Complete data sovereignty and zero AI model training.

Learn how ADXO CRM safeguards customer records with AES-256 encryption, strict zero-model-training isolation, and GDPR/CCPA compliance.
ADXO CRM Security & Privacy Architecture
AI Data Isolation
Zero model training
100% Isolated
Data Privacy & Trust•v2.4

Global Privacy Policy

At ADXO CRM, privacy and data sovereignty are fundamental to our architecture. This policy explains how we collect, safeguard, and process your enterprise information.

Effective: January 1, 2026
Updated: March 15, 2026
Legal Support

Executive Summary (Plain English)

Key terms and commitments summarized for rapid review.

Zero Model Training on Your Data

We strictly never use your proprietary inputs, invoices, CRM data, or prompts to train foundation AI models.

End-to-End Encryption

All client data is encrypted with AES-256 at rest and TLS 1.3 in transit with isolated tenant partitions.

GDPR & CCPA Compliant

Full support for data subject access requests, automated right-to-be-forgotten deletion pipelines, and DPA agreements.

Data Sovereignty Options

Dedicated regional data residency options across North America, Europe, and Middle East (GCC/KSA) cloud zones.

01

Information We Collect

Summary in plain English:We only collect data necessary to provide and secure our enterprise CRM & ERP services.

Account & Contact Details: Name, business email, organization name, billing address, and phone number when you register.

Operational & Financial Telemetry: Transactional metadata, invoice amounts, timestamp logs, and system performance metrics necessary for ERP reconciliation.

Agent Task Execution Context: Prompts, workflow rules, and approval actions configured by authorized workspace users.

02

AI Model Isolation & Data Confidentiality

Summary in plain English:Customer data is strictly isolated per tenant and never shared with public model training sets.

ADXO CRM employs dedicated zero-retention inference endpoints with our AI infrastructure partners. Your prompts and business context are never logged, stored, or retained by third-party model providers.

Fine-tuned models or custom workflow heuristics created within your enterprise workspace remain exclusively accessible to your authenticated organization.

03

How We Use Your Information

Summary in plain English:Data is used strictly to deliver services, automate workflows, ensure security, and fulfill legal compliance.

To deliver core ERP functionalities including automated reconciliation, lead scoring, invoice dispatching, and agent task scheduling.

To prevent fraud, verify multi-factor authentication, and monitor for unauthorized intrusion or anomalous API behavior.

To comply with legal obligations including tax reporting, audit trails, and government e-invoicing standards.

04

Subprocessors & Third-Party Sharing

Summary in plain English:We only share data with vetted cloud infrastructure and payment partners under strict Data Processing Agreements.

Infrastructure Providers: Amazon Web Services (AWS) and Google Cloud Platform (GCP) for isolated cloud compute and encrypted object storage.

Payment Processors: Stripe Inc. and localized payment gateways for PCI-DSS Level 1 compliant payment settlement.

We never sell, rent, or monetize your personal or business data under any circumstances.

05

International Data Transfers & Residency

Summary in plain English:We provide regional data storage options and rely on Standard Contractual Clauses (SCCs) for cross-border transfers.

Customers may select regional hosting zones during workspace provisioning (US-East, EU-Central Frankfurt, or GCC-Riyadh).

For transfers between the EEA, UK, Switzerland, and third countries, we execute EU Standard Contractual Clauses (SCCs) and UK IDTA.

06

Data Retention & Erasure Rights

Summary in plain English:You can export or request complete deletion of your data at any time through our automated privacy dashboard.

Customer Data is retained for the duration of the active subscription plus a 30-day grace period following account closure.

Upon written request or automated workspace de-provisioning, all tenant databases, backups, and encryption keys are permanently destroyed within 30 days.

07

Your Legal Privacy Rights (GDPR / CCPA)

Summary in plain English:You have full rights to access, correct, export, restrict, or delete your personal data.

Right of Access & Portability: Request a structured JSON export of all personal data held in your account.

Right to Rectification: Correct inaccurate or outdated company and user profile information.

Right to Erasure ('Right to be Forgotten'): Request irreversible deletion of all personally identifiable records.

08

Security Safeguards & DPO Contact

Summary in plain English:Our dedicated Data Protection Officer and security team ensure continuous compliance and threat mitigation.

We maintain SOC2 Type II compliance, continuous penetration testing, 2FA/SSO enforcement, and automated audit trails.

If you have questions regarding this Privacy Policy or wish to execute a Data Processing Addendum (DPA), please contact our Data Protection Officer at privacy@adxocrm.com.

THE ADXO CRM EXPERIENCE

Create experiences people remember for the right reasons

Chat with our team to talk through build vs. buy and how to level up your customer experience.

BEFORE YOU SWITCH

Questions business owners ask.

ADXO CRM's AI agents do more than answer questions. They work inside your CRM, inbox, projects, proposals, and finance, so they can understand the context, take real actions, and keep work moving within the approval rules you set.