Privacy Policy

Last updated: August 2026

Your privacy matters to us. This policy explains what we collect, how we use it, who we share it with, and the choices you have over your data.

1. Introduction

1.1 Who We Are

Vridesk is a multi-tenant CRM platform for agencies, operated by Vriyox. When this Privacy Policy refers to "Vridesk", "we", "us", or "our", it means Vriyox operating the Vridesk platform. You can reach us at vridesk@vriyox.com or through our Contact page.

1.2 Scope of This Policy

This Privacy Policy explains how we collect, use, store, and share information about you when you visit our marketing website, sign up for a free trial, or use the Vridesk platform as the owner or a team member of a workspace, or as a client signing in to a workspace's client portal.

This policy does not apply to the business data that your team enters into Vridesk - such as customer records, orders, or financial entries. That data belongs entirely to you. We act only as a data processor for that content. For the terms governing your use of the platform, see our Terms of Service.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account or use the Service, you provide us with information such as:

  • Full name and email address.
  • Company or workspace name.
  • Password (stored as a secure cryptographic hash - never in plain text).
  • Job title, phone number, employment type, and location (optional profile fields).
  • Profile photo or avatar if uploaded.
  • Payment details, which are handled exclusively by our payment processor - we never store card numbers.

2.2 Business Data You Enter

As you use Vridesk, you and your team enter business data in the CRM - including leads and contacts, follow-up notes, email campaigns, emails received from your leads, client records, projects and tasks, and invoices. If you connect a mailbox, its password is stored encrypted.

We store this data to provide the Service. It remains yours at all times. We do not analyse, monetise, or share it beyond what is strictly necessary to operate the platform.

2.3 Automatically Collected Information

When you interact with Vridesk, we automatically collect limited technical data to keep the Service secure and functioning:

  • IP address and approximate location.
  • Browser type, version, and operating system.
  • Pages visited and actions taken (for session integrity, not behavioural tracking).
  • Login timestamps and device identifiers (parsed from User-Agent for session management).
  • Error logs and crash reports.

3. How We Use Your Information

3.1 To Provide and Operate the Service

We use your information primarily to run your workspace, authenticate you, enforce role-based access controls, and deliver the features you have subscribed to.

3.2 To Communicate with You

We send the following types of communications:

  • Account and security notifications - password changes, suspicious login alerts, session terminations.
  • Subscription and billing updates - renewal reminders, payment receipts, plan change confirmations.
  • Responses to support requests and enquiries.
  • Product updates, new feature announcements, and tips - you may opt out of non-essential emails at any time.

3.3 To Improve the Platform

We use aggregated, anonymised usage data to understand how the platform is used and to prioritise improvements. We do not build individual behavioural profiles for this purpose.

3.4 To Ensure Security and Prevent Fraud

We monitor for unusual activity, failed login attempts, and potential abuse to protect you and other users from unauthorised access and fraud.

3.5 Legal Basis for Processing (GDPR)

For users in the European Economic Area or UK, we rely on the following legal bases: performance of a contract (operating your account), legitimate interests (security, fraud prevention, product improvement), legal obligation (compliance with applicable law), and consent where you have explicitly given it for optional communications.

4. How We Share Your Information

4.1 Within Your Workspace

Profile information such as your name and role is visible to other members of your workspace. Your email address is visible to your workspace owner.

4.2 Service Providers

We share data with trusted third-party service providers who help us operate Vridesk, including:

  • Cloud hosting and infrastructure providers - for storing and serving your data.
  • Payment processors - for billing, under their own security and compliance standards.
  • Email delivery services - for transactional and notification emails.
  • Error monitoring tools - for detecting and fixing platform bugs.

4.3 Legal Requirements

We may disclose your information if required by law, court order, or government authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Vridesk, its users, or the public.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, your data may be transferred to the acquiring entity. We will notify you before this occurs and provide you with the option to delete your account.

4.5 We Never Sell Your Data

We do not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes. Full stop.

5. Multi-Tenant Architecture and Data Isolation

Vridesk is a multi-tenant platform - meaning multiple businesses run their workspaces on shared infrastructure. Each workspace's data is logically isolated using strict tenant-level access controls. Every database query is scoped to your workspace's unique identifier.

No user from one workspace can access the data of another workspace. Role-based access controls within each workspace further restrict what individual team members can see and do. These controls are enforced at the server level and cannot be bypassed through the interface. For more on your account and role structure, see our Terms of Service.

6. Data Security

6.1 Technical Safeguards

We apply industry-standard technical measures to protect your data, including HTTPS/TLS encryption for all data in transit, encrypted database connections, firewall rules, and regular security patching.

6.2 Password Security

Passwords are hashed using the argon2id algorithm with a unique salt per user. They are never stored in plain text and are never visible to Vridesk staff. Legacy bcrypt-hashed passwords are transparently rehashed to argon2id on next login.

6.3 Session Management

Authentication sessions are database-backed, cryptographically signed JSON Web Tokens (JWT) delivered via httpOnly, Secure cookies. You can view all active sessions and revoke any or all of them at any time from your account settings.

6.4 Breach Response

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant authorities within the timeframes required by applicable law. Notifications will describe the nature of the breach, data affected, and steps taken to mitigate harm.

7. Data Retention

7.1 Active Accounts

We retain your data for as long as your account remains active or as necessary to provide the Service. We do not delete data while your subscription is active unless you request it.

7.2 After Account Deletion

When you delete your account, your personal and workspace data are queued for deletion and permanently removed within 30 days - except for data we are legally required to retain, such as billing records for tax purposes.

Workspace owners who delete their account trigger a cascading deletion of the entire workspace, including all team member accounts and all business data within that workspace.

7.3 Backups

Deleted data may persist in encrypted backups for up to 90 days before being overwritten by routine backup rotation. We do not restore deleted data from backups except in the event of a system failure affecting active accounts.

8. Cookies and Tracking

Vridesk uses cookies primarily for session management and user preferences. We use only the cookies necessary for the platform to function, and we do not engage in cross-site tracking or behavioural advertising without your explicit consent. Read our Cookie Policy for a full list of cookies we set and how to manage them.

9. Your Rights and Choices

9.1 Access and Portability

You have the right to request a copy of the personal data we hold about you. Where technically feasible, we will provide your data in a machine-readable format suitable for transfer to another service.

9.2 Correction

You can update most of your profile information directly in your account settings. If you need to correct data that cannot be changed through the interface, contact us at vridesk@vriyox.com.

9.3 Deletion

You can delete your account at any time from Settings > Account > Delete Account. For workspace owners, this also deletes the entire workspace. For team members, only their personal account is removed.

9.4 Restriction and Objection

You may request that we restrict processing of your data in certain circumstances, or object to processing carried out on the basis of our legitimate interests. We will assess each request on its merits.

9.5 How to Exercise Your Rights

To exercise any of the above rights, contact us at vridesk@vriyox.com with your account email and a description of your request. We will respond within 30 days.

10. International Data Transfers

Vridesk is hosted on servers located in India. If you access the Service from outside India, your data will be transferred to and processed in India. By using the Service, you consent to this transfer.

Where we transfer personal data of users in the EEA or UK to countries without an equivalent level of data protection, we implement appropriate safeguards such as Standard Contractual Clauses to ensure your data remains protected.

11. Children's Privacy

Vridesk is designed for business use by adults aged 18 and over. We do not knowingly collect personal information from anyone under the age of 18. If you believe that a minor's information has been submitted to the platform, please contact us at vridesk@vriyox.com and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. We will update the "Last updated" date at the top of this page.

For material changes, we will notify active users by email at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes your acceptance of the updated policy.