1. Scope and our privacy roles
This Privacy Policy explains how CloseUp CRM (“CloseUp,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal information when you visit our website, create or administer an account, use the CloseUp platform, contact us, or interact with services that are connected to CloseUp.
The legal entity providing the paid Service is the entity identified in your applicable order form, invoice, subscription checkout, or other agreement with CloseUp.
When CloseUp is the controller
CloseUp generally acts as the data controller (or equivalent business under applicable privacy law) for information relating to website visitors, prospective customers, customer account administrators and users, billing contacts, support contacts, and information we process for our own business operations.
When CloseUp is a processor or service provider
For personal information that a customer uploads, imports, synchronizes, records, generates, or otherwise processes in its CloseUp workspace (“Customer Data”), the customer normally determines why and how that information is processed. In that context, the customer is generally the controller/business and CloseUp acts as its processor, service provider, or contractor. If you are a lead, contact, employee, customer, prospect, or other person whose information is stored by a CloseUp customer, the relevant customer is usually the primary party responsible for responding to your privacy request.
This Policy supplements, and does not replace, any Data Processing Addendum (“DPA”) or other written data protection terms between CloseUp and a customer. If there is a conflict concerning Customer Data, the DPA or signed customer agreement controls to the extent stated there.
2. Information we collect
| Category | Examples | Why it is needed |
|---|---|---|
| Account and profile information | Name, business email, phone number, job title, password/authentication data, language, profile settings, company/workspace, role and permissions. | Account creation, authentication, administration, support, security, and personalization. |
| Organization and subscription information | Company name, plan, seats, workspace configuration, billing contact, tax/VAT information, invoices, payment status and transaction references. | Contract administration, billing, tax, fraud prevention, and customer support. Full payment-card details should be handled by the payment processor when applicable. |
| CRM and lead information | Names, phone numbers, email addresses, company information, lead source, status, notes, tasks, tags, custom fields, assignment history, proposals, deal values, campaigns, attribution parameters and other customer-defined CRM fields. | Provide the CRM and sales-execution functions requested by the customer. |
| Communications and interaction data | Email messages, WhatsApp messages, telephony metadata, call recordings, call direction, participants, timestamps, transcripts, meeting information, notes and attachments, where the customer connects those channels and applicable law permits processing. | Centralize customer interactions, create timelines, enable search, follow-up, reporting, quality control and AI features. |
| AI inputs and outputs | Prompts, transcripts, messages, CRM context, summaries, classifications, sentiment, extracted entities, lead scores, recommended next actions, and other generated insights. | Deliver AI-assisted product functionality and improve product quality as described below. |
| Integration data | Integration identifiers, OAuth grants/tokens, webhook identifiers, external account IDs, provider configuration and data returned from customer-authorized services such as email, calendar, WhatsApp/Meta, telephony, advertising and lead-form providers. | Connect and operate third-party services selected by the customer. |
| Technical, usage and security data | IP address, browser/device information, session data, authentication events, audit logs, timestamps, API activity, error logs, security events, feature usage and performance telemetry. | Operate, secure, troubleshoot and improve the Service; prevent abuse and unauthorized access. |
| Website and marketing data | Pages viewed, referral source, campaign parameters, cookie identifiers, consent preferences, forms, demo requests and marketing engagement. | Operate the website, measure performance, respond to inquiries and, where permitted, conduct marketing. |
| Support and correspondence | Support tickets, emails, chat messages, screen recordings or attachments you choose to send us, and feedback. | Provide support, investigate issues and improve the Service. |
Customers may configure custom fields and integrations that cause additional categories of information to be processed. Customers are responsible for determining whether those categories are appropriate and lawful for their use case.
3. Where information comes from
- Directly from you when you register, contact us, configure the Service, upload information, submit a form, or communicate with us.
- From your organization when an administrator invites you, assigns roles, imports contacts, or configures a workspace.
- From connected services when a customer authorizes CloseUp to connect to email, calendar, telephony, Meta/WhatsApp, advertising, web forms, or other systems.
- Automatically from the website and Service through cookies, logs, security tooling and similar technologies.
- From customers and business partners when they provide lead, contact or interaction information for processing in the CRM.
4. How we use personal information
We use personal information only for legitimate business and service purposes, including to:
- provide, maintain, configure and support CloseUp;
- authenticate users, manage accounts, roles, permissions and workspaces;
- ingest, match, normalize, organize and display leads and interactions;
- connect customer-authorized integrations and synchronize information;
- transcribe and analyze communications and provide AI summaries, classifications, recommendations, scores and other requested features;
- process subscriptions, invoices and payments;
- detect fraud, abuse, security incidents and technical problems;
- maintain auditability, service reliability, backups and disaster recovery;
- respond to support, privacy, accessibility and legal requests;
- measure and improve product performance, usability and feature quality;
- send service communications and, where permitted, marketing communications;
- comply with law, enforce agreements, protect rights and resolve disputes.
We may create aggregated or de-identified information that is not reasonably linkable to an identifiable person and use it for analytics, benchmarking, product improvement and business planning, subject to applicable law and our contractual obligations.
5. Legal bases for processing
Where a law requires us to identify a legal basis, we rely on one or more of the following, depending on the context:
- Performance of a contract to provide the Service you or your organization requested.
- Legitimate interests in operating, securing, supporting and improving a business SaaS platform, preventing fraud, communicating with customers, and understanding product usage, where those interests are not overridden by applicable privacy rights.
- Consent where consent is required, including for certain cookies, marketing activities or processing initiated by the customer.
- Legal obligations such as tax, accounting, lawful requests, security, and regulatory requirements.
For Customer Data processed on behalf of a customer, CloseUp generally relies on the customer’s instructions and processor relationship. The customer is responsible for establishing its own lawful basis and providing required notices or obtaining required consents.
6. Artificial intelligence and automated analysis
CloseUp includes AI-assisted features that may analyze CRM records, messages, call transcripts, recordings converted to text, campaign data and related context to generate summaries, classifications, extracted details, sentiment, lead prioritization, forecasts, coaching suggestions and recommended next actions.
- AI output can be incomplete, incorrect or inappropriate and should be reviewed by a qualified user before material action is taken.
- CloseUp is designed as a decision-support and workflow tool. Customers remain responsible for decisions made using AI output.
- We do not authorize third-party general-purpose AI providers to use identifiable Customer Data to train their general foundation models unless the customer has expressly opted in or a separate written agreement specifically permits that use.
- We may use de-identified or aggregated product telemetry and quality signals to improve our own features, subject to applicable law and customer agreements.
Where applicable law grants rights relating to solely automated decisions that produce legal or similarly significant effects, you may contact us or the relevant CloseUp customer to exercise those rights.
Google Workspace APIs — Google Calendar and Google Meet
This section describes how CloseUp CRM uses Google Workspace APIs for the Google Calendar and Google Meet integration. CloseUp CRM includes AI capabilities in other parts of the product. However, Google Workspace API user data received through this Google Calendar integration is not transferred to or processed by those AI capabilities.
Google Account connection
A user may connect their Google account to CloseUp CRM by granting permission explicitly through Google’s OAuth consent flow. CloseUp accesses Google Workspace data only after that authorization.
Data accessed
Subject to the permissions you grant, CloseUp may access only the Google Calendar data needed for meeting-scheduling functionality, including:
- calendar events required for that functionality;
- meeting attendees;
- conference / Google Meet information associated with those events;
- free/busy availability information; and
- the Google account email address or identifier needed to manage the connection.
CloseUp does not read all information in your Google account.
Purpose of use
Google Calendar and Google Meet data obtained through this integration is used solely to provide the scheduling functionality you request, including:
- scheduling, rescheduling, and cancelling meetings;
- creating, updating, rescheduling, and cancelling Calendar events;
- adding attendees and sending Calendar invitations;
- creating Google Meet as part of a Calendar event; and
- displaying or calculating availability using Free/Busy.
AI and machine learning
CloseUp CRM includes AI capabilities in other parts of the product. Raw or derived user data received from Google Workspace APIs through the Google Calendar integration:
- is not used to train AI/ML models;
- is not used to improve foundation or generalized models, including fine-tuning, evaluation, or other model improvement;
- is not sent to third-party AI providers;
- is not used for AI inference, prompts, embeddings, or vector stores within CloseUp; and
- is not used for any secondary AI purpose within CloseUp.
That Google Workspace API user data is used only for the scheduling functionality described in this section.
Google Limited Use
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Disconnect
You can disconnect the Google Calendar integration from within CloseUp CRM at any time. After you disconnect, CloseUp will no longer access your Google Calendar through that connection. Requests to access, correct, or delete personal data more generally may be made as described in the retention and privacy-rights sections of this Policy, including by emailing privacy@closeup.co.il or using our Data Deletion page.
8. International data transfers
CloseUp serves customers globally. Personal information may therefore be processed in Israel, the European Economic Area, and other countries where CloseUp or its authorized service providers operate. Those countries may have privacy laws that differ from the laws where you live.
Where a cross-border transfer requires a specific legal mechanism, we use an appropriate safeguard such as an adequacy decision, approved contractual clauses, or another lawful transfer mechanism. Customers may contact us for information about applicable transfer safeguards and subprocessors.
9. Data retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Service, comply with law, resolve disputes, maintain security, and enforce agreements.
- Customer Data: retained while the workspace is active and then deleted or returned according to the applicable subscription, DPA, configured retention rules and lawful backup lifecycle.
- Account and billing records: retained for the relationship and for applicable tax, accounting, fraud-prevention and legal retention periods.
- Security and audit logs: retained for a limited period appropriate to security, investigation and compliance needs.
- Support records: retained as needed to resolve issues, preserve case history and meet legal obligations.
- Backups: deleted or overwritten on a rolling schedule. Information may remain in protected backups until the applicable backup expires, unless law requires a longer period.
Customers can request deletion or return of Customer Data as described in our Data Deletion page and applicable agreement.
10. Security
CloseUp uses administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration and disclosure. Depending on the component, safeguards may include encrypted transport, protected credentials and secrets, access controls, role-based permissions, tenant separation, authentication controls, logging and monitoring, backups, vulnerability management, change controls and incident-response procedures.
No internet service can guarantee absolute security. Customers are responsible for protecting their credentials, configuring permissions appropriately, securing connected systems, and promptly notifying CloseUp of suspected unauthorized access.
11. Your privacy rights
Your rights depend on where you live, the nature of the information, and whether CloseUp is acting as controller or processor.
Common rights
Subject to applicable law, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, and information about how personal information is processed. You may also have rights concerning certain automated decisions and the right to complain to a competent privacy authority.
Israel
Where Israeli privacy law applies, individuals may have rights concerning review and correction of personal information held in databases and additional rights or remedies under the Protection of Privacy Law and related regulations, as amended from time to time.
European Economic Area, United Kingdom and similar jurisdictions
Where GDPR or similar law applies, rights can include access, rectification, erasure, restriction, portability, objection, withdrawal of consent and rights relating to certain automated decision-making. You may also lodge a complaint with your local supervisory authority.
California
If CloseUp is subject to California consumer privacy law for a particular processing activity, California residents may have rights to know/access, correct, delete, obtain information about categories and sources, opt out of certain sale/sharing, limit certain uses of sensitive personal information where applicable, and receive non-discriminatory treatment for exercising rights.
How to exercise rights
Email privacy@closeup.co.il or follow the instructions on our Data Deletion page. We may need to verify your identity and authority before fulfilling a request. If the request concerns Customer Data controlled by one of our customers, we may direct you to that customer or assist the customer in responding.
12. Customer responsibilities for CRM, recordings and communications
CloseUp customers control what Customer Data they place in the Service. Each customer is responsible for ensuring that its collection and use of leads, messages, call recordings, transcripts, marketing information and other Customer Data complies with applicable privacy, direct-marketing, recording, telecommunications, employment and consumer-protection laws.
This includes providing required notices, establishing a lawful basis, obtaining consent where required, respecting opt-outs and do-not-contact requests, configuring retention appropriately, limiting internal access, and ensuring that connected third-party accounts are authorized.
14. Children
CloseUp is a business-to-business service and is not directed to children. We do not knowingly offer accounts to children or intentionally collect personal information from children for our own purposes. Customers must not use CloseUp to process children’s data unless their use is lawful, appropriate for the Service, and covered by any required consent or authorization.
15. Security incidents and breach notification
CloseUp maintains procedures for investigating suspected security incidents. If we confirm a personal-data breach affecting Customer Data, we will notify affected customers as required by applicable law and contractual obligations and provide information reasonably necessary for the customer to meet its own notification duties.
16. Changes to this Privacy Policy
We may update this Policy to reflect changes in our product, technology, legal obligations or business practices. We will update the “Last updated” date and, when required, provide additional notice of material changes. Previous versions may be retained for reference.
17. Contact us
Privacy requests and questions
Email: privacy@closeup.co.il
Website: closeup-crm.com/en/contact
If your organization has a signed CloseUp order form or DPA, please use the legal entity and notice details stated in that agreement for formal notices.