DJ-CRM DJ-CRM

Privacy Policy

Last updated 14 August 2026

DJ-CRM is booking management software for DJs, magicians, bands and entertainment agencies. This policy explains what the software stores, why, and how Google user data is handled.

DJ-CRM is operated by Paddy Gordon DJ, Glasgow, United Kingdom. For any question about this policy, contact [email protected].

1. Who this policy covers

There are two groups of people whose data appears in DJ-CRM.

Where a user's business is the data controller for their own clients, DJ-CRM acts as the processor for that data.

2. What is stored

Account data

Name, email address, profile photo, role and organisation membership. Sign-in is by Google, by Apple, or by passkey; DJ-CRM never sees or stores a Google or Apple password.

Business data

Bookings, events, venues, quotes, contracts, invoices, payments, availability, and the planning information a client submits for their event, such as running order, song choices and venue logistics.

Client contact data

Names, email addresses, phone numbers and event addresses, entered by a user or submitted through an enquiry form.

Correspondence

Emails sent by the software are recorded so a user can see what was sent to whom and whether it was delivered and opened. Where a user has connected a Google account with read access, message content from that user's own mailbox is stored so the conversation with a client can be shown against their booking.

Technical data

Session cookies, device tokens for push notifications, and server logs containing IP addresses and request paths, kept for security and troubleshooting.

3. Google user data

Connecting a Google account is optional and is done by the individual user for their own account. DJ-CRM only ever accesses that user's own calendar and mailbox, never anyone else's, and requests the narrowest scopes that support the features described.

OAuth tokens are stored encrypted. A user can disconnect their Google account at any time in Settings, which deletes the stored tokens, and can revoke access independently at myaccount.google.com/permissions.

Limited Use disclosure

DJ-CRM's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, DJ-CRM does not transfer Google user data to third parties except as necessary to provide or improve the features described above, to comply with applicable law, or as part of a merger or acquisition. DJ-CRM does not use Google user data for serving advertisements, does not sell it, and does not use it to develop, improve or train generalised artificial intelligence or machine learning models. Humans do not read Google user data except with the user's explicit consent for a specific support issue, where required by law, or where it is aggregated and anonymised for security or troubleshooting.

4. Where data is held

DJ-CRM runs on servers hosted by Hetzner in the European Union. Databases and file storage are held on those servers, with encrypted backups retained on separate machines under the operator's control for disaster recovery. Traffic is encrypted in transit with TLS. Stored credentials, including OAuth tokens and mail passwords, are encrypted at rest.

5. Third parties

Data is shared only with services needed to run the product:

Google user data is not shared with any of the others.

6. Retention

Business records such as bookings, contracts and invoices are retained while the account is active and afterwards for as long as needed to meet legal and accounting obligations. Synchronised mail is retained while the Google account remains connected and is removed when it is disconnected or the account is deleted. Server logs are kept for a limited period for security and troubleshooting.

7. Your rights

Under UK GDPR you may request access to your personal data, correction of it, deletion of it, restriction of processing, or a copy in a portable format, and you may object to processing. Requests go to [email protected] and are answered within one month.

If a request concerns data entered by a business that uses DJ-CRM about its own client, it is passed to that business as the controller.

You may also complain to the Information Commissioner's Office at ico.org.uk.

8. Children

DJ-CRM is business software and is not directed at children. Accounts are not knowingly created for anyone under 18.

9. Changes

Material changes to this policy will be notified to account holders by email. The date at the top records the last revision.