•
Webinar on automating 0 to 100 sales in 30 days
Transparency · Security · Privacy
Everything you need to know about how we protect your data, the standards we comply with, and our privacy commitments.
Frequently asked questions
Everything you need to know about how Clientify protects the integrity, availability, and confidentiality of your information.
Your data is stored on our servers, which are secured and protected by firewalls, access control measures, and information segmentation.
Clientify has implemented and certified an Information Security Management System (ISMS) based on ISO/IEC 27001:2022, applying all 93 controls of Annex A.
Yes, we use encryption protocols to protect your data both when it is in transit over the network and when it is stored on our servers.
Access to your data is restricted exclusively to authorized personnel. Access rights are based on the principle of least privilege, ensuring that only those who need access can obtain it.
We employ a multi-layered security approach that includes two-factor authentication (2FA), access controls, intrusion detection systems, and periodic security audits.
We conduct internal audits and ISMS certification audits at least once a year. We also perform technical audits and monthly vulnerability assessments.
Our platform is certified under ISO/IEC 27001:2022, the international standard for information security management.
We perform regular backups to ensure recovery in the event of data loss or security incidents. We also conduct periodic restoration tests to verify their effectiveness.
We have developed a security incident management procedure covering investigation, incident registration, digital evidence collection, containment, resolution, and communication to stakeholders.
Yes, we have established business continuity and disaster recovery procedures. We periodically test critical disaster scenarios to evaluate the effectiveness of our plans.
Yes, you can request the deletion of your data, and we have established procedures to securely remove it in accordance with the GDPR.
We have established a vendor security evaluation procedure to comply with the GDPR's accountability principles. We periodically review that our providers meet the security levels established by Clientify.
Our employees receive ongoing training on information security. We have awareness policies in place to ensure all staff maintain a continuous culture of security and data protection.
Yes, we support multi-factor authentication as an additional layer of security, helping to prevent unauthorized access even if login credentials are compromised.
Yes, the application allows users to view activity logs related to their data and which user has accessed it.
We have a proactive policy to implement security fixes and address known vulnerabilities. We also have a continuous improvement plan for the application.
We use an agile development methodology that incorporates Security & Privacy by Design. We systematically perform security tests on our application code.
Yes, we have an automated system to analyze resource capacity levels and act proactively on any anomaly.
Frequently asked questions
How we manage your personal data, our GDPR commitments, and your rights as a user.
Yes, Clientify fully complies with the General Data Protection Regulation (GDPR), applying appropriate technical and organizational measures, internal privacy policies, data processing agreements, and transparency and accountability mechanisms.
Clientify has appointed a Data Protection Officer with the AEPD (www.aepd.es): [email protected].
Clientify's customers act as data controllers with respect to the personal data they manage through the platform (contacts, leads…), while Clientify acts as the data processor (Art. 28 GDPR). The obligations of both parties are governed by the DPA available on the platform.
Clientify acts as data controller for its own users' data (registration, billing, support) as set out in its Privacy Policy.
Available at: clientify.com/politicas-de-privacidad.
Clientify has appointed a DPO with the AEPD. Contact: [email protected].
Clientify's servers are located in Europe. Data is hosted within the European continent to comply with GDPR requirements. Clientify's registered office is in Almería, Spain.
While Clientify maintains data centers in Europe, we cannot guarantee that data will remain exclusively within the EU. Clientify uses subprocessors based in the US (with SCCs in place) and has employees in various countries who may access your data to provide support. Data is not stored outside the EU.
Clientify has a comprehensive governance structure certified under ISO 27001. Detailed technical and organizational measures are described in the Annex of our DPA.
Yes. The DPA, pre-signed on behalf of the relevant Clientify entity, is available in the privacy section of our website.
We are unable to sign individual DPAs given our global customer base. Instead, we invite you to review and sign our standard DPA, which complies with GDPR best practices, including specific requirements for the UK and Switzerland. Available here.
Yes. Clientify engages subprocessors for certain functionalities. The full list, including their identity, location, and transfer mechanisms, is available in our Privacy Policy.
Since the European Commission's adequacy decision (July 2023), data flows securely from the EU to US companies certified under the EU-U.S. Data Privacy Framework. For other transfers, Clientify applies Standard Contractual Clauses (SCCs) and conducts the relevant Transfer Impact Assessments (TIA).
Clientify works with subprocessors certified under the EU-U.S. Data Privacy Framework where applicable, ensuring a level of data protection equivalent to that of the EU.
Full details are available in our Cookie Notice.
When using features such as Chatbot, Web Forms, or the Web Visitors add-on, certain cookies are used. More information is available in our Cookie Policy.
Go to Company Settings → My Account → Notifications. For help, contact our support team.
Clientify is not designed to process special categories of personal data (Art. 9 GDPR: health data, ideology, religion, sexual orientation, biometrics…). It is suitable for general or professional personal data.
A) Direct request: email [email protected] or [email protected] requesting erasure (Art. 17 GDPR).
B) From the platform: the account administrator can request cancellation from the settings panel.
Go to Settings → Users and teams. Deleting a user immediately revokes their access. To erase their personal data, write to [email protected].
Data is retained for a maximum of 90 days after closure for technical and security reasons. After that period, it is permanently and securely deleted in accordance with Art. 5.1(e) GDPR. Certain billing data may be retained in a blocked state for the applicable legal periods (5–6 years) solely for legal compliance.
Documentation & certifications
Access our legal documents, policies, and security certifications.
How we collect, use, and protect your personal data in accordance with the GDPR.
View document →Information about the cookies we use on our platform and websites.
View document →Data Processing Agreement pursuant to Article 28 of the GDPR.
View document →Certificate of conformity with the international standard for information security management.
Coming soonAI Transparency
Our commitment to the responsible and transparent use of artificial intelligence on our platform.
Clientify incorporates artificial intelligence features
Clientify integrates AI capabilities in some of its features to improve the productivity of sales and marketing teams. Our commitment is to be transparent about which technologies we use, how they affect your data, and what guarantees we offer.
Assistance for drafting emails, notes, and messages within the platform, with AI-generated suggestions.
Automated prospect scoring based on behavior and interactions to prioritize sales work.
We are documenting in detail the AI models and providers we use. This information will be available soon.
•
Webinar on automating 0 to 100 sales in 30 days