Effective May 31, 2026
STATIM (“STATIM,” “we,” “us”) provides multi-tenant customer relationship management (CRM) software. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to use of the STATIM web application and related services (the “Service”).
Information you provide. When you register or use the Service we collect your name, email address, password (stored hashed), organization name, and any data you enter into the application — including companies, contacts, deals, tasks, notes and communications, marketing audiences, form and e-signature submissions, and uploaded files such as logos or documents.
Information from connected services. If your organization enables optional integrations, we process the data needed to operate them: outbound message content and recipient addresses for email delivery (SendGrid); phone numbers, call metadata, recordings and transcripts for telephony (Twilio); and the content you submit for AI-assisted features (Anthropic). If you enable single sign-on with Microsoft or Google, we receive the identity and OAuth tokens required to authenticate your users.
Operational information. We collect basic logs (IP address, browser, timestamps) needed to operate, secure, and debug the Service.
We use the information you and your connected services provide to deliver the features of the Service — manage your contacts and pipeline, send marketing and transactional email, place and log calls, generate AI-assisted content, and collect form and e-signature submissions — and to operate, secure, and improve the platform. We do not sell your personal information.
Some features let your organization publish forms and send e-signature requests that are accessible without a STATIM login, through a unique link. When someone submits one of these, we collect the information entered on the form or document — which may include name, email, phone, typed signature, and, for audit purposes, the IP address and timestamp of the submission — and associate it with the organization that published the link.
We share information only with: (a) service providers acting on our behalf — for example, hosting and storage (AWS), email delivery (SendGrid), telephony (Twilio), and AI processing (Anthropic) — under contracts requiring confidentiality and limited use; (b) other users within your own organization, based on the role you assign them; (c) authorities when legally required.
We follow industry-standard practices to protect your data: TLS in transit, encryption at rest at the storage layer, per-tenant database isolation (each organization’s CRM data lives in its own dedicated database), scoped access controls on every API endpoint, password hashing with bcrypt, and optional multi-factor authentication. No system is perfectly secure, but we work to minimize risk and to respond promptly to incidents.
We retain your account and the data you enter for as long as your organization uses the Service. If your organization deletes its account, we delete or anonymize your information in accordance with our standard schedule, except where retention is required by law or for legitimate business purposes such as audit logs.
You can update your profile and your organization’s information from the Settings page. To request access, correction, or deletion of your personal information, contact us at the address below. We will respond consistent with applicable law (including the GDPR and CCPA, where they apply).
The Service is not directed to children under 13, and we do not knowingly collect personal information from them.
We may update this Privacy Policy from time to time. We’ll change the Effective Date above and, for material changes, notify account owners by email or in-app message.
Questions about this Privacy Policy or our handling of your data? Email privacy@myitdept.ai.