Legal

Privacy Policy

Last updated: 9 August 2026

BM CRM (“BM CRM”, “we”, “us”) is a customer relationship management platform operated by BM DIGITAL MARKETING SERVICES VIA SOCIAL MEDIA CO. L.L.C (“BM Digital Marketing”), Concord Tower, Office 44, 9th Floor, Al Sufouh — Dubai Media City, Dubai, United Arab Emirates. This policy explains what personal data we process, why we process it, who we share it with, and the choices you have. It covers the BM CRM application, our mobile apps, and this website.

1. Who is responsible for your data

BM CRM is a multi-tenant service used by businesses (“Customers”) to manage their own leads and customers. Responsibility depends on whose data it is:

  • Data a Customer collects through the platform — their leads, contacts, and conversations — belongs to that Customer. The Customer is the data controller; BM CRM acts as their data processor and follows their instructions.
  • Customer account data and website data — your BM CRM account, billing details, and your visits to this website — are controlled by BM CRM.

2. Data we collect

  • Account data: name, email, phone number, password (stored only as a secure hash), workspace and team details, and billing records.
  • Lead & contact data: names, phone numbers, email addresses, and other details Customers collect from Meta Lead Ads, click-to-WhatsApp ads, website forms, imports, or manual entry.
  • Messaging data: the content and metadata of conversations exchanged through WhatsApp, Messenger, and Instagram via the platforms’ official APIs.
  • Advertising metadata: ad, campaign, and click identifiers used to attribute leads and — where a Customer enables it — to send conversion signals back to the advertising platform.
  • Website & enquiry data: if you send our contact form, the details you enter (name, email or WhatsApp number, and your message) are stored in our own BM CRM workspace so a person can reply to you.
  • Usage & device data: log data, IP address, browser/device type, and product usage needed to operate and secure the service.

3. How we use data

  • To provide the CRM: capture leads, route them, send and receive messages, qualify leads with AI, schedule meetings, and run campaigns — always within the messaging platforms’ consent and messaging-window rules.
  • To operate AI features that draft replies, assess intent, and book meetings — under the Customer’s configured controls, and a human can take over at any time.
  • To respond to enquiries you send us, and to operate, secure, and improve this website.
  • To secure the service, prevent abuse, provide support, bill for the service, and comply with law.

Two things we never do: we never sell personal data, and customer conversations, contacts, and knowledge bases are never used to train AI models — ours or anyone else’s.

4. Cookies, analytics, and advertising technology on this website

This website uses cookies and similar technologies. Essential cookies keep the site working and remember your consent choice. With your permission — asked for in our cookie banner before anything non-essential is set — we also use analytics (Google Analytics 4) to understand how the site is used, and advertising tools from the platforms we advertise on (Google Ads, Meta, Snapchat, LinkedIn, TikTok, X, and Microsoft Advertising) to measure and improve our campaigns. These providers may set their own cookies and receive data about your visit under their own privacy policies. You can accept, refuse, or change your choice at any time — see our Cookie Notice for the full list and controls. Refusing non-essential cookies does not limit your use of the site or the product.

When you enquire, create an account, or subscribe, we may also report that conversion directly from our servers to the advertising platforms we advertise on, with identifiers hashed before they leave our systems. This happens only if you accepted advertising cookies. If you chose “Essential only”, nothing about you is reported to any advertising platform — not from your browser, and not from our servers. Server-side reporting is a reliability measure for people who already said yes, never a way around someone who said no.

5. Messaging and advertising platform data

When a Customer connects WhatsApp Business, Facebook, or Instagram, we process messages and lead data through Meta’s official APIs solely to deliver the features that Customer enables, in accordance with the WhatsApp Business Terms and the Meta Platform Terms (including their rules on Platform Data). We request only the permissions the product actually uses, and we stop processing new data from a source the moment its connection is removed.

The same applies to the other advertising platforms a Customer can connect. Where a Customer connects a TikTok ad account or TikTok account, we process their lead, conversion, and — where they enable those features — post and comment data (including the identities of people who comment on their content) through TikTok’s official Business APIs, in accordance with TikTok’s Business Products (Data) Terms — only to deliver the features that Customer switches on, and only for as long as the connection is authorised. The Customer or the account holder can withdraw that authorisation at any time from within TikTok, after which we stop processing new data from that source. Snapchat and LinkedIn connections work the same way.

6. Who we share data with

We share personal data only in these situations:

  • Service providers (sub-processors) who help us run the service, listed in section 7 — each bound to use the data only to provide its function to us.
  • Advertising platforms a Customer connects — for example when a Customer sends a conversion signal to Meta, Snapchat, LinkedIn, or TikTok. The platform receives that data as an independent controller under its own business terms, not as a vendor acting on our instructions.
  • Advertising and analytics partners for this website — only with your cookie consent, as described in section 4.
  • Legal reasons — where required by law, to protect our rights, or to prevent abuse of the service.

7. Sub-processors

We rely on vetted providers to run the service: Meta (WhatsApp, Facebook and Instagram messaging APIs), Google (the Gemini API that powers AI features, Firebase Cloud Messaging for app notifications, and Google Calendar where a user connects one), Cartesia and Inworld (AI voice generation), OpenAI (specific AI features), Stripe (payment processing), Resend (email delivery), Expo (mobile app updates and notifications), Cloudflare (media file storage), and Amazon Web Services (application hosting and database, EU — London region). Each receives only the minimum data needed to provide its function, and none may use it for anything else.

Google Calendar data. When a user chooses to connect a Google Calendar, BM CRM reads the calendar’s busy times — so it can show real availability and avoid double-booking — and writes, updates, or removes only the meetings the user books, reschedules, or cancels through the CRM. It does not read the contents of the user’s other events. BM CRM’s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is never sold and never used to train AI models. A user can disconnect their calendar at any time in Calendar settings, after which we stop accessing it.

8. Data retention

We retain personal data for as long as a Customer’s account is active or as needed to provide the service. Customers can delete records from within the app; deleted records go to a recycle bin for 7 days (so a mistake can be undone) and are then permanently removed from active systems. Website enquiry payloads are retained for up to 90 days in their raw form. We may retain limited data where required for legal, security, or accounting purposes. See our Data Deletion page for how deletion works and how to request it.

9. How we protect data

  • Every workspace’s data is isolated from every other workspace.
  • Access tokens and secrets are encrypted at rest and never displayed in plain text.
  • Raw message contents and tokens are never exposed in diagnostics or logs.
  • Media files are private and served only through signed, expiring links.
  • Sensitive actions are recorded in an audit trail, and every automated action is attributable to the AI, a person, or the system.
  • Nightly encrypted backups with tested restores protect against data loss.

10. Your rights

Depending on your jurisdiction (including under the GDPR), you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with your local data-protection authority. If your data was collected by a business that uses BM CRM, that business is the controller — contact them first, and we will support them in fulfilling your request. You can also reach us directly using the details below, or through our contact page.

11. International transfers

We are based in the UAE and host the service in the EU (London region). Our sub-processors may process data in other countries; where required, we use appropriate safeguards for international transfers.

12. Children

BM CRM is for businesses and is not directed to children under 16. We do not knowingly collect data from children.

13. Changes to this policy

We may update this policy as the product and law evolve. Material changes will be reflected by updating the “Last updated” date above, and significant changes will be highlighted to Customers in the product.

14. Contact

BM DIGITAL MARKETING SERVICES VIA SOCIAL MEDIA CO. L.L.C — Concord Tower, Office 44, 9th Floor, Al Sufouh, Dubai Media City, Dubai, UAE. WhatsApp: +971 55 488 7801, or use our contact page.