BullCRM Privacy Policy
Effective Date: July 10, 2026
Last Updated: July 10, 2026
This Privacy Policy explains how Jamtech Technologies Private Limited, operating the BullCRM platform ("BullCRM," "Company," "we," "us," or "our"), collects, uses, stores, discloses, and protects personal data when individuals and businesses:
- Visit the BullCRM website;
- Create or use a BullCRM account;
- Use BullCRM's CRM, Books, HRMS, messaging, campaign, web form, automation, email, AI, SalesBot, reporting, or customer-support features;
- Connect a Meta Business Portfolio, WhatsApp Business Account, WhatsApp phone number, email account, telephony account, payment account, or another third-party service;
- Communicate with a business using WhatsApp or another communication channel managed through BullCRM; or
- Contact BullCRM for sales, support, onboarding, billing, or other purposes.
BullCRM is a business CRM and customer communication platform provided by:
Jamtech Technologies Private Limited Product: BullCRM Registered Office: 1st Floor, The Engineering Tower, Plot No. CP-43, Sector-E, Engineering College Road, Aliganj, Lucknow, Uttar Pradesh – 226021, India CIN: [●] Website: https://bullcrm.io/ Email: support@bullcrm.io
This Privacy Policy is issued in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), the Information Technology Act, 2000 and the rules and directions issued under it, and other applicable laws. Terms such as "personal data," "Data Fiduciary," "Data Processor," "Data Principal," and "Consent Manager" have the meanings given to them in the DPDP Act.
By accessing or using BullCRM, you acknowledge the practices described in this Privacy Policy. Where we rely on your consent, we will ask for it separately and clearly, as described in Section 7.
1. Scope of This Privacy Policy
This Privacy Policy applies to the BullCRM website, dashboard, applications, APIs, integrations, communication tools, and related services.
It covers information processed through BullCRM features including:
- Customer relationship management;
- Lead, contact, account, deal, and opportunity management;
- WhatsApp Business Platform integration;
- Shared customer-support inboxes;
- WhatsApp message templates;
- Marketing, utility, authentication, and service communications;
- Email campaigns and transactional emails;
- Web forms and website chat;
- Sales and customer-support automation, including SalesBot;
- AI-assisted messaging and chatbot functionality;
- Books (invoicing and accounting records);
- HRMS (employee and HR records);
- Reports, analytics, delivery status, and campaign tracking;
- Payment and subscription management; and
- Third-party integrations configured by BullCRM customers.
This Privacy Policy does not replace the privacy notices that BullCRM customers are required to provide to their own customers, contacts, employees, leads, or other individuals.
2. Our Role in Processing Personal Data
BullCRM's role depends on the context in which information is processed.
2.1 BullCRM as a Data Fiduciary
BullCRM acts as a Data Fiduciary (also referred to as a "data controller" under some foreign laws) when processing personal data relating to:
- Website visitors;
- BullCRM account owners and authorized users;
- Subscription, billing, and payment administration;
- Sales and support enquiries;
- Security, fraud prevention, and platform administration;
- Product usage and service improvement;
- BullCRM's own legal and regulatory obligations; and
- BullCRM's direct marketing activities.
In these situations, BullCRM determines the purpose and means of processing, and this Privacy Policy is our notice to you.
2.2 BullCRM as a Data Processor
When a business customer uploads or collects personal data through BullCRM, connects its WhatsApp Business Account, sends messages, manages contacts, maintains employee or accounting records, or uses BullCRM to communicate with its own customers, the business customer acts as the Data Fiduciary.
BullCRM acts as a Data Processor and processes that personal data only on the customer's documented instructions, under a valid contract, to provide the requested services.
Each BullCRM customer, as Data Fiduciary, is responsible for:
- Providing privacy notices that meet the requirements of the DPDP Act and DPDP Rules;
- Obtaining free, specific, informed, unconditional, and unambiguous consent, or relying on another legitimate use permitted by law;
- Maintaining verifiable records of consent;
- Respecting withdrawal of consent, opt-out, correction, and erasure requests;
- Ensuring uploaded data was collected lawfully;
- Publishing its own grievance redressal contact; and
- Complying with applicable privacy, marketing, telecommunications, and anti-spam laws.
3. Information We Collect
The information we collect depends on how BullCRM is used and which features or integrations are enabled. We collect only the personal data necessary for the purposes described in Section 5.
3.1 Account and User Information
We may collect:
- Full name;
- Business email address;
- Telephone number;
- Password or authentication information;
- Job title and department;
- Company or organization name;
- Workspace or tenant information;
- User roles and permissions;
- Profile preferences;
- Account status;
- Login history; and
- Multi-factor authentication information.
Passwords are stored using secure password-hashing methods. We do not store passwords in readable form.
3.2 Business and Organization Information
We may collect:
- Business name;
- Business address;
- Industry and business category;
- Website address;
- GSTIN, PAN, or other tax and registration information;
- Billing contact details;
- Team size;
- Subscription plan;
- Connected services;
- Business preferences;
- Business verification status; and
- Customer-support or onboarding information.
3.3 CRM and Customer Data
BullCRM customers may upload, create, import, or collect:
- Customer and lead names;
- Email addresses;
- Telephone and WhatsApp numbers;
- Company information;
- Postal addresses;
- Lead sources;
- Communication preferences;
- Consent and opt-in status;
- Notes and activity history;
- Deals, opportunities, and sales information;
- Tasks and appointments;
- Support requests;
- Files and attachments;
- Form submissions;
- Purchase or service history; and
- Other information entered into CRM records.
The BullCRM customer determines which CRM data is collected and is responsible for ensuring it has the right to process that data.
3.4 WhatsApp Business Platform Data
When a customer connects a Meta Business Portfolio or WhatsApp Business Account, BullCRM may receive and process:
- Meta Business Portfolio identifiers;
- WhatsApp Business Account identifiers;
- WhatsApp phone number identifiers;
- Display phone numbers;
- Business profile information;
- Business verification or connection status;
- Access tokens and authorization information;
- Message templates;
- Template categories, languages, content, and approval status;
- Customer telephone numbers and profile names;
- Incoming and outgoing WhatsApp messages;
- Message text;
- Images, documents, audio, video, and other message attachments;
- Customer replies;
- Message timestamps;
- Conversation identifiers;
- Message delivery, read, failed, and other status information;
- Opt-in and opt-out information;
- Campaign records;
- Webhook events;
- Messaging quality or account status information; and
- Other information made available through authorized WhatsApp Business Platform APIs.
BullCRM accesses this information only after a business customer authorizes the connection or otherwise provides valid access.
3.5 Meta Permissions
BullCRM may request the following Meta permissions:
whatsapp_business_management
This permission allows BullCRM to access and manage authorized WhatsApp Business assets, which may include:
- WhatsApp Business Accounts;
- Business phone numbers;
- Business profiles;
- Message templates;
- Template submission and status;
- Account configuration; and
- Other authorized WhatsApp Business assets.
whatsapp_business_messaging
This permission allows BullCRM to provide messaging functionality, which may include:
- Sending approved WhatsApp messages;
- Receiving customer messages;
- Replying to customer messages;
- Receiving message delivery and read status;
- Processing customer replies;
- Managing customer-support conversations; and
- Sending utility, authentication, service, and approved marketing messages on behalf of BullCRM customers.
BullCRM uses these permissions only to provide features requested and authorized by the relevant business customer.
BullCRM does not use consumer Facebook Login for general BullCRM account authentication. Meta authorization or Embedded Signup may be used only for connecting and managing authorized business assets.
3.6 Communication Information
When users communicate through BullCRM, we may process:
- Message content;
- Sender and recipient information;
- Email subject lines and content;
- WhatsApp conversations;
- Customer-support conversations;
- Message timestamps;
- Attachments;
- Delivery and engagement status;
- Campaign information;
- Unsubscribe or opt-out requests; and
- Communication history.
3.7 Books and HRMS Data
When a customer uses the Books or HRMS modules, BullCRM processes, as Data Processor, the information the customer enters, which may include:
- Invoices, quotations, payments, and ledger records;
- Customer and vendor details, including GSTIN;
- Employee names, contact details, designations, and employment records;
- Attendance, leave, and payroll information; and
- Bank account details and other information entered for payroll or accounting purposes.
Customers must ensure they have a lawful basis to process employee and financial information and must configure appropriate access controls.
3.8 Payment and Billing Information
We may collect:
- Billing name;
- Billing address;
- Tax information;
- Invoice records;
- Subscription plan;
- Payment status;
- Transaction identifiers;
- Wallet or credit balance;
- Recharge history; and
- Partial payment-method information received from payment providers.
Payments are processed by RBI-authorized payment aggregators and gateways. BullCRM does not store complete payment card numbers, card security codes (CVV), or UPI PINs.
3.9 Technical and Usage Information
We may automatically collect:
- Internet Protocol address;
- Browser and device type;
- Operating system;
- Device identifiers;
- Login time;
- Session information;
- Referring website;
- Pages or features accessed;
- Error reports;
- API and webhook activity;
- Security events;
- Audit logs;
- Approximate location derived from IP address;
- Cookie identifiers; and
- Usage and performance information.
3.10 Support and Enquiry Information
When someone contacts us, we may collect:
- Name;
- Email address;
- Telephone number;
- Company information;
- Support request details;
- Screenshots or attachments;
- Call or meeting notes (calls are recorded only with prior notice);
- Technical diagnostic information; and
- Other information voluntarily provided.
4. How We Collect Information
We may collect information:
- Directly from account owners, users, customers, and website visitors;
- From information uploaded, imported, or entered into BullCRM;
- Through websites, forms, chat widgets, APIs, and integrations;
- From Meta and the WhatsApp Business Platform after authorization;
- From email, telephony, payment, analytics, hosting, and other connected providers;
- From customer communications and support interactions;
- Automatically through cookies, logs, and similar technologies; and
- From publicly available or lawful business sources where permitted by law.
5. How We Use Information
We use personal data only for the specific purposes listed below:
- Create and administer BullCRM accounts;
- Authenticate users and manage permissions;
- Provide CRM, Books, HRMS, and customer-management functionality;
- Connect authorized Meta and WhatsApp Business assets;
- Send and receive messages on behalf of business customers;
- Manage WhatsApp message templates;
- Process customer-support conversations;
- Track message delivery, read, failure, and reply status;
- Run approved campaigns and customer notifications;
- Manage email communications and campaigns;
- Provide workflow, automation, chatbot, SalesBot, and AI-enabled features;
- Associate conversations with CRM contacts and leads;
- Provide analytics and reporting;
- Process subscriptions, payments, GST invoices, and account credits;
- Provide customer support and technical assistance;
- Detect fraud, abuse, spam, and security threats;
- Maintain audit and security records;
- Troubleshoot errors and improve service reliability;
- Enforce our agreements and acceptable-use rules;
- Comply with legal and regulatory requirements;
- Respond to lawful government or regulatory requests;
- Communicate service changes and security notices; and
- Send marketing communications where you have consented.
We will not use personal data for a new purpose that is not compatible with these purposes without giving you notice and, where required, obtaining fresh consent.
We do not use WhatsApp Platform Data for unrelated advertising or sell it to data brokers.
6. Grounds for Processing
6.1 Under Indian Law
Under the DPDP Act, we process personal data for which BullCRM is the Data Fiduciary on one of the following grounds:
Consent
We rely on your consent when you create an account, subscribe to a plan, submit a form, enable optional features or integrations, accept non-essential cookies, or agree to receive marketing communications. Consent for marketing is always separate from consent needed to provide the services.
Legitimate Uses
We may process personal data without separate consent where permitted under Section 7 of the DPDP Act, including:
- Where you voluntarily provide personal data for a specified purpose and have not indicated that you do not consent to its use (for example, when you contact us for support or a sales demo);
- To comply with any law, judgment, decree, or order in force in India (for example, tax, GST, accounting, and CERT-In requirements);
- To respond to a medical emergency or threat to life or health; and
- For employment-related purposes, in relation to our own employees.
Customer Instructions
When BullCRM acts as a Data Processor, we process personal data according to the documented instructions of the relevant BullCRM customer, who is responsible for the grounds of processing.
6.2 Outside India
Where the laws of another country apply to our processing (for example, the GDPR for individuals in the European Economic Area or the United Kingdom), we rely on the legal bases recognized by those laws, which may include contractual necessity, consent, legitimate interests, and compliance with legal obligations.
7. Notice and Consent
Where we rely on consent, we will:
- Present a clear notice, separate from other information, before or at the time of collection;
- Describe the personal data collected and the specific purpose for which it will be used;
- Tell you how to withdraw consent and exercise your rights; and
- Tell you how to complain to the Data Protection Board of India.
You may withdraw consent at any time, as easily as you gave it, by:
- Using the unsubscribe link in any marketing email;
- Updating your privacy and communication preferences in your BullCRM account settings; or
- Emailing support@bullcrm.io.
Once registered Consent Managers become operational under the DPDP Rules, you may also give, manage, review, or withdraw consent through a registered Consent Manager where BullCRM supports it.
Withdrawal of consent does not affect processing carried out before withdrawal. If you withdraw consent needed to provide the services, we may be unable to continue providing them, and we will stop processing your personal data within a reasonable time unless retention is required by law.
This Privacy Policy is available in English. You may request it in any language listed in the Eighth Schedule to the Constitution of India by writing to support@bullcrm.io.
8. WhatsApp Business Communications and Consent
BullCRM customers are responsible for ensuring they have valid consent and any required WhatsApp opt-in before sending messages, and for complying with the DPDP Act, WhatsApp Business policies, and, for SMS and voice communications, the Telecom Commercial Communications Customer Preference Regulations issued by the Telecom Regulatory Authority of India (TRAI).
BullCRM customers must not use BullCRM to send:
- Unsolicited or unauthorized messages;
- Messages to individuals who have opted out or withdrawn consent;
- Misleading or fraudulent messages;
- Messages prohibited by law;
- Messages that violate Meta or WhatsApp policies; or
- Content that unlawfully requests or exposes sensitive information.
BullCRM may suspend, limit, reject, or investigate messaging activity that appears to violate applicable laws, Meta policies, WhatsApp policies, user consent requirements, or BullCRM's Terms of Service.
Message delivery is also subject to Meta and WhatsApp's systems, rules, technical availability, quality requirements, messaging limits, and template-approval processes.
9. How We Use WhatsApp Platform Data
WhatsApp Platform Data is used only to:
- Connect authorized WhatsApp Business Accounts;
- Display and manage authorized business assets;
- Create, submit, synchronize, and manage message templates;
- Send and receive WhatsApp messages;
- Display customer conversations;
- Route conversations to authorized team members;
- Link conversations with CRM records;
- Process message and webhook events;
- Track message delivery and engagement status;
- Run customer-authorized workflows and automations;
- Provide customer support;
- Maintain security and audit records; and
- Provide reporting requested by the business customer.
BullCRM does not:
- Sell WhatsApp Platform Data;
- Rent WhatsApp Platform Data;
- Use WhatsApp Platform Data for third-party targeted advertising;
- Share WhatsApp Platform Data with unrelated third parties;
- Build unrelated advertising profiles using WhatsApp Platform Data; or
- Use one customer's WhatsApp Platform Data for another customer's benefit.
Each customer's information is logically separated from other customers' information.
10. AI and Automated Processing
BullCRM may offer optional AI, chatbot, SalesBot, recommendation, summarization, classification, or automation features.
When a customer enables these features, relevant message content, CRM information, instructions, or conversation context may be sent to:
- An AI provider configured by BullCRM;
- An AI provider selected by the customer; or
- An AI provider accessed using a customer-provided API key.
Such processing is performed only to provide the enabled feature. AI providers configured by BullCRM are engaged as sub-processors under written terms.
BullCRM does not use one customer's private CRM or WhatsApp data to train models for other customers.
Customers are responsible for:
- Reviewing AI-generated responses;
- Configuring suitable instructions and safeguards;
- Informing individuals that they are interacting with an automated system where required;
- Avoiding automated decisions that create unlawful or significant effects on individuals without human review; and
- Ensuring AI-generated communications comply with applicable laws and platform policies.
Users should not rely on AI-generated content as legal, medical, financial, or other regulated professional advice.
11. Cookies and Similar Technologies
BullCRM may use cookies, local storage, pixels, and similar technologies for:
- User authentication;
- Session management;
- Security;
- Remembering preferences;
- Measuring website and product usage;
- Diagnosing performance problems;
- Preventing fraud; and
- Improving the website and services.
Essential cookies are necessary for BullCRM to function. Analytics and marketing cookies are used only after you give consent through our cookie banner, and you can change your choice at any time.
Users can also control cookies through their browser settings. Disabling essential cookies may prevent certain BullCRM features from working correctly.
12. How We Share Information
We may disclose information in the following circumstances.
12.1 BullCRM Customers and Authorized Users
Information may be visible to the BullCRM customer that controls the workspace and to users authorized by that customer.
Workspace administrators may access, export, correct, restrict, or delete information held in their workspace, subject to their permissions.
12.2 Service Providers and Sub-processors
We may use service providers for:
- Cloud hosting;
- Database and file storage;
- Email delivery;
- WhatsApp and communication services;
- Payment processing;
- Customer support;
- Security and monitoring;
- Analytics;
- Error tracking;
- Telephony;
- AI processing; and
- Other infrastructure services.
These providers process personal data only on our instructions, under valid contracts, and only as necessary to provide contracted services. A list of our principal sub-processors is available on request at support@bullcrm.io.
12.3 Meta and WhatsApp
Information may be exchanged with Meta and WhatsApp when necessary to:
- Connect business accounts;
- Access authorized business assets;
- Send or receive messages;
- Manage message templates;
- Process webhooks;
- Retrieve message status; and
- Provide other authorized WhatsApp Business Platform functionality.
Meta and WhatsApp may independently process information under their own terms and privacy policies.
12.4 Connected Third-Party Services
When a customer enables an integration, information may be exchanged with that provider according to the customer's configuration and the provider's terms.
Customers should review the privacy practices of connected providers before enabling integrations.
12.5 Legal and Safety Disclosures
We may disclose information where we reasonably believe disclosure is necessary to:
- Comply with applicable law, including requirements of CERT-In and the Data Protection Board of India;
- Respond to a court order, warrant, summons, or lawful government request;
- Protect the rights, safety, or property of BullCRM, our customers, users, or others;
- Investigate fraud, abuse, spam, or security incidents;
- Enforce our agreements; or
- Establish, exercise, or defend legal claims.
12.6 Corporate Transactions
Information may be transferred as part of a merger, acquisition, investment, financing, restructuring, sale of assets, or similar transaction, as permitted under applicable law.
Where required, we will provide notice, and the successor entity will be bound to protect the information in accordance with this Privacy Policy and applicable law.
12.7 With Consent
We may disclose information for another purpose when the relevant individual or business has consented to the disclosure.
13. Sale and Advertising Use of Personal Data
BullCRM does not sell personal data or WhatsApp Platform Data.
BullCRM does not use WhatsApp message content or Platform Data for third-party targeted advertising.
Where a foreign privacy law defines "sale" or "sharing" more broadly, individuals may contact us at support@bullcrm.io to exercise applicable opt-out rights.
14. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Once the purpose is served, or consent is withdrawn, we erase personal data unless retention is required by law.
Retention periods depend on the type of information and how it is used:
| Information | Retention Period |
|---|---|
| Account and user information | While the account is active, and up to 90 days after account closure to allow data export, after which it is erased |
| CRM, WhatsApp, Books, HRMS, and campaign data (Customer Data) | As instructed by the customer while the account is active; erased within 90 days after account closure or a verified deletion request |
| Access tokens and integration credentials | Revoked and erased promptly on disconnection or account closure |
| Invoices, GST, and accounting records | 8 years, as required under the Companies Act, 2013 and GST laws |
| Security, access, and audit logs | At least one year, as required by the DPDP Rules, and at least 180 days within India, as required by CERT-In directions |
| Consent records | For the duration of the consent and as long as needed to demonstrate compliance |
| Marketing information | Until you unsubscribe or withdraw consent |
| Support and enquiry information | Up to 3 years from the closure of the request |
Backups
Deleted information may remain temporarily in encrypted or access-restricted backups until those backups are overwritten according to our backup schedule, which does not exceed 35 days.
Backup data is not restored for ordinary business use after a verified deletion request, except where necessary for disaster recovery, security investigation, or legal compliance.
Aggregated Information
We may retain information that has been irreversibly anonymized or aggregated so that it can no longer reasonably identify an individual.
15. Data Deletion
BullCRM provides a publicly accessible Data Deletion page through the website footer.
15.1 Requests by BullCRM Customers
Business customers may request deletion of:
- Their BullCRM account;
- Workspace or tenant information;
- CRM, Books, and HRMS records;
- WhatsApp connection information;
- Access credentials and tokens;
- WhatsApp conversations;
- Message templates;
- Campaign records;
- Files and attachments; and
- Other eligible account information.
To request deletion, email support@bullcrm.io from the email address registered with the BullCRM account.
The request should include:
- The company or organization name;
- Registered account email;
- Workspace or tenant details;
- The information to be deleted; and
- Any relevant WhatsApp Business Account or phone number details.
We may request additional information to verify account ownership and prevent unauthorized deletion. We will confirm completion of deletion in writing.
15.2 Requests by WhatsApp End Users and Other Individuals
Individuals who communicated with a business through WhatsApp, or whose data is held by a business using BullCRM, should normally submit privacy, access, correction, or deletion requests directly to that business, which is the Data Fiduciary for that information.
An individual may also contact BullCRM at support@bullcrm.io. Where BullCRM acts only as the Data Processor, we will forward the request to the relevant business customer where we can identify it, and inform the individual.
15.3 Disconnecting Meta or WhatsApp
A BullCRM customer may disconnect its Meta or WhatsApp Business integration through available connection settings or by contacting BullCRM support.
Disconnecting an integration stops BullCRM from obtaining new information through that authorization. Existing CRM or conversation records may remain until deleted by an authorized user or through a verified deletion request.
15.4 Information That May Be Retained
Certain information may be retained where necessary for:
- Legal or regulatory compliance;
- Tax and accounting obligations;
- Security investigations;
- Fraud and abuse prevention;
- Dispute resolution;
- Establishing or defending legal claims;
- Backup integrity; or
- Compliance audits.
When retention is required, the information will be restricted to the relevant purpose and deleted when the retention requirement ends.
16. Data Accuracy and Customer Controls
BullCRM customers and authorized users may be able to:
- Review CRM information;
- Correct inaccurate records;
- Delete records;
- Export information;
- Manage users and permissions;
- Manage consent and opt-out status;
- Disconnect integrations;
- Configure retention and communication settings; and
- Close their account.
Customers are responsible for keeping their account and customer information accurate, complete, and current.
17. Your Rights
17.1 Rights Under the DPDP Act
If you are a Data Principal whose personal data BullCRM processes as a Data Fiduciary, you have the right to:
- Obtain a summary of the personal data being processed and the processing activities undertaken;
- Know the identities of other Data Fiduciaries and Data Processors with whom your personal data has been shared, and the categories of personal data shared;
- Correct inaccurate or misleading personal data;
- Complete incomplete personal data;
- Update your personal data;
- Erase personal data that is no longer necessary for the purpose for which it was collected, unless retention is required by law;
- Withdraw consent at any time;
- Access readily available grievance redressal; and
- Nominate another individual to exercise your rights in the event of your death or incapacity.
17.2 Rights Under Other Laws
Depending on your location and applicable law, you may also have rights to restrict or object to processing, request data portability, opt out of sale or sharing, appeal decisions on privacy requests, and complain to your local data-protection authority.
17.3 How to Exercise Your Rights
To exercise a right relating to a BullCRM account, email support@bullcrm.io with the subject line "Privacy Request."
To exercise a right relating to information controlled by a BullCRM business customer, contact that customer directly. BullCRM will reasonably assist customers with valid requests where BullCRM acts as their Data Processor.
We may verify your identity or authority before completing a request. We aim to respond within 30 days and, in any case, within the period prescribed under the DPDP Rules.
We will not discriminate against an individual for exercising a privacy right.
17.4 Your Duties
Under the DPDP Act, Data Principals must not impersonate another person, suppress material information, register false or frivolous grievances, or provide information that is not authentic when exercising their rights.
18. Grievance Redressal
If you have any concern or complaint about how we process your personal data, you may contact our Grievance Officer:
Grievance Officer: [Name] Designation: [Designation] Jamtech Technologies Private Limited (BullCRM) 1st Floor, The Engineering Tower, Plot No. CP-43, Sector-E, Engineering College Road, Aliganj, Lucknow, Uttar Pradesh – 226021, India Email: support@bullcrm.io (Subject: "Grievance") Phone: +91 90096 70084 Working hours: Monday to Friday, 10:00 AM to 6:00 PM IST
We will acknowledge your grievance within 24 hours and aim to resolve it within 15 days of receipt, and in any case within the period prescribed under applicable law.
If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India. Under the DPDP Act, you must first exhaust our grievance redressal process before approaching the Board.
19. Marketing Communications
BullCRM may send product information, service updates, offers, or marketing communications where you have consented.
Recipients may unsubscribe at any time by:
- Using the unsubscribe link in an email;
- Updating communication preferences; or
- Contacting support@bullcrm.io.
Service-related notices, security alerts, billing notifications, and other essential account messages may still be sent.
BullCRM customers are independently responsible for managing consent and opt-outs for communications they send using BullCRM.
20. Cross-Border Data Transfers
BullCRM is operated from India. Our primary hosting is located in [India / name the region and hosting provider]. Some of our service providers may be located in the United States, the European Economic Area, the United Kingdom, or other countries.
We transfer personal data outside India only as permitted under Section 16 of the DPDP Act, and not to any country or territory to which the Central Government has restricted transfers.
For all international transfers, we use appropriate safeguards, which may include:
- Contractual data-protection obligations;
- Standard contractual clauses, where required by foreign law;
- Data-processing agreements;
- Access restrictions;
- Security controls; and
- Other legally recognized transfer mechanisms.
21. Data Security
BullCRM implements reasonable security safeguards, as required under the DPDP Act and DPDP Rules, to protect personal data against breach.
These safeguards include:
- Encryption of data during transmission (TLS);
- Encryption of stored data, and masking or tokenization of sensitive values where appropriate;
- Secure password hashing;
- Role-based access controls and the principle of least privilege;
- Tenant data separation;
- Multi-factor authentication;
- Audit and security logging, with logs retained for at least one year to detect and investigate unauthorized access;
- Secure infrastructure configuration;
- Monitoring and incident detection;
- Backup and recovery controls to ensure continued availability of data;
- Employee and contractor confidentiality obligations; and
- Contractual security obligations for vendors and sub-processors.
Access tokens, API credentials, and integration secrets are treated as sensitive information, and access is restricted to authorized systems and personnel.
No system is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.
Customers are responsible for securing their devices, login credentials, connected accounts, and user permissions.
22. Personal Data Breaches
If we identify a personal data breach, we will investigate and take prompt steps to contain, mitigate, and remediate it.
Where BullCRM is the Data Fiduciary, we will:
- Inform each affected Data Principal without delay, describing the breach, its likely consequences, the measures we have taken, the steps they may take to protect themselves, and our contact details;
- Inform the Data Protection Board of India without delay, and provide a detailed report within 72 hours of becoming aware of the breach, or such longer period as the Board may allow; and
- Report cyber security incidents to CERT-In within 6 hours of noticing them, as required by CERT-In directions.
Where the breach affects Customer Data for which BullCRM is the Data Processor, we will notify the affected customer without undue delay and provide the information it reasonably needs to meet its own notification obligations.
Customers must promptly notify BullCRM if they suspect unauthorized access to their BullCRM account or connected integrations.
23. Government and Public-Authority Requests
We review requests from government agencies and public authorities to determine whether they are lawful, valid, appropriately authorized, and sufficiently specific.
Where legally permitted and appropriate, we may:
- Challenge requests that appear unlawful or excessive;
- Request clarification or narrowing;
- Disclose only the minimum information legally required;
- Document the request, response, legal basis, and involved parties; and
- Notify the affected customer unless prohibited by law.
BullCRM complies with lawful directions issued under Indian law, including the Information Technology Act, 2000 and the DPDP Act. BullCRM does not provide governments or public authorities with direct or unrestricted access to customer data.
24. Sensitive Personal Data
BullCRM is not designed for unnecessary collection of highly sensitive personal data.
Customers should not upload or transmit sensitive information, such as financial account details, health information, biometric data, or government identifiers (for example, Aadhaar numbers), unless:
- It is necessary for a lawful business purpose;
- They have a valid ground for processing;
- Required notices and consent have been provided; and
- Suitable security and access controls have been configured.
Customers should not request passwords, OTPs, payment credentials, medical information, or similar sensitive information through WhatsApp messages unless lawful, necessary, and permitted by applicable WhatsApp policies. Aadhaar numbers must be handled only as permitted under the Aadhaar Act, 2016 and related regulations.
25. Children's Privacy
BullCRM is a business service and is not directed to children. Under the DPDP Act, a child is any individual under 18 years of age.
We do not knowingly allow children to create BullCRM accounts, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
If we learn that a child has provided personal data directly to BullCRM, we will take reasonable steps to delete it.
Businesses using BullCRM must not process children's personal data unless they have obtained verifiable consent from a parent or lawful guardian as required under the DPDP Act and DPDP Rules, and must ensure their communications with minors comply with applicable laws.
26. Third-Party Websites and Services
BullCRM may contain links to or integrations with third-party websites and services.
We are not responsible for the independent privacy practices, content, availability, or security of those third parties.
Users should review the privacy policies and terms of each third-party service they choose to use.
27. Data Processing Agreements
BullCRM's Terms of Service include data processing terms that apply when BullCRM acts as a Data Processor. Business customers that require a separately signed Data Processing Agreement may contact support@bullcrm.io.
A Data Processing Agreement may describe:
- The subject and duration of processing;
- The nature and purpose of processing;
- Categories of personal data;
- Categories of Data Principals;
- Confidentiality obligations;
- Security controls;
- Sub-processor requirements;
- Assistance with Data Principal rights;
- Breach notification;
- Cross-border transfers;
- Data return and deletion; and
- Audit and compliance obligations.
28. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- Changes to BullCRM services;
- New integrations or features;
- Changes to our data practices;
- Changes to service providers;
- Security improvements;
- Legal or regulatory requirements, including rules and guidance issued under the DPDP Act; or
- Meta and WhatsApp platform changes.
The updated version will be posted on the BullCRM website with a revised "Last Updated" date.
For material changes, we will notify account holders through the BullCRM dashboard or by email at least 15 days before the changes take effect and, where required by law, seek fresh consent.
Previous versions may be retained where required for legal, contractual, or Meta Platform compliance purposes.
29. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India.
Subject to your right to approach the Data Protection Board of India and any other statutory authority under applicable law, the courts at Lucknow, Uttar Pradesh, India shall have exclusive jurisdiction over all disputes arising out of or in connection with this Privacy Policy.
30. Contact Information
For privacy questions, data requests, complaints, or deletion requests, contact:
Jamtech Technologies Private Limited Product: BullCRM Registered Office: 1st Floor, The Engineering Tower, Plot No. CP-43, Sector-E, Engineering College Road, Aliganj, Lucknow, Uttar Pradesh – 226021, India Email: support@bullcrm.io Phone: +91 90096 70084 Website: https://bullcrm.io/
Please include sufficient information for us to understand and verify the request.
31. Meta and WhatsApp Disclaimer
BullCRM integrates with the WhatsApp Business Platform and Meta business technologies.
WhatsApp and Meta are trademarks of their respective owners.
BullCRM is not endorsed by, affiliated with, or an official partner of Meta or WhatsApp unless such status has been separately approved and expressly disclosed.