Privacy Policy

Last updated: 2026-01-22

1. Introduction

YourWay CRM ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our customer relationship management (CRM) service.

We operate in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and Greek data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

YourWay CRM

Email: support@yourwaycrm.com

3. Information We Collect

We collect information that you provide directly to us, including:

  • Account Information: Name, email address, phone number, and password when you register
  • Business Information: Organization name, business details, and service offerings
  • Customer Data: Information about your customers that you store in the CRM. Depending on your profession this may include health-related information, such as appointment records or notes kept by a healthcare or mental health practitioner. See section 4 below.
  • Payment Information: Billing details processed through our payment provider (Stripe)
  • Usage Data: Information about how you interact with our service
  • Communications: Messages you send to us or through our platform

4. Legal Basis for Processing

We process your personal data based on the following legal grounds (GDPR Article 6):

  • Contract Performance: Processing necessary to provide our services to you
  • Legitimate Interests: For business operations, security, and service improvement
  • Legal Obligations: Compliance with applicable laws and regulations
  • Consent: For optional features like marketing communications

Special Category Data (GDPR Article 9)

Some customers use our service to record health-related information about their own clients — for example appointment records or session notes kept by a psychologist, therapist or other healthcare practitioner. Under GDPR Article 9 this is "special category" data and receives additional protection.

  • Our respective roles: where you store data about your own clients, you act as the data controller and we act as a data processor on your behalf.
  • Your responsibility: as controller, you are responsible for having a valid Article 9 condition for that processing — typically the explicit consent of your client, or Article 9(2)(h) where processing is necessary for the provision of health or social care. You are also responsible for informing your clients how their data is handled.
  • Our processing: we process this information only to provide the service to you and on your instructions. We do not use client health information for analytics, profiling, advertising, or to train machine learning models.
  • Data minimisation: you should only enter information that is necessary for running your practice. Our service is not designed to be a clinical record system.
  • Access: records are restricted to your organisation. Session notes are visible only to the practitioner who wrote them, and are not shown to colleagues. Other client information — contact details, appointments, packages and uploaded files — is available to the colleagues you invite to your organisation, so you remain responsible for who you grant access to.

5. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve our CRM services
  • Process transactions and send related information
  • Send technical notices, updates, and support messages
  • Respond to your comments, questions, and requests
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent transactions and abuse

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Specifically:

  • Account Data: Retained while your account is active and up to 30 days after deletion
  • Customer Data: Retained according to your data management preferences
  • Payment Records: Retained for 7 years as required by Greek tax law
  • Usage Logs: Retained for up to 12 months

7. Data Sharing

We may share your information with:

  • Service Providers: Third parties that help us operate our business (hosting, payment processing)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

We do not sell your personal information to third parties.

8. Your Rights (GDPR)

Under the GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise these rights, contact us at support@yourwaycrm.com

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • All traffic encrypted in transit using TLS
  • Passwords stored using one-way hashing, never in readable form
  • Third-party integration credentials you provide (such as payment or messaging tokens) encrypted in our database
  • Strict separation between organisations, so each practice can access only its own data
  • Session notes readable only by the practitioner who wrote them
  • Regular security updates and daily backups

10. Where Your Data Is Stored

Your account and client data — including client records, appointments, notes and uploaded files — is stored on servers located in Germany, within the European Union. We do not replicate this data outside the EU.

A small number of service providers support specific features and may process limited data. Where any of these operate outside the EEA, the transfer relies on appropriate safeguards such as Standard Contractual Clauses or an EU adequacy decision:

  • Hosting: our servers and database (Germany, EU)
  • Payment processing: Stripe, for subscription billing and — where you enable it — online payments from your clients
  • Email delivery: our email provider, used to send appointment confirmations and reminders

Where you connect your own WhatsApp Business account to send reminders, those messages are sent using your own credentials and your own agreement with that provider.

11. Cookies

We use essential cookies to provide our service functionality. These cookies are necessary for the website to function and cannot be switched off. For more information, see our cookie notice in the application.

12. Supervisory Authority

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):

Hellenic Data Protection Authority

1-3 Kifissias Avenue, 115 23 Athens, Greece

Phone: +30 210 6475600

Website: www.dpa.gr

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Significant changes will be communicated via email.

14. Contact Us

If you have any questions about this Privacy Policy, please contact us: