Legal
Privacy Policy
How we collect, use and protect personal data — worldwide service
Effective 25 June 2026 · Version 1.1 · Governing law: England & Wales
1. Introduction
This Privacy Policy explains how McNif Global Limited ("McNif", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit our website at mcnifglobal.com, use the McNif CRM software-as-a-service platform at crm.mcnifglobal.com or any successor domain (the "Service"), or otherwise interact with us.
McNif Global Limited is a private company limited by shares registered in England and Wales under company number [to be confirmed], with registered office at [to be confirmed].
McNif CRM is provided worldwide. We are based in the United Kingdom, and our processing is primarily governed by the United Kingdom General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018. However, we acknowledge that you may reside in, or your personal data may originate from, a jurisdiction with its own privacy laws. Where so, we comply with the additional or alternative requirements of that jurisdiction's privacy laws to the extent they apply to you, as further described in Section 10 (Your Rights).
Privacy laws and regulations material to this Policy include, without limitation, the UK GDPR, the European Union General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively "CCPA/CPRA"), other United States state privacy laws (including in Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Montana, and Delaware), the Australian Privacy Act 1988 and the Australian Privacy Principles ("APPs"), the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA"), the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados) ("LGPD"), the Singapore Personal Data Protection Act ("PDPA"), the Japanese Act on the Protection of Personal Information ("APPI"), and any other privacy law applicable to the processing of your personal data.
Please read this Policy carefully. By using the Service, you confirm that you have read and understood this Policy. If you do not agree with this Policy, please do not use the Service.
2. Who We Are and Our Role
McNif Global Limited acts in two distinct capacities in relation to the personal data processed through the Service.
2.1 As a Data Controller
We are the data controller (or under United States laws, the equivalent "business") for personal data we collect about you when you (i) visit our website, (ii) create an account on the Service, (iii) communicate with us directly, or (iv) when we process your data for our own business purposes such as billing, support and service improvement. In this capacity we determine the purposes and means of processing your personal data.
2.2 As a Data Processor (or Service Provider)
When our Subscribers (defined below) upload, enter, or otherwise transmit personal data about their own end customers and contacts ("Customer Data") into the Service, we act as a data processor (or under United States laws, a "service provider" or "processor") on the Subscriber's behalf. In that capacity, the Subscriber is the controller (or business), and McNif processes the Customer Data only on the documented instructions of the Subscriber, in accordance with our Data Processing Agreement and applicable privacy law.
For the purposes of this Policy, "Subscriber" means any business, organisation, or individual that creates an account on the Service and, by doing so, becomes party to our Terms of Service.
If you are an end customer of a Subscriber and you have a question about how your data is being used in the Service, please contact that Subscriber directly. We will assist Subscribers in responding to your requests but, when acting as a processor or service provider, we cannot act on instructions other than those of the relevant Subscriber.
3. Definitions
In this Policy, the following terms have the meanings given below. Other capitalised terms used but not defined here have the meanings given in the UK GDPR or, where applicable, the equivalent term in the privacy law applicable to you.
- "Personal Data" means any information relating to an identified or identifiable natural person, and includes (where applicable) "personal information" under the CCPA/CPRA, "personal data" under the EU GDPR, and "personal information" under the APPs.
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transmission, and erasure.
- "Data Subject" means the individual to whom Personal Data relates, and includes (where applicable) the "consumer" under the CCPA/CPRA.
- "Service" means McNif CRM, including the software-as-a-service platform, the mobile applications (where available), the marketing website at mcnifglobal.com, and any related services we provide.
- "Subscriber" means a business, organisation, or individual that has created an account on the Service.
- "Subscriber Data" means Personal Data that we process as a controller in relation to Subscribers and the individuals authorised to use the Service on a Subscriber's behalf.
- "Customer Data" means Personal Data about end customers and contacts of Subscribers that is uploaded to, entered into, or transmitted through the Service by the Subscriber.
- "Sell" or "Sale" has the meaning given in the CCPA/CPRA and the laws of other United States states with equivalent provisions. We do NOT sell Personal Data.
- "Share" or "Sharing" has the meaning given in the CCPA/CPRA, including disclosure for cross-context behavioural advertising. We do NOT share Personal Data for cross-context behavioural advertising.
4. Personal Data We Collect
We collect Personal Data in the following ways and categories.
4.1 Subscriber Account Data
When a Subscriber creates an account or invites colleagues to use the Service, we collect: name, email address, telephone number (where provided), job title or role, company name and address, business registration number (where applicable), and password (stored as a hash).
4.2 Billing Data
When a Subscriber subscribes to a paid plan, we collect: billing name and address, VAT or other tax identification number (where applicable), payment method information, and transaction history. Payment card details are processed by our payment processor and are not stored on McNif's own infrastructure.
4.3 Usage Data
As you use the Service, we automatically collect: log data (IP address, browser type and version, operating system, referring URLs, pages visited, timestamps), device identifiers, session identifiers, error and crash reports, and feature usage analytics. We use cookies and similar technologies to collect some of this information (see Section 11).
4.4 Communications Data
When you contact us by email, telephone, in-app chat, or through any other support channel, we collect the content of your messages, your contact details, and a record of the communication.
4.5 Customer Data Uploaded by Subscribers
Subscribers may upload, enter or otherwise transmit Personal Data about their end customers and contacts (Customer Data) into the Service. This may include names, email addresses, telephone numbers, postal addresses, deal and pipeline information, communication history, file attachments and any other fields that the Subscriber chooses to store. As described in Section 2.2, we process this Customer Data as a processor only, on the documented instructions of the Subscriber.
4.6 Connected Third-Party Platform Data
Where a Subscriber connects their account on the Service to a third-party platform (such as Meta, Google, SendGrid, Twilio, Stripe or any other supported integration), we collect data from those platforms strictly to provide the features the Subscriber has enabled, and in accordance with the permissions the Subscriber has granted on those platforms. The categories of data we receive vary by integration. Examples include connected Page identifiers and access tokens (Meta), advertising account identifiers and campaign metrics, lead form responses, customer list audience identifiers, and payment transaction identifiers (Stripe). We do not access data outside the scope of the permissions granted on those platforms.
4.7 Marketing Preferences
Where you have opted in to receive marketing communications from us, we keep a record of your consent and your preferences.
4.8 Categories of Personal Information (United States residents)
For residents of California and other United States jurisdictions with equivalent disclosure requirements, the categories of Personal Information we collect (using the CCPA's category schema) include: identifiers (Section 4.1, 4.3, 4.6), commercial information (Section 4.2), internet or network activity information (Section 4.3), professional information (Section 4.1), customer record information (Section 4.5), and inferences drawn from any of the above (Section 4.6).
5. How We Use Personal Data
We use Personal Data for the following purposes. Each purpose is supported by a legal basis under Article 6 of the UK GDPR (and equivalent provisions of the EU GDPR), and (where applicable) constitutes a permitted business purpose under the CCPA/CPRA and other United States privacy laws.
5.1 Providing the Service
To create and operate Subscriber accounts; authenticate Subscribers and their users; deliver the Service's features; store and synchronise data across devices; integrate with third-party platforms the Subscriber has connected; and deliver in-product notifications.
5.2 Billing and Account Management
To process payments and refunds; manage subscription lifecycle (renewals, upgrades, downgrades, cancellations); issue invoices and receipts; collect overdue payments; and comply with our financial-reporting obligations.
5.3 Customer Support and Communications
To respond to enquiries; provide technical support; investigate and resolve issues; send transactional emails and notifications; and communicate operationally about the Service.
5.4 Service Improvement
To analyse usage of the Service in an aggregated and where possible anonymised form; identify and fix bugs and performance issues; understand which features are valuable to Subscribers; develop new features; and inform the product roadmap.
5.5 Security and Fraud Prevention
To detect, prevent, and respond to security threats, fraud, unauthorised access, malicious activity, and abuse of the Service; to enforce our Terms of Service; and to protect our systems, our users, and third parties.
5.6 Marketing
Where you have opted in, to send marketing communications about the Service and related products and services; to manage marketing campaigns; and to measure their effectiveness. You can opt out of marketing communications at any time using the unsubscribe link in any marketing email or by contacting us directly.
5.7 Legal and Regulatory Compliance
To comply with our obligations under applicable law, court orders, and lawful requests by public authorities; to establish, exercise or defend legal claims; and to maintain records for accounting, tax and audit purposes.
6. Legal Bases for Processing
Under Article 6 of the UK GDPR (and equivalent provisions of the EU GDPR for EU/EEA-resident data subjects), McNif relies on the following legal bases for processing Personal Data as a controller. For residents of jurisdictions without an Article 6-equivalent legal basis framework (for example, residents of California whose data is governed by the CCPA/CPRA), the purposes set out in Section 5 are nonetheless our authorised purposes for processing and we comply with the disclosure, opt-out and other rights granted by the applicable law.
| Purpose | Legal basis (UK/EU GDPR) | Notes |
|---|---|---|
| Providing the Service | Performance of a contract (Article 6(1)(b)) | Necessary to perform the Terms of Service. |
| Billing and account management | Performance of a contract; Legal obligation (Article 6(1)(b), (c)) | Including tax record-keeping under applicable law. |
| Customer support and operational communications | Performance of a contract (Article 6(1)(b)) | Necessary to provide and maintain the Service. |
| Service improvement and analytics | Legitimate interests (Article 6(1)(f)) | Maintaining and improving the Service. Balanced against your interests, including via aggregation. |
| Security and fraud prevention | Legitimate interests; Legal obligation (Article 6(1)(f), (c)) | Protecting Service, users, and third parties. |
| Marketing — existing customers (limited) | Legitimate interests (Article 6(1)(f)) under PECR soft opt-in (UK/EU only) | With opt-out path. |
| Marketing — other | Consent (Article 6(1)(a)) | Withdrawable at any time. |
| Compliance with legal obligations | Legal obligation (Article 6(1)(c)) | Including responses to lawful requests by public authorities. |
When processing Customer Data as a processor, our processing is governed by the Subscriber's instructions and the relevant Data Processing Agreement; we do not rely on our own Article 6 basis for that processing.
7. How We Share Personal Data
We share Personal Data with the categories of recipient described below. We do not sell Personal Data, and we do not share Personal Data for cross-context behavioural advertising as defined under the CCPA/CPRA.
7.1 Subprocessors
We engage carefully selected third-party service providers to assist in operating the Service. These subprocessors process Personal Data on our behalf or on a Subscriber's behalf, under written contracts that require them to comply with applicable privacy law and to provide appropriate safeguards. Our subprocessors include the following categories of provider; a current list of named subprocessors is maintained on our website.
- Cloud hosting and database infrastructure (for example, Supabase) for storage and processing of Subscriber Data and Customer Data.
- Payment processing (for example, Stripe) to process card payments and manage subscriptions.
- Email delivery and inbound email handling (for example, SendGrid).
- SMS and instant messaging delivery (for example, Twilio).
- AI and machine-learning services (for example, Anthropic) where Subscribers have enabled AI-assisted features.
- Analytics, error monitoring, and customer support tooling providers.
7.2 Connected Third-Party Platforms (at the Subscriber's Direction)
Where a Subscriber connects a third-party platform to the Service, Personal Data flows to or from that platform as part of the integration the Subscriber has enabled. McNif acts as a conduit for that data flow at the Subscriber's direction; the receiving platform is an independent controller for the data it receives.
7.3 Professional Advisers, Authorities and Corporate Transactions
We may share Personal Data with our professional advisers (lawyers, accountants, auditors, insurers) under conditions of confidentiality; with law enforcement, regulators and courts where required by law; and with parties to a merger, acquisition, financing, due diligence or business reorganisation subject to confidentiality undertakings.
8. International Transfers
McNif is based in the United Kingdom and our primary processing infrastructure is located in the United Kingdom and the European Economic Area. Some of our subprocessors process Personal Data outside the United Kingdom and EEA, including in the United States, Canada, Australia, and elsewhere.
Where Personal Data is transferred to a country that the originating jurisdiction has not deemed to provide an adequate level of data protection, we put in place appropriate safeguards under applicable privacy law. These safeguards include, depending on the transfer:
- Transfers from the United Kingdom: the United Kingdom International Data Transfer Agreement ("UK IDTA"), or the European Commission's Standard Contractual Clauses as supplemented by the United Kingdom Addendum ("UK Addendum"), or another approved transfer mechanism.
- Transfers from the European Economic Area: the European Commission's Standard Contractual Clauses ("EU SCCs"), Module 2 (Controller-to-Processor) or Module 3 (Processor-to-Sub-processor), as appropriate, or another approved transfer mechanism.
- Transfers from other jurisdictions: the transfer mechanism required or permitted by the privacy law of the originating jurisdiction (for example, written agreement and standard contractual provisions under PIPEDA, comparable contractual safeguards under APP 8, and similar mechanisms under LGPD and other applicable laws).
We carry out transfer impact assessments where required and may request additional safeguards from importers where necessary. You may request a copy of the safeguards in place for international transfers by contacting us at the details in Section 16.
9. Data Retention
We retain Personal Data only for as long as necessary for the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, regulatory or reporting requirements. The principal retention periods are:
- Subscriber Account Data: for the duration of the Subscriber's subscription, and for ninety (90) days after termination, after which the data is permanently deleted or fully anonymised.
- Customer Data uploaded by Subscribers: for the duration of the Subscriber's subscription, in accordance with the Subscriber's instructions.
- Billing records: retained for at least six (6) years following the relevant transaction (or longer where required by applicable tax law in your jurisdiction).
- Support and communications records: retained for up to three (3) years from the date of the last related interaction.
- Marketing data: retained for as long as you remain opted in, plus a reasonable period afterwards.
- Security and audit logs: retained for up to twelve (12) months, or longer where required.
Subscribers may request earlier deletion of their data and Customer Data in accordance with our in-product data export and deletion controls.
10. Your Rights
This Section describes the rights you have in respect of your Personal Data. The specific rights available to you depend on where you reside and which privacy law applies. To exercise any of the rights described below, please contact us using the details in Section 16.
10.1 Rights Available to Everyone
Regardless of where you reside, you have the right to contact us with any question or complaint about how we process your Personal Data, and we will respond promptly.
10.2 United Kingdom and European Economic Area (UK GDPR and EU GDPR)
If you are in the United Kingdom or the European Economic Area, you have the rights set out in Articles 15 to 22 of the UK GDPR or EU GDPR (as applicable):
- Right of access (Article 15) — to obtain confirmation as to whether we process your Personal Data and to receive a copy together with related information.
- Right to rectification (Article 16) — to have inaccurate Personal Data corrected.
- Right to erasure (Article 17) — to have your Personal Data erased in certain circumstances (also known as the "right to be forgotten").
- Right to restriction of processing (Article 18).
- Right to data portability (Article 20).
- Right to object (Article 21) — including to direct marketing at any time.
- Rights in relation to automated decision-making and profiling (Article 22).
- Right to withdraw consent where processing is based on consent.
- Right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in EU/EEA member states, your national data protection authority).
10.3 California and Other United States Jurisdictions (CCPA/CPRA and Equivalent Laws)
If you are a resident of California, you have the rights granted by the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020:
- Right to know — to request disclosure of the categories and specific pieces of Personal Information we collected about you in the preceding twelve (12) months.
- Right to delete — to request the deletion of your Personal Information held by us, subject to legal exemptions.
- Right to correct — to request correction of inaccurate Personal Information.
- Right to opt-out of "sale" or "sharing" of Personal Information — McNif does not sell Personal Information and does not share Personal Information for cross-context behavioural advertising. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link as required.
- Right to limit use and disclosure of sensitive Personal Information.
- Right to non-discrimination — we will not deny you the Service, charge you a different price, or provide a different level of service because you exercised a right.
- You may submit requests by emailing privacy@mcnifglobal.com or via our in-product privacy controls. We will verify your identity before responding and aim to respond within forty-five (45) days, extendable by an additional forty-five (45) days where necessary.
If you are a resident of Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Montana, Delaware or any other US state with a comprehensive consumer privacy law, you have rights substantially similar to the California rights above. Our process for handling those requests is the same; we calibrate response timeframes to the applicable law's requirements.
10.4 Australia (Australian Privacy Principles)
If you are in Australia, you have the rights granted by the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), including the right to access (APP 12) and correct (APP 13) personal information we hold about you, and the right to make a complaint about a breach of the APPs to us or to the Office of the Australian Information Commissioner (OAIC).
10.5 Canada (PIPEDA)
If you are in Canada, you have the rights granted by the Personal Information Protection and Electronic Documents Act (PIPEDA) or any equivalent provincial law, including rights to access, correct, and request the deletion of your personal information, and to complain to the Office of the Privacy Commissioner of Canada (OPC).
10.6 Brazil (LGPD)
If you are in Brazil, you have the rights granted by the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados / LGPD), including confirmation of the existence of processing, access, correction, deletion, data portability, and information about the entities with whom we have shared your personal data. You may complain to the Autoridade Nacional de Proteção de Dados (ANPD).
10.7 Other Jurisdictions
If you reside in another jurisdiction with applicable privacy laws (including the Singapore PDPA, Japanese APPI, South Korean PIPA, or any other), the rights granted by that law apply to your Personal Data. We endeavour to honour all such rights as required by applicable law. Please contact us using the details in Section 16 to exercise any right granted by the privacy law applicable to you.
10.8 Response Process
We aim to respond to all requests within the timeframe required by the privacy law applicable to you (one calendar month for UK GDPR / EU GDPR; forty-five days for most United States laws; thirty days under PIPEDA; fifteen days under LGPD; and so on). We may need to verify your identity before responding. We will not charge a fee unless your request is manifestly unfounded or excessive.
If you are an end customer of a Subscriber, your rights in relation to Customer Data are exercised against the Subscriber as controller. We will support Subscribers in responding to requests but we cannot act on a request that should properly be directed to the Subscriber.
11. Cookies and Similar Technologies
We use cookies and similar technologies on our website and within the Service to provide functionality, remember preferences, analyse usage, and improve the Service.
Categories of cookies we use include strictly necessary, functional, analytics, and performance cookies. We will request your consent before placing non-essential cookies where required by applicable law (including the Privacy and Electronic Communications (EC Directive) Regulations 2003 in the UK, ePrivacy regimes in EU/EEA member states, the CCPA/CPRA in California, and other comparable consent requirements). You can manage your cookie preferences via the cookie banner on our website or in your browser settings.
12. Children
The Service is intended for use by businesses and not by children. We do not knowingly collect Personal Data from individuals under the age of sixteen (16). Where applicable privacy law sets a different minimum age for processing children's data (for example, thirteen (13) in some United States jurisdictions or fifteen (15) in some EU member states), we apply the higher of the applicable thresholds. If we become aware that we have inadvertently collected Personal Data from a child without appropriate consent, we will take reasonable steps to delete that data promptly.
13. Security
We implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent industry standard); role-based access controls with multi-factor authentication; tenant data isolation; regular vulnerability scanning and patching; logging, monitoring and alerting; background checks and confidentiality obligations on McNif personnel with access to Personal Data; and documented incident response procedures, including notification of supervisory authorities and affected individuals where required by applicable law.
No method of transmission or storage is one hundred per cent secure. If you become aware of a security vulnerability or suspect a security incident affecting your data, please contact us immediately at security@mcnifglobal.com.
14. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Last Updated" date at the top of the Policy. Where the changes are material, we will provide additional notice (for example, by email to the registered Subscriber contact, by an in-product banner, or by a prominent notice on our website) before the changes take effect.
15. Complaints and Supervisory Authorities
If you have a concern about how we have handled your Personal Data, we encourage you to contact us first at the details in Section 16 so we can try to resolve it. If we are unable to resolve your concern, you have the right to lodge a complaint with the privacy supervisory authority of your jurisdiction. Examples include:
- United Kingdom: Information Commissioner's Office (ICO), ico.org.uk, telephone 0303 123 1113.
- European Economic Area: the data protection authority of your member state — a directory is maintained at edpb.europa.eu.
- California: the California Privacy Protection Agency (CPPA), cppa.ca.gov, and the California Attorney General, oag.ca.gov/privacy.
- Other US states with comprehensive privacy laws: the respective state Attorney General.
- Australia: Office of the Australian Information Commissioner (OAIC), oaic.gov.au, telephone 1300 363 992.
- Canada: Office of the Privacy Commissioner of Canada (OPC), priv.gc.ca, and any applicable provincial commissioner.
- Brazil: Autoridade Nacional de Proteção de Dados (ANPD), gov.br/anpd.
- Singapore: Personal Data Protection Commission (PDPC), pdpc.gov.sg.
- Japan: Personal Information Protection Commission (PPC), ppc.go.jp.
- Other jurisdictions: the supervisory authority designated by the privacy law applicable to you.
16. Contact Us
If you have any questions about this Policy or about how we handle Personal Data, please contact us using the following details.
McNif Global Limited
[Registered office address to be inserted at publication]
Email: privacy@mcnifglobal.com
Security incidents: security@mcnifglobal.com
General contact: hello@mcnifglobal.com
McNif Global Limited has not appointed a statutory Data Protection Officer because it is not required to do so under the UK GDPR or EU GDPR. However, our Privacy contact above is empowered to respond to data protection enquiries on our behalf. For residents of jurisdictions requiring a designated local representative (for example, an EU representative under Article 27 EU GDPR, or a UK representative under Article 27 UK GDPR for non-UK controllers), we will appoint a representative where required and update this Policy to identify them.
— End of Privacy Policy —