crmIQ Essentials Privacy Policy

Effective and last updated: July 12, 2026 · Version 2026-07-12

1. Scope and accountability

This Privacy Policy explains how crmIQ Inc., operating crmIQ and crmIQ Essentials (“crmIQ,” “we,” “us,” or “our”), collects, uses, discloses, protects, retains, and provides access to personal information. It applies to registration, account administration, use of crmIQ Essentials, support, billing, and related communications.

2. Information we collect

We may collect account and contact details such as name, firm, email, phone number, role, login and verification information; billing and transaction details; service usage, device, browser, log, IP address, security and diagnostic information; communications with us; and Customer Data entered or imported by authorized users, including information about clients, prospects, households, companies, relationships, notes, to-dos, and custom fields.

3. How we use information

We use information to create and administer accounts; provide, operate, personalize, secure, troubleshoot, and improve the service; verify identity and prevent abuse; provide support; process payments and issue invoices; communicate about the service; maintain audit and security records; meet legal obligations; and enforce agreements. We limit collection, use, and disclosure to purposes a reasonable person would consider appropriate in the circumstances.

4. Consent and customer instructions

We obtain consent where required and explain material purposes at or before collection. A firm using crmIQ Essentials is responsible for ensuring it has authority and any required consent to submit personal information about its clients, prospects, employees, or other individuals. For Customer Data, we generally act on the firm’s instructions as its service provider.

5. Disclosure and service providers

We do not sell personal information. We may disclose information to hosting, infrastructure, security, email, support, payment, accounting, analytics, and other service providers that help operate crmIQ Essentials; to professional advisers; in a business transaction; to comply with law, court orders, or valid government requests; or to protect rights, safety, and security. Service providers receive only the information reasonably required for their functions and are expected to protect it.

6. Processing locations

Personal information may be processed or stored in Canada or other jurisdictions where we or our service providers operate. Information in another jurisdiction may be subject to that jurisdiction’s laws and lawful access requirements.

7. Safeguards

We use safeguards appropriate to the sensitivity of the information, which may include access controls, password hashing, encryption where configured, logging, backups, monitoring, vendor controls, and administrative procedures. No safeguard is perfect. Users must protect credentials, assign access appropriately, and notify us promptly of suspected compromise.

8. Retention and deletion

We retain information only as long as reasonably needed for the purposes described, to provide the service, maintain security and business records, resolve disputes, enforce agreements, and meet legal obligations. Retention periods vary by information type. Deleted information may remain temporarily in backups or logs until overwritten under normal retention cycles.

9. Access and correction

Subject to legal exceptions, individuals may request access to personal information we control and ask that inaccurate or incomplete information be corrected. Where information was submitted by a customer firm, requests may need to be directed to that firm. We may take reasonable steps to verify identity before responding.

10. Cookies and similar technologies

We may use session cookies and similar technologies necessary for authentication, security, preferences, and core service operation. We may also use limited analytics or diagnostics to understand and improve service performance. Browser settings can control cookies, but disabling required cookies may prevent the service from functioning.

11. Security incidents

We investigate suspected security incidents and take steps appropriate to the circumstances. Where required by applicable law, we will notify affected organizations, individuals, regulators, or other authorities and maintain required records.

12. Changes to this Policy

We may update this Privacy Policy as our service, practices, providers, or legal obligations change. We will post the revised policy with its effective date and provide additional notice or seek renewed consent where required.

13. Contact and privacy requests

Questions, complaints, access requests, or correction requests may be sent to our Privacy Contact at ai@blueprintcrm.ca. We will review and respond in accordance with applicable law.