Perfexly

Privacy Policy

Last updated: 27 July 2026

This Privacy Policy explains how Perfexly collects, uses, stores, shares, and protects personal data when you visit our website, contact us, create an account, start a trial, subscribe to a plan, use a hosted CRM workspace, or receive support.

Plain English summary

We use account, billing, support, security, and usage data to run Perfexly. Customers control the business records they add to their own CRM workspace. We do not sell personal data. Payment details such as full card numbers are handled by payment providers, not stored directly by Perfexly.

1. Who we are

Perfexly is a hosted CRM workspace provider. Our contact address is 20 Wenlock Road, London, N1 7GU, United Kingdom. You can contact us about privacy or data protection at support@perfexly.com.

2. Our role

For account, billing, website, support, and direct customer relationship data, Perfexly normally acts as a data controller. For personal data that customers upload into their CRM workspaces, such as their own client, lead, invoice, project, and support records, Perfexly normally acts as a processor on behalf of the customer.

Customers are responsible for telling their own contacts, clients, staff, and leads how their data is used inside the customer workspace.

3. Personal data we collect

We may collect and process the following categories of personal data:

We may also process preferences such as language, notification choices, consent records, security settings, cookie choices, and customer portal permissions. If you send us screenshots or files during support, those files may include personal data depending on what is visible in the image or document.

4. How we collect data

We collect data when you submit forms, register, subscribe, pay invoices, contact support, use the platform, accept cookies, or otherwise interact with Perfexly. We may also receive data from payment processors, email systems, hosting/security providers, and integrations connected to the service.

5. Why we use personal data

We use personal data for the following purposes:

6. Lawful bases

Where UK GDPR applies, we rely on different lawful bases depending on the purpose. These may include contract performance for providing the service, legitimate interests for security and service improvement, legal obligation for accounting and compliance records, consent for optional marketing or non-essential cookies, and vital interests where urgently required to protect someone.

7. Customer workspace data

Customers control the data they enter into their CRM workspace. This may include personal data about their customers, leads, suppliers, staff, or end users. Perfexly processes this data to host the workspace, provide functionality, run backups, secure the service, and support the customer.

Customers must make sure they have appropriate permission, notices, lawful bases, and internal controls for the data they add to Perfexly.

Customer workspace data may include contact details, sales notes, invoices, proposals, contracts, support tickets, uploaded files, project notes, task comments, internal reminders, and other business records. Customers decide what is entered, who can access it, how long it should be kept, and when it should be exported or deleted, subject to the controls available in the platform and any legal obligations that apply.

If an individual contacts Perfexly about data stored inside a customer workspace, we may need to refer the request to the relevant customer because that customer controls the purpose and content of the workspace data.

8. Sharing personal data

We do not sell personal data. We may share personal data with trusted service providers who help us operate Perfexly, including hosting providers, email providers, payment processors, security tools, analytics services, professional advisers, and support systems.

We may also share data where required by law, to enforce our terms, to protect the rights or safety of Perfexly, customers, users, or others, or as part of a business transfer such as a merger, restructuring, or sale.

Examples of service providers may include website hosting, database hosting, email delivery, payment processors, fraud prevention, support tooling, logging, backup storage, analytics, and professional advisers. We aim to give providers access only to the data they need for their role.

9. International transfers

Some service providers may process data outside the United Kingdom. Where this happens, we aim to use appropriate safeguards such as adequacy decisions, standard contractual clauses, or equivalent protections required by applicable data protection law.

10. Security

We use reasonable technical and organisational measures to protect personal data, including access controls, password protection, server security, backups, logging, and secure payment handling through payment providers. No online service can be guaranteed to be completely secure, so customers should also use strong passwords, limit staff permissions, and report suspected misuse quickly.

Customers should review staff accounts regularly, remove access when someone leaves, avoid shared logins, and check file/contact permissions before making information visible through the customer portal. Where multi-factor authentication or other security options are available, customers should decide whether to enable them for their own risk level.

11. Retention

We keep personal data only for as long as needed for the purposes described in this policy. Account and billing records may be kept for legal, tax, accounting, fraud prevention, and dispute resolution reasons. Workspace data may be retained while the account is active and for a limited period after cancellation or termination before deletion, unless a longer period is required by law or agreed with the customer.

Backups may retain deleted records for a limited period until backup cycles expire. This means data removed from the live workspace may not disappear immediately from all backup copies. Backup copies are used for continuity, security, and recovery purposes and are not normally accessed unless needed.

12. Cookies and similar technologies

Perfexly may use cookies and similar technologies for login sessions, security, preferences, analytics, and service performance. Some cookies are necessary for the website and customer area to work. Optional cookies, if used, should be controlled through the choices shown on the website or your browser settings.

13. Marketing

We may send service-related messages that are necessary for your account, billing, security, or use of Perfexly. We will only send optional marketing where allowed by law. You can opt out of marketing messages, but you may still receive important service emails.

14. Your rights

Depending on your circumstances and applicable law, you may have the right to request access to your personal data, correction of inaccurate data, deletion, restriction, objection, portability, withdrawal of consent, or review of automated decisions where applicable.

If your data is held inside a customer workspace, we may need to refer your request to the customer who controls that workspace data.

To help us respond, include your name, email address, company name, workspace URL if relevant, and the type of request you are making. We may need to verify your identity before actioning a request. Some requests may be refused or limited where we need to keep information for legal, accounting, security, dispute, or fraud prevention reasons.

15. Complaints

Please contact us first at support@perfexly.com so we can try to resolve your concern. You may also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.

16. Changes to this policy

We may update this Privacy Policy from time to time. The latest version will be published on this page, and the date above will show when it was last updated.

17. Contact

For privacy questions or requests, contact support@perfexly.com.