Start free

Privacy Policy

Version v1.0 β€’ Last updated: 13 July 2026 β€’ Applies to ohana360.com and the Ohana360 mobile app

This is a courtesy translation provided for convenience. The legally binding version is the Gizlilik PolitikasΔ± (Turkish).

Data controller: digitalforce360 OÜ (Estonian registry code 16940165), Narva mnt 5, Kesklinna linnaosa, 10117 Tallinn, Estonia. Contact: legal@ohana360.com

1. Scope

This policy explains the personal data processed when you use the Ohana360 cloud CRM service (web and mobile). Ohana360 is a multi-tenant business application: each organization owns its own data.

2. Data we process

DataPurposeLegal basis
Name, email, password (stored irreversibly with bcrypt)Account creation, authentication, session managementPerformance of contract
Your organization's CRM records (customers, contacts, deals, cases and similar)Providing the service; the content of these records is controlled by your organizationPerformance of contract
Usage and audit logs (logins, administrative actions, IP-based rate limiting)Security, abuse prevention, troubleshootingLegitimate interest
Session cookie (ohana_sess) and mobile session tokenMaintaining your session (essential; no ad or tracking cookies)Legitimate interest
Push notification subscription (only if you enable it)Delivering notificationsConsent

3. Sharing

Your personal data is never sold and never shared with third parties for advertising. Data is hosted only with the infrastructure providers required to run the service (hosting: Hostinger; transactional email is sent from the server). Disclosure to competent authorities may occur where legally required.

4. Retention and deletion

You can permanently delete your account in the app via User Menu > Delete My Account. If you are the last user, the organization and all its data are deleted. Deleted data rolls off backups within at most 7 days (backups are kept on a 7-day cycle). You may also request deletion by email.

5. Your rights (KVKK art. 11 and GDPR art. 15-22)

You have the rights of access, rectification, erasure, restriction of processing, portability and objection. Write to the contact address above; requests are answered within 30 days at the latest. Under the GDPR you may also lodge a complaint with your local supervisory authority.

6. Security

All traffic is encrypted with HTTPS. Passwords are stored with bcrypt, sessions are protected by HttpOnly cookies or device-specific tokens, and optional two-factor authentication (2FA) is offered. Database access uses parameterized queries and administrative actions are recorded in the audit log.

7. Children's privacy

Ohana360 is a business application and is not directed at persons under 16.

8. Changes

Updates to this policy are published on this page; significant changes are announced in the app.

Ready to see it with your own data?

Create your organization in minutes. Free to start, no credit card required.