How CommitControl collects, uses, discloses, processes, and safeguards information when you use our platform, website, integrations, and related services.
ZeusGlobal Nexus Limited, trading as CommitControl or CommitControl.com ("CommitControl", "we", "our", or "us"), is committed to protecting your privacy and handling personal data transparently and securely. CommitControl is a cloud-based commercial intelligence and revenue operations platform that integrates with enterprise CRM systems to provide sales pipeline visibility, commercial risk analysis, forecasting support, analytics, workflow intelligence, and operational reporting. CommitControl also offers optional messaging integrations Slack and Microsoft Teams that deliver risk briefings to a channel you choose.
CommitControl is operated by ZeusGlobal Nexus Limited, a private company limited by shares registered in Ireland under the Companies Act 2014 (company no. 820109), registered office 77 Camden Street Lower, Dublin D02 XE80, trading as CommitControl.com. Email: legal@commitcontrol.com. Data protection contact: Brian Bendera,Founder, legal@commitcontrol.com.
Account and identity information: name, business email address, company name, job title, telephone number, user account credentials, authentication metadata, and profile information.
Business and CRM data: depending on integrations and customer configuration, we may process contacts and leads, opportunities and deal records, quotes and orders, notes and activity logs, sales pipeline information, forecasting metadata, commercial analytics data, custom CRM fields, and uploaded customer datasets.
Billing and subscription information: billing address, subscription details, payment identifiers, transaction metadata, and VAT or tax information. Payment card information is processed by third-party payment providers and is not stored directly by CommitControl.
Usage and telemetry data: IP addresses, device identifiers, browser type, operating system, login timestamps, session activity, feature usage metrics, error logs, API request metadata, and audit and security logs.
Cookies and tracking technologies: we use cookies and similar technologies for authentication, session management, security, analytics, preferences, and performance optimization.
We process personal data to provide and operate the Service, authenticate users and manage accounts, support CRM integrations, process billing and subscriptions, monitor platform performance and reliability, detect fraud, abuse, and security threats, provide customer support, improve product functionality, generate analytics and reporting, comply with legal obligations, and enforce contractual rights.
Where GDPR applies, we rely on contract performance to provide the Service, manage subscriptions, authenticate users, support integrations, and deliver analytics and reporting.
We rely on legitimate interests for service security, fraud prevention, platform monitoring, product improvement, reliability engineering, usage analytics, and customer communications, subject to balancing assessments.
Where required by law, we rely on consent for marketing communications, optional analytics cookies, and certain tracking technologies. We may also process data to comply with tax obligations, respond to lawful requests, meet regulatory requirements, and enforce legal rights.
If we contacted you and you have never been a CommitControl customer, this section is the one that applies to you. It is our notice under Article 14 GDPR, which covers personal data we did not obtain from you directly.
What we hold: business contact data only. Name, job title, employer, business email address, and publicly stated company attributes such as industry, headcount band, and location. We do not seek or hold special category data, and we do not hold personal financial data about prospects.
Where it came from: business contact data providers, principally Apollo, together with publicly available professional sources such as company websites and professional networking profiles.
Why we process it: to contact people in roles likely to have a professional interest in forecasting and revenue software, and to measure whether that outreach is working. Our legal basis is legitimate interests under Article 6(1)(f), namely direct business-to-business marketing, balanced against your interests and rights. Where electronic marketing rules require consent, we rely on consent instead.
How long we keep it: until you ask us to stop, until it becomes inaccurate, or until it has produced no engagement for 24 months, whichever is soonest. Suppression records are kept indefinitely for the sole purpose of ensuring we do not contact you again.
Your rights: you can object to this processing at any time, and we will stop. You do not need to give a reason, and objecting to direct marketing is an absolute right under Article 21(2). You can also request access to what we hold, correction, or erasure. Email legal@commitcontrol.com, or reply to any message we sent you and say stop. Either route works and both are actioned the same way.
Complaints: if you are unhappy with how we have handled your data, you can complain to the Irish Data Protection Commission at dataprotection.ie, or to the supervisory authority in your own country.
We use carefully selected third-party service providers to operate the Service, including cloud infrastructure providers, authentication providers, payment processors, email delivery providers, analytics providers, security monitoring vendors, and customer support platforms. Our subprocessor list is maintained in our Security & Data Processing page, which separates providers that process customer data under contract from those that process only website and prospect data.
You may choose to connect CommitControl to your own CRM (such as Salesforce) and to messaging platforms (Slack and Microsoft Teams). These integrations are optional and enabled by you. When connected, CommitControl shares data with these platforms only at your direction for example, posting a Weekly Risk Briefing to the Slack or Teams channel you select. Connection credentials are encrypted, and you can disconnect an integration at any time from your account settings.
Where personal data is transferred outside the European Economic Area, CommitControl implements appropriate safeguards, which may include EU Standard Contractual Clauses, adequacy decisions, contractual protections, and technical safeguards.
CommitControl implements technical and organisational security measures designed to protect personal data, including encryption in transit, encryption at rest where appropriate, tenant isolation controls, role-based access controls, least privilege access management, MFA for administrative access, audit logging and monitoring, vulnerability management, backup and recovery procedures, secure software development practices, and incident response procedures.
We retain personal data while accounts remain active, as necessary to provide the Service, for legitimate business purposes, and to comply with legal obligations. Billing and tax records may be retained for up to seven years. Security logs and backups are retained according to operational security and internal retention schedules. Following account termination, data may be deleted or anonymised in accordance with our retention policies and contractual obligations.
Subject to applicable law, you may have the right to access your personal data, correct inaccurate data, delete personal data, restrict processing, object to processing, withdraw consent, receive data portability, and lodge a complaint with a supervisory authority. To exercise these rights, email legal@commitcontrol.com. We aim to acknowledge requests within 24 hours and respond substantively within 30 days.
Essential cookies are required for authentication and core platform functionality. Analytics cookies help us understand Service usage and improve performance. Preference cookies remember settings and preferences. Users may manage cookies through browser settings or platform cookie controls.
The Service is not intended for individuals under the age of 16. If we become aware that personal data has been collected from a child without lawful basis, we will take reasonable steps to delete the information.
We may update this Privacy Policy from time to time. Material changes may be communicated through email notification, in-product notices, or website publication. Continued use of the Service after updates constitutes acceptance of the revised policy.
ZeusGlobal Nexus Limited, trading as CommitControl.com. Email: legal@commitcontrol.com.
Application and CRM storage are in Frankfurt. Limited US processing by the explanation layer is disclosed in the data processing terms.