Privacy Policy

Last updated: 31.07.2026 · Oxirgi yangilanish: 31.07.2026

English O‘zbekcha

1. Who we are

5CRM (https://5crm.uz) is a customer relationship management (CRM) and marketing platform operated in Uzbekistan. Businesses ("Customers") create an account and use 5CRM to manage their own customers, sales pipelines, calls, messages and advertising results.

Contact: [email protected]

2. Our role

For data that a business uploads or connects (its leads, contacts, messages, ad results), the business is the data controller and 5CRM acts as a data processor on its instructions. For account and billing data of the business itself, 5CRM is the controller.

3. What data we process

CategoryExamplesSource
Account dataBusiness name, user name, login, email, phone, roleProvided by the Customer
CRM dataLeads, contacts, deals, tasks, notes, call recordsCreated by the Customer or its integrations
Facebook / Instagram dataLead Ads submissions, page and ad identifiers, ad performance, Instagram Direct messages, comments, media and their metricsMeta APIs, only after the business owner explicitly authorises the connection
Technical dataIP address, browser, device, timestamps, action logAutomatically, for security and audit

4. Facebook & Instagram data — specifics

  • We request access only after an authorised administrator of the business connects their Facebook Page / Instagram Business account through the official Meta login dialog.
  • We use the data solely to provide the requested features to that same business: delivering leads into its CRM, showing and answering its Instagram Direct messages and comments, and reporting the performance of its own posts and ads.
  • We do not sell this data, do not use it for advertising to third parties, and do not transfer it to any other business inside 5CRM. Each business is stored in a separate, isolated database.
  • Access tokens are stored encrypted and are never shown to other users.
  • A business can disconnect the integration at any time. Disconnection immediately stops any further data collection from Meta and deletes the Instagram content we hold — posts, comments and their statistics. Customer records already created in the CRM belong to the business and remain; they can be deleted separately at any time.

4a. Telegram account connection and the shared lookup network

A business may connect its own Telegram account to 5CRM. This is optional. When connected, we store an encrypted session token so the platform can send and receive messages on that business's behalf.

Shared lookup network. A connected account also performs phone-number lookups — checking whether a given phone number has a Telegram account. These lookups may be made on behalf of other businesses using 5CRM, and in return that business's own lookups may be performed by other connected accounts. This shared capacity is what makes the feature work at all: Telegram applies strict per-account rate limits, so a single account cannot serve a whole business.

What a connected account never does for others: it does not send messages, does not read chats, does not join groups, and does not expose your contacts, your customer data, or your message history to any other business. Only the technical question "does this number exist on Telegram?" is answered, and only the requesting business receives the answer.

Limits and control. Each account has a daily lookup cap that starts low for newly connected accounts and increases with account age. You can disconnect your Telegram account at any time from Settings → Integrations → Telegram; the shared lookups stop immediately and the stored session is deleted.

4b. WhatsApp Business data — specifics

A business may connect its own WhatsApp Business account through the official Meta WhatsApp Cloud API. This is optional and is done by an authorised administrator of that business.

  • What we receive: messages that customers send to that business — text, images, audio, video and documents — together with the sender's WhatsApp phone number and the message timestamp. Media files are downloaded so the business's own team can view them inside the CRM.
  • What we send: replies written by that business's team. Following Meta's rules, free-form replies are only possible within 24 hours of the customer's last message; outside that window only message templates approved by Meta can be used.
  • We never initiate contact with people who have not messaged the business first. We do not send marketing blasts and we do not import external phone lists into WhatsApp.
  • Isolation: each business's WhatsApp data is stored in its own separate database and is never shown to, or shared with, any other business inside 5CRM.
  • Security: the access token is stored encrypted and is never displayed to users — the interface only shows a masked value.
  • Disconnection: a business can disconnect WhatsApp at any time. Message delivery stops immediately and the stored token is removed. Conversations already saved in the CRM belong to the business and can be deleted separately, or removed entirely on request.

4c. Compliance with Meta terms

We comply with the Meta Platform Terms and the Meta Developer Policies. Platform Data received from Facebook, Instagram or WhatsApp is used only to provide the features described in this policy to the business that authorised the connection. We do not sell it, do not use it for advertising to third parties, and do not transfer it to any other business. When a business revokes access, or when we no longer need the data for the purpose it was collected for, the Platform Data is deleted. Requests to delete data can also be made at any time — see our Data Deletion page.

4d. Government and legal requests

We may receive requests for user data from courts, law-enforcement bodies or other public authorities. Our practice for handling them is as follows.

  • We check that the request is lawful. Every request is reviewed to confirm it comes through valid legal process and has a proper basis under the applicable law of the Republic of Uzbekistan. We do not disclose data on an informal or verbal request.
  • We disclose the minimum necessary. We provide only the specific data the request actually requires, and nothing beyond its stated scope.
  • We challenge requests we consider unlawful. Where a request appears overbroad, unlawful or improperly issued, we push back or contest it through the available legal channels.
  • We document every request. Each request, our legal reasoning, who was involved and what was disclosed is recorded and retained.
  • Platform Data. Data received from Meta is treated the same way, in line with the Meta Platform Terms.

5. Why we process data (legal basis)

  • Contract — to provide the service the Customer subscribed to.
  • Legitimate interest — security, abuse prevention, service improvement.
  • Consent — where required, e.g. connecting a Meta account.

6. Sharing

We do not sell personal data. We share it only with infrastructure providers strictly necessary to run the service (hosting, telephony, e-mail delivery, AI text processing), each acting under contract and only for that purpose, and with authorities where legally required.

7. Retention

  • Active account data — for as long as the account exists.
  • After account closure — deleted or anonymised within 90 days, unless the law requires longer.
  • Technical logs — up to 12 months.
  • Data deleted on request — see Data Deletion Instructions.

8. Security

Encrypted transport (HTTPS), encrypted storage of tokens and secrets, per-business database isolation, role-based access control, device binding and session control for operators, and a full audit trail of changes.

9. Your rights

You may request access, correction, deletion, restriction, or a copy of your data by writing to [email protected]. We respond within 30 days. If you are an end customer of a business that uses 5CRM, please contact that business first — it controls the data.

10. Children

The service is intended for businesses. We do not knowingly collect data from children under 16.

11. Changes

We publish any change on this page and update the date above. Material changes are also announced inside the product.

Mobile application (5CRM Operator)

We publish a native Android application, 5CRM Operator (package uz.crm.operator). It gives an operator access to their own work cabinet: employment history, personal performance figures, connected workplaces and security settings.

What the app collects

  • Account data — e-mail address and name you registered with. Used to sign you in.
  • Device information — manufacturer and model, shown to you in «My devices» so you can recognise where your account is signed in.
  • IP address — recorded with each sign-in for security notifications and to let you review unfamiliar activity.

What the app does NOT collect

  • Biometrics. Your fingerprint or face never reaches our servers. The phone verifies you locally and only reports success or failure.
  • Passkey private keys. A passkey is created and stored inside the secure hardware of your device. We only store the public key, which cannot be used to impersonate you.
  • Contacts and your photo gallery. Never accessed.
  • Camera — only for attendance face check (see below), and only while that screen is open. The QR scanner runs inside Google Play Services and returns only the scanned text. The app never records video and never opens the camera in the background.
  • Location — only if your employer turns on attendance (see below). Otherwise never requested.
  • We do not use advertising identifiers and we do not share app data with advertisers.

Deleting your account from the app

Open Profile → Danger zone → Delete account and confirm with your password. Access is revoked immediately. The account and all related data (work history, statistics, passkeys, devices, sessions) are permanently erased after 30 days; within that period you can restore it by signing in again. Residual backup copies are removed within 90 days. The same request can be made at 5crm.uz/data-deletion.

Deleting your operator cabinet does not delete the employee record that a business keeps in its own workspace — that data belongs to the business as data controller.

Attendance (only if your employer enables it)

A business can switch on attendance for its own workspace. If it is switched on, the app shows «I have arrived» / «I am leaving» buttons for that workplace. If it is off, the feature does not appear at all and nothing is collected.

  • Location is read only at the moment you press the button and sent once. There is no background tracking — the app does not hold the ACCESS_BACKGROUND_LOCATION permission and cannot follow you during the day.
  • A selfie is taken with your phone’s own camera app and attached to that check-in. It is stored privately, is never published, and is visible only to the owners of that workspace.
  • If the workspace has an office point configured, we compute the distance to it and record whether you were inside the allowed radius.

This data belongs to your employer, which is the data controller for it. Deleting your operator cabinet does not erase the attendance records that the business keeps.

Face verification (biometric data)

If your employer turns on face verification for attendance, the app asks you to show your face when you mark «I have arrived» / «I am leaving». This is used for one purpose only: to confirm that the person marking attendance is really you.

  • What is stored is a mathematical template, not your photo. During enrolment your employer takes a few frames; each is converted into a list of numbers (a face template). The template is stored encrypted and cannot be turned back into a picture.
  • Enrolment is done by your employer, in their workspace. The template belongs to that workspace only and is never shared with other businesses on the platform.
  • Liveness. Two frames are taken (one facing the camera, one with your head turned) so that a printed photo cannot be used in your place.
  • Processing happens on our own servers. Face data is never sent to any third-party recognition service and is never used for advertising or profiling.
  • Deletion. Ask your employer to remove your face template at any time; it is deleted immediately. Deleting your operator cabinet also removes it.
  • If face verification is off, none of this is collected and the camera is never opened for it.

This data belongs to your employer, which is the data controller for it.