Blob CRM

Privacy Policy

Last updated: 21 July 2026

1. Who we are

Blob Works Limited ("we", "us", "Blob CRM") operates the Blob CRM platform. For any privacy questions or to exercise your rights below, contact us at [email protected].

2. What we collect

When you sign up and use Blob CRM, we collect:

3. How we use it

To run the service: authentication, multi-tenant isolation, search, transactional email (verification, password reset, lifecycle notifications), backups, and abuse prevention. We do not sell your data. We do not use your workspace data to train AI models.

4. Legal basis for processing (GDPR Article 6)

Where the GDPR applies, we rely on the following legal bases:

For personal data inside your workspace, you (the customer) are the data controller and decide the lawful basis for contacting your own contacts; Blob acts as your processor. See our Data Processing Addendum.

5. Cookies & tracking

The Blob CRM application uses only strictly necessary storage — a login token and device identifier kept in your browser's localStorage to keep you signed in and to remember trusted devices. We do not use advertising or cross-site tracking cookies inside the app.

Our public marketing website (blobcrm.com) uses Google Analytics, Google Ads and the LinkedIn Insight Tag to measure traffic and advertising performance. These are optional and are controlled by consent:

Marketing emails contain an open-tracking pixel and click-tracking links so the sending workspace can measure engagement; every marketing email carries a one-click unsubscribe.

6. Sub-processors

We rely on a small set of vendors to run the service. The authoritative, always-current list (with purpose and location) is in DPA Schedule 1. In summary:

7. Your rights (GDPR / UK GDPR / Privacy Act 2020)

You have the right to:

8. Retention

We keep workspace data for the life of your account plus a 30-day cooling-off window after deletion (in case you change your mind). After that the tenant database is purged. Backups roll off on a 90-day cadence.

9. International data transfers

Blob hosts customer data on AWS in one or more of the United States, United Kingdom, European Union, and Australasia, depending on your workspace's region. Where personal data is transferred out of the EEA or UK to a country without an adequacy decision, we rely on the European Commission's / UK Standard Contractual Clauses, incorporated into our DPA, together with appropriate technical safeguards (encryption in transit and at rest).

10. Security

TLS in transit (via Cloudflare). Encryption at rest on AWS storage. Bcrypt password hashing. TOTP two-factor authentication required for all accounts. Per-tenant database isolation (your data physically can't be read by another tenant). Audit logging on every mutation. Full detail on our Security page.

11. Children

Blob CRM is a B2B product. We don't knowingly collect data from anyone under 16.

12. Changes

If we make material changes to this policy we'll notify the workspace admin by email at least 30 days before they take effect.

13. Contact

Privacy enquiries: [email protected]. Blob Works Limited is the data controller for account and website data and the data processor for workspace data.