Privacy policy
What data we process, why, with whom, for how long, and how to take control of it back.
Last updated: August 3, 2026
1. In short
We do not sell your data. We do not share it with any other customer. It is not used to train any artificial intelligence model. You can cut off access to your CRM and request deletion of your data at any time.
Jipup operates a platform of agents that analyse, clean and enrich CRM data. This policy describes the processing of personal data carried out in that context, on crm.jipup.com.
2. Two kinds of data, two distinct roles
This distinction shapes everything below. We process two categories of data, and our legal role differs between them.
Your account data — we are the controller
This is information about you as a user: your identity, your email address, your billing details. We determine the purposes, so under the GDPR we are the controller.
Your CRM data — we are a processor
This is the records held in your CRM: your customers, your prospects, your companies. That data is yours. You are the controller; we act only on your instructions, to deliver the service you asked for. We do not use it for any purpose of our own.
The matching contractual commitments are set out in our Data processing agreement (DPA), which forms part of the contract.
3. Account data we collect
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| First name, last name, business email address | Your signup | Account creation, authentication, service emails | Performance of the contract |
| Password | Your signup | Authentication. Stored as a cryptographic hash, never in clear text | Performance of the contract |
| Onboarding questionnaire answers (industry, team size, CRM in use) | Your signup flow | Tailoring the audit report and commercial follow-up | Legitimate interest |
| Phone number, where provided with an integration request | Your request | Contacting you about the CRM you asked for | Legitimate interest |
| Billing data | Your subscription | Billing, accounting | Performance of the contract, legal obligation |
| Technical logs (IP address, timestamp, action performed) | Your usage | Security, abuse detection, incident diagnosis | Legitimate interest |
4. Your CRM data: what we read, what we keep
When you connect your CRM, you grant us access through the vendor's official authorisation mechanism (OAuth). We never see your CRM credentials.
What we read
Depending on the permissions you grant: contact records, company records, lists, and optionally deals, record owners and the structure of your custom properties. A declined permission does not break the service: the corresponding part of the analysis is simply reported as not analysed.
What we keep on our side
We do not copy your CRM. We keep the output of the work, which requires a limited amount of real data:
- Aggregate metrics: number of records analysed, completeness rates, scores per theme. These are counters and contain no personal data.
- Examples of the records concerned: for each issue found, the record's id in your CRM, its name, a link to it, and the nature of the issue (empty field, likely duplicate, bouncing email). Without those examples an audit report asserts without evidence and cannot be acted upon.
- Proposed actions awaiting your approval: the change under consideration, the record concerned and the associated confidence level, until you accept or reject it.
- Run history: what was done, when, on which records.
- The access tokens issued by your CRM, needed to perform those operations.
What we never do
- Copy your entire CRM database into our systems.
- Use your CRM data for another customer, or pool it into a shared database.
- Sell, rent or transfer your data to third parties.
- Use your data to train artificial intelligence models, ours or anyone else's.
- Modify a record in your CRM outside the scope of the agent you enabled.
The free audit in particular is a read operation: it analyses and reports, it changes nothing in your CRM.
5. Enrichment: data sent to providers
When you enable an enrichment agent, we query specialist data providers to complete an incomplete record. That requires sending them the minimum needed for identification: first name, last name, company, domain name or professional profile URL.
Those providers act as sub-processors. The Subprocessors page states how many there are, what is sent to them and where they are established. Their named list is not published there — it is the core of our know-how — but it is provided on request at hello@jipup.com, under a confidentiality undertaking, to customers and prospects under evaluation alike.
As controller of your CRM data, it is for you to ensure that enriching your contacts rests on a valid legal basis and that the individuals concerned are informed as required. We provide the material you need for that information.
6. Who has access to the data
- Our team, strictly as needed to operate the service and provide support. Access to production data is limited to those who need it and is logged.
- Our technical subprocessors, listed and documented on the Subprocessors page. Each is bound by a contract meeting article 28 GDPR.
- Authorities, where a legal obligation or judicial order compels us.
No other sharing takes place. No data is transferred under commercial or advertising partnerships.
7. Transfers outside the European Union
Application data (accounts, audit reports, proposed actions) is hosted in France. Some providers necessary to run the service are, however, established outside the European Union or may access data from there for support and operational purposes.
Those transfers are governed by the European Commission's standard contractual clauses or by a recognised adequacy mechanism. The detail is given provider by provider on the Subprocessors page.
8. Retention periods
| Data | Period |
|---|---|
| User account | For the duration of the contractual relationship, then deleted within 30 days of account closure |
| CRM access tokens | Deleted immediately when the CRM is disconnected, or when the account is closed |
| Audit reports and their evidence records | 24 months, or immediately on a deletion request |
| Agent run history | 24 months |
| Technical logs | 12 months |
| Accounting records and invoices | 10 years (legal obligation) |
Disconnecting your CRM immediately ends all access on our side. It does not by itself delete reports already produced: those remain available in your workspace until they expire or until you ask for their deletion.
9. Your rights
In respect of personal data concerning you, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions on what happens to your data after your death.
To exercise them, write to hello@jipup.com. We reply within one month at the latest. Proof of identity may be requested where there is reasonable doubt.
If your request concerns data held in a customer's CRM, we pass it on to that customer, who is the controller, and assist them in responding.
You may also lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris — cnil.fr.
10. Security
The technical and organisational measures protecting this data are described in detail on the Security page, which also states, openly, the work still in progress.
11. Changes to this policy
This policy may change as the service evolves. Any substantive change — a new purpose, a new subprocessor, a longer retention period — is notified by email to active account holders before it takes effect. The last update date is shown at the top of the page.
12. Contact
We have not appointed a data protection officer, as our activity does not fall within the mandatory cases set out in article 37 GDPR. Any data protection question can be sent to hello@jipup.com or by post to JIPUP, 60 rue François Ier, 75008 Paris, France.