Legal
Privacy Policy
This explains what Fexo CRM stores about people, why it is stored, where it lives and how to have it removed. It is written to be read, not to be survived — if anything here is unclear, ask us and we will answer plainly.
The short version
- Brokerages put their own business records into Fexo CRM. Those records belong to the brokerage, not to us.
- We do not sell personal data, and we do not share it for advertising.
- Each brokerage's data is separated at the database level, not by application code remembering to filter.
- Reminder emails carry a one-click unsubscribe. Using it stops emails about that property for good.
- If you are a landlord or tenant, the brokerage that entered your details is the right first contact — we hold the data on their behalf.
This summary is for orientation. The sections below are the actual terms.
1. Who we are
FexoCRM is built and operated from Sharjah, United Arab Emirates. Where this policy says “we”, it means FexoCRM.
2. Controller and processor — which one we are
This distinction decides who you should contact, so it comes early rather than buried.
The brokerage is the controller
For the records a brokerage enters — landlords, tenants, properties, contracts, cheques, receipts — the brokerage decides what to collect and why. We hold and process it on their instructions. If you are a landlord or tenant asking about your details, the brokerage you deal with is the right first contact.
We are the controller for our own account data
For the accounts of the brokerage's own staff, billing records, and the technical logs we keep to run the service, we decide the purpose, so we are the controller. Ask us directly about those.
If you contact us about data a brokerage controls, we will help — but we may need to refer you to them, because acting on their records without their instruction is exactly what a processor must not do.
3. What we hold
Staff accounts
Name, sign-in email, phone number, role, an optional profile photo, and a password stored only as a one-way hash — we cannot read it, which is why we cannot email you your existing password.
Records a brokerage enters
Landlord and tenant names, contact details and identification documents the brokerage chooses to upload; properties, tenancy contracts, cheque schedules, receipts and the documents generated from them. We do not decide what goes in here — the brokerage does.
Files
Photos, logos, scanned documents and generated PDFs, held in object storage under a prefix belonging to that brokerage.
Operational records
A log of significant actions (who issued a document, who changed a contract), a record of emails we attempted to send and what the mail provider reported back, sign-in timestamps, and billing and credit history. These exist so the brokerage can audit its own office and so we can tell whether a message actually arrived.
The website
fexocrm.com sets no advertising or analytics cookies. A theme preference is stored in your browser's local storage and never leaves your device. There is no signup form and no tracking pixel — the only way to contact us from the site is WhatsApp or email, both of which you initiate.
4. Why we hold it
- To provide the service the brokerage signed up for — producing documents, tracking tenancies, sending the reminders they switch on.
- To keep accounts secure — sign-in, two-factor codes, and detecting misuse.
- To bill correctly — credits consumed, packages held, payments recorded.
- To keep email deliverable — recording bounces and complaints so we stop emailing an address that does not want or cannot receive mail.
- To meet legal obligations in the UAE, including record-keeping and tax requirements.
We do not profile people for advertising, and we do not build a product out of one brokerage's data to sell to another.
5. Email, and how to stop it
Fexo CRM can send reminders about cheques and contracts on a brokerage's behalf. Those emails are sent because the brokerage switched them on for a property you are connected to.
Every such email carries a one-click unsubscribe link, and supports the unsubscribe button your mail client shows. Using it stops those emails permanently — no account and no reply needed. The confirmation page also offers an undo, because someone who unsubscribes by accident and then misses a cheque reminder is worse off than someone who receives one more email.
Unsubscribing stops automated reminders. It does not stop your agent contacting you directly about your own tenancy, and it does not stop essential account messages such as a sign-in code, which are not marketing and carry no unsubscribe link.
6. Where it lives
Fexo CRM runs on dedicated Amazon Web Services infrastructure in the Asia Pacific (Mumbai) region, with encrypted connections in transit and regular backups that we have tested by restoring.
We name the region rather than saying “the region” because data residency is a real requirement for brokerages here and a vague answer is worse than an honest one. We intend to move to UAE infrastructure when we can do so without interrupting service, and we will say so here when it happens rather than implying it beforehand.
Outbound email is sent through Amazon Simple Email Service. A recipient's address and the message content necessarily pass through it in order to be delivered.
7. Who can reach it
Separation is enforced by the database itself, not by application code remembering to filter. Every query runs inside a tenancy boundary the database applies, so one brokerage cannot read another's records even if a bug in our code asked it to. We built that before any feature, because it cannot be retrofitted honestly.
Inside a brokerage, its owner controls who sees what: agents are scoped to their own clients and properties, and managers are granted access section by section. A landlord signing in to the owner portal sees only their own properties and nothing about the brokerage's other business.
On our side, access is limited to the people who operate the service, and only when needed to run it, support it, or fix a fault. We do not browse customer records.
We share data with third parties only where it is necessary to run the service — our hosting and email providers named above — or where the law requires it. We do not sell personal data, and we do not share it for advertising.
8. How long we keep it
While a brokerage's account is active, we keep its records so the office can work — a tenancy from three years ago is still the history of that property.
A brokerage can delete records at any time from within the product. When an account closes, we delete or irreversibly anonymise its data within a reasonable period, except where we must keep something to meet a legal obligation, such as financial records for the retention period UAE law requires.
Two deliberate exceptions, because pretending otherwise would be misleading: an issued document keeps the details it was issued with even after those details change, since a receipt is a record of what was true when it was given; and a record that an address unsubscribed or hard-bounced is retained, because that is the only way to keep not emailing it.
9. Your rights
Under UAE data protection law you may ask to access the personal data held about you, have it corrected, have it deleted, object to how it is used, or receive a copy of it.
Where to ask matters. If your details were entered by a brokerage — as a landlord or a tenant — ask that brokerage first: they are the controller and can act immediately. If they cannot help, or the request concerns your own Fexo CRM staff account, contact us at the address below and we will respond within 30 days.
We may need to verify your identity before acting. That is a protection for you: acting on an unverified request is how someone else's data gets handed to the wrong person.
10. Children
Fexo CRM is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, tell us and we will remove it.
11. Changes to this policy
When this policy changes we update the date at the top. If a change materially affects how personal data is handled, we will tell affected brokerages directly rather than relying on you to notice a new date.
12. Contact
Questions about this policy, or a request about your data, go to a person — not a ticket queue.
FexoCRM
Sharjah, United Arab Emirates