Privacy Policy
How Propel collects, uses, shares and protects personal data, and the rights you have under the GDPR and Spanish data-protection law.
Effective date: 2 October 2026 · Version 2.5
This Privacy Policy explains how personal data is collected, used, shared and protected in connection with Propel (“Propel”, “we”, “us”, “our”), an AI-native, multi-tenant B2B CRM provided as a fully managed online service (the “Service”) at propeltech.io. It is written to comply with the EU General Data Protection Regulation (Reg. 2016/679, the “GDPR”), the Spanish Organic Law 3/2018 (“LOPDGDD”), Law 34/2002 (“LSSI-CE”) and the ePrivacy rules for cookies and commercial communications.
Propel is a B2B product intended for professional and business use only. If you use the Service as a member of a customer organization, that organization is your primary point of contact for how your data is handled within the CRM, see Controller and processor roles below.
Questions or concerns? Reading this Policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use the Service. If you still have questions, contact us at hello@clovrlabs.com.
Summary of key points
This summary gives the key points of our Privacy Policy. Follow the link after each point for the full detail.
- What personal data do we process? Account and identity data, subscription data, security and usage records, and your communications with us; product analytics only if you accept them. What information do we collect?
- Do we process sensitive personal data? No. We do not intentionally collect special categories of data under Art. 9 GDPR. What information do we collect?
- Do we receive data from third parties? Only from services you choose to connect, such as Google, Microsoft or a telephony provider. We do not buy personal data. Who we share with
- Is the data in the CRM covered by this Policy? Not as controller. The contacts, leads, deals and emails your team works with belong to your organization, which is their controller; we process them on its behalf. Controller and processor roles
- How do we process your information? To provide, secure, support and improve the Service, to manage trials and subscriptions, to communicate with you, and to comply with the law. How do we process your information?
- What happens with AI features? Requests go through an AI gateway that Clovr Labs operates in the EU, or to the provider your organization connected with its own key. Propel trains no model on your data. How do we use AI?
- Do we sell your personal data? No. We never have and we do not intend to. Who we share with
- Where is the data held? The Service and its database are hosted in the European Union. Some providers you may connect are established outside the EEA. International transfers
- What are your rights? Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Your privacy rights
- How do you exercise them? Email hello@clovrlabs.com. We respond within one month. Your privacy rights
Table of contents
- Who we are
- Controller and processor roles
- What information do we collect?
- How do we process your information?
- What legal bases do we rely on?
- How do we use AI?
- When and with whom do we share your information?
- Do we use cookies and other tracking technologies?
- How long do we keep your information?
- Do we transfer information internationally?
- How do we keep your information safe?
- Do we collect information from minors?
- What are your privacy rights?
- Controls for Do-Not-Track features
- Automated decision-making and profiling
- Do we update this Policy?
- How can you contact us about this Policy?
- How can you review, update or delete your data?
1. Who we are
In short: Propel is a CRM provided by a company established in Spain, and we are the controller of the account data described in this Policy.
The controller of the personal data described in this Policy is:
- Provider: Clovr Labs, S.L., a company incorporated in Spain.
- Registered office: Avenida Generalitat 24, 08840 Viladecans, Barcelona, Spain.
- Tax ID (CIF/NIF): B67306894.
- Website: propeltech.io.
All privacy and data-protection matters are handled at hello@clovrlabs.com. We have not appointed a Data Protection Officer, as our processing does not currently require one under Art. 37 GDPR. You also have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es.
2. Controller and processor roles
In short: we are the controller of your account data. For the records your team keeps in the CRM, your organization is the controller and we act on its instructions.
Propel handles two distinct kinds of personal data, and our legal role differs for each. For account, subscription, website, security and usage data, the details you provide to create and administer an account and how you interact with the Service, Propel is the data controller, and this Privacy Policy governs that processing.
When a customer’s users put personal data into the CRM, their contacts, leads, deals, activities, notes, emails, calls, messages, quotes and form or booking submissions (“Customer Data”), Propel processes it on behalf of and under the instructions of the customer. The customer is the controller of Customer Data and Propel is the processor, under the data-processing terms in our Terms of Service. If your data appears inside a customer’s CRM, for example because you received an email, filled in a form, booked a meeting or opened a quote link, please contact that customer to exercise your rights; Propel will assist them as processor.
3. What information do we collect?
In short: what you give us when you create and use an account, records the Service keeps to run and secure itself, and, only if you accept them, product analytics.
Personal data you disclose to us. As controller, Propel collects and processes the following categories:
- Account and identity data: name, business email and, where provided, phone number; organization name, role and team membership; sign-in data (a hashed password managed by our self-hosted authentication service, sign-in with Google or Microsoft if you use it, and whether two-factor authentication is enabled); profile settings, preferences and language.
- Subscription data: the plan you chose, trial dates, number of users, your organization’s AI-credit balance and usage, and the billing details an administrator enters for invoices (legal name, address, country, VAT number and billing email). Online payment is not yet active: no card details are collected. When it is enabled, card payments will be handled by our payment provider (SumUp), and Propel will receive only the payment status, a customer reference, the card’s brand and last four digits, and a token that lets Propel charge the saved card for renewals, never the card number.
- Communications data: support requests, emails and messages you send us; correspondence about your account, security and legal matters; your marketing preferences.
- Acceptance records: when and which version of the Terms of Service you accepted when you created your account.
Information recorded automatically.
- Security and audit records: sign-ins, failed sign-ins and other security events with the IP address and browser used, and an audit log of administrative actions, with secrets redacted.
- Technical data: IP address, browser and device type, operating system and language, processed to deliver pages and protect the Service against abuse. We do not derive your location from your IP address.
- Product analytics, only with your consent: which screens are opened and which actions are used, recorded by screen name and never by record. See the Cookie Policy.
- Notifications: if you turn on browser notifications, the subscription your browser gives us (an endpoint address and keys) so we can deliver them.
Data from services you connect. If you connect an integration, we receive data from it strictly to run that feature: for example mail, calendar events and contact photos when you connect Google or Microsoft, call records when you connect a telephony provider, or messages when you connect WhatsApp Business. When you send email from Propel through a connected Gmail or Outlook mailbox, the message is sent by that provider from your own account and kept in its Sent folder. You control these connections and can disconnect them at any time in Settings.
Customer Data (processed as processor). Listed here for transparency. It includes the people your team contacts and the records about them, and some data the Service records about those people for your organization: whether and when an email your team sent was opened or a link in it clicked (with the browser and a hashed, never plain, IP address), unsubscribe and suppression status, and the answers people give in your forms, booking pages and quote links.
We do not intentionally collect special categories of personal data (Art. 9 GDPR). Please do not enter such data into free-text fields unless strictly necessary and lawful.
4. How do we process your information?
In short: to provide, secure, support and improve the Service, to manage trials and subscriptions, to communicate with you, and to comply with the law.
- To provide and operate the Service: create your account, authenticate you and enforce roles and permissions.
- To manage trials, plans and subscriptions: apply plan limits and AI credits, warn owners before a trial ends, lock a workspace whose trial ended without billing, and invoice.
- To provide support: answer your requests and resolve problems. With your organization’s request or for security reasons, authorized Propel staff may access a workspace to help; every such access is recorded in the audit log.
- To secure the Service: prevent abuse and fraud, isolate organizations from each other, keep security and audit records and apply rate limits.
- To maintain and improve the product: fix errors and, where you consented, learn from product analytics which parts of the Service are used.
- To provide the AI features you invoke, see How do we use AI?.
- To send service messages, such as security alerts, trial and billing notices and changes to our terms.
- To send marketing about Propel, where you have opted in or where permitted for existing business customers. You can opt out at any time.
- To comply with legal obligations and to establish, exercise or defend legal claims.
5. What legal bases do we rely on?
In short: we process your personal data only when we have a valid legal basis to do so under the GDPR.
Each purpose above rests on a legal basis under Art. 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Provide and operate the Service | Performance of a contract, Art. 6(1)(b) |
| Trials, plans, subscriptions and invoicing | Contract, 6(1)(b), and legal obligation for accounting, 6(1)(c) |
| Support, including audited staff access | Contract, 6(1)(b), and legitimate interests, 6(1)(f) |
| Security, abuse prevention and audit records | Legitimate interests, 6(1)(f), and legal obligation, 6(1)(c) |
| Maintain and fix the product | Legitimate interests, 6(1)(f) |
| Product analytics | Consent, 6(1)(a), see Cookies |
| AI features you invoke | Contract, 6(1)(b) |
| Service messages | Contract, 6(1)(b), and legal obligation, 6(1)(c) |
| Marketing about Propel | Consent, 6(1)(a), or legitimate interests for existing-customer B2B messaging, with opt-out |
| Legal compliance and legal claims | Legal obligation, 6(1)(c), and legitimate interests, 6(1)(f) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you may object at any time. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
6. How do we use AI?
In short: AI requests go through a gateway Clovr Labs operates in the EU, or to the provider your organization connected. Propel trains no model on your data.
Propel includes an AI sales assistant and AI features such as drafting, summaries, scoring and suggested field values. To answer, the assistant can use tools that read CRM records and mail your organization holds and, when you ask it to, create or update records; if an administrator turns on the background agent, it also reads new emails, calls and meetings on its own to fill empty fields and add a short summary, never replacing a value someone entered; it works within your own permissions, and every change it makes is recorded. By default, requests are sent to an AI gateway operated by Clovr Labs and hosted in the EU, which forwards them to the model provider configured for the platform; the current model provider is available on request. If your organization connects its own key for a provider (for example OpenAI, Anthropic, Google Gemini or Mistral), its requests go to that provider under your organization’s own agreement with it, and never fall back to ours.
AI apps outside Propel. A user can connect an AI assistant of their choice, such as Claude, ChatGPT or Microsoft Copilot, to Propel. It signs in as that user and can read and change only what that user can, in their workspace; it cannot delete records, make bulk changes or send emails. What it reads is then processed by that assistant’s provider under the user’s or the organization’s own agreement with it. Every change it makes is recorded and can be undone, the user can disconnect it at any time in Settings → AI apps, and an administrator can turn off every outside AI app for the workspace.
Propel does not train any model on your prompts, context or Customer Data. What a model provider may do with what it receives is governed by its terms for the account used. AI conversations are deleted 90 days after their last activity. AI use is limited by your plan’s AI credits and by per-organization controls an administrator can switch off. AI output is advisory: it does not, by itself, make decisions with legal or similarly significant effects.
7. When and with whom do we share your information?
In short: only with providers that help us run the Service, and with the services you choose to connect. We do not sell personal data.
We share personal data only with parties that help us provide the Service, under appropriate contracts and safeguards:
- Hosting: the infrastructure provider that runs the application, database and backups, in the European Union.
- Email delivery: Resend, which delivers the sign-in, notification and outbound messages the Service sends, from its EU region.
- AI: the model provider behind our EU gateway, or the provider your organization connected with its own key, see How do we use AI?.
- Payments: SumUp Payments Limited (Ireland), once online payment is enabled (not yet active).
- VAT number validation: the European Commission’s VIES service, which receives an EU VAT number entered in the billing details, to confirm it for invoicing.
- Browser push services (for example Google, Mozilla or Apple), only if you turn on notifications.
- Services you choose to connect, only while the connection is active: Google (Gmail, Calendar, Contacts, sign-in), Microsoft (Outlook, sign-in), Yousign (e-signature), WhatsApp Business (Meta), Aircall and Ringover (telephony), Zoom, Calendly, HubSpot, Salesforce, Pipedrive, Mailchimp, Klaviyo, Holded, Odoo, Sage, Microsoft Dynamics 365 Business Central, SAP Business One, Stripe (importing your own account’s data), lead sources such as Typeform or Google Ads, chat and automation destinations such as Slack, Microsoft Teams, Discord, Telegram, Zapier, Make, n8n or a webhook address you enter, AI assistants a user connects to their own account (for example Claude, ChatGPT, Microsoft Copilot, Cursor or VS Code), and AI agents on the N0 platform that a user authorizes to read, on their behalf, the CRM data that user can see (read only: they cannot change anything).
- Professional advisers, auditors and authorities, where legally required or to establish or defend legal claims.
- A successor entity, in connection with a merger, financing, acquisition or sale of assets, subject to this Policy continuing to apply.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. More detail on any provider, including its location and the safeguard used, is available from hello@clovrlabs.com.
8. Do we use cookies and other tracking technologies?
In short: strictly necessary storage, plus product analytics only if you accept them in the banner. You can change your choice at any time.
The Service uses strictly necessary cookies and browser storage (for example the sign-in session) that do not need consent, and one optional category, first-party product analytics, which is off until you accept it in the cookie banner and can be withdrawn at any time. Emails your organization sends through Propel can carry open and click tracking for your organization’s records, described in section 3. Every cookie and storage item is listed in the Cookie Policy.
9. How long do we keep your information?
In short: only as long as we need it for the purposes in this Policy, plus any period the law requires.
- Account data and Customer Data: for the life of the organization. When an owner deletes the organization, its data and its members’ accounts are deleted at once.
- Workspaces whose free trial ends without billing ever being activated: locked when the trial ends and deleted with their Customer Data 90 days later. Owners and admins are warned by email two weeks before and again the day before, and can export their data until then.
- AI conversations: deleted 90 days after their last activity.
- Product analytics (with consent): 180 days.
- Email open and click records: the hashed IP address and browser are removed after 90 days and the records deleted after 400 days.
- Webhook delivery and AI error logs: 30 days.
- Security events and the audit log: for the life of the organization, because they are the record of who did what in it.
- Billing and invoicing records: for the period required by Spanish tax and accounting law.
- Marketing and consent records: until consent is withdrawn or the relationship ends, plus the period needed to prove consent.
Deleted data can remain in infrastructure backups until those backups expire in their normal rotation; it is not restored into the Service except to recover from an incident.
10. Do we transfer information internationally?
In short: the Service is hosted in the EU. Some providers you may connect are established outside the EEA, under recognized safeguards.
The Service, its database, its backups and our AI gateway are hosted in the European Union. Some providers listed in section 7 are established outside the European Economic Area, mostly in the United States (for example Google, Microsoft, Resend or the AI provider your organization connects). Where personal data reaches them, the transfer relies on an adequacy decision, such as the EU–US Data Privacy Framework for certified providers, or on the European Commission’s Standard Contractual Clauses. You may ask which safeguard applies to a specific provider at hello@clovrlabs.com.
11. How do we keep your information safe?
In short: we apply technical and organizational measures appropriate to the risk. No system can be guaranteed perfectly secure.
Our measures include TLS encryption in transit; AES-256-GCM encryption at rest for stored integration credentials; database row-level security that isolates each organization, with role-based permissions; two-factor authentication; security-event and audit logging that no user can modify or delete; hardened outbound webhooks; least-privilege access; support access that is recorded in the audit log and cannot erase data or mint credentials; and automated security checks before every release. Backups are kept by our hosting infrastructure in the EU.
Despite these measures, transmission over the internet can never be guaranteed to be completely secure. You should only access the Service from a secure environment. If you discover a vulnerability, please contact hello@clovrlabs.com.
12. Do we collect information from minors?
In short: no. The Service is a business tool for users aged 18 or over.
The Service is not directed to children and we do not knowingly collect personal data from minors. By using the Service you represent that you are at least 18 years old. If we learn that we have collected personal data from a user under 18, we will deactivate the account and take reasonable steps to delete that data promptly. If you believe a minor has provided us with personal data, contact hello@clovrlabs.com.
13. What are your privacy rights?
In short: you can access, correct, delete, restrict, port and object. Email us and we will respond within one month.
Subject to the conditions and exceptions in the GDPR and LOPDGDD, you have the right to:
- Access your personal data and obtain a copy of it.
- Rectify data that is inaccurate or incomplete.
- Erase your data, where one of the grounds in Art. 17 GDPR applies.
- Restrict processing in the circumstances set out in Art. 18 GDPR.
- Port the data you provided to us, in a structured, machine-readable format.
- Object to processing based on legitimate interests, and at any time to direct marketing.
- Withdraw consent at any time, where processing is based on consent. This does not affect processing carried out before withdrawal.
To exercise these rights, contact hello@clovrlabs.com. We may need to verify your identity, and will use anything you send for that verification and nothing else. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need that extension.
Opting out of marketing. You can unsubscribe from marketing email at any time using the link in the message or by emailing us. You will still receive service messages that are necessary to administer your account, respond to support requests, or meet a legal obligation.
If your data is inside a customer’s CRM, the customer is the controller, please direct your request to that organization, and we will support them as processor. To help customers meet these obligations, Propel provides admin-only tools: full organization export, per-person data export, and erasure of a contact, lead or team-member profile. You may also lodge a complaint with the AEPD (www.aepd.es) or the supervisory authority in your country of residence, though we would appreciate the chance to address your concern first.
14. Controls for Do-Not-Track features
In short: we do not respond to browser Do-Not-Track signals. The cookie banner is the control that actually works.
Most browsers include a Do-Not-Track (“DNT”) setting that signals you do not want your browsing monitored. No uniform standard for honouring DNT has been finalized, and Propel does not currently respond to DNT or Global Privacy Control signals. We say so plainly rather than imply a protection we do not provide.
What does work is the cookie banner: product analytics is not recorded at all until you accept it, and you can change that choice at any time from Cookie settings. See the Cookie Policy.
15. Automated decision-making and profiling
In short: our scoring features rank records to help a human decide. They do not make decisions about you on their own.
Propel offers lead scoring, lead routing and analytics that rank, prioritize or assign records to help sales teams focus their effort, which involves a form of profiling. These are decision-support tools: a person reviews and decides on any action, and they do not produce decisions based solely on automated processing that have legal or similarly significant effects, so the Art. 22 GDPR safeguards are not triggered. They operate on Customer Data, for which the customer is the controller; questions about a specific score should be directed to that organization.
16. Do we update this Policy?
In short: yes, as the Service and the law change. Material changes are notified.
We may update this Policy to reflect changes in the Service, our practices or the law. When we make material changes, we will revise the date above and, where appropriate, notify you by email or in the app. The current version is always available at propeltech.io.
17. How can you contact us about this Policy?
In short: email us, or write to our registered office.
Email hello@clovrlabs.com, or visit our contact page. By post: Clovr Labs, S.L., Avenida Generalitat 24, 08840 Viladecans, Barcelona, Spain.
18. How can you review, update or delete your data?
In short: most of it from your account settings; the rest by emailing us.
You can review and update much of your account and profile data directly in the Service, under Settings, and an owner can export or delete the whole organization there. To request a copy of everything we hold about you, to correct it, or to have it deleted, email hello@clovrlabs.com and we will handle it as a data-subject request under section 13.
Related documents: the Terms of Service, the Legal Notice and the Cookie Policy.
Published and in force as of the date above. It describes the processing this Service actually performs and contains no unfilled placeholders. It has not been reviewed by external counsel, and it addresses the EU and Spanish regime only: if the Service takes on users in a jurisdiction with its own privacy statute, that coverage needs assessing separately.