Blob CRM
One Blob. Total Clarity.
Privacy Policy
Last updated: 21 July 2026
1. Who we are
Blob Works Limited ("we", "us", "Blob CRM") operates the Blob CRM platform.
For any privacy questions or to exercise your rights below,
contact us at [email protected].
2. What we collect
When you sign up and use Blob CRM, we collect:
- Account info — your name, work email, company,
IP address at signup, and a hashed password (we never see the
plaintext).
- Workspace data — the contacts, organisations,
deals, activities, notes, emails, and other CRM records you
choose to put into your workspace. This is your data; we
process it on your behalf.
- Usage logs — login timestamps, IP, browser
user-agent, and audit-trail entries for security and
compliance.
- Email content — when you connect a mailbox,
we store inbound and outbound emails linked to your contacts
so you can search them.
3. How we use it
To run the service: authentication, multi-tenant isolation, search,
transactional email (verification, password reset, lifecycle
notifications), backups, and abuse prevention. We do not sell
your data. We do not use your workspace data to train AI models.
4. Legal basis for processing (GDPR Article 6)
Where the GDPR applies, we rely on the following legal bases:
- Contract — to provide the service to the
workspace that signed up (account data, workspace data, billing).
- Legitimate interests — security, fraud and abuse
prevention, audit logging, and product reliability, balanced
against your rights.
- Legal obligation — tax, accounting, and responding
to lawful requests.
- Consent — for non-essential cookies on our
marketing website and for any optional feature you switch on
(e.g. the AI Assistant). You can withdraw consent at any time.
For personal data inside your workspace, you (the customer)
are the data controller and decide the lawful basis for
contacting your own contacts; Blob acts as your processor.
See our Data Processing Addendum.
5. Cookies & tracking
The Blob CRM application uses only strictly necessary
storage — a login token and device identifier kept in your browser's
localStorage to keep you signed in and to remember trusted devices.
We do not use advertising or cross-site tracking cookies inside the
app.
Our public marketing website (blobcrm.com) uses Google Analytics,
Google Ads and the LinkedIn Insight Tag to measure traffic and
advertising performance. These are optional and are
controlled by consent:
- If you are in the EEA, the United Kingdom or Switzerland, we ask
before setting any non-essential cookie. Declining is a single
click, is remembered, and means no advertising or analytics
cookies are set. Google's tags remain in a cookieless mode.
- Elsewhere, these cookies are set without a prompt. You can
prevent them with your browser's cookie controls.
Marketing emails
contain an open-tracking pixel and click-tracking links so the
sending workspace can measure engagement; every marketing email
carries a one-click unsubscribe.
6. Sub-processors
We rely on a small set of vendors to run the service. The
authoritative, always-current list (with purpose and location) is in
DPA Schedule 1. In summary:
- Amazon Web Services (AWS) — server hosting,
compute, encrypted storage and backups. Hosted in one or more of
the United States, United Kingdom, European Union, and Australasia,
depending on your workspace's region.
- Cloudflare — DNS, edge TLS, WAF, DDoS protection.
- MXroute / your chosen SMTP provider —
transactional email delivery.
- Your chosen bulk-email provider (e.g. Brevo,
Elastic Email, SendGrid, Amazon SES) — marketing campaign delivery,
if you use Campaigns.
- Stripe — subscription billing and payments. We
never store full card numbers; Stripe holds card data under
PCI-DSS.
- ntfy.sh — operational push notifications to the
platform operator (no customer personal data in the payload).
- Anthropic / OpenAI / xAI — only when you enable
the optional AI Assistant. Workspace data sent for inference is
governed by the chosen provider's policies.
- Google / Microsoft — only if you connect calendar
sync, mailbox OAuth, or SSO for your workspace.
7. Your rights (GDPR / UK GDPR / Privacy Act 2020)
You have the right to:
- Access — download a copy of your data from
Settings → Account → Export.
- Rectification — edit or correct your records
directly in the workspace.
- Erasure — delete your account from Settings →
Account → Delete workspace.
- Portability — data exports include CSVs of
every entity for use in another system.
- Restrict or object to processing,
and complain to your supervisory authority. In the
EU that's your local data-protection authority; in the UK the
Information Commissioner's Office (ICO); in New Zealand the Office
of the Privacy Commissioner.
8. Retention
We keep workspace data for the life of your account plus a 30-day
cooling-off window after deletion (in case you change your mind).
After that the tenant database is purged. Backups roll off on a
90-day cadence.
9. International data transfers
Blob hosts customer data on AWS in one or more of the United States,
United Kingdom, European Union, and Australasia, depending on your
workspace's region. Where personal data is transferred out of the
EEA or UK to a country without an adequacy decision, we rely on the
European Commission's / UK Standard Contractual Clauses, incorporated
into our DPA, together with appropriate
technical safeguards (encryption in transit and at rest).
10. Security
TLS in transit (via Cloudflare). Encryption at rest on AWS storage.
Bcrypt password hashing. TOTP two-factor authentication required for
all accounts. Per-tenant database isolation (your data physically
can't be read by another tenant). Audit logging on every mutation.
Full detail on our Security page.
11. Children
Blob CRM is a B2B product. We don't knowingly collect data from
anyone under 16.
12. Changes
If we make material changes to this policy we'll notify the
workspace admin by email at least 30 days before they take
effect.
13. Contact
Privacy enquiries: [email protected].
Blob Works Limited is the data controller for account and website data and the
data processor for workspace data.