Skip to content

Legal

Privacy policy

Last updated: October 2, 2026

We take the privacy of the people we work with, and the applicants our customers serve, seriously. This policy explains what we collect, why, and the choices you have, in language we have tried to keep plain.

1. Who we are and what this policy covers

higheredcrm.ai ("we", "us" or "our"). This policy explains how we handle personal data when you visit higheredcrm.ai (the "website"), contact us, request a demo, request a free pilot, or use our CRM software and related services (the "service").

This policy is effective from October 2, 2026. If you have any questions about it, contact us at privacy@higheredcrm.ai.

2. Our two roles: controller and processor

Data protection laws distinguish between organizations that decide why and how personal data is used and organizations that process it on their behalf. We act in both roles, depending on the data.

When we are a controller

We are the controller of personal data we collect for our own purposes: information about visitors to our website, people who contact us, request a demo or sign up, the staff contacts at our customers and prospective customers, and people who apply to work with us. This policy mainly describes that processing.

When we are a processor

Colleges, universities and other higher education institutions ("customers") use the service to manage inquiries, applicants, applications and related communications. For that data, including information about prospective and current students, their families and other contacts, the customer is the controller and we are its processor. We process that data only on the customer's documented instructions, under a data processing agreement, and for no other purpose.

If you are a prospective student or applicant and have questions about how an institution uses your information, please contact that institution directly. If you contact us, we will pass your request to the relevant institution and help it respond.

3. Information we collect

Information you give us

  • Demo requests and inquiries: your name, work email address and institution, anything you choose to tell us in your message, and whether you opted in to product updates.
  • Pilot requests: when you request a pilot under our free launch offer, your name, work email address, institution, role if you give it, country, approximate annual inquiry volume, the channels you plan to use (such as WhatsApp, email, SMS, calling or Messenger), how you plan to connect them (your own provider accounts, built-in credits or not sure yet), your agreement to our terms and whether you opted in to product updates.
  • Campaign and source information: when you submit a demo request or sign up, the form also sends the campaign details of your visit so we can tell which of our marketing brought you to us. This can include UTM parameters (such as source, medium and campaign), advertising click identifiers, the page you first landed on, the website that referred you and the page you submitted the form from.
  • Customer account information: names, work contact details and roles of customer staff who use the service, and billing contact details.
  • Communications: emails, support requests, meeting notes and feedback you share with us.
  • Job applications: information you send us if you apply to work with us.

Information collected automatically

  • Website technical data: IP address, browser type, device information, pages requested and the date and time of your visit, as recorded in standard server and security logs.
  • Analytics and advertising data: only if you accept analytics or advertising cookies, information about how you use the website and whether you arrived from one of our ads. See the cookies section below.
  • Service usage data: when customer staff use the service, we record information such as sign-in events, feature usage and error reports so we can secure, support and improve the service.

Information from other sources

We may receive business contact information from people who refer you to us, from events we attend, or from publicly available professional sources, where the law allows.

4. How we use information, and our legal bases

Where data protection laws such as the GDPR apply, we rely on the following legal bases:

  • To respond to your request and arrange demos (our legitimate interest in responding to business inquiries, and steps you ask us to take before entering into a contract with us).
  • To review pilot requests, activate accounts and send login details (steps you ask us to take before entering into a contract with us, and our legitimate interest in running the free launch offer fairly, for example checking that each organization holds one account).
  • To provide, secure and support the service for customers (performance of our contract with the customer, and our legitimate interests in operating a secure service).
  • To send product updates and resources, only if you opt in on one of our forms (your consent, which you can withdraw at any time with the unsubscribe link in every email).
  • To understand which of our marketing works, using the campaign and source information sent with demo requests and sign-ups and, if you accept them, analytics and advertising cookies (our legitimate interests, or your consent where the law requires it).
  • To improve our website and service using aggregated or de-identified information where possible (our legitimate interests).
  • To meet legal obligations, such as tax, accounting and responding to lawful requests (legal obligation).
  • To protect our rights and prevent fraud, abuse and security incidents (our legitimate interests).

We do not sell personal data. We do not use personal data that customers entrust to us as processor for our own marketing, and we do not use it to train artificial intelligence models for other customers or for general use without the customer's explicit permission.

The AI Assistant

When a customer's user asks the AI Assistant a question, the question and the account records needed to answer it are sent to our AI provider, Anthropic, which processes them to generate the answer as our sub-processor. The assistant does not change data or send messages itself. We process this data as the customer's processor, under the same data processing agreement as the rest of the service.

5. Free launch offer

Our free launch offer makes the service available free of charge for the first 12 months to colleges, universities and other higher education institutions, with one account per institution (including all its campuses). When you request a pilot on our website, we use the information described in section 3 to check that your institution is eligible, activate your account, email your login details and help you get started. The full offer terms are in our terms of service.

Messages and calls sent through the service are handled in one of two ways, which you choose. If you connect your own provider accounts (for example for WhatsApp, Messenger, SMS, email or calling), those providers process the messages and calls under their own terms and privacy policies and bill you directly. If you use the built-in channels with credits, messages and calls are delivered through service providers we engage, as described in the section on how we share information.

6. Cookies and similar technologies

Cookies are small files stored on your device. This website currently uses no analytics or advertising cookies and loads no analytics or advertising scripts.

Categories you can choose

  • Analytics: cookies that help us understand how visitors use the website, such as which pages are viewed and how people move between them, so we can improve it.
  • Advertising: cookies that help us measure our advertising, for example whether a visit from an ad led to a demo request or sign-up, and show relevant ads on other websites.

Strictly necessary storage

The website keeps a few items in your browser that it needs to work: your cookie choice (local storage, so we don't ask again), whether you closed the announcement bar, and a marker that lets a confirmation page count a form submission once (session storage). None of them is sent to us.

Browser storage for attribution

To connect a demo request or sign-up with the campaign that brought you here, the website keeps the campaign details of your visit (described in section 3) in your browser's session storage, which is cleared when you close the tab. Only if you accept analytics or advertising, the details of your first visit are also kept in local storage so they can be matched to a later request. This information stays in your browser and is sent to us only if you submit a form.

The service

The CRM service itself uses cookies that are necessary for signing in, keeping sessions secure and remembering user settings.

7. How we share information

We share personal data only as described below:

  • Service providers and sub-processors who help us run our business and the service, such as cloud hosting, email and messaging delivery, customer support and billing. They may use personal data only to provide services to us, under written contracts with appropriate confidentiality and security obligations. Our current list, by category, is on our sub-processors page.
  • Analytics and advertising providers, only if you accept those cookies, as described in the cookies section above.
  • Professional advisers such as lawyers, accountants and auditors, under duties of confidentiality.
  • Authorities where we are required to by law, or where necessary to protect the rights, property or safety of our customers, users, us or others. Where permitted, we will tell the affected customer before disclosing data we hold as its processor.
  • Business transfers, if we are involved in a merger, acquisition or sale of assets, in which case personal data would remain subject to the protections in this policy.

8. International transfers

We serve institutions around the world, and our team and service providers may process personal data in countries other than the one in which it was collected. Those countries may have data protection laws that differ from yours.

Where we transfer personal data internationally, we put appropriate safeguards in place as required by applicable law. These may include standard contractual clauses approved by the relevant authorities, transfers to countries recognized as providing adequate protection, and additional technical and organizational measures. Customers can discuss hosting location options with us, and details of the safeguards we use are available on request.

9. How long we keep information

We keep personal data only for as long as we need it for the purposes described in this policy, including to meet legal, accounting and reporting requirements. In general:

  • Demo request and inquiry information is kept for as long as we are in active discussion, and then for a limited period in case you return to us, unless you ask us to delete it sooner.
  • Pilot request information is kept while we review and activate your account and then as part of your customer account information. If we don't activate an account, we keep it for a limited period and then delete it, unless you ask us to delete it sooner.
  • Customer account and billing information is kept for the length of the contract and afterwards for as long as required by law.
  • Website and security logs are kept for a limited period and then deleted or anonymized.
  • Data we process for customers is kept according to the customer's instructions. At the end of a contract, we return or delete it as set out in the agreement, after giving the customer the opportunity to export it.

10. How we protect information

We use technical and organizational measures designed to protect personal data against loss, misuse and unauthorized access. In the service, these include multi-factor authentication, single sign-on, role-based permissions, contact masking for chosen roles, audit logs, AES-256 encryption of stored credentials and of custom fields marked for encryption, rate limiting and IP allow-lists on API keys. We also limit our own staff's access to customer data to what is needed to support the service.

No system is completely secure. If we become aware of a personal data breach that affects you or data we process for a customer, we will notify those affected and the relevant authorities as required by law and by our agreements. You can read more in our trust center.

11. Your rights

Depending on where you live, you may have some or all of the following rights over your personal data:

  • to be informed about how your data is used, and to access a copy of it;
  • to have inaccurate data corrected or incomplete data completed;
  • to have your data deleted in certain circumstances;
  • to restrict or object to certain processing, including processing based on legitimate interests;
  • to object at any time to direct marketing;
  • to receive your data in a portable format and have it transmitted to another organization;
  • to withdraw consent at any time, where we rely on consent, without affecting processing that took place before; and
  • not to be subject to decisions based solely on automated processing that have legal or similarly significant effects.

To exercise any of these rights, contact us at privacy@higheredcrm.ai. We may need to verify your identity before responding. We will respond within the time required by applicable law and will not discriminate against you for exercising your rights.

If your request concerns data we process on behalf of an institution, we will refer it to that institution, which as controller is responsible for responding, and we will assist it.

You also have the right to complain to your local data protection supervisory authority. We would appreciate the chance to address your concerns first, so please consider contacting us before you do.

12. Children's and students' data

Our website and marketing are directed at professionals working in higher education, not at children. We do not knowingly collect personal data from children through the website. If you believe a child has provided us with personal data, please contact us and we will delete it.

Institutions may use the service to manage information about prospective students, some of whom may be under the age of majority in their country. We process that information solely as a processor on the institution's instructions. The institution is responsible for providing appropriate notices, obtaining any required consents (including from parents or guardians where applicable) and meeting its obligations under laws that apply to student and children's data. The service includes features that help institutions do so, such as do-not-contact and per-channel opt-outs, role-based permissions, contact masking, audit logs and data export.

13. Marketing communications

We send emails about our service, resources and events only to people who opt in, for example with the optional box on our demo and pilot forms. Every marketing email includes a way to unsubscribe, and you can also opt out by writing to privacy@higheredcrm.ai. Replies to your own request, and service messages if you are a customer user, are not marketing and don't need an opt-in.

Our website may link to other websites. We are not responsible for the privacy practices of websites we do not operate, and we encourage you to read their privacy policies.

15. Changes to this policy

We may update this policy from time to time. When we do, we will change the "Last updated" date at the top of this page and, if the changes are significant, we will take reasonable steps to let you know, for example by notice on the website or by email to customers.

16. Contact us

If you have questions about this policy or how we handle personal data, please contact us:

Where required by law, details of our data protection representative or officer will be provided on request.

Questions about data protection?

Our team is happy to walk your data protection officer or IT colleagues through how higheredcrm.ai handles applicant data.