Skip to content
Privacy Statement

Your data is yours. We just process it for you.

This is a plain-English explanation of what data TriarchCRM handles, who controls it, where it lives, who else touches it, and how to exercise your rights. We've kept the legalese to a minimum.

Effective date: June 17, 2026

The short version

Who controls your data

When your firm uses TriarchCRM, you are the data controller, it's your CRM and advisory data, and you decide what goes into the platform and why. Triarch acts as a processor, running the software and infrastructure on your behalf. We process the data to provide the service to you; we don't sell it, and we don't repurpose it for our own ends.

What data the platform processes

TriarchCRM processes the operational data your firm puts into it and the signals you connect to it, including:

  • CRM and advisory records you create, companies, contacts, deals, engagements, contracts, finance and billing data.
  • Content from connected sources you choose to link, for example email, calendar, messaging, banking, and CRM integrations.
  • Contact details that may include personal data such as names, email addresses, and phone numbers.
  • Account and usage information needed to operate, secure, and audit your instance, including the audit log of access and actions.

You decide which sources to connect and what to load. The intelligence features of the platform derive insights from this data to help you run your operation.

We practice data minimization on connected sources. Only a redacted snippet of source content is retained in the database, with personal data stripped so that no PII is persisted in plain form. Anything that escapes redaction is encrypted in transit and at rest, and is decrypted only at runtime when needed to serve your instance.

Data isolation & retention

Each customer runs on a dedicated, single-tenant deployment, its own cloud project, its own database, and its own domain. Your data is never commingled with another customer's, and there is no shared multi-tenant database. For the technical detail of how this works, see our security page.

Retention follows your account. Your data persists for as long as your subscription is active. On account termination, your tenant and its dedicated environment are deleted, and backups may be retained for up to 30 days afterward before they are purged. Specific terms are set in the agreement between us.

Sub-processors

To deliver TriarchCRM, we rely on a small set of infrastructure providers that may process data on our behalf:

Google Cloud / Firebase

Hosting, application runtime, identity provider, and key management (KMS).

CockroachDB Cloud

The managed database that stores your instance's data.

Your chosen LLM provider

For AI features, under your own key, e.g. Anthropic, OpenAI, or Google, configured for no training and zero retention.

Because AI runs on a bring-your-own-key basis, your firm chooses the LLM provider, and AI calls over your data require an attested no-training / zero-data-retention configuration.

Security measures

We protect your data with isolation by architecture, KMS-backed encryption of sensitive PII fields at rest, TLS in transit, hardened authentication with short-lived server-signed sessions in httpOnly cookies, role-based access control, and an audit log. The full description lives on our security page.

Data subject requests

If an individual whose personal data appears in your instance wishes to access, correct, or delete that data, those requests are generally directed to your firm as the data controller. As your processor, Triarch will support you in responding to such requests in line with our agreement and applicable law.

Contact

Questions about this statement or how we handle data? Reach us at privacy@triarchcrm.com. For security matters, contact security@triarchcrm.com.

This statement describes current practices and may be updated. Material changes will be reflected here with a revised effective date.

Want the technical detail?

See exactly how isolation, encryption, and access control are engineered into the platform.