What happens to your data, what we do and don't do with it, and the standards KamoCRM is built to align with.
Your data is yours
The information your organization puts into KamoCRM belongs to your organization. It isn't sold, it isn't shared with other customers, and it isn't used to build products for anybody else.
GDPR
KamoCRM is built to align with GDPR, which matters whether or not you're in Europe — if any of your customers are, it applies to you.
In practice that means the things GDPR requires are possible rather than theoretical: a person's records can be found, exported and deleted; access to personal data is logged; and the separation between organizations is enforced in the data layer rather than by convention.
Health information
If your organization handles medical information, KamoCRM has a specific mode for it. Turning on PHI handling changes behavior across the product: access to patient records is audited individually, and clinical features become available.
It isn't a checkbox to try. What Turning On PHI Handling Does explains what changes before you change it, and The PHI Access Audit covers the trail it produces.
SOC 2
KamoCRM's controls are built in alignment with the SOC 2 framework — access control, change management, monitoring and incident response. If your procurement process needs formal documentation of current attestation status, ask through Getting Support; that's a question with a specific answer at a specific date, and this page isn't the right place to give it.
AI and your data
The AI Assistant answers from your own organization's data. Knowledge base articles are used to train it only when marked for it, and even then the audience rules on the article still apply — a team-only article is never quoted to a customer.
If your organization connects its own AI provider, your data goes to that provider under your agreement with them. AI Providers Explained covers what that means.
Asking a specific question
Compliance questions usually have a specific answer that depends on your industry, your country and your contract. A help center page can tell you how the platform is built; it can't tell you whether that satisfies your regulator. Ask, and get an answer you can put in front of them.
Related articles
Other guides that answer questions close to this one.
How Your Data Is Encrypted
Encryption appears in three places, and they protect against three different things. In transit Everything between your browser and KamoCRM is encrypted with TLS — the same technology as the padlock in your address bar.…
Who Can See Your Data
The honest version, including the parts that are usually left out. Other customers: never Organizations are separated in the database itself. Every query is scoped to one organization before it runs, so there is no…
Uptime, Backups and Disaster Recovery
What happens when something breaks, and what you can expect while it's being fixed. The target KamoCRM is offered against a 99.9% uptime commitment. That's about 43 minutes of unavailability in a month — and it's a…
Where Your Data Is Stored
Three kinds of storage, holding three different sorts of thing. Records Anything with fields — leads, accounts, contacts, calendar events, timecards, settings — lives in a distributed SQL database. "Distributed" means…
How KamoCRM Is Built
You don't need to know any of this to use KamoCRM. It's here because IT teams, security reviewers and procurement people ask, and it's easier to hand them a page than to arrange a call. Many small services, not one big…