art. 6 para. 1 lit. a GDPR to the processing that follows from it: retaining the identifier, attaching it to a workspace you create, measuring which of our advertisements brought people to Customermates, and transmitting the report described above to the advertising platform that issued the click. If you decline, the same cookie is stored for 90 days, but it then holds only the preference, decision time, notice version and expiry, and no identifier at all. You can withdraw consent at any time through "Privacy choices" in the footer, the same control in the same place as the choice you were originally offered. Withdrawing immediately removes the identifiers from the cookie. If a copy was already attached to a workspace, sign in first: the same control then also deletes the workspace copy, which Art. 17 para. 1 lit. b GDPR requires us to do. Withdrawal does not affect the lawfulness of the processing carried out before it (Art. 7 para. 3 sentence 3 GDPR), and a report already submitted to a platform cannot be recalled. Expired identifiers are removed by a daily automated deletion run. The record that a workspace was created, and later that it became a paying subscription, contains no advertising identifier; it is kept for as long as the workspace exists and is deleted with it. No advertising pixel, tag, measurement SDK, Customer Match, enhanced-conversions transfer or advanced matching is active.
Contact form
If you send us inquiries via the contact form, your information from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. In processing the inquiry, these data are transmitted to the infrastructure and e-mail providers described in section 2; we otherwise disclose them only where a legal basis permits it.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR, if your request is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the requests addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; the consent can be revoked at any time.
The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.
Request by e-mail
If you contact us by e-mail, your request, including all resulting personal data (name and content of the request), will be stored and processed by us for the purpose of handling it. These data pass through the e-mail providers described in section 2; we otherwise disclose them only where a legal basis permits it. The processing is based on Art. 6 para. 1 lit. b GDPR if your request relates to a contract or pre-contractual measures. In all other cases, it is based on our legitimate interest in handling requests effectively (Art. 6 para. 1 lit. f GDPR) or, where requested, on your consent (Art. 6 para. 1 lit. a GDPR), which you may revoke at any time.
The data you send to us by email will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory legal provisions - in particular legal retention periods - remain unaffected.
Data Processing Agreement
Incoming email to our own @customermates.com business addresses is received and stored in our hosted operator mailbox at Forward Email. Resend sends the automated transactional and account messages generated by the application; ordinary human replies are sent from the Forward Email mailbox. No separate downstream mailbox provider is used. Resend's processing is governed by a data processing agreement pursuant to Art. 28 GDPR. Forward Email's standard data processing agreement is accepted electronically through its service Terms and incorporates the EU Standard Contractual Clauses for applicable transfers.
Registration on this website
You can register on this website to use additional functions on the site. We use the data entered for this purpose only for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration. Providing this data is not required by statute; it is required in order to conclude and perform the contract with us. Without the information marked as mandatory we cannot create an account for you and cannot provide the service. Beyond that you are not obliged to provide us with personal data, and apart from being unable to use the function concerned there are no consequences if you do not.
For important changes, such as the scope of the offer or technically necessary changes, we use the e-mail address provided during registration to inform you in this way. The processing of the data entered during registration is based on the purpose of carrying out the user relationship established by the registration and, if applicable, for the initiation of further contracts (Art. 6 para. 1 lit. b GDPR). The data collected during registration will be stored by us as long as you are registered on this website and will then be deleted. Legal retention periods remain unaffected.
Legal-document notices and acceptance records
For the managed cloud service, we record legal-document notices and electronic acceptances in the existing company audit log. Every record includes the company and user identifiers, event type, and audit-record creation time. A notice record also contains the current document versions, the exact documents included in the email, a snapshot of the recipient's email address, and any applicable effective or objection date. An acceptance record also contains the current document versions, a snapshot of the accepting user's email address, and whether acceptance occurred during initial onboarding or after a later update. The audit-record creation time is the notice or acceptance time.
We use these records to avoid duplicate notices, identify notices that remain to be sent, calculate a consistent company deadline, present or enforce the legal-update flow in the managed-service user interface, and prove which identified documents were notified or accepted. The processing is based on Art. 6(1)(b) GDPR where it is necessary to form, administer, or amend the business-customer contract and on Art. 6(1)(f) GDPR for our legitimate interests in reliable delivery, access control, and legal evidence. The records currently follow the audit log's existing retention relationships: they remain while the related company and user records exist and are deleted automatically if either related record is deleted. This is the audit system's existing cascade-deletion behavior and must be reassessed before a production user- or company-deletion feature is introduced. No separate immutable legal archive is maintained in the application.
Registration with Google
Instead of registering directly on this website, you can register with Google. The provider of this service is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Your browser redirects you to Google's sign-in page, where you enter your Google credentials; Customermates does not receive or store your password. Google authenticates you and returns the account information covered by the authorization screen so that we can create or complete your profile. You can review connected access in your Google settings at https://myaccount.google.com/security and https://myaccount.google.com/permissions. The processing associated with Google registration is based on our legitimate interest in offering a simple registration process (Art. 6 para. 1 lit. f GDPR). The function is voluntary.
For transfers to the United States, Google LLC is an active participant in the EU-US Data Privacy Framework (DPF). The participant record is available at: https://www.dataprivacyframework.gov/participant/5780.
Registration with Microsoft
Instead of registering directly on this website, you can register with Microsoft. The provider of this service is Microsoft Ireland Operations Limited ("Microsoft"), One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. Your browser redirects you to Microsoft's sign-in page, where you enter your Microsoft credentials; Customermates does not receive or store your password. Microsoft authenticates you and returns the account information covered by the authorization screen so that we can create or complete your profile. You can review your security and privacy settings at https://account.microsoft.com/security and https://account.microsoft.com/privacy.
The data processing associated with Microsoft registration is based on our legitimate interest in making the registration process as simple as possible for our users (Art. 6 para. 1 lit. f GDPR). Since the use of the registration function is voluntary and users can decide for themselves about the respective access options, no opposing overriding rights of the data subjects are apparent.
For transfers to the United States, Microsoft Corporation is an active participant in the EU-US Data Privacy Framework (DPF). The participant record is available at: https://www.dataprivacyframework.gov/participant/6474.
5. Digital Platform and Payment Provider
Processing of Customer and Contract Data
We collect, process, and use personal customer and contract data for the establishment, content design, execution, and modification of our contractual relationships. Personal data relating to the use of this website (usage data) is collected, processed, and used only insofar as this is necessary to enable the use of the service or for billing purposes.
The legal basis for this data processing is Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures).
The collected customer data will be deleted after termination of the business relationship and expiry of any applicable statutory retention periods. Statutory retention obligations remain unaffected.
We disclose personal data to the recipients identified in this privacy policy where this is necessary to perform a contract, to comply with a legal obligation, to pursue a legitimate interest after balancing the affected interests, or where another legal basis permits the disclosure. We do not sell personal data. The only disclosure we make to a third party for that party's own advertising purposes is the conversion report described under First-party advertising attribution above, which happens only with your consent and which you can withdraw at any time.
Payment Services (Lemon Squeezy)
For self-service payment processing, we use the external payment service provider Sold through Link, LLC (formerly Lemon Squeezy LLC), 222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA (hereinafter “Lemon Squeezy”).
When you make a self-service purchase, your payment data (e.g. name, billing address, email address, payment amount, and, where applicable, payment information such as credit card or bank details) is processed directly by Lemon Squeezy. We do not receive access to full payment details.
For a self-service purchase, Lemon Squeezy acts as the Merchant of Record and is responsible for payment processing and, where applicable, the calculation, collection, and remittance of statutory sales taxes. It does not act on our behalf for that purchase but as an independent controller under its own terms; there is no data processing agreement pursuant to Art. 28 GDPR for that processing.
Data processing is carried out on the basis of:
- Art. 6(1)(b) GDPR (performance of a contract),
- Art. 6(1)(f) GDPR (legitimate interest in secure and efficient payment processing).
As Lemon Squeezy is based in the USA, personal data may be transferred to a third country. For a self-service purchase, Lemon Squeezy acts as merchant of record under its own terms and as an independent controller, so its own privacy policy governs that processing. Its published data processing agreement provides that the parties rely on the EU Standard Contractual Clauses; we have archived that text but have not concluded a separate agreement with the provider.
Affiliate Tracking (Lemon Squeezy)
Our payment provider Sold through Link, LLC (formerly Lemon Squeezy LLC) also offers an affiliate tracking system,
222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA.
Customermates loads Lemon Squeezy's standard affiliate script only on managed-cloud public content pages. Every visit to one of those pages requests the script from lmsqueezy.com; that request can disclose the visitor's IP address, request time, browser and HTTP headers, and, depending on browser policy, the referring page to Lemon Squeezy even when the URL contains no affiliate code. When a visitor arrives through an affiliate link, the script reads the aff URL parameter. On that visit, or on a return visit to a public content page with an existing referral cookie, it sends the landing URL, referrer, referral reference, and a browser-derived visitor identifier to Lemon Squeezy. It stores the first-party ls_aff_ref referral cookie for the tracking period configured in Lemon Squeezy and can add the referral reference to Lemon Squeezy checkout links on those pages.
The purpose is to attribute referred visits and purchases, allocate commission, administer the affiliate programme, and prevent incorrect attribution. We rely on Art. 6(1)(f) GDPR for the personal-data processing that follows device access, based on our legitimate interests and those of participating affiliates in accurate attribution and remuneration. This legal basis does not replace consent where § 25(1) TDDDG requires it for storing information on or accessing a visitor's device. The current standard script is not gated by a separate Customermates consent mechanism. Browser settings may block or delete the cookie, which can prevent referral attribution.
Authenticated, authentication, invitation, demo, and upstream self-hosted routes do not load the script. Affiliate-registration links open Lemon Squeezy's hosted website, where Lemon Squeezy's own privacy policy applies. An independent self-host operator controls its own deployment and is responsible for any integration it adds.
Further information on data processing by Lemon Squeezy can be found in their privacy policy:
https://www.lemonsqueezy.com/privacy
and their terms of service:
https://www.lemonsqueezy.com/terms
6. Connected Accounts (Email, Messaging, and Calendar)
Our CRM system offers an optional connected-account feature that lets you connect your own email mailboxes (Gmail/Google, Microsoft/Outlook, and IMAP), messaging accounts (LinkedIn, including its Sales Navigator and Recruiter variants, as well as WhatsApp, Instagram, and Telegram), and calendars. Depending on the connected provider, the feature can send, receive, and manage business communications and appointments; retrieve and display social posts, comments, reactions, and person or company profiles; list, send, accept, withdraw, or decline relationship requests; run Sales Navigator lead and company searches; and view existing lead or account lists and add entries to them. The use of this feature is optional and only takes effect if you actively choose to connect an account.
The technical transport of connected-account data is provided by our service provider UNIPILE SAS, RCS Roanne 885265595, 168 rue de la Rotonde, 42153 Riorges, France (hereinafter "Unipile").
Authentication takes place via a Unipile-hosted flow in which you enter provider credentials or complete the provider's OAuth login. Those credentials or OAuth authorization are processed within that flow; Customermates receives neither provider passwords nor OAuth tokens and stores only an opaque account identifier together with non-secret account metadata.
Processed Data
When you use the connected-account feature, the following personal data may be processed, depending on the accounts you connect:
- connected-account metadata (e.g., the connected address or handle, display name, and connection status);
- email content, including subject, body, sender and recipient addresses, and attachments;
- chat and direct-message content across the connected messaging channels;
- contact and participant profile data (name, avatar, LinkedIn headline/occupation, profile URL, and the relevant email address, phone number, or handle);
- social posts and engagement data (post or comment text, authors, reactors, timestamps, reaction types, and counters);
- person and company profile and relationship data (provider identifiers, names, profile URLs and images, descriptions, employment, location, industry, network distance, connection status, and request messages);
- Sales Navigator search inputs, results, and list data (search URLs and filters, lead and company profiles, list names and membership, and saved status);
- calendar events, including attendee email addresses and RSVP status;
- message and account metadata.
Attachment files are transmitted on demand and are not stored by Customermates; only attachment metadata is stored. In addition to the processing at Unipile, Customermates stores a copy of the synchronized connected-account content in its own database (see section 2, "Neon"), in particular message bodies (text and HTML), subjects, sender and recipient identifiers, thread participant profiles, calendar events with attendee email addresses, and the raw inbound data received from the providers. Social posts and engagement, profile lookups, relationship requests, and Sales Navigator search, result, and list data are retrieved or transmitted through Unipile when a customer requests the relevant operation and are returned to the requesting user or a customer-authorized API or MCP client. Customermates does not store that operation data as connected-account content unless the customer separately saves information as a CRM record. Relationship-request and list actions modify the underlying platform on the customer's instruction.
The data processed via the connected-account feature includes personal data of your own users as well as third parties, including correspondents, post and comment authors, reactors, profile subjects, parties to relationship requests, Sales Navigator leads, and company representatives.
Please note that connecting an account also ingests the content of conversations with people who are not users of our service. This content is determined by you and your correspondents and may contain special categories of personal data within the meaning of Art. 9 GDPR. As controller for this content, you are responsible for having a legal basis for its processing and for fulfilling your information duties toward the people concerned.
Roles and Data Processing on Behalf
For connected-account content and operations (including mailboxes, messages, contacts, calendars, social content and engagement data, profiles, relationship requests, and Sales Navigator search and list data), you are the controller within the meaning of Art. 4 no. 7 GDPR. Customermates processes this data exclusively on your behalf and according to your instructions as a processor pursuant to Art. 28 GDPR. Customermates engages Unipile as a subprocessor for this purpose. The underlying communication platforms (Google, Microsoft, LinkedIn, Meta/WhatsApp/Instagram, and Telegram) act as independent controllers for their own respective services.
A list of the subprocessors we engage is available at Subprocessors, and further information on the data processing agreement is available at Data Processing Agreement.
Legal Basis
For account and feature metadata that Customermates processes as controller, processing is necessary to perform our contract with you (Art. 6 para. 1 lit. b GDPR). For connected-account content processed on your behalf, you determine the applicable legal basis and instruct us under the data processing agreement pursuant to Art. 28 GDPR; those instructions are not an independent legal basis under Art. 6 GDPR. This processing by Customermates is not based on consent under Art. 6 para. 1 lit. a GDPR.
Storage and Transfer to Third Countries
Connected-account data is processed at Unipile and is additionally stored in Customermates' own database (see section 2). Unipile states that connected-account data is stored in the EU (France). Its data processing agreement nevertheless permits transfers outside the European Union where Chapter V GDPR safeguards apply, and its subprocessor list names a payment provider in the USA and five proxy providers whose location is not stated. We therefore do not represent that connected-account data never leaves the European Union.
Further information can be found in Unipile's privacy policy at https://www.unipile.com/privacy-policy/, its terms of use at https://www.unipile.com/terms-of-use/, and its security and compliance information at https://www.unipile.com/security-compliance/.
Retention and Deletion
A connected account can be removed in two ways, and the two paths currently have different consequences for the content already stored.
If you disconnect a connected account yourself, we delete the threads, messages, participant profiles, calendar entries, and account activity records stored for that account from our database, and we request Unipile to remove the account.
A connected account is also removed automatically, in particular if a payment fails, if a trial period expires, if the owner of the account has been inactive for a prolonged period, or if after a change of plan more accounts are connected than the plan includes. In these cases we likewise request Unipile to remove the account, but in our own database it is currently only deactivated and marked as deleted. The content already stored for that account, that is the threads, messages, participant profiles, calendar entries, and account activity records, is retained.
Content retained in this way is deleted when the connected account is disconnected, when your user account or your company account is deleted, or through the post-contract return and deletion process described below. You can request deletion at any time, and we will then delete the content.
CRM records that were created or supplemented from connected-account data, in particular contacts and the communication identifiers assigned to them, form part of your CRM data. They are not deleted when a connected account is removed, and they remain until you delete them yourself, your company account is deleted, or the post-contract return and deletion process applies.
We also store technical records of the inbound data received from the providers. Records assigned to a connected account are deleted together with that account. Records that could not be assigned to a connected account are retained for error analysis without a fixed period and cannot currently be attributed to a customer for per-account export or deletion.
Deletion takes effect in our production systems immediately. Copies contained in backups are removed as those backups expire.
We do not apply a fixed retention period to stored connected-account content while the contract remains in force. After the contract ends, data available in our systems and attributable to your company is retained during the 30-day election period under section 11 of the Data Processing Agreement. It is then deleted, or returned and then deleted, in accordance with that section. Statutory retention obligations and the limitations for unassigned raw inbound records described above remain unaffected.
Information for people whose data reaches us through a customer (Art. 14 GDPR)
If you are not a customer of ours but your personal data reaches our systems because one of our customers communicates with you or stores your data in its CRM, that customer and not Customermates is the controller for this data. We process it exclusively on that customer's documented instructions as a processor pursuant to Art. 28 GDPR.
The categories of data concerned are those set out in section 6, in particular contact and profile data; message and calendar content; social-post and engagement data; relationship-request data; and Sales Navigator search, result, and list data. They reach us from the customer directly or, for connected accounts, from the email, messaging, social-network, and calendar providers the customer has connected.
Because we act as a processor, we cannot decide on your rights ourselves. Please address requests for information, rectification, erasure, restriction or objection to the customer who is the controller. If you contact us and we can identify the customer concerned, we forward your request to them without undue delay and inform you that we have done so. Our own contact details are set out in section 3.
Data Subject Requests
Requests from data subjects concerning connected-account content that are addressed to Customermates are forwarded to you as the controller; within the scope of its role as processor, Customermates supports you in responding to such requests. Where you process the personal data of third parties within the CRM, you remain responsible for that processing under data protection law.
7. Mate AI Assistant (Vercel AI Gateway and Microsoft Azure)
Mate is an AI assistant available to registered users of the managed Customermates cloud service. It has been active in the managed service since 29 August 2026. Mate is not part of an independently operated self-hosted installation. Its availability depends on an eligible subscription, available AI credits, and the managed service's global operating controls. A user initiates processing by sending a message or confirming an action in Mate. Where the managed service offers Routines or other saved or automated Mate runs, an authorised user may also configure and activate a saved instruction for manual execution or execution on a schedule or configured in-product event; a resulting run may start without contemporaneous user interaction. Merely having an account does not submit CRM content to a model.
Notice on the use of an AI system
When you use Mate, you interact with an artificial intelligence system and not with a human being. The product identifies the feature as AI. This notice is given pursuant to Art. 50(1) of Regulation (EU) 2024/1689 (AI Act). During interactive use, Mate's output is generated automatically, may be inaccurate or incomplete, and must be checked before it is relied on. Mate and any output about a person are not offered or permitted for any purpose that could have a legal or material impact on that person, including decisions concerning credit, education, employment, housing, insurance, legal matters, or medical matters. Existing permissions apply to Mate's tools. An interactive action with material side effects may require separate confirmation in the product. Where a Routine is offered and enabled, the customer must instead review its instruction, owner, trigger, data scope, permissions, limits, possible side effects, and safeguards before activation or material change and monitor operation and results. An action permitted by the applicable permissions and confirmation controls may occur without separate case-by-case confirmation under the customer's standing instruction.
Data processed and recipients
Depending on the request and the tools used, processing may include:
- the user's name, locale, current application route, prompt or saved instruction, and recent Mate conversation;
- CRM or connected-account content that the user supplies or that an authorised tool retrieves for the requested task, such as contacts, organisations, deals, tasks, services, messages, and related record fields;
- tool descriptions, tool inputs and results, approval and confirmation state, UI-command results, and generated output;
- where Routines are offered, the Routine owner, trigger configuration, schedule, event name and relevant record identifier, run status, limits and guardrail state, and loop-risk findings; and
- company and user identifiers, model and provider identifiers, timestamps, status and diagnostic data, token usage, cost, credit, and billing metadata.
Mate does not automatically upload the entire workspace. A model request contains the prompt or saved instruction and recent conversation together with the context and tool results needed for the requested task. A Routine triggered by a configured in-product event may additionally include the event name and relevant record identifier, after which authorised tools may retrieve the record or connected-account context needed for the instruction. Requests are routed through Vercel AI Gateway, operated by Vercel Inc., to Microsoft Azure as the selected downstream inference provider for the OpenAI-created models used by Mate. Vercel and Microsoft Azure therefore receive the parts of a request necessary to generate the response. Microsoft states that prompts and outputs processed by Azure-hosted models are not available to OpenAI. The current provider chain and transfer information are listed at Subprocessors.
Where event-triggered Routines are offered, Customermates may send the full saved instruction through the model-provider chain when the Routine is saved or materially changed and during recurring safety checks to identify possible trigger loops, even before a Routine run starts. This safety analysis is separate from execution of the saved instruction.
Legal basis and roles
For CRM and connected-account content, including personal data concerning the customer's contacts and correspondents, the customer is the controller and Customermates processes that content on the customer's documented instructions as a processor pursuant to Art. 28 GDPR. Sending a Mate request or confirming an action is such an instruction. Where Routines are offered, configuring and activating the saved instruction, owner, trigger, limits, and connected permissions constitutes a standing documented instruction for each resulting run until the Routine is disabled or materially changed. These instructions are not consent within the meaning of Art. 6(1)(a) GDPR. The customer remains responsible for having a legal basis for the content and for deciding whether it may be included in a Mate request or Routine.
For user-account, entitlement, usage, billing, security, and diagnostic data that Customermates processes as controller, processing is based on Art. 6(1)(b) GDPR where it is necessary to provide and meter the contracted feature and on Art. 6(1)(f) GDPR for our legitimate interests in secure and reliable operation, abuse prevention, diagnostics, and accurate usage records.
Storage and deletion
Customermates stores Mate conversations and messages, turn requests, model-round records, approvals, tool receipts and results, UI-command results, and associated model, provider, usage, cost, timestamp, company, and user metadata. Where Routines are offered, Customermates also stores the saved instruction, trigger configuration, schedule, owner, limits and guardrail state, run records, loop-risk findings, and relevant event and record references. Each Routine run creates an ordinary Mate conversation. Archiving a conversation hides it but does not delete it. When an authorised user permanently deletes an archived conversation, Customermates deletes that conversation and its messages, turns, rounds, approvals, tool receipts, and UI-command results. Deleting a saved Routine does not itself delete the resulting Mate conversations; those conversations remain until separately deleted through the ordinary Mate deletion controls. Usage and billing records, and CRM records created or changed through Mate, remain subject to their own retention and deletion rules. There is no automatic age-based expiry for an active Mate conversation during an active contract. After the contract ends, customer-controlled data is deleted or returned as described in the Data Processing Agreement, subject to statutory retention obligations and provider-level deletion limits.
If a user expressly escalates a Mate conversation to support, the support request may contain recent conversation text and is then handled as described for support communications in this policy.
Provider handling and international transfers
Customermates has enabled Vercel's team-wide Zero Data Retention (ZDR) control. Vercel states that, while this control remains enabled, it applies to every AI Gateway request for the team, routes requests only to providers with which Vercel has a ZDR agreement, and includes a prompt-training opt-out. Mate additionally pins its selected models to Microsoft Azure; Vercel currently identifies both selected Azure endpoints as supporting ZDR and no prompt training. According to Vercel, Gateway-level prompts and outputs are deleted after inference under ZDR. These Gateway and downstream-provider controls do not delete, shorten, or otherwise change the Customermates application-level storage described above; routing and usage metadata and Customermates usage and billing records may still be retained. The customer may make authorised personal data available to Mate only where necessary for the requested task and remains responsible for an applicable legal basis, purpose limitation, transparency, data minimisation, access restrictions, and safeguards appropriate to the risk. Before making special categories of personal data under Art. 9 GDPR, data relating to criminal convictions and offences under Art. 10 GDPR, financial-account information, or government-issued identifiers available to Mate, the customer must satisfy the additional legal requirements applicable to that data and restrict the data and access to what is necessary.
Use of Mate can involve processing in the United States and other countries used by Vercel, Microsoft Azure, and their subprocessors. Vercel's data processing addendum incorporates the 2021 EU Standard Contractual Clauses for restricted transfers covered by that addendum. The Microsoft Azure terms identified by Vercel, recipient roles, ZDR scope, transfer information, and known contractual and regional limitations are set out at Subprocessors. Further information:
- Vercel AI Product Terms: https://vercel.com/legal/ai-product-terms
- Vercel AI Gateway notices: https://vercel.com/legal/notices-and-license-information
- Vercel Zero Data Retention: https://vercel.com/docs/ai-gateway/security-and-compliance/zdr
- Vercel Data Processing Addendum: https://vercel.com/legal/dpa
- Microsoft information on data privacy for Azure-hosted models: https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/openai/data-privacy
Responsibility
Where Customermates acts as controller, it is responsible for processing involved in providing and technically operating Mate. Where a customer uses Mate with personal data for which that customer is controller, Customermates acts as processor as described above and in the Data Processing Agreement.