GDPR compliance
Last updated: 31 July 2026
Zen Brew CRM is designed to help small and medium businesses handle personal data in line with the UK GDPR and EU GDPR principles. This page summarises the controls and rights that apply to the app.
Data controller and processors
The workspace owner acts as data controller for the contact records held in Zen Brew CRM. Zen Brew and its subprocessors act as processors to deliver the service. A list of subprocessors is available on request.
Security controls
- Two factor login on every sign in.
- Encrypted transport (HTTPS) and encryption of sensitive tokens at rest.
- Row level security on customer data with per user access.
- Audit logs for authentication, email sending and document downloads.
Data subject rights
Individuals have the right to access, correct, delete, restrict or port their personal data, and to object to processing. Requests can be sent to privacy@zenbrew.co.uk and are answered within one month.
Marketing and unsubscribe
Every marketing email sent from Zen Brew CRM includes a one click unsubscribe link. Unsubscribed contacts are added to a suppression list and are not emailed again unless they opt back in.
International transfers
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses with our processors.
Breach notification
If we become aware of a personal data breach that is likely to result in a risk to individuals, we will notify affected workspace owners without undue delay and support them with regulator notifications where required.