Privacy Policy
Effective date: [Effective Date]
[Company Legal Name] · EduLearn CRM
1. Introduction
This Privacy Policy describes how [Company Legal Name] ("we," "us," or "our") collects, uses, stores, and protects information when you use EduLearn CRM (the "Service"), including through web browsers and supported mobile applications.
By accessing or using the Service, you acknowledge that you have read this Privacy Policy. This document is provided as a draft and may be updated following legal review.
2. Information We Collect
Depending on how you use the Service, we may collect the following categories of information:
- Account and user information — such as name, email address, role, and other profile details associated with your user account.
- Authentication and session information — such as login credentials (stored in hashed or otherwise protected form where applicable), session tokens, and related security data used to authenticate you and maintain your session.
- Daily Activity Report (DAR) information — activity records, notes, statuses, timestamps, and other fields you enter or generate when creating or managing DAR entries.
- School, customer, and business information — information about schools, customers, contacts, products, and related business data entered into or linked with CRM activities.
- Photos — images captured or uploaded through the Service in connection with activities, reports, or related workflows.
- Location information — GPS or other location data when a location feature is enabled and you (or your organization) choose to use it in connection with an activity or report.
- Device and application information — technical information that may be collected in the normal course of operating the Service, such as device type, operating system, app version, IP address, browser type, and diagnostic or log data where technically collected.
3. How We Use Information
We use collected information to:
- Provide, operate, maintain, and improve the Service;
- Authenticate users and manage accounts and access permissions;
- Record, display, and process CRM and DAR data submitted by authorized users;
- Support offline or synchronized workflows where those features are enabled;
- Respond to support requests and operational needs;
- Monitor performance, troubleshoot issues, and help protect the security and integrity of the Service;
- Comply with applicable legal obligations and enforce our terms and policies.
4. How Information Is Stored and Protected
We apply reasonable administrative, technical, and organizational measures intended to protect information against unauthorized access, loss, misuse, or alteration. No method of transmission or storage can be guaranteed to be completely secure.
Access to the Service is intended for authorized personnel only. Your organization may impose additional access controls, policies, or procedures that apply to your use of the Service.
5. When Information May Be Shared
We do not sell personal information. Information may be shared in limited circumstances, such as:
- With service providers or subprocessors that help us operate the Service, subject to appropriate contractual or operational safeguards where applicable;
- Within your organization, according to role-based permissions and business needs configured in the Service;
- When required by law, regulation, legal process, or governmental request, or to protect rights, safety, security, or the integrity of the Service;
- In connection with a business transaction such as a merger, acquisition, or asset transfer, subject to applicable notice requirements.
Specific third-party providers, if any, should be listed here after review: [Third-Party Service Providers — To Be Completed].
6. Data Retention
We retain information for as long as reasonably necessary to provide the Service, meet operational and legal requirements, resolve disputes, and enforce agreements. Retention periods may vary by data type and by your organization's policies.
Detailed retention schedules should be confirmed by authorized personnel: [Data Retention Schedule — To Be Completed].
7. User Responsibilities
Users of the Service are responsible for:
- Using the Service only as authorized by their organization;
- Protecting login credentials and signing out when using shared or unattended devices;
- Entering accurate information and obtaining necessary permissions before uploading photos, location data, or business information relating to third parties;
- Following applicable organizational policies and applicable laws when using the Service.
8. Account Access and Logout
You should log out of the Service when finished, especially on shared devices. Logging out is intended to end your active session on that device or browser. Depending on device, browser, or application settings, local cached data may persist until cleared according to your organization's procedures or device controls.
9. Third-Party Services
The Service may rely on third-party infrastructure, hosting, authentication, storage, analytics, or related services. Those providers may process information according to their own terms and privacy practices where applicable.
A reviewed list of material third-party services should be published here when available: [Third-Party Services List — To Be Completed].
10. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we may revise the effective date and provide notice through the Service or by other reasonable means. Continued use of the Service after an update may constitute acknowledgment of the revised policy, subject to applicable law.
11. Contact Us
For privacy-related questions or requests, contact: [Privacy Contact Email] or [Privacy Contact Address — To Be Completed].
