Privacy Policy

Last updated: April 2026. Questions? Email support@unavoidablem.com

๐Ÿ”’ Your data and security are our number one priority

1. Who We Are

Unavoidable Marketing Ltd (company number 08013355) operates the Unavoidable Marketing CRM platform. Our registered address is 152 Osmondthorpe Lane, Leeds, LS9 9EG. We are the Data Controller for your personal data.

We take privacy seriously. This policy explains what data we collect, why we collect it, how it is used, and your rights under UK GDPR and the Data Protection Act 2018.

2. What Data We Collect

Account data

Usage data

Client data you store in the CRM

When you import contacts, create jobs or log communications, that data is stored on your behalf. You are the Data Controller for your clients' data. We are the Data Processor. See our Data Processing Agreement for full details.

๐Ÿ’ก We never sell your data or your clients' data to third parties. We never will. Your data is yours.

3. How We Use Your Data

4. Security - Our Number One Priority

๐Ÿ”
Encrypted passwords
All passwords are hashed with bcrypt (cost factor 12). We cannot see your password.
๐Ÿ”’
HTTPS everywhere
All data in transit is encrypted using TLS 1.2+. HTTP is automatically redirected to HTTPS.
๐Ÿ›ก๏ธ
Two-factor authentication
2FA via TOTP (Google Authenticator compatible) is available for all accounts.
โฑ๏ธ
Session timeout
Sessions expire after 30 minutes of inactivity to protect unattended devices.
๐Ÿšซ
Brute force protection
Login attempts are rate-limited and accounts are temporarily locked after repeated failures.
๐Ÿข
Data isolation
Each company's data is strictly isolated. No account can access another's data.
๐Ÿ”‘
API key encryption
Third-party API keys (Twilio, Bland.ai etc.) are encrypted before storage.
๐Ÿ“‹
CSRF protection
All forms include CSRF tokens to prevent cross-site request forgery attacks.

5. Data Retention

We retain your account data for as long as your subscription is active. After cancellation, your data is retained for 30 days to allow recovery, then permanently deleted. You can request immediate deletion at any time by contacting us.

Backups are retained for up to 90 days and are then permanently destroyed.

6. Your Rights Under UK GDPR

To exercise any of these rights, email dpo@unavoidablem.com. We will respond within 30 days.

7. Cookies

We use strictly necessary session cookies only. We do not use tracking cookies, advertising cookies or third-party analytics cookies. No cookie banner is required because we only use cookies that are essential for the service to function.

8. Third-Party Services

We use the following third-party services to operate the platform:

Each processor is subject to a Data Processing Agreement. We only share the minimum data necessary for each service to function.

9. Contact & Complaints

Data Protection Officer

For any privacy-related queries, data subject requests or complaints:

dpo@unavoidablem.com  |  support@unavoidablem.com

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection authority.