Legal information

Security Policy

Last updated: October 3, 2026.

GixiCRM applies reasonable technical and organizational measures to protect the service and information managed by our customers. This page summarizes our general security practices.

1. Communications security

The website and authenticated areas should operate over HTTPS to protect information while it travels between your browser and our servers. No Internet-connected transmission or storage method can guarantee absolute security.

2. Access and authentication

CRM access is controlled through user accounts, sessions, and permissions. Each customer is responsible for granting only the access required, protecting credentials, and promptly disabling users who should no longer have access.

3. Operations and maintenance

We perform maintenance and updates intended to reduce vulnerabilities, correct defects, and maintain service continuity. We also apply controls to files, configurations, and sensitive functions according to the platform’s operational needs.

4. Backups and recovery

Backup frequency and retention depend on the infrastructure and subscribed service. We recommend that each customer maintain its own review and export procedures for business-critical information.

5. Providers and integrations

Some features may depend on external hosting, authentication, email, messaging, calendar, or payment providers. Those services apply their own security measures, terms, and policies.

6. Reporting incidents

If you identify unauthorized access, a vulnerability, or suspicious activity involving GixiCRM, report it to [email protected] with the information needed to investigate. Avoid publishing sensitive data or details that could increase the risk.

7. Customer responsibility

Security also depends on system configuration and use. We recommend strong passwords, protected access devices, regular permission reviews, and current email addresses and phone numbers for all accounts.