Privacy Policy
Effective date: October 13, 2025
1. Introduction
Welcome to ConFYI CRM. The Service at crm.con.fyi and its related applications, APIs, integrations, and support channels is operated by Open Growth Group INC, a Delaware corporation (“Open Growth Group”, “Company”, “we”, “us”, or “our”). The deployment uses Twenty software, but Open Growth Group INC operates this Service.
This Privacy Policy explains how we collect, use, safeguard, and disclose information resulting from use of the Service. We aim to comply with applicable data-protection laws, including the General Data Protection Regulation (“GDPR”) and California privacy laws. By using the Service, you acknowledge this Policy and our Terms of Service.
2. Definitions
Service means the hosted ConFYI CRM service and related pages or applications operated by Open Growth Group. Personal Data means information relating to an identified or identifiable living person. Usage Data means information collected automatically from use of the Service or its infrastructure. Cookies are small files stored on a device.
Data Controller means the person or organisation that determines why and how Personal Data is processed. We are controller for account, billing, security, support, public-site, and direct communications data. Data Processor means a person or organisation processing Personal Data for a controller. When a Customer places CRM records and other Customer Data in a workspace, Open Growth Group processes that data on Customer’s behalf, and Customer is the controller.
Data Subject means the individual to whom Personal Data relates. User means an individual using the Service, whether for themselves or as an authorised user of an organisation.
3. Information we collect
3.1 Personal Data you provide
When you create an account, purchase access, subscribe to communications, or contact support, we may collect your name, email address, phone number, organisation, job title, profile information, workspace role, billing address, tax information, preferences, and any other details you choose to provide. Full payment-card data is handled by a payment processor rather than stored by us.
3.2 Customer Data and CRM records
You or your organisation may input or upload information about customers, leads, contacts, companies, opportunities, activities, communications, tasks, files, and related business records (“Customer Data”). Customer determines the purpose and lawful basis for this processing and is responsible for notices, consents, access permissions, accuracy, and rights requests involving those records. We process Customer Data only to provide, secure, support, and maintain the Service and follow Customer’s instructions.
3.3 Usage and device data
When you use the public pages or Service, we may automatically collect IP address, browser type and version, operating system, device identifiers, language, pages and features used, referring and exit URLs, timestamps, session duration, error and diagnostic reports, performance metrics, authentication activity, and security events. Approximate location may be derived from IP address.
3.4 Cookies and similar technologies
We use cookies, local storage, and similar technologies for authentication, security, session continuity, preferences, and limited analytics. We do not use this data to sell personal information or for cross-context behavioural advertising. Disabling essential cookies may prevent login and other Service functions.
3.5 Information from third parties
We may receive information from identity providers and integrations you choose to connect, including name, email, identifiers, access tokens, synchronisation metadata, and data you authorise the provider to share. Third-party-sourced information is handled under this Policy.
We do not knowingly collect sensitive personal data unless you or your organisation intentionally provides it and has authority to do so. We do not sell Personal Data.
4. How we use information
We use information to:
- provide and maintain accounts, workspaces, CRM records, workflows, APIs, and integrations;
- authenticate users, manage permissions, process transactions, subscriptions, and billing;
- send account, security, support, billing, product, and policy communications;
- respond to requests, troubleshoot problems, and provide customer support;
- analyse usage, monitor performance, test and improve features, and create aggregated reporting;
- detect, prevent, and investigate abuse, fraud, unauthorised access, security incidents, and technical failures;
- send marketing where permitted, with an opt-out available at any time;
- fulfil a purpose you request or another purpose disclosed with your consent; and
- comply with law, enforce agreements, and protect the rights and safety of the Company, users, and others.
Where GDPR or similar law applies, our legal bases include performance of a contract, legitimate interests in operating and securing a reliable Service, consent for optional processing, and compliance with legal obligations. We will not use Personal Data incompatibly with the purposes described above without an appropriate lawful basis.
5. How we share information
We do not sell or rent Personal Data and do not disclose it to third parties for their independent direct marketing. We may share information with:
- hosting, infrastructure, network, security, database, payment, monitoring, analytics, support, authentication, and email providers under contractual restrictions;
- integrations and services you instruct us to connect;
- other members of your workspace according to roles and permissions;
- affiliates and professional advisers where needed for operations and subject to confidentiality;
- authorities when required by law or necessary to prevent fraud, abuse, security threats, or harm; and
- a successor in a merger, acquisition, financing, reorganisation, bankruptcy, or asset sale, with appropriate notice and continued protection.
We may disclose aggregated or de-identified information that cannot reasonably identify a person. We will not attempt to re-identify it. If our sharing practices materially change, we will update this Policy and provide notice where required.
6. Cookies and tracking technologies
Cookies are small text files used to make websites function and remember state. We may use session cookies that expire when a browser closes, preference cookies that remember settings, and security cookies that support authentication and fraud prevention. Local storage, pixels, or scripts may perform similar strictly functional or limited analytic tasks.
We do not use third-party advertising or social-media cookies to profile you across unrelated websites. Your browser can refuse, alert on, or clear cookies, but some features may stop working. Infrastructure and security providers may set cookies needed to deliver or protect the Service under their own privacy notices.
7. Data security
We use technical and organisational safeguards designed to protect Personal Data from unauthorised access, alteration, disclosure, or destruction. Measures may include encryption in transit and appropriate encryption at rest, password hashing, access controls, role-based permissions, authentication safeguards, logging, monitoring, backups, vulnerability management, and staff confidentiality practices.
No internet transmission or storage method is completely secure. You should protect your credentials, use appropriate workspace permissions, secure your devices, and report suspected compromise. If a breach affects Personal Data, we will notify affected parties and authorities as required by law.
8. Data retention
We retain Personal Data only as long as needed for the purposes described here, including while an account or workspace remains active. Account and Customer Data may remain available during the customer relationship and for a reasonable export period after termination, then be deleted or anonymised subject to backups and legal requirements.
Billing and tax records may be retained for approximately seven years. Raw Usage Data and security logs are generally retained for up to twelve months. Support data is retained while needed to resolve a matter and meet legal obligations. Backups expire on their normal rotation.
We may retain information longer to comply with law, resolve disputes, prevent fraud, enforce agreements, or preserve evidence. When identifiable data is no longer required, we delete, aggregate, or anonymise it.
9. Your rights and choices
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, opt out of marketing, and complain to a regulator. Some account information can be managed in the Service. Other requests may be sent to hello@opengrowthgroup.co.
We may verify your identity or an authorised agent’s authority before responding. Rights are subject to legal exceptions; for example, we may retain data required by law or decline a request that would adversely affect another person’s rights. If your request concerns CRM records controlled by a Customer, contact that Customer; we will assist it as required.
10. GDPR rights
People in the European Economic Area, United Kingdom, or Switzerland may request access and rectification; erasure in applicable circumstances; restriction; portability for certain automated processing; objection to legitimate-interest or direct-marketing processing; and withdrawal of consent without affecting earlier lawful processing.
You may also lodge a complaint with your local supervisory authority. We generally respond within the legally required period and may request identity verification.
11. California and other U.S. state rights
California residents may request the categories and specific pieces of personal information collected, sources, purposes, disclosure categories, correction, and deletion, subject to exceptions. Residents of other states with comprehensive privacy laws may have similar access, correction, deletion, portability, and opt-out rights.
We do not sell Personal Data or share it for cross-context behavioural advertising, and we do not discriminate against people for exercising privacy rights. Categories collected may include identifiers, commercial information, internet or network activity, professional information, Customer Data, and security or usage inferences.
12. International data transfers
Open Growth Group is based in the United States and uses service providers that may operate in the United States, European Economic Area, United Kingdom, and other jurisdictions. Personal information may therefore be transferred outside your country.
Where required, we use appropriate safeguards, including adequacy decisions, European Commission Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, and supplementary technical, organisational, and contractual controls.
13. Links to other sites
The Service may link to or integrate with sites and services we do not operate. Their privacy practices may differ. We do not control and are not responsible for their content or data handling. Review their privacy notices before providing information or enabling an integration.
14. Children’s privacy
The Service is business-oriented and not intended for people under 18. We do not knowingly collect Personal Data from children. If we learn that a child supplied Personal Data without appropriate authorisation, we will take steps to delete it. Parents or guardians may contact us about a concern.
15. Changes to this Privacy Policy
We may update this Policy to reflect changes in our practices, technologies, Service, or legal requirements. We will publish the revised Policy and update its effective date. Material changes will receive reasonable notice by email, in-product message, or prominent notice before taking effect where required.
16. Contact us
For privacy questions or to exercise your rights, contact:
Open Growth Group INC
Delaware, USA
hello@opengrowthgroup.co

