HelloClient - CRM system for service centers

Privacy Policy for Personal Data

Effective date: 31.12.2025

1. General Provisions

1.1. This Privacy Policy defines how Individual Entrepreneur DENIS NEUSTROYEV, Identification Number 302360558, registered in Georgia, legal address: Georgia, Tbilisi, Chugureti district, Mikheil Tsinamdzghvrishvili street, N52, attic (the "Company", "we", "us") processes personal data and which security measures we apply, in accordance with applicable data protection law.

1.2. This Policy supplements our Terms of Service and, where applicable, the Data Processing Agreement.

1.3. By registering an account, creating a profile or providing contact information, you agree to the processing of your personal data in accordance with this Policy. If you do not agree, you should not use the Service.

1.4. We take all necessary measures to protect personal data from unauthorised access, alteration, blocking, copying, distribution, deletion and other unlawful acts.

2. Personal Data We Collect

2.1. We process the following categories of personal data:

  • data you provide yourself (name, email address, phone number, business information);
  • data collected automatically when you use the Service (IP address, browser and operating system information, cookies);
  • billing data (payment status, transaction ID, billing email; full card data are processed by our payment service provider and are not stored by us; payments are processed by PayPro Global).

2.2. Processing is based on the following legal grounds: performance of a contract with you, your consent, our legitimate interests and legal obligations.

We use cookies in accordance with our Cookie Policy. Non-essential cookies are set only with your consent.

3. Purposes of Processing

3.1. We process personal data solely for the following purposes:

  • identification of the user when using the Service;
  • provision of the Service;
  • performance of obligations under the contract with the user;
  • sending informational messages, news and notifications (with your consent);
  • statistical and analytical research based on anonymised data.

3.2. Personal data are not used for purposes other than those stated in this Policy.

3.3. We retain personal data as follows:

  • account data — while the account is active and not more than 3 years after its termination;
  • billing data — not more than 5 years from the date of payment processing, as required by tax law;
  • CRM data — deleted not more than 3 years after deletion by the user or termination of the account;
  • backups — not more than 3 years;
  • logs — not more than 3 years.

4. Disclosure to Third Parties

4.1. Personal data may be disclosed to third parties only in the following cases:

  • you have given your consent to such disclosure, including consent to cross-border transfer;
  • disclosure is necessary to perform the contract to which you are a party;
  • disclosure is necessary to protect our rights and legitimate interests;
  • disclosure is required by law, including court orders and requests of competent state authorities.

4.2. We may engage processors bound by contracts ensuring data protection. The current list of processors, the purposes of processing, the categories of processed data and the actions performed is available at: helloclient.app/en/documents/partners.

4.3. Hosting and storage: Personal data are hosted on the servers of Amazon Web Services (AWS), Regions: EU and/or US.

4.4. Where processors are located outside the EU/EEA, processing is carried out under their local law and a data protection agreement with them.

5. Data Subject Rights

5.1. You have the right to:

  • access your personal data;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • restrict processing;
  • receive your data in a portable format;
  • object to processing;
  • withdraw your consent at any time.
5.2. To exercise these rights, send a request to: info@helloclient.app

We will respond within one month; where necessary, this period may be extended by two further months, and we will inform you of any such extension.

5.3. You may lodge a complaint with the competent supervisory authority if you consider that processing infringes applicable data protection law.

6. Security Measures

6.1. Organisational measures:

  • access rights restricted by the least-privilege principle;
  • system of recording and logging actions with personal data;
  • integrity assurance;
  • regular security analysis;
  • control of physical access to data media;
  • internal data protection policies;
  • designated persons responsible for data processing;
  • internal control of data protection measures.

6.2. Technical measures:

  • TLS 1.3 encryption of all connections;
  • two-step authentication (password and one-time code);
  • automatic and semi-automatic incident response;
  • proactive filter (WAF — Web Application Firewall);
  • regular security audits of code and infrastructure, internally and by independent companies;
  • firewall-restricted access to all infrastructure;
  • continuous activity monitoring;
  • timely updates of system software;
  • password rotation every 90 days;
  • antivirus software.

6.3. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay. Where required by applicable law, we will notify the competent authorities.

7. Changes to this Policy

We may update this Policy unilaterally. The current version is published at helloclient.app/en/documents/privacy-policy. Please review it regularly.

8. Contact Information

Individual Entrepreneur DENIS NEUSTROYEV, Identification Number 302360558, Georgia, Tbilisi, Chugureti district, Mikheil Tsinamdzghvrishvili street, N52, attic.

Email: info@helloclient.app

Still have questions? We're here to help:
Contact us on What's AppWhat's App support

If everything is clear — join us! Register now and start managing your business for free