Last updated: October 10, 2025
This Privacy Policy explains how Penda CRM ("we", "our", or "us") collects, uses, and protects your personal information when you use our service. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We use your information to:
We process your personal data under the following lawful bases:
We share your data only with trusted service providers:
We do not sell, rent, or share your personal information with third parties for their marketing purposes. All third-party providers are contractually obligated to protect your data and comply with UK GDPR.
We retain your personal data for as long as your account is active or as needed to provide you services. After account termination, we retain data for 90 days for backup purposes, then permanently delete it unless we are legally required to retain it longer. Job and financial records may be retained for up to 7 years to comply with UK tax and accounting regulations.
We implement industry-standard security measures including encryption in transit (TLS/SSL), encryption at rest, row-level security policies, regular security audits, and secure authentication protocols. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Under UK GDPR, you have the right to:
To exercise any of these rights, please contact us at the email address below.
Your data is primarily stored in EU/UK data centers. Where data is transferred outside the UK/EU, we ensure adequate safeguards are in place through standard contractual clauses or other approved mechanisms under UK GDPR.
Our service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
We use essential cookies for authentication and session management. These are necessary for the service to function and cannot be disabled. We do not use advertising or analytics cookies without your explicit consent.
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a prominent notice on our service. The "Last updated" date at the top indicates when the policy was last revised.
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Email: privacy@penda.work
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection authority, at ico.org.uk.
This Privacy Policy is compliant with UK GDPR and the Data Protection Act 2018. If you are based outside the UK, additional protections may apply under your local laws.