Trust centre

Your customer data, handled properly.

We store your data in the UK, encrypt it at rest, and never sell it. This page tells you exactly how, in plain English.

Where your data lives

🇬🇧
UK hosted
All application servers and databases run inside UK data centres. Data does not leave the UK for storage.
🔒
Encrypted at rest
Full-disk encryption on every database server. Backups encrypted separately with a different key.
🛡️
TLS 1.3 in transit
All traffic between your browser, our servers, and our subprocessors uses TLS 1.3 with modern ciphers.
📋
Daily backups
Full database backups every 24 hours with a 14-day retention window. Ask for point-in-time restore for critical incidents.

GDPR posture

We act as your data processor for customer records you store in the CRM. You are the data controller. Our processing is governed by our Data Processing Agreement, available on request.

  • Lawful basis: we process your data only to deliver the service you subscribe to.
  • Data portability: full data export in JSON or CSV from Settings at any time.
  • Right to erasure: account deletion from Settings removes all your data within 30 days.
  • Subprocessor notice: we notify you of any new subprocessor 30 days before it processes your data.
  • Breach notification: we notify you within 72 hours of any personal data breach affecting your records.
  • DPA: our standard Data Processing Agreement is available on request from info@unavoidablecrm.com.

Subprocessors

These are the third-party services we use to deliver the CRM. Each is contractually bound to protect your data to the same standard we do.

ProviderPurposeRegion
TwilioSMS delivery, phone numbersUK / EU
Retell AIAI receptionist voiceEU
StripeSubscription billingUK / EU
GoCardlessDirect Debit billingUK
PayPalCustomer payment processingUK / EU
AnthropicAI content generation, KB synthesisUS (data not retained)

Last updated 21 July 2026. We notify all customers by email at least 30 days before adding a new subprocessor.

Operational security

Two-factor auth
Available for every user account. Required for owner and admin roles.
Session controls
Configurable session timeout per tenant. Optional IP allowlist per company.
Audit log
Every write action is logged with actor, target and timestamp. Exportable to CSV.
Role-based access
Five system roles plus custom roles with granular wildcard permissions.

Reporting security concerns

Found a vulnerability? Please email info@unavoidablecrm.com. We respond within one business day.

System status Product changelog