Privacy Policy
Last updated: 16 August 2026
1. Controller
Friars Technologies Limited ("we", "us", "our") operates CaesarCRM, a customer relationship management and related services platform. We are the data controller in respect of personal data processed in connection with CaesarCRM. Our registered address is Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom. For privacy enquiries you may contact us at that address or via the contact details provided on our website.
2. What data we collect
We collect and process information that you provide (e.g. account details, profile information, content you create or upload, communications, and billing details), information generated by your use of our services (e.g. usage data, logs, and device information), and information from third-party integrations you connect (e.g. email or calendar providers). We may also collect information from publicly available or third-party sources where relevant to providing or improving our services.
3. How we use your data
We use your data to provide, operate, secure and support CaesarCRM; to communicate with you; to process payments and enforce our terms; and to comply with legal obligations. We also use data to analyse and improve our services, to develop new features, and to maintain and improve the quality, safety and reliability of our platform.
As part of improving our services, we may use aggregated, anonymised or pseudonymised data, and usage data (including how you interact with our product and AI-powered features), but excluding data obtained from Google Workspace APIs, for analytics, product development, and to develop and improve our machine learning and artificial intelligence systems. This enables us to improve accuracy, personalisation and functionality of our services, including AI-driven tools. Where required by applicable law we rely on our legitimate interests in improving and developing our services, or on consent where we have obtained it. You may have the right to object to processing based on legitimate interests in certain circumstances (see your rights below).
By using our services you agree that we may use your data for the purposes described in this policy. Such use is made without any obligation to compensate you or to account to you for any use or benefit we derive from it. Our right to use data for service improvement, analytics, and the development and operation of our systems (including AI and machine learning) is not subject to any restriction beyond what is set out in this policy and in applicable law. This paragraph does not apply to data obtained from Google Workspace APIs.
Exclusion of Google Workspace API data. Nothing in this section applies to data obtained from Google Workspace APIs. Google Workspace API data, including raw, aggregated, anonymised, pseudonymised and derived data, is never used to develop, improve, or train generalised or foundational artificial intelligence or machine learning models, in accordance with the Google API Services User Data Policy, including the Limited Use requirements. Our use of that data is governed exclusively by section 10 (Google Workspace API Limited Use Disclosure), which prevails over any conflicting statement in this policy.
4. Lawful basis (UK & EU)
We process personal data on the basis of: performance of contract (providing the service); legitimate interests (e.g. improvement of services, security, analytics, and AI/ML development where not overridden by your rights); consent where we have asked for it; and legal obligation where required. Where we rely on legitimate interests we have assessed that our interests are balanced against your rights and freedoms. We do not rely on legitimate interests, consent, or any other lawful basis to use data obtained from Google Workspace APIs to develop, improve, or train generalised or foundational artificial intelligence or machine learning models; see section 10.
5. Data sharing
We may share data with service providers who process data on our instructions (e.g. hosting, payments, email, analytics). We require them to act only on our instructions and to protect your data. We may disclose data where required by law or to protect our rights, safety or property. We do not sell your personal data.
6. International transfers
Your data may be processed in the United Kingdom and in other countries where we or our service providers operate. Where we transfer data outside the UK or EEA we ensure appropriate safeguards (e.g. adequacy decisions, standard contractual clauses, or other approved mechanisms) are in place as required by applicable law.
7. Retention
We retain personal data for as long as necessary to provide our services, comply with legal obligations, resolve disputes and enforce our agreements. When data is no longer needed we delete or anonymise it in accordance with our retention policies.
8. Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration or disclosure. No system is completely secure; we encourage you to use strong credentials and to notify us of any suspected breach.
9. Your rights (UK GDPR / EU GDPR)
Depending on where you are, you may have the right to: access your data; have inaccurate data corrected; have data erased in certain cases; restrict or object to certain processing; data portability; withdraw consent where processing is based on consent; and lodge a complaint with a supervisory authority (in the UK, the ICO: ico.org.uk). To exercise these rights, contact us using the details above. We will respond within the timeframes required by applicable law.
10. Google Workspace API Limited Use Disclosure
CaesarCRM's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Workspace user data is used solely to provide the user-facing functionality requested by the user, including displaying email conversations, analysing replies, generating AI-assisted recommendations, and sending authorised emails from the user's connected Gmail account.
CaesarCRM does not use Google Workspace user data, including raw, aggregated, anonymised, or derived data, to develop, improve, or train generalised or foundational artificial intelligence or machine learning models.
Where CaesarCRM uses third-party AI service providers to process Google Workspace user data on behalf of the user, those providers are used only to deliver the requested functionality. Google Workspace user data is not used to train or improve general AI models.
CaesarCRM does not sell Google Workspace user data or use it for advertising purposes.
This section governs all data obtained from Google Workspace APIs and prevails over any other statement in this policy. Where any other section describes the use of data (including raw, aggregated, anonymised, pseudonymised or derived data) for analytics, product development, or the development, improvement or training of artificial intelligence or machine learning systems, that description excludes data obtained from Google Workspace APIs.
11. Data protection complaints
If you have a concern about how Friars Technologies Limited handles your personal data, you can make a data-protection complaint by emailing [email protected].
We will acknowledge your complaint within 30 days of receiving it and will investigate and respond without undue delay. We may ask you for information we need to understand your complaint or to verify your identity or authority.
If you remain dissatisfied after our response, you can raise your concern with the Information Commissioner's Office (ICO) at ico.org.uk.
12. Changes
We may update this policy from time to time. We will post the updated version on this page and indicate the date of the last update. Continued use of CaesarCRM after changes constitutes acceptance of the updated policy where permitted by law.