Torro CRM is a multi-channel customer-communication platform (CRM) that lets a business manage its conversations from connected messaging channels — including Telegram, WhatsApp, TikTok and (where available) Instagram — in a single inbox, with team collaboration, automation and AI-assisted replies, tasks, and a sales pipeline. This Privacy Policy explains what personal data we process, why, on what legal basis, with whom we share it, how we protect it, and the rights available to individuals.
This policy applies to https://torrocrm.com and the Torro CRM application and APIs. It does not apply to third-party services (including the messaging platforms) that have their own privacy policies.
Torro CRM serves two categories of individuals, and our role differs for each:
Where this policy describes end-customer conversation data, we act as a processor and process it only to provide the service to the relevant business.
When a business connects a channel, we process, on its behalf:
We process end-customer data only for the business that owns the conversation and only to provide the service.
Where a business authorizes a channel, we receive data through that platform's official integration:
| Purpose | Data | Legal basis (controller data) |
|---|---|---|
| Provide, operate and secure the service | Account, configuration, conversation, usage data | Performance of a contract; legitimate interests |
| Deliver messaging features (send/receive, inbox, assignment, templates) | Conversation data | Processor — on the business's instructions |
| AI-assisted features (agent replies, translation, transcription, suggestions) | Message content and derived data | Processor — on the business's instructions (see §5) |
| Billing and account management | Identity, billing, usage | Performance of a contract |
| Support, communications, security, fraud/abuse prevention | Account, usage, log data | Legitimate interests; legal obligation |
| Product analytics and improvement | Aggregated/technical usage data | Legitimate interests |
For end-customer conversation data we act as processor; the lawful basis for that processing is the responsibility of the business (controller).
Torro CRM offers AI-assisted features (an AI agent that drafts/sends replies, automatic translation, voice-message transcription, and content classification). To provide these features, message content and related context may be processed by third-party AI/LLM sub-processors (see §8).
We commit that:
A business can control or disable AI features for its account.
Our access to and use of data from TikTok, Meta and other platforms is governed by those platforms' developer terms and policies, in addition to this policy. Specifically, data obtained through a platform integration is:
For TikTok specifically: we only interact with conversations of Business Accounts that have authorized our app; personal (non-business) TikTok accounts are not supported; availability depends on the sign-up region of the Business Account.
A business user may connect their own Google Calendar to Torro CRM through Google OAuth. We request exactly one scope — https://www.googleapis.com/auth/calendar.readonly — which is read-only. We never create, modify or delete calendar events, and we request no other Google scope.
What we read and why: for a bounded window around the present, we read event metadata — title, start and end time, status, attendee e-mail addresses, and the meeting link. This data is used solely to show the customer's meetings inside that customer's card in the CRM, and to trigger the business's own automations when a meeting is booked or cancelled. It is not used for advertising or ad-targeting, is not sold or rented, and is not shared with third parties other than the sub-processors strictly necessary to deliver the feature (§8).
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In particular, Google user data — whether raw, aggregated or derived — is never used to create, train, fine-tune or improve any generalized or foundational AI/ML model, whether ours or a third party's. Where the business has enabled AI features, a customer's meeting details may be passed to our AI sub-processors as context, strictly to draft that business's own reply, on the same terms as §5: that content is not used for model training and is not retained by the AI sub-processor beyond delivering the response.
Google user data is stored encrypted at rest and is logically isolated per tenant. Disconnecting the calendar stops synchronization immediately, and the mirrored event data is deleted on disconnect or by retention, in line with §10.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We share personal data only with service providers that process it on our behalf to deliver the service, under contractual confidentiality and data-protection obligations. Categories and current providers:
We do not sell personal data. A current list of sub-processors is available on request.
Business and conversation data is primarily stored on infrastructure located in the European Union (the Netherlands and Germany). Some sub-processors (for example certain AI or payment providers) may process data in other countries. Where data is transferred across borders, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision, as required by applicable law.
We apply technical and organizational measures appropriate to the risk, including:
No method of transmission or storage is 100% secure; we work to protect data but cannot guarantee absolute security.
Depending on your jurisdiction, individuals may have rights to access, correct, delete, restrict or object to processing, and to data portability, and to withdraw consent.
You may also lodge a complaint with your local data-protection authority.
We use strictly necessary cookies to run the service and, where enabled, analytics/preference cookies. You can control cookies through your browser.
The service is intended for businesses and is not directed to children under 16. We do not knowingly collect data from children.
Controller / operator: Paper Mark Limited, Units 1-3, 20F Strand 50, 50 Bonham Strand, Sheung Wan, Hong Kong.
Privacy contact: [email protected]. For privacy questions or to exercise your rights, contact [email protected].
This policy is governed by the laws of Hong Kong, without prejudice to mandatory data-protection rights available to individuals under the laws applicable to them.
We may update this policy. Material changes will be notified via the service or by email, and the “Last updated” date will change. Continued use after changes take effect constitutes acceptance where permitted by law.