Privacy Policy
Last updated: 14/09/2026
1. WHO WE ARE
GuardiaCRM is a portfolio management app for independent insurance intermediaries and their clients.
Provider: Panayiotis Eleftheriou (sole trader), Nicosia, Cyprus.
Contact: info@guardiacrm.eu
For the client data that each agent enters, the agent is the Data Controller; GuardiaCRM acts as the Data Processor.
2. WHAT DATA WE COLLECT
- Account details: name, email, phone, password (encrypted).
- Client details entered by the agent: full name, ID number, phone, email, date of birth, address, occupation.
- Insurance data: policies, premiums, payments, documents (PDF), receipts, signatures.
- Communication: agent–client chat messages, reminder history, notes (including voice notes).
- Technical data: device identifier for notifications, language, sign-in details.
- Emails to clients: the client's email address and language are used to send, on the agent's behalf, emails about their policies (documents, receipts, renewals and, if the agent enables it, an annual review email for life policies).
- Shared visibility: the agent may make a specific policy visible to another of their clients (for example the driver of a car owned by a family member), and the owner of a company client can see the company's policies from their own account.
3. WHY WE PROCESS IT (LEGAL BASIS)
- Performance of a contract: running the CRM service and the client app.
- Legitimate interests: renewal and payment reminders, security of the service.
- Consent: communication by WhatsApp/SMS/email, birthday wishes. Freely withdrawable.
- Legal obligation: record-keeping under insurance legislation (IDD) and tax rules.
- Legitimate interests — policy emails: emails about existing policies sent on the agent's behalf, and the annual review email for life policies. You can object at any time by replying to the email or telling your agent, and you will not receive it again.
4. WHERE IT IS STORED
Data is hosted on servers within the European Union (Supabase, EU region). Each agent sees ONLY their own data and each client ONLY their own — the isolation is enforced at database level (Row Level Security).
5. WHO HAS ACCESS
- Your agent (for client data) and you.
- Infrastructure providers: Supabase (database/files, EU), Expo (app updates), Apple/Google (subscriptions, notifications), RevenueCat (subscription management).
- AI features: when used (document reading, signature spot detection), extracts of documents are processed by the AI provider (Anthropic PBC, USA) solely to perform the requested function — never to train models. Transfers outside the EU rely on Standard Contractual Clauses.
- Email delivery: Resend (EU sending region, Ireland), for account emails and emails to clients. Website and web app hosting: Netlify. Push notifications: Expo and Google Firebase.
- AI assistant and suggestions: when the agent uses the AI assistant, bulk import or the weekly opportunity suggestions (where AI is enabled), the relevant data from the agent's account is sent to Anthropic under the same conditions. The results are suggestions only and are always reviewed by the agent.
We do not sell or rent personal data to third parties.
6. HOW LONG WE KEEP IT
For as long as the account is active. After a subscription is cancelled, the agent's data is kept in read-only mode for up to 2 months and then deleted. If the account is deleted, the data is erased immediately and permanently. Documents belonging to archived policies are deleted automatically after 10 years; the policy record itself (number, amounts, dates) remains. Records of emails sent to clients (recipient, type, date, status) are kept for 12 months and then deleted automatically.
7. SECURITY
Encryption in transit (TLS) and at rest, private file storage with temporary access links, optional biometric app lock, per-user access control.
8. YOUR RIGHTS
See the section "GDPR — Your rights".
9. CONTACT
For any privacy matter: info@guardiacrm.eu. You have the right to lodge a complaint with the data protection supervisory authority of your country of residence, or with the authority where we are established, the Office of the Commissioner for Personal Data Protection of Cyprus (dataprotection.gov.cy).