Privacy Policy

Last updated: 12 July 2026

This Privacy Policy explains how EasyPeasy Sales ("we", "us", or "our") collects, uses, discloses, and protects personal data when you use our SaaS CRM platform, website, and related services (the "Service").

We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), collectively the "GDPR", and the Data Protection Act 2018.

1. Who We Are

EasyPeasy Sales is operated by TKC Consulting LLC, which is the data controller for personal data we process in connection with the Service.

Company: TKC Consulting LLC
Jurisdiction: United Arab Emirates
Contact: privacy@easypeasysales.co.uk

2. Data We Collect

We collect and process the following categories of personal data:

2.1 Account Data

  • Name, email address, and password (encrypted)
  • Role within your organisation (admin or user)
  • Company name and business details provided at registration

2.2 Contact Data (CRM Records)

You may upload or create contact records within the Service containing personal data about your prospects and customers, including:

  • Names, email addresses, phone numbers, job titles
  • Company information and business addresses
  • LinkedIn profiles and social media links
  • Notes, activity history, and deal information

You are the data controller for this Contact Data. We process it as your data processor solely to provide the Service. You are responsible for ensuring you have a lawful basis for processing this data.

2.3 Usage Data

  • IP address, browser type, device information
  • Pages visited, features used, time spent in the Service
  • Error logs and technical diagnostic data

2.4 Billing Data

  • Billing name, company, and billing address
  • Payment method (processed securely by our payment provider, Stripe — we do not store card numbers)
  • Transaction history and invoice details

2.5 Communication Data

  • Email and campaign content you create within the Service
  • Records of emails sent through the Service (open rates, click tracking)
  • Support requests and correspondence with us

3. Legal Basis for Processing

We process personal data under the following legal bases permitted by the GDPR:

3.1 Performance of a Contract (Article 6(1)(b))

Processing your account data, billing data, and Contact Data is necessary to provide the Service you have subscribed to under our Terms of Service.

3.2 Legitimate Interests (Article 6(1)(f))

We process usage data and communication data for legitimate business interests including:

  • Improving, securing, and maintaining the Service
  • Preventing fraud, abuse, and unauthorised access
  • Analyzing usage patterns to develop new features
  • Communicating with you about your account and the Service

3.3 Consent (Article 6(1)(a))

Where we use cookies for analytics or marketing, or process data for optional features, we rely on your consent. You may withdraw consent at any time.

3.4 Legal Obligation (Article 6(1)(c))

We may process personal data to comply with legal obligations, such as tax and accounting records.

4. How We Use Your Data

  • Providing the Service: Operating the CRM platform, AI features, email campaigns, and document generation
  • Account management: Authenticating users, managing subscriptions, processing payments
  • Communication: Sending service notifications, support responses, and product updates
  • Security: Monitoring for suspicious activity, preventing fraud, maintaining audit logs
  • Improvement: Analyzing usage to improve features and user experience
  • Legal compliance: Meeting our legal and regulatory obligations

5. AI Processing

The Service uses artificial intelligence (AI) and large language models (LLMs) to provide features such as coaching insights, email drafting, prospecting strategies, and market intelligence. When you use these features:

  • Your input data (e.g., deal information, company notes) may be sent to our AI sub-processors for processing
  • AI-generated outputs are based on patterns in training data and may not always be accurate
  • We do not use your personal data to train AI models
  • You should review AI-generated content before relying on it for business decisions

6. Data Sharing & Sub-Processors

We do not sell your personal data. We share data with the following categories of recipients:

6.1 Cloud Infrastructure

  • Base44 — Platform infrastructure, database hosting, and backend services

6.2 Payment Processing

  • Stripe — Subscription payment processing (PCI-DSS compliant)

6.3 AI & LLM Providers

  • Google (Gemini) — AI text generation and web-enhanced features
  • OpenAI — AI text generation
  • Anthropic (Claude) — AI text generation

6.4 Email Delivery

  • Our email infrastructure provider for sending campaigns and transactional emails

6.5 Other Disclosures

We may disclose personal data when required by law, court order, or to protect our rights, property, or safety, or that of our users or others.

6.6 Sub-processor Updates

We will notify you of any new sub-processors by updating this policy. You may object to a new sub-processor by contacting us within 30 days of the update.

7. International Data Transfers

Your personal data may be transferred to and processed in countries outside the UK/European Economic Area (EEA), including the United States. Where this occurs, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner and the European Commission
  • Data transfer impact assessments where required
  • Selection of sub-processors with adequate privacy and security practices

8. Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this policy:

  • Account data: For the duration of your subscription, then up to 90 days after account closure for account recovery
  • Contact Data: Until you delete it or terminate your account, at which point it is permanently deleted within 30 days
  • Billing data: Up to 6 years for tax and accounting compliance
  • Usage data: Up to 24 months
  • Communication data: Up to 12 months after the relevant communication

9. Your Data Protection Rights

Under the GDPR, you have the following rights regarding your personal data:

  1. Right of Access: Request a copy of the personal data we hold about you
  2. Right to Rectification: Request correction of inaccurate or incomplete data
  3. Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data
  4. Right to Restriction of Processing: Request that we limit how we use your data
  5. Right to Data Portability: Receive your data in a structured, machine-readable format
  6. Right to Object: Object to processing based on legitimate interests or direct marketing
  7. Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
  8. Right to Lodge a Complaint: Complain to the Information Commissioner's Office (ICO) or your local data protection authority

10. Exercising Your Rights

To exercise any of these rights, contact us at privacy@easypeasysales.co.uk. We will respond within one month of receiving your request, as required by the GDPR. In certain cases, we may extend this period by two months for complex requests, and we will inform you of the extension.

We may need to verify your identity before processing your request and may ask for additional information to help us locate your data.

11. Cookies

We use cookies and similar technologies on our website. For details, please see our Cookie Policy.

12. Security Measures

We implement appropriate technical and organisational measures to protect personal data, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure password hashing and authentication
  • Role-based access controls and least-privilege access
  • Regular security monitoring and audit logging
  • Secure sub-processor infrastructure (SOC 2 / ISO 27001 certified providers where available)
  • Regular data backups and disaster recovery procedures

13. Data Breaches

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.

14. Children's Data

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on this page and updating the "Last updated" date. For material changes, we may also notify you by email.

16. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact:

Email: privacy@easypeasysales.co.uk
Subject: Data Protection / Privacy

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or your local data protection authority.

EasyPeasy Sales is operated by TKC Consulting LLC, UAE. © 2026 TKC Consulting LLC. All rights reserved.