01
Who we are
AGA CRM ("we", "us") provides a customer-support CRM for businesses. This policy explains what data we process when you visit this website or use the AGA CRM application, and the choices you have. You can reach us at info@agadigitaltech.com.
02
Data we collect
Account data: name, work email address, role, and login credentials (passwords are stored only as salted bcrypt hashes) for staff accounts created by your workspace administrator.
Support data: emails, tickets, internal notes, customer profiles, call logs, and attachments that your team processes through the CRM. This data belongs to your company; we process it on your behalf.
Usage data: sign-in times, staff presence (online/idle/break), and an audit trail of actions taken in the application, kept for accountability within your workspace.
Website data: if you submit our contact form we receive the name, email, company, and message you provide, used solely to respond to your enquiry.
03
Google Workspace data
When your administrator connects a Gmail or Google Workspace mailbox, AGA CRM accesses that mailbox through the official Gmail API using OAuth. We read incoming support messages to create tickets, and send replies your agents write. OAuth tokens are stored encrypted (AES-256-GCM) and can be revoked at any time from the CRM or your Google account settings.
AGA CRM’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your permission, for security purposes, or to comply with law.
04
AI features
The optional AI reply assistant sends the content of a ticket conversation to Anthropic’s Claude API to generate summaries and suggested replies. Suggestions are always reviewed by a human agent before anything is sent. Your workspace administrator can disable AI features entirely in workspace settings.
05
How we protect data
Data is encrypted in transit (TLS) and sensitive secrets are encrypted at rest. Access inside the application is governed by role-based permissions, two-factor authentication is available for every account, sessions expire on inactivity, and every action is recorded in an audit log your managers can review.
07
Retention & deletion
Support data is retained for as long as your company uses AGA CRM. When a trial ends without a subscription, or on written request from your administrator, workspace data is deleted. You may request access to or deletion of your personal data by contacting info@agadigitaltech.com.
08
Changes
We will post any changes to this policy on this page and, for material changes, notify workspace administrators by email.
