CMS Group · CMS Connect

Privacy Policy

How CMS Connect, CMS Group's CRM, collects, uses, and safeguards information across its web application and its Android and iOS apps.
Effective
September 15, 2026
Version
1.1
Applies to
CMS Connect — crm.cmsgrps.com, Android & iOS

Quick summary

Collect

Your work account details, the contact, company, and project records you enter on the company's behalf, and technical/security data such as login times and IP address. On the mobile apps, location and push notifications are required; camera/photos, file attachments, and phone contacts are optional.

Share

Other authorized CMS Group staff using the CRM, and the service providers that host and operate the Service for us. We never sell information or use it for advertising.

Control

Ask us to access, correct, or delete your personal account details at any time. On the mobile apps, camera and contacts access are yours to control, while location and notifications are required to use them.

§01 About This Policy

This Privacy Policy explains how CMS Group ("CMS Group," "we," "us") collects, uses, shares, and protects information through CMS Connect, our CRM, made available as a web application at crm.cmsgrps.com and as mobile apps for Android and iOS (together, the "Service").

The Service is an internal business tool. Access is provisioned to authorized CMS Group employees and personnel by a CMS Group administrator, and it is not offered to the general public or intended for personal, consumer use.

Some of the information handled by the Service — the contact, company, and project records our staff enter — relates to CMS Group's business contacts rather than to the staff using the Service. Section 02 explains this distinction in more detail.

By using the Service, you agree to the practices described in this Policy. If you have questions, Section 10 tells you how to reach us.

§02 Information We Collect

2.1 Account & profile information

When your administrator sets up your account, we collect your name, work email address or username, role, and the CMS Group entity or department you belong to. Accounts are issued and removed by your administrator — you cannot self-register for the Service.

2.2 CRM business data you enter

The Service's core purpose is managing business relationships, which necessarily involves collecting and storing personal information about CMS Group's business contacts — customers, vendors, and partners. As you use the Contacts, Companies, and Projects modules — on the web or in the mobile apps — the Service stores the records you create or edit: names, phone numbers, email addresses, physical addresses, company details, project notes, and similar business information. This information belongs to CMS Group's business records rather than to individual users of the Service, and is entered and processed on the company's behalf as part of its ordinary business operations.

These details are understood to be provided directly by the business contact themselves — for example, when they share a phone number or business card with a CMS Group employee — in the ordinary course of doing business with CMS Group, for the evident purpose of enabling that relationship.

2.3 Mobile app permissions

The permissions below apply to the Android and iOS apps specifically; the web application at crm.cmsgrps.com does not request device permissions the same way. The mobile apps request the permissions below through your device's standard permission prompt. Location and push notifications are required to use the mobile apps — each item below explains why, and what to do if you'd rather not grant one. Camera/photo library and phone contacts are optional, requested only when you use a feature that needs them, and can be granted, denied, or withdrawn at any time in your phone's Settings without affecting the rest of the app. Attaching a file works differently: you pick each file yourself through your device's file picker, so there's no separate permission to grant or withdraw.

Location — Required on the mobile app

Used for location-based CRM features such as field-visit check-ins and the activity map, and collected only while the relevant screen is open. Granting this permission is required to use the mobile app. If you'd prefer not to, contact your supervising director.

iOS: NSLocationWhenInUseUsageDescription · Android: ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION

Camera & photo library — Optional · you control this

Lets you attach a photo — a product shot, a signed document, a site photo — to a contact, company, or project record.

iOS: NSCameraUsageDescription, NSPhotoLibraryUsageDescription · Android: CAMERA, READ_MEDIA_IMAGES

Files & documents — Optional · you choose each file

Lets you attach a file — a quote, an invoice, a signed contract, a spreadsheet — to a contact, company, or project record. You select the file yourself through your device's built-in file picker each time; the app only receives the specific file you choose, not broader access to your device's storage.

iOS: Files app / document picker — no separate permission · Android: Storage Access Framework document picker — no separate permission

Phone contacts — Optional · you control this

Optionally matches or imports entries from your phone's address book, so you don't have to retype contacts that already exist on your device into the CRM.

iOS: NSContactsUsageDescription · Android: READ_CONTACTS

Push notifications — Required on the mobile app

Delivers alerts for tasks assigned to you, project updates, and similar CRM activity, using a device notification token issued by Apple's or Google's push service. Granting this permission is required to use the mobile app. If you'd prefer not to, contact your supervising director.

iOS: Push notification entitlement · Android: POST_NOTIFICATIONS (Android 13+)

2.4 Technical & diagnostic data

Like most software, we automatically collect some technical data needed to keep the Service working and secure: device model and OS version on mobile, or browser and operating system on the web; app or software version; general crash and error logs; and basic usage such as which modules are opened. We also log login activity — sign-in and sign-out timestamps, session duration, and IP address — to help secure accounts and investigate suspicious activity, and the web application uses cookies or similar technologies to keep you signed in between visits. This data is tied to your account, is not sold, and is used only to run, secure, and improve the Service.

§03 How We Use Information

We use the information described above to:

  • Operate the CRM. Run the Contacts, Companies, Projects, and Dashboard modules, and keep your data in sync across your devices.
  • Authenticate and authorize you. Confirm who you are and enforce role-based access to CMS Group's records.
  • Notify you. Send task assignments, project updates, and similar alerts you're entitled to see.
  • Maintain and improve the Service. Diagnose crashes, fix bugs, and understand which features are used so we can prioritize what to build next.
  • Protect CMS Group and our staff. Secure our systems and investigate misuse.

We do not use Service data for third-party advertising, and we do not build advertising profiles of Service users.

§04 How Information Is Shared

We share information only in the following circumstances:

  • With other authorized CMS Group staff. The Service is a shared business tool — colleagues with appropriate access can see contact, company, and project records, consistent with their role.
  • With service providers who run the Service for us. We use third-party infrastructure to host our backend, store data, and deliver push notifications — for example, cloud hosting and database providers, and Apple's or Google's push notification services. These providers may only process data on our instructions and under confidentiality obligations. Current hosting/backend provider: Himalayan Hosting.
  • With app store platforms (mobile apps only). Apple and Google receive limited technical data, such as device and crash information, as part of operating the App Store and Google Play.
  • For legal reasons. We may disclose information if required by law, to protect CMS Group's rights, or to investigate misuse of the Service.
  • In a business transfer. If CMS Group reorganizes, merges, or transfers part of its business, Service data may transfer as part of that transaction, subject to this Policy.

We do not sell personal information, and we do not share Service data with third parties for their own marketing purposes.

§05 Data Storage & Security

Data is transmitted using industry-standard encryption (HTTPS/TLS) and encrypted at rest in storage. Access to CRM data is restricted to authorized staff based on their role, and administrator accounts control who can be provisioned or removed from the Service. Primary hosting region: Nepal.

No method of transmission or storage is completely secure. If we become aware of a security incident affecting your information, we will notify affected users and appropriate authorities as required by law.

§06 Data Retention

We retain account and CRM data for as long as your account is active and as needed for CMS Group's legitimate business purposes — for example, maintaining a continuous record of customer and project history.

When someone leaves CMS Group or an account is deactivated, we retain the business records they created, since these belong to CMS Group's ongoing operations rather than to the individual, and we remove or restrict access to their personal account data within a reasonable period. This doesn't apply where we're required to keep information longer for legal, accounting, or dispute-resolution purposes.

§07 Your Rights & Choices

Access and correction. You can review and update most of your account details in the Service, or by asking your administrator.

Delete your personal account information. You, or your administrator on your behalf, can request deletion of your own personal account details — such as your name, work email, and login credentials — using the account deletion or personal data deletion request pages, or by contacting sadrish@cmsgrps.com. We'll act on verified requests within a reasonable time, subject to the retention exceptions in Section 06. Because the CRM's contact, company, and project records are shared business data entered on CMS Group's behalf and relied on by other staff, they remain part of CMS Group's business records rather than being deleted along with an individual account. This same contact method is available to anyone who wants to request deletion of their personal account information after leaving CMS Group or no longer using the Service, including after uninstalling the mobile app.

Mobile app permissions. Camera and phone-contacts access are optional — grant, deny, or withdraw either at any time from your phone's Settings without affecting the rest of the app. Attaching a file works differently: you choose each file yourself through your device's file picker, with no separate permission involved. Location and push-notification access are required to use the mobile app, since the CRM depends on them for core functionality there; if you'd prefer not to grant these, contact your supervising director.

Questions from business contacts. If you're a customer, vendor, or partner whose details a CMS Group employee has entered into the Service, and you have a question about how that information is used, you can reach us using the same contact details in Section 10 — this isn't limited to CMS Connect's own staff.

§08 Children's Privacy

The Service is a workplace tool for CMS Group personnel. It is not directed at children, and we do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us with personal information, contact us using Section 10 and we will delete it.

§09 Changes to This Policy

We may update this Policy as the Service evolves — for example, as new modules such as outbound communication or a sales pipeline view are added. We'll revise the effective date above, and for material changes we'll notify staff through the Service or by email before the changes take effect.

§10 Contact Us

Questions about this Policy, or requests relating to your information, can be sent to:

CMS Group
sadrish@cmsgrps.com