Back to buffcrm.co.uk

Buff CRM — Privacy Policy

DASE Systems Limited 45 Main Street, Leeds, West Yorkshire, LS25 1DS Company Number: 17333059 VAT Registration: Pending registration with HMRC ICO Registration: Pending registration with the Information Commissioner's Office

Version 1.0 Effective date: 22 July 2026 Last updated: 22 July 2026


IMPORTANT NOTICE

This Privacy Policy explains how DASE Systems Limited collects, uses, stores, and shares your personal data when you use the Buff CRM Platform and associated services. Please read it carefully.


PART 1 — WHO WE ARE

DASE Systems Limited ("DASE", "we", "us", "our") is the controller of personal data collected through the Buff CRM marketing website (buffcrm.co.uk) and is a processor of personal data that our subscribers input into the Buff CRM Platform (app.buffcrm.co.uk).

Contact details: DASE Systems Limited, 45 Main Street, Leeds, West Yorkshire, LS25 1DS Email: [email protected]


PART 2 — WHAT DATA WE COLLECT

2.1 Data you provide directly

When you sign up for Buff CRM, we collect: your name, email address, phone number, business name, and billing information. When you use the Platform, you may input customer personal data, vehicle records, job records, booking information, and payment records.

2.2 Data we collect automatically

When you visit our website or use the Platform, we automatically collect: IP address, browser type and version, pages visited, time spent on pages, referring URLs, and device information. We use cookies and similar technologies for this purpose — see our Cookie Policy for full details.

2.3 Data from third parties

We may receive data from Stripe (payment processing), Twilio (SMS delivery), and Cloudflare (security and infrastructure) in connection with providing the Platform.


PART 3 — HOW WE USE YOUR DATA

3.1 To provide the Platform

We use your data to: create and manage your account, provide the features and functionality of the Platform, process payments, send transactional communications (booking confirmations, invoices, receipts), and provide customer support.

Legal basis: Performance of a contract (Article 6(1)(b) UK GDPR).

3.2 To improve the Platform

We use aggregated and anonymised usage data to understand how the Platform is used, identify issues, and develop new features.

Legal basis: Legitimate interests (Article 6(1)(f) UK GDPR) — improving our service.

3.3 To communicate with you

We send you service-related communications (account notices, security alerts, policy updates) and, where you have consented or we have a legitimate interest, marketing communications about Buff CRM.

Legal basis: Legitimate interests for service communications; consent for marketing.

3.4 To comply with legal obligations

We retain certain data to comply with financial record-keeping requirements and other legal obligations.

Legal basis: Legal obligation (Article 6(1)(c) UK GDPR).


PART 4 — YOUR DATA AS A SUBSCRIBER

4.1 Your customers' data

When you use Buff CRM to manage your detailing business, you input personal data about your own customers (their names, contact details, vehicle information, and so on). In relation to that data:

Our obligations as your processor are set out in our Data Processing Agreement, which forms part of your subscription agreement.

4.2 Your responsibilities

As the controller of your customers' data, you are responsible for: having a lawful basis to collect and process that data, providing your customers with appropriate privacy information, responding to any data subject rights requests from your customers, and ensuring you comply with UK GDPR and any other applicable data protection laws.


PART 5 — WHO WE SHARE YOUR DATA WITH

We do not sell your personal data. We share it only with:

Infrastructure and hosting: Hetzner Online GmbH (server hosting, EU-based).

Payment processing: Stripe, Inc. (payment processing). Stripe's privacy policy: stripe.com/gb/privacy.

Email delivery: Resend Inc. (transactional email delivery). Resend's privacy policy: resend.com/legal/privacy-policy.

SMS delivery: Twilio Inc. (SMS delivery). Twilio's privacy policy: twilio.com/en-us/legal/privacy.

Security and CDN: Cloudflare, Inc. (DDoS protection, CDN, DNS). Cloudflare's privacy policy: cloudflare.com/privacypolicy.

Error monitoring: Sentry (error tracking, EU servers, no PII collected).

All third-party processors are bound by data processing agreements and are required to process your data only on our instructions.


PART 6 — INTERNATIONAL TRANSFERS

Some of our third-party processors are based outside the UK. Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or UK adequacy decisions.


PART 7 — HOW LONG WE KEEP YOUR DATA

Account data: Retained for the duration of your subscription and for 90 days after termination, after which it is deleted or anonymised, unless we are required to retain it longer by law.

Invoice and financial records: Retained for 6 years following the end of the relevant tax year, in accordance with HMRC requirements. Invoice records are anonymised after this period.

Marketing data: Until you withdraw consent or object to processing.

Server logs: Typically retained for 30 days.


PART 8 — YOUR RIGHTS

Under UK GDPR, you have the following rights:

Right of access: You can request a copy of the personal data we hold about you.

Right to rectification: You can ask us to correct inaccurate personal data.

Right to erasure: You can ask us to delete your personal data in certain circumstances.

Right to restriction: You can ask us to restrict how we process your data in certain circumstances.

Right to data portability: You can ask us to provide your data in a machine-readable format.

Right to object: You can object to processing based on legitimate interests or for direct marketing.

Rights related to automated decision-making: We do not make solely automated decisions with legal or similarly significant effects.

To exercise any of these rights, contact us at [email protected]. We will respond within one month.


PART 9 — SECURITY

We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit (TLS), access controls, regular backups, error monitoring, and security reviews. However, no method of transmission over the internet is 100% secure.


PART 10 — COOKIES

We use cookies and similar technologies. For full details, see our Cookie Policy.


PART 11 — CHILDREN

The Platform is not directed at children under 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data about a child, please contact us at [email protected].


PART 12 — CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify you of material changes via the Platform or by email at least 30 days before they take effect. The current version and effective date are shown at the top of this document.


PART 13 — COMPLAINTS

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Website: ico.org.uk Telephone: 0303 123 1113

We would appreciate the opportunity to address your concerns directly before you contact the ICO — please email us at [email protected].


PART 14 — CONTACT US

By email: [email protected]

By post: Data Protection DASE Systems Limited 45 Main Street Leeds West Yorkshire LS25 1DS

This Privacy Policy was last updated on 22 July 2026 and is effective from 22 July 2026.