GatherCRM Security & Data Protection
Your data is at the heart of your business. We protect it with robust security, industry best practices and transparent policies designed to give you complete peace of mind.
Your data is safe with us
At GatherCRM, we understand that you’re trusting us with your business’s most important information; your clients, your projects and your finances. We take that responsibility seriously.
Where your data is stored
Your GatherCRM data is hosted in the United Kingdom on infrastructure provided by 20i Ltd, a UK-based hosting provider.
Some trusted services we use may process limited data outside the UK/EEA. Where this happens, appropriate safeguards are used as required under UK GDPR.
- 20i Ltd — hosting and backups (UK)
- Stripe — payment processing (South San Francisco, California and Dublin, Ireland)
- Postmark — transactional email, including login and notifications (USA & Amazon Web Servers)
Encryption
All data transmitted between you and GatherCRM is encrypted in transit using industry-standard TLS/HTTPS.
Twice-daily backups
Your data is automatically backed up twice daily and retained for 14 days.
Protected infrastructure
Backups are held within the same UK-based, access-controlled infrastructure as your live data.
Control who can access your data
GatherCRM combines flexible account permissions with strict internal controls around access to customer information.
Role-based permissions
You control who on your team can see and do what using configurable user roles and permissions.
Restricted staff access
Our team only accesses your account where necessary for support, maintenance or troubleshooting.
Confidentiality
All staff with access to customer data are bound by confidentiality obligations.
Security controls built into GatherCRM
Practical tools designed to protect sensitive information and give you greater visibility over account access.
PIN-protected sensitive data
GatherCRM includes an optional PIN-protected area for your most sensitive information. Data in this area is only accessible using the PIN you set; our team cannot view it.
Configurable auto-logout
Set your own inactivity timeout so users are automatically logged out after a period you define.
Passwordless login
Secure magic-link login means there are no passwords to be weak, reused or stolen. Access is tied to control of your registered email account.
Access logging
Export a log of who has logged in and accessed your CRM, including name, username, date, time, device and IP address.
GDPR compliance
GatherCRM is designed to help you meet your own obligations under UK GDPR.
- We, Giraffe LTD, act as your Data Processor. You remain the Data Controller. Our ICO registration number is ZA315935 .
- We provide a Data Processing Agreement as part of our terms, setting out how we handle personal data, our sub-processors, breach notification and data deletion.
- On termination, we delete your data within 30 days, except where retention is required by law.
- We will notify you without undue delay, and within 72 hours, of any personal data breach affecting your data.
Questions about security?
If you have specific security or data protection questions — particularly for procurement or due diligence — we’re happy to help and provide the information you need.