Privacy Policy
Last updated: 8 July 2026
This Privacy Policy explains how Eazi-Business Ltd ("Eazi-Business", "we", "our", or "us") collects, uses, shares, and protects personal information when you use the Eazi-Business Partner Platform available at partners.cmslogin.io (the "Platform"), together with any related websites, applications, and services that link to this policy.
We are committed to protecting your privacy and to handling your personal information in a lawful, fair, and transparent way. Although Eazi-Business is based in the United Kingdom, this policy is written to meet the requirements of the UK GDPR and the Data Protection Act 2018, the EU General Data Protection Regulation, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection laws worldwide.
1. Who we are and how to contact us
Eazi-Business Limited is a company registered in England and Wales (company number 08364226) with its registered office at The Old School House, 65a London Road, Oadby, Leicester, Leicestershire, LE2 5DN, United Kingdom. We act as the data controller for personal data described in this policy, except where we act as a processor on behalf of our Partners (see Section 3).
- Privacy and data protection contact: [email protected]
If you have any question about this policy or about how we handle your personal information, please contact us using the details above.
2. Summary
- We collect the information you give us and the information we need to operate the Platform securely.
- We use it to provide, secure, and improve the services you subscribe to.
- We do not sell your personal information.
- Where you connect a Google Calendar account, we use that access only to synchronise your mentoring sessions and to display your own calendar events back to you within the Platform, and our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements (see Section 6).
- You have rights over your personal information, including access, correction, and deletion.
3. Our roles: controller and processor
As a controller, we determine how and why personal data is processed for account management, security, billing, support, and improving the Platform. This includes data about Partners and the individual users who log in.
As a processor, we process personal data that a Partner uploads or generates about their own customers, leads, and contacts (for example CRM records and email engagement data). For that data, the Partner is the controller and we process it on the Partner's documented instructions under our Data Processing Agreement.
4. Personal data we collect
- Account data: name, email address, hashed password, role, and multi-factor authentication status.
- Partner profile: business name, contact details, address, currency and timezone settings, and branding assets such as logos.
- CRM data uploaded by Partners: organisations, people, notes, tasks, and opportunity records, which may include names, email addresses, telephone numbers, and company information about the Partner's contacts.
- Communications data: emails sent through the Platform, message open and click events, unsubscribe requests, and suppression lists.
- Connected account data: where you connect a third-party account such as Google Calendar, the tokens and calendar information described in Section 6.
- Authentication and security metadata: login timestamps, device and session information, trusted-device records, and audit log entries.
- Billing data: invoice and subscription records. Card payments are handled by our payment processor; we do not store full card numbers.
- Usage and technical data: IP address, browser type, pages viewed, and diagnostic information used to keep the Platform secure and reliable.
5. How we use personal data and our legal bases
Under the UK GDPR and EU GDPR we rely on the following legal bases:
- Performance of a contract: to create and manage accounts and to provide the services you subscribe to.
- Legitimate interests: to secure the Platform, prevent fraud and abuse, understand how the Platform is used, and improve our services, balanced against your rights.
- Consent: for optional features such as certain marketing communications, non-essential cookies, and connecting a third-party calendar account. You may withdraw consent at any time.
- Legal obligation: where we must retain records for tax, accounting, or other legal and regulatory compliance.
6. Google Calendar integration and connected accounts
The Platform offers an optional feature that lets you connect your Google Calendar so that mentoring sessions booked on the Platform stay in sync with your personal calendar. This feature is only enabled if you choose to connect your account, and you can disconnect it at any time.
What we access
When you connect Google Calendar, you are asked to grant the https://www.googleapis.com/auth/calendar.events scope. This allows the Platform to view and manage events on your calendar. We use this access only to:
- create and update calendar events that correspond to mentoring sessions you book, reschedule, or complete on the Platform;
- remove those events from your calendar when a session is cancelled; and
- display your own calendar events back to you, read-only, within the Platform (for example on the CRM calendar) so you can see them alongside your tasks and sessions.
Events we display are fetched on demand for the date range you are viewing and are shown only to you. We do not store the content of events we did not create, we do not use your calendar data for advertising, and we do not sell it or share it with third parties.
What we store
To keep the connection working we store the OAuth access and refresh tokens issued by Google, and the identifiers of the calendar events we create. Tokens are stored securely and are used only to perform the calendar sync described above.
How you can revoke access
You can disconnect Google Calendar at any time from your Platform settings, which deletes the stored tokens from our systems. You can also revoke access directly from your Google Account at myaccount.google.com/permissions.
Limited Use disclosure
Eazi-Business's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell Google user data, we do not transfer it except as necessary to provide or improve this feature, comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read this data unless we have your consent for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised.
7. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and to keep the Platform secure. Where required by law, we ask for your consent before setting non-essential cookies such as analytics cookies. You can control cookies through your browser settings.
8. How we share personal data
We share personal data only with:
- infrastructure and hosting providers that store and run the Platform on our behalf;
- email delivery providers used to send messages, including each Partner's configured email provider;
- a payment processor for billing;
- error monitoring and analytics providers, where enabled;
- professional advisers, and authorities where required by law; and
- a buyer or successor in the event of a merger, acquisition, or sale of assets.
All of our sub-processors are bound by contractual obligations that are consistent with this policy and with applicable data protection law. We do not sell personal information.
9. International data transfers
We are based in the United Kingdom and may process personal data in the UK, the European Economic Area, and other countries where our providers operate. Where we transfer personal data outside the UK or the EEA, we rely on an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, together with additional safeguards where appropriate.
10. Data retention
We keep personal data only for as long as necessary for the purposes set out in this policy. Account data is retained while the Partner remains active and for a limited period afterwards for audit and compliance purposes, unless a valid deletion request is received. Connected-account tokens are deleted when you disconnect the integration. When data is no longer needed we delete or anonymise it.
11. How we protect your data
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, tenant isolation, access controls, multi-factor authentication for administrative access, and audit logging. No system can be guaranteed to be completely secure, but we work to protect your information and to respond promptly to any incident.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to processing, to withdraw consent, and to lodge a complaint with a regulator. To exercise these rights, contact [email protected]. Partners can also export their own account data from within the Platform. We will respond within the timeframes required by applicable law and will not discriminate against you for exercising your rights.
13. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to request access to and deletion of your personal information, to correct inaccurate information, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. You may exercise these rights by contacting [email protected], and you will not be discriminated against for doing so.
14. Other jurisdictions
If you are located in another country, additional local rights may apply. We aim to honour recognised privacy rights globally. Please contact us if you would like to exercise a right available under your local law.
15. Children
The Platform is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
16. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the date at the top of this page and, where appropriate, notify you through the Platform. Please review this page periodically.
17. Complaints
If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to complain to a data protection authority. In the United Kingdom this is the Information Commissioner's Office at ico.org.uk. If you are in the EEA, you may contact your local supervisory authority.