Privacy policy.
How we handle personal data, in plain English. No cookies, no tracking, data kept in the UK.
Last updated 11 October 2026
Who we are
Trojan CRM is made by TG Digital, a small UK business owned and run by its two founders.
You can contact us about anything in this policy at [email protected]. We are a small business and are not required to appoint a data protection officer; every data protection request is dealt with personally by one of the two founders.
Two different roles
We handle personal data in two ways, and the rules are different for each.
When we are the controller
We decide how and why the data is used. That covers people who email us or visit this website, people at firms we are talking to or who are our customers, and the user accounts we set up for each firm's staff (names, work email addresses, roles, and sign-in and security records).
When we are a processor
A building firm that uses Trojan CRM keeps its own records in it: its customers, suppliers, subcontractors and staff, their contact details and addresses, job details, photos, documents, costs, quotes and invoices. The firm is the controller of that data and decides what goes in. We process it only on the firm's instructions, to provide the service, under our agreement with the firm.
If you are a customer or supplier of a building firm and want to know what it holds about you, or to use your rights, contact that firm. If you contact us instead, we will pass your request to the firm and help it respond.
What we collect, and why
| Whose data | What | Why, and our lawful basis |
|---|---|---|
| People who email us | Your name, email address, firm, and what you write | To reply and, if you ask, arrange a demo or quote. Legitimate interests in answering enquiries, or steps you ask for before a contract. |
| Visitors to this website | Standard request records kept by our host: IP address, browser, the page requested and when | To keep the site running and secure. Legitimate interests. We use no cookies, analytics or tracking on this website. |
| Our customers' contacts | Names, work contact details, billing details and our correspondence | To provide the service, invoice for it and keep business records. Contract, and legal obligation for accounting records. |
| Users of the system | Name, work email, role, a one-way hash of the password, and sign-in and security records | To let people sign in, keep accounts secure and investigate misuse. Contract with the firm, and legitimate interests in security. |
We do not sell personal data, use it for advertising, or make decisions about anyone by automated means.
Cookies
This website sets no cookies and loads nothing from other companies: no analytics, no adverts, no embedded videos or maps, no external fonts. That is why there is no cookie banner.
The Trojan CRM application, at each firm's own address, uses one cookie that is strictly necessary to keep a signed-in user signed in. It is not used for anything else.
Who we share it with
We use a small number of service providers (sub-processors) to run the business. Each has a written contract with us that limits what it may do with the data.
| Provider | What for | Where the data is held |
|---|---|---|
| DigitalOcean | Hosting the website, the application and each firm's database | London, UK |
| Amazon Web Services | Sending the emails firms send through the system, and reporting bounces and complaints | London, UK |
| Microsoft | Our own email mailbox, for messages to [email protected] | UK |
DigitalOcean, Amazon and Microsoft are US-headquartered companies. Where any of them may access data from outside the UK (for example to provide support or keep their services secure), the transfer is covered by the UK government's adequacy regulations for the UK Extension to the EU-US Data Privacy Framework or by the UK's International Data Transfer Addendum.
We will update this list before we start using any new provider that handles personal data. We may also disclose data if the law requires it.
How long we keep it
- Enquiries that don't lead to a customer relationship: up to two years from our last contact.
- Customer business records, including invoices: six years after the end of the financial year they relate to, as UK tax law requires.
- A firm's own records in the system: for as long as the firm is a customer. When it leaves, we give it its data back and then delete its database, as set out in our agreement with the firm.
- Website request records: kept by our host for a short period for security, then deleted.
How we keep it safe
- Each firm has its own separate database with its own credentials, hosted in London.
- Everything is encrypted in transit: pages only over HTTPS, and the application's connection to its database encrypted and verified.
- Passwords are stored only as strong one-way hashes, must be at least 12 characters, and common or easily guessed passwords are refused. Sign-in is rate-limited.
- Each firm's staff see only what their role allows; site supervisors see only their own jobs and no financial figures.
- Only the two founders have access to the systems that run the service, and we never put customer data in our development tools or test data.
Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal data we hold about you;
- ask us to correct it if it is wrong or incomplete;
- ask us to delete it, or to restrict how we use it;
- object to our using it on the basis of legitimate interests;
- ask for data you gave us in a format you can take elsewhere.
Email [email protected] with "Data protection" in the subject. We may need to confirm who you are. We will respond within one month, and tell you if we need longer for a complex request. There is normally no charge.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first at [email protected]. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome without undue delay.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator: ico.org.uk/make-a-complaint, or 0303 123 1113.
Changes to this policy
We will update this policy when how we handle personal data changes. The date at the top shows when it last changed. If a change affects our customers significantly, we will tell them directly.