Sync CRM Back to website

Legal

Privacy Policy

Effective 2 August 2026 · Last updated 5 August 2026

This Policy explains how Sync CRM handles personal data when businesses visit our website, use our Service, contact us or connect third-party services.

On this page

1. About this Policy 2. Our Privacy Roles 3. Data We Collect 4. How We Use Data 5. Legal Grounds 6. How We Share Data 7. International Transfers 8. Connected Email 9. Payments 10. OCR and AI 11. Children 12. Cookies 13. Retention 14. Security 15. Your Rights 16. Marketing 17. Changes 18. Contact

1. About this Policy

This Privacy Policy describes how The Vysa Technologies FZ-LLC, trading through the Sync CRM brand (“Sync CRM”, “we”, “us” or “our”), collects, uses, discloses, stores and protects personal data.

It applies to our website, the Sync CRM software-as-a-service platform, support and sales communications, connected services, client-facing forms and portals, and related services (together, the “Service”). It should be read with our Terms of Service.

Sync CRM currently serves business customers in the United Arab Emirates. This Policy is intended to address the UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data and other applicable requirements. It is not a substitute for the privacy notice each agency must provide to its own clients and applicants.

2. Our privacy roles

For agency and website relationships: we generally determine why and how we process account, billing, website, sales, support, security and service-administration data.

For agency Customer Data: the agency generally determines why and how applicant, client, case, document and related information is processed. Sync CRM processes that information on the agency’s instructions to provide the Service.

Applicants and agency clients should normally direct privacy requests about their case information to the agency responsible for their application. We will reasonably assist the agency with verified requests where required.

3. Personal data we collect

Depending on how the Service is used, we may process the following categories.

Agency, account and staff data

  • names, business email addresses, telephone numbers, job titles and organisation details;
  • account identifiers, roles, branch access, permissions and subscription details;
  • password hashes, session identifiers, login activity and account-recovery information; and
  • support messages, feedback, call details and communications with us.

Applicant, client and case data

  • names, contact details, dates of birth, nationality, residence and family information;
  • passport, identity, visa, immigration, travel, appointment and refusal information;
  • employment, education, financial and supporting application information;
  • uploaded files, photographs contained in documents, notes, reminders, forms and case history;
  • communications, requested documents, workflow events and portal activity; and
  • information about child applicants where an agency has lawful authority to process it.

Payments and transactions

  • payer name and contact information;
  • amount, currency, payment status, reference, timestamps, invoice and refund information; and
  • payment-related activity and fraud-prevention records.

Connected email and integrations

  • connected Gmail or Outlook address, encrypted OAuth authorisation and connection metadata;
  • limited mailbox metadata cached temporarily so that a connected mailbox can be displayed and synchronised, such as message and thread identifiers, sender and recipient information, subject, timestamps, folder or label information and status information such as unread, starred or whether a message carries attachments;
  • email body content and attachments retrieved from the connected provider when a user opens a message, processed for that request and not persistently stored in our connected-email cache;
  • specific emails or details a user intentionally links, copies or saves to CRM records; and
  • information exchanged with other integrations the agency chooses to enable.

Website, device and security data

  • IP address, browser, device, operating system, referring page and requested pages;
  • session, authentication, security-event, audit and error-log information; and
  • demo-request details such as name, business email, agency, business type, team size, telephone number and stated business needs.

We receive this information directly from agency users and applicants, automatically from devices and service activity, from connected providers, and from agencies that upload or create records about their clients.

4. How we use personal data

We use personal data to:

  • provide, operate, maintain and support the Service;
  • create accounts, authenticate users and apply roles and permissions;
  • manage leads, clients, cases, documents, appointments, workflows, communications and payments as instructed by an agency;
  • retrieve connected email, perform OCR and provide enabled integrations;
  • process subscriptions, invoices, refunds and transaction records;
  • respond to enquiries, demo requests and support issues;
  • secure the Service, detect abuse and fraud, enforce our Terms and investigate incidents;
  • maintain audit trails, diagnose errors, plan capacity and improve reliability;
  • send essential account, billing, security, support and legal communications;
  • send permitted business marketing and manage opt-out preferences;
  • comply with law, lawful requests and protect legal rights; and
  • create aggregated or irreversibly anonymised statistics that do not reasonably identify a person or agency.

We do not sell Customer Data. We do not use applicant contact information for our own marketing.

5. Legal grounds

Where required, we rely on one or more appropriate grounds, including:

  • consent, such as for certain marketing or optional integrations;
  • steps requested before entering and performance of a service agreement;
  • compliance with legal and regulatory obligations;
  • establishing, exercising or defending legal claims;
  • protecting the interests of a person where recognised by law; and
  • other grounds permitted by applicable UAE law.

When we process Customer Data for an agency, the agency is responsible for identifying and maintaining the appropriate legal basis, notices and permissions. An agency must not instruct us to process data unlawfully.

6. How we disclose personal data

We may disclose limited personal data to:

  • the Customer and its authorised staff, according to configured roles and branches;
  • applicants or recipients selected by the agency through client portals, payment pages or communications;
  • infrastructure, hosting, backup, security, communications and technical-support providers;
  • Google and Microsoft for enabled email connections;
  • Google Cloud Document AI for requested OCR processing;
  • Nomod for payment processing;
  • Web3Forms for delivering demo-request and contact submissions made through our website to us by email;
  • Telegram and other integrations when the agency enables or uses them;
  • professional advisers, auditors and insurers subject to appropriate duties;
  • government, regulatory, judicial or law-enforcement authorities where legally required; and
  • a successor or participant in a genuine merger, financing, reorganisation or sale, subject to applicable safeguards.

We require providers to process information only for relevant services and under appropriate confidentiality, privacy and security obligations where required. Third-party services also operate under their own privacy policies.

We do not share applicant contact information with partners for their independent marketing.

7. International data transfers

Sync CRM is operated from the UAE. Our production infrastructure is currently hosted by DigitalOcean in Singapore, so personal data may be stored and processed in Singapore. Enabled providers such as Google, Microsoft, Google Cloud Document AI, Nomod, Web3Forms and Telegram may process information in other countries according to their infrastructure and policies.

Where required, we use contractual, organisational and technical measures intended to protect personal data transferred across borders. These may include contractual data-protection obligations, access restrictions, encryption and vendor review. No location or transfer method eliminates all risk.

We do not promise UAE-only data residency. Customers with specific residency requirements should contact us before using the Service.

8. Connected Gmail and Outlook

A user may choose to connect a Gmail or Microsoft Outlook account. We access the mailbox only within the permissions granted and for requested email features. We do not permanently copy or archive the complete mailbox.

Mailbox metadata. So that a connected mailbox can be displayed and kept in step with the provider, Sync CRM may temporarily cache limited metadata about messages. This includes message and thread identifiers, sender and recipient information, subject, timestamps, folder or label information, and status information such as whether a message is unread, starred or carries attachments. This temporary cache exists so that message lists load and remain current without repeatedly calling the provider.

Message content. Email body content and attachments are retrieved from the connected provider at the point a user opens a message. That content is processed to display the message and is not persistently stored in Sync CRM’s connected-email cache after processing, so opening the same message again retrieves it from the provider again. Records of messages sent through the Service keep recipient, subject, delivery status, provider message identifiers and timestamps, not the message body.

Automated cleanup. Scheduled retention and cleanup jobs run regularly to remove expired temporary connected-email cache records, and content fields in that cache are cleared rather than retained. In the current configuration, cached mailbox metadata and records of sent messages are removed after 30 days. These jobs do not disconnect a mailbox or interrupt access to it.

Information saved into CRM records. If a user intentionally links an email, or copies or saves information from it, to a CRM client, case or record, that linked or saved information becomes part of Customer Data. It then follows the normal Customer Data retention rules described in section 13 and the agency’s own retention rules, not the temporary cache rules above.

Credentials and disconnection. We securely retain encrypted OAuth credentials and connection metadata for as long as the mailbox remains connected, because they are needed to maintain the authorised connection. When the mailbox is disconnected, or when the applicable account data is deleted, we revoke or invalidate those credentials, delete the stored connection, and remove that mailbox’s cached metadata, synchronisation state and sent-message records for the disconnected provider. Disconnecting one provider does not affect a different mailbox the same user has connected.

Email content is not used for advertising or general-purpose AI-model training.

9. Payments

Payment-card information is collected and processed by Nomod. Sync CRM does not receive or store complete card numbers or CVVs. We may receive and retain payment status, amount, currency, reference, payer information, timestamps, invoices, receipts and refund records for service delivery, accounting, support, fraud prevention and legal compliance.

10. OCR, automation and AI

When an agency requests document extraction, relevant documents may be transmitted to Google Cloud Document AI to extract text and structured fields. OCR output may be inaccurate and must be reviewed by agency staff.

We do not use customer documents, emails, passport information, applicant records or other Customer Data to train Sync CRM or third-party general-purpose AI models. Sync CRM does not perform facial recognition, fingerprint processing, liveness checks, biometric identity matching or other biometric analysis.

11. Children’s information

CRM staff users must be at least 18 years old. The Service is not offered directly to children.

An agency may process information about an applicant under 18 only where necessary for lawful visa, immigration, travel or related case-management purposes and with authority from a parent, guardian or another legally authorised person. The agency is responsible for required notices and permissions. Children’s information must not be used for unrelated marketing, profiling or advertising.

12. Cookies and similar technologies

The authenticated Service uses essential cookies or similar storage required to keep users signed in, maintain security, remember necessary session state and protect forms. Blocking essential cookies may prevent the Service from working correctly.

At the date of this Policy, the public Sync CRM website does not intentionally use third-party advertising pixels or behavioural advertising cookies. If we later introduce non-essential analytics or advertising technologies, we will update this Policy and provide any notice or choice required by law.

13. Data retention and deletion

We retain personal data only for as long as reasonably needed for the purposes described in this Policy, an agency’s instructions, security, dispute handling and legal obligations.

After a subscription ends, the inactive account and Customer Data may be retained for up to 180 days so the agency can request a reasonably available standard export. Data may be deleted earlier following a verified request unless continued retention is required. After that period, Customer Data may be deleted from active systems.

Residual encrypted copies may remain in backup cycles for up to a further 90 days and are not ordinarily restored except for disaster recovery. Financial, tax, audit, fraud-prevention, security and legal records may be retained longer where reasonably necessary or legally required.

Temporary connected-email caches are retained only as long as needed for their function and operational security. Email body content is not persistently stored in that cache; cached mailbox metadata and records of sent messages are removed by automated cleanup after 30 days in the current configuration, as described in section 8. Other temporary technical caches are retained for a limited operational period. Information a user links, copies or saves into a CRM record is Customer Data and follows the Customer Data rules above rather than these cache rules. Retention may vary where a Customer configures or requests a different lawful period under a written agreement.

14. Security

We use reasonable technical and organisational measures designed to protect personal data. Depending on the system, these include encrypted transmission, password hashing, encryption of sensitive connection credentials, role-based and branch-based access, session controls, rate limiting, login lockouts, audit trails, access restriction and security monitoring.

No storage or transmission system is completely secure. Users must keep credentials confidential, use individual accounts and notify us immediately of suspected compromise. We will notify affected Customers of a confirmed personal-data breach without undue delay where required by applicable law.

15. Privacy rights and requests

Subject to applicable law and relevant exceptions, a person may have rights to:

  • obtain information about and access personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion where there is no lawful reason to retain data;
  • request restriction or cessation of certain processing;
  • withdraw consent where processing relies on consent;
  • object to certain processing or automated decisions where applicable;
  • request transfer of data where applicable; and
  • raise a complaint with the appropriate authority.

Agency staff may contact us about their account data. Applicants and clients should normally contact the agency handling their case because that agency controls their records. If an applicant contacts us directly, we may refer the request to the relevant agency after appropriate verification.

We may request information needed to verify identity and authority. We will not disclose data where doing so would adversely affect another person’s rights, breach law or compromise security.

16. Marketing communications

We may send agency business contacts information about Sync CRM features, upgrades, offers, events and closely related services where permitted. Promotional emails will include an unsubscribe method. Opting out of marketing does not stop essential account, billing, security, legal, support or service communications.

We record and respect marketing preferences. We do not use applicant or client contact details uploaded by agencies for our own marketing. We do not provide those details to partners for their independent marketing without separate permission.

17. Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, law or our practices. We will update the “Last updated” date and provide advance notice of material changes where appropriate or required. Earlier versions may be made available on request.

18. Contact and company details

Sync CRM is operated by:

The Vysa Technologies FZ-LLC
FDBC5042, Compass Building
Al Shohada Road, Al Hamra Industrial Zone-FZ
Ras Al Khaimah, United Arab Emirates

Email: contact@sync-crm.io

Licence numbers: 45034530 and 47029788. Privacy requests, legal notices and support enquiries may be sent to the contact details above.

© 2026 Sync CRM. A service of The Vysa Technologies FZ-LLC.
Terms of Service · Home