Privacy Policy
Last updated: 28 June 2026
This Privacy Policy explains how MAP Platform FZE ("MAP Platform", "we", "us") collects, uses, stores, and discloses information when you use AgentiCRM (the "Service"). By using the Service you agree to this policy.
1. Who we are
MAP Platform FZE is the data controller for personal data we collect about account holders and visitors. For data that our customers upload or sync into the Service about their own contacts, our customers are the controller and we act as a processor on their behalf.
Contact: gary@map-platform.com
2. Information we collect
- Account data: name, email, password hash, company, role.
- Customer CRM data: contacts, conversations, notes, tasks, appointments, deals, and files that you create or import.
- Usage data: log records of feature use, IP address, browser type, and timestamps used to operate and secure the Service.
- Billing data: handled by our payment processor; we store only the minimum needed for invoicing.
- Google user data: when you connect a Google account, we access Gmail and Google Calendar with your permission (see section 4).
- Microsoft user data: when you connect a Microsoft account, we access Outlook Mail and Calendar with your permission.
3. How we use information
- To provide, maintain, and improve the Service.
- To authenticate users and prevent fraud or abuse.
- To send service notifications and respond to support requests.
- To meet legal, accounting, and regulatory obligations.
We do not sell personal data. We do not use Google user data, Microsoft user data, or customer CRM content to train generalised AI/ML models.
4. Google user data — Limited Use disclosure
AgentiCRM's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We request the minimum Gmail and Google Calendar scopes needed for the features you enable (reading and sending mail, reading and writing calendar events).
- We use Google user data only to provide user-facing features inside AgentiCRM — syncing your inbox into Conversations, sending email from your address, and creating/reading calendar events and Google Meet links for appointments.
- We do not transfer Google user data to third parties except as needed to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data unless we have your explicit consent, it is needed for security purposes (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymised for internal operations.
- You can revoke our access at any time from your Google Account permissions page or by disconnecting the integration inside AgentiCRM.
5. Legal basis for processing (UK/EU users)
- Contract: to deliver the Service you subscribed to.
- Legitimate interests: to secure the Service, prevent abuse, and improve our product.
- Consent: for optional marketing communications and to access connected Google/Microsoft accounts.
- Legal obligation: to retain records required by law.
6. Data sharing and subprocessors
We share data only with vetted subprocessors who help us run the Service, including:
- Cloud hosting and database (Supabase, Cloudflare)
- Email delivery (Resend)
- SMS and voice (Twilio)
- Voice AI (ElevenLabs)
- AI model providers (used for AI agent responses)
- Payments (Stripe Payments Europe, Ltd.) — processes card payments, receipts, and refunds on our behalf
Each is bound by a data processing agreement and may only use data to perform services for us.
7. Data retention
We retain account and CRM data for as long as your account is active. When you cancel, we delete or anonymise personal data within 90 days, except where we are required to retain it for legal or accounting purposes. You can export your data at any time from Settings.
8. Your rights
Depending on your jurisdiction you may have the right to access, correct, export, restrict, or delete your personal data, and to lodge a complaint with a supervisory authority. Contact gary@map-platform.com to exercise these rights.
9. Security
We use encryption in transit (TLS) and at rest, role-based access controls, row-level security on the database, and audit logging. No system is perfectly secure; report security concerns to security@map-platform.com.
10. International transfers
Our infrastructure may process data in the UK, EU, and US. Where data leaves the UK/EEA, we rely on Standard Contractual Clauses or equivalent safeguards.
11. Children
The Service is not directed at children under 16 and we do not knowingly collect their data.
12. Changes to this policy
We will post material changes here and, where appropriate, notify you by email. Continued use of the Service after changes take effect constitutes acceptance.
13. Contact
MAP Platform FZE
38th Floor, Media One Hotel, Office Tower
PO Box 334069, Dubai Media City
Dubai, United Arab Emirates
Email: gary@map-platform.com