This is Clienta’s current policy, not legal advice. If you store your own customers’ data in a workspace, you are responsible for that relationship; Clienta is the processor for that data.
1. Scope and roles
This policy covers clienta.ir, the web app at app.clienta.ir, the Clienta mobile apps and related services.
A cloud CRM holds two kinds of data, and our role is different for each:
- Account and site data: name, email, mobile, billing details and website visits. Clienta is the organisation that collects and processes this.
- Workspace data: contacts, companies, leads, deals, activities, synced email, files and similar content you enter. You own that data. Clienta processes it only to provide the service, on your instructions and within the product.
2. What we collect
Depending on how you use Clienta, we may receive:
- Identity and contact: name, email, mobile number, organisation, role.
- Account: hashed password, roles, permissions and sign-in history.
- Demo or contact forms: name, company and phone submitted on the site.
- Billing: plan, amount, payment date and gateway reference. We do not store full card numbers; payments go through an Iranian banking gateway.
- Technical data: IP address, browser and device type, access time and events needed for security and uptime.
- Workspace data: anything you store in the CRM, including your customers’ details and attachments.
We collect only what the service needs. Leave optional fields empty if you do not need them.
3. Why we process data
Articles 59(a) and 59(b) of the Electronic Commerce Act require a stated purpose and collection limited to that purpose. We use data to:
- Create and run accounts, workspaces and access control.
- Provide the CRM, sync, backups and technical support.
- Run the 14-day trial, subscriptions, invoices and payment follow-up.
- Protect accounts, prevent abuse and fix outages.
- Send service notices such as term changes, planned downtime or trial end.
- Improve the product with aggregated, non-identifying statistics — not by selling your contact list.
- Meet legal, tax and competent-authority requirements.
Marketing messages are separate from required service notices. You can opt out of marketing.
4. Sensitive data
Article 58 of the Electronic Commerce Act makes it unlawful, without explicit consent, to store, process or distribute personal data that reveals ethnic origin, ideological or religious views, moral characteristics, or physical, psychological or sexual condition.
Clienta does not need that data to run a CRM and does not collect it as a separate category. If you put sensitive data in free-text fields, notes or files, you are responsible for consent and a lawful basis.
5. Consent and basis
By creating an account, using the site or submitting a form, you agree to processing of account data under this policy. The main basis is performing the subscription contract and the service you asked for.
For workspace data, you confirm you have the right to collect and store it — including any consent or other lawful basis required for your own customers and contacts.
6. Where data is stored
Primary workspace and account data is kept on cloud infrastructure in Iran. That is part of how the service is built for teams that need data residency in the country.
9. Security
We apply measures appropriate to business cloud software, including encrypted transport (HTTPS), workspace isolation, role-based access, password hashing and backups.
No online system is risk-free. You are responsible for passwords, account security features and your team’s access. Permission levels are configurable in the product.
10. Retention
- Account and workspace data is kept while a trial or paid subscription is active, then for a reasonable retention period, unless you ask us to delete sooner.
- Records you soft-delete in the product usually stay in a restore bin for 30 days, then are purged.
- Financial and tax records may be kept longer where Iranian law requires it.
- After an account ends, workspace data is deleted or made unrecoverable within 90 days, unless we must keep it for a dispute, audit or legal order.
11. Your rights
Article 59 of the Electronic Commerce Act recognises the right to access files that hold your personal data messages, to correct incomplete or inaccurate data, and to request full deletion subject to the relevant rules.
You can view and edit most account details in the product. For account deletion, an export, or anything the product cannot do, email support.
If a request is about your customers’ records in a workspace, we refer it to that workspace’s admin, because your organisation is the controller of that data.
12. Under-18s
Clienta is a business service and is not designed for people under 18. If we learn an account was created for a child without a legal guardian, we will close it and delete related data.
13. Changes to this policy
If the policy changes, the date at the top of this page is updated. Material changes are announced by account email or in-product notice. Continued use after the new version takes effect means you accept it, unless the law gives you another right.
Personal data requests
Write to support@clienta.ir to access, correct or delete personal data, or to ask about this policy. We review requests within a reasonable time.
