Privacy Policy — Torro CRM

Operated by Paper Mark Limited (“Torro CRM”, “we”, “us”, “our”)
Last updated: 6 September 2026 · Effective: 11 August 2026

Torro CRM is a multi-channel customer-communication platform (CRM) that lets a business manage its conversations from connected messaging channels — including Telegram, WhatsApp, TikTok and (where available) Instagram — in a single inbox, with team collaboration, automation and AI-assisted replies, tasks, and a sales pipeline. This Privacy Policy explains what personal data we process, why, on what legal basis, with whom we share it, how we protect it, and the rights available to individuals.

This policy applies to https://torrocrm.com and the Torro CRM application and APIs. It does not apply to third-party services (including the messaging platforms) that have their own privacy policies.

1. Our role: controller and processor

Torro CRM serves two categories of individuals, and our role differs for each:

Where this policy describes end-customer conversation data, we act as a processor and process it only to provide the service to the relevant business.

2. Data we process

2.1 Business account data (we are controller)

2.2 End-customer conversation data (we are processor)

When a business connects a channel, we process, on its behalf:

We process end-customer data only for the business that owns the conversation and only to provide the service.

2.3 Data from connected platforms

Where a business authorizes a channel, we receive data through that platform's official integration:

3. How we collect data

4. Purposes and legal bases

Purpose Data Legal basis (controller data)
Provide, operate and secure the service Account, configuration, conversation, usage data Performance of a contract; legitimate interests
Deliver messaging features (send/receive, inbox, assignment, templates) Conversation data Processor — on the business's instructions
AI-assisted features (agent replies, translation, transcription, suggestions) Message content and derived data Processor — on the business's instructions (see §5)
Billing and account management Identity, billing, usage Performance of a contract
Support, communications, security, fraud/abuse prevention Account, usage, log data Legitimate interests; legal obligation
Product analytics and improvement Aggregated/technical usage data Legitimate interests

For end-customer conversation data we act as processor; the lawful basis for that processing is the responsibility of the business (controller).

5. AI processing of messages

Torro CRM offers AI-assisted features (an AI agent that drafts/sends replies, automatic translation, voice-message transcription, and content classification). To provide these features, message content and related context may be processed by third-party AI/LLM sub-processors (see §8).

We commit that:

A business can control or disable AI features for its account.

6. Platform compliance and use limitations

Our access to and use of data from TikTok, Meta and other platforms is governed by those platforms' developer terms and policies, in addition to this policy. Specifically, data obtained through a platform integration is:

For TikTok specifically: we only interact with conversations of Business Accounts that have authorized our app; personal (non-business) TikTok accounts are not supported; availability depends on the sign-up region of the Business Account.

7. Google user data (Google Calendar integration)

A business user may connect their own Google Calendar to Torro CRM through Google OAuth. We request exactly one scope — https://www.googleapis.com/auth/calendar.readonly — which is read-only. We never create, modify or delete calendar events, and we request no other Google scope.

What we read and why: for a bounded window around the present, we read event metadata — title, start and end time, status, attendee e-mail addresses, and the meeting link. This data is used solely to show the customer's meetings inside that customer's card in the CRM, and to trigger the business's own automations when a meeting is booked or cancelled. It is not used for advertising or ad-targeting, is not sold or rented, and is not shared with third parties other than the sub-processors strictly necessary to deliver the feature (§8).

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

In particular, Google user data — whether raw, aggregated or derived — is never used to create, train, fine-tune or improve any generalized or foundational AI/ML model, whether ours or a third party's. Where the business has enabled AI features, a customer's meeting details may be passed to our AI sub-processors as context, strictly to draft that business's own reply, on the same terms as §5: that content is not used for model training and is not retained by the AI sub-processor beyond delivering the response.

Google user data is stored encrypted at rest and is logically isolated per tenant. Disconnecting the calendar stops synchronization immediately, and the mirrored event data is deleted on disconnect or by retention, in line with §10.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

8. Sub-processors and third parties

We share personal data only with service providers that process it on our behalf to deliver the service, under contractual confidentiality and data-protection obligations. Categories and current providers:

We do not sell personal data. A current list of sub-processors is available on request.

9. International transfers

Business and conversation data is primarily stored on infrastructure located in the European Union (the Netherlands and Germany). Some sub-processors (for example certain AI or payment providers) may process data in other countries. Where data is transferred across borders, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision, as required by applicable law.

10. Data retention and deletion

11. Security

We apply technical and organizational measures appropriate to the risk, including:

No method of transmission or storage is 100% secure; we work to protect data but cannot guarantee absolute security.

12. Your rights

Depending on your jurisdiction, individuals may have rights to access, correct, delete, restrict or object to processing, and to data portability, and to withdraw consent.

You may also lodge a complaint with your local data-protection authority.

13. Cookies

We use strictly necessary cookies to run the service and, where enabled, analytics/preference cookies. You can control cookies through your browser.

14. Children

The service is intended for businesses and is not directed to children under 16. We do not knowingly collect data from children.

15. Contact

Controller / operator: Paper Mark Limited, Units 1-3, 20F Strand 50, 50 Bonham Strand, Sheung Wan, Hong Kong.

Privacy contact: [email protected]. For privacy questions or to exercise your rights, contact [email protected].

16. Governing law

This policy is governed by the laws of Hong Kong, without prejudice to mandatory data-protection rights available to individuals under the laws applicable to them.

17. Changes

We may update this policy. Material changes will be notified via the service or by email, and the “Last updated” date will change. Continued use after changes take effect constitutes acceptance where permitted by law.

Download as PDF