Evrondesk
Legal

Privacy Policy

Effective date: July 12, 2026

This Privacy Policy describes how Evrondesk (“Evrondesk”, “we”, “us”) collects, uses, stores, shares, and protects information when you use our CRM application, website, and related services (the “Service”). By using the Service you agree to this Policy.

1. Who we are

Evrondesk provides a customer-relationship-management workspace for teams. This Policy applies to individuals who sign up for an Evrondesk account, teammates invited into a workspace, and end-users whose data is stored in a workspace by our customers.

2. Information we collect

  • Account data: name, email address, profile photo, workspace membership, role, authentication identifiers, and preferences.
  • Customer data: contacts, companies, deals, tickets, notes, tasks, files, and any other records you or your team create inside Evrondesk.
  • Communications data: email messages, calendar events, chat and SMS content that you explicitly connect to Evrondesk through an integration.
  • Usage data: log data, device and browser information, IP address, pages viewed, features used, and diagnostic events used to keep the Service reliable and secure.
  • Billing data: if applicable, plan, invoices, and limited payment metadata (full card numbers are handled by our payment processor, never by us).

3. How we use information

  • Provide, operate, and maintain the Service.
  • Authenticate users, prevent abuse, and secure accounts.
  • Sync email, calendar, and other data you explicitly connect.
  • Respond to support requests and communicate service updates.
  • Improve reliability, performance, and product quality.
  • Comply with legal obligations and enforce our terms.

We do not sell your personal information, and we do not use the content of your emails, calendars, contacts, or CRM records to serve advertisements or to train generalized AI/ML models.

4. Google API Services — Limited Use disclosure

Evrondesk’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect a Gmail or Google Calendar account, we request the minimum scopes required to provide the feature you enabled. Specifically:

  • Gmail (gmail.modify, gmail.send): read, compose, send, and organize messages inside your own Evrondesk inbox; associate messages with the CRM records you choose.
  • Google Calendar: read and write calendar events so meetings scheduled or logged in Evrondesk stay in sync with your calendar.
  • Basic profile (openid, email, profile): identify which Google account is connected and display your name and avatar.

Google user data accessed through these scopes is used only to provide user-facing features inside Evrondesk. We do not transfer this data to third parties except as necessary to provide the Service, to comply with applicable law, or as part of a merger or acquisition (in which case we will notify you). We do not use Google user data for advertising and we do not allow humans to read your Google user data unless (a) you have given us explicit consent for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.

You can disconnect a Google account at any time from Settings → Email inside Evrondesk, or by revoking access at myaccount.google.com/permissions.

5. How we share information

We share information only in these limited situations:

  • Within your workspace: teammates in the same Evrondesk workspace can access records according to the permissions your workspace admin configures.
  • Service providers (subprocessors): hosting, database, email delivery, error monitoring, and analytics vendors that process data on our behalf under written data-processing terms.
  • Legal: when required by law, subpoena, or to protect the rights, safety, or property of Evrondesk, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, or asset sale, subject to standard confidentiality obligations.

6. Data retention

We retain account and customer data for as long as your workspace is active. When you delete a record, it is removed from active systems promptly and purged from backups within 30 days. When you delete your account or disconnect an integration, associated tokens are revoked immediately and the underlying data is deleted or anonymized within 30 days, except where retention is required by law.

7. Security

We use industry-standard safeguards including TLS in transit, encryption at rest, least-privilege access controls, audit logging, and regular dependency scanning. OAuth refresh tokens for third-party integrations are encrypted before storage. No system is perfectly secure, but we work continuously to protect your data.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. You can exercise most of these rights directly inside the app or by contacting us at privacy@evrondesk.com.

9. Children

Evrondesk is not directed to children under 16 and we do not knowingly collect personal information from them.

10. International transfers

We may process data in countries other than your own. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be announced in-app or by email. The “Effective date” at the top always reflects the latest version.

12. Contact

Questions about this Policy or your data? Email privacy@evrondesk.com.