
From day one, Onpipeline was designed with privacy in mind.
We wanted to help our customers, while keeping privacy at the core.
Simple navigation and consultation of the website do not generally involve the gathering of users personal data and only relate to the processing in anonymous form of so-called navigation data.
This Notice applies to the processing of Personal Data collected by us when you:
This Privacy Notice describes our privacy practices and addresses certain privacy and data protection frameworks relevant to our Services, including, where applicable, the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
References to these laws do not mean that every provision applies to every individual or processing activity. The applicability of a particular law depends on the circumstances and the scope of that law.
Data controlled and processed by us
Where we are required to identify a legal basis for processing Personal Data, we rely on one or more of the following:
Where identifying a legal basis in this manner is not required, we process Personal Data for the purposes described in this Privacy Notice.
Customers may submit or upload Personal Data relating to third parties into the Services (“Customer Data”). Customers are responsible for ensuring that they are authorized to collect, use and submit Customer Data to the Services and for providing any notices or obtaining any permissions required for their processing activities.
Onpipeline processes Customer Data only for the purpose of providing, operating, maintaining and securing the Services requested by the Customer, and does not independently determine the purposes for which Customer Data is collected or used by the Customer.
Our Clients have the option to integrate certain services provided by third parties (i.e. calendars provided by Google, Microsoft, etc.). By authorizing us to connect with a third party, Clients authorize us to access and store information that the Integrated Service makes available to us, and to use and disclose it in accordance with this Policy. We consider data from integrated services as “data collected and entered by Clients”. Please refer to privacy settings and terms of use of each Integrated Service to understand what information they make available to us.
We may work with external providers for development, hosting, systems maintenance, etc. Real data is not accessible in case of external developers, but third parties may have access to data as part of providing their services. We always limit the information provided to what is reasonably necessary, and our agreements ask them to maintain confidentiality. Third parties that have access to data and might potentially process personal information are listed in the processors section.
The rights described in the section “Rights of the User” apply to all users, including California residents. In accordance with the California Consumer Privacy Act (CCPA), California residents have the right to:
Onpipeline does not sell or share Personal Information as those terms are defined under the CCPA.
California residents may exercise their rights using the same contact details and procedures indicated in the “Rights of the User” section. We may need to verify the requester’s identity before responding, in accordance with the CCPA.
We offer HIPAA-compliant processing, including the execution of a Business Associate Agreement (“BAA”), only under the Advanced plan.
If a Client requires Onpipeline to process Protected Health Information (“PHI”) as a Business Associate, a BAA must be executed before the Client uses the Services to store, transmit or otherwise process PHI. Unless a BAA is in place, Clients must not upload, store or process PHI within the Services. In such circumstances, Onpipeline does not act as a Business Associate and does not assume Business Associate obligations under HIPAA.
If Clients connect third-party services, including cloud storage, communication or other software, through APIs or integrations, Clients are responsible for determining whether those services satisfy any legal, regulatory or contractual requirements applicable to the Client’s use of those services. Onpipeline does not guarantee the HIPAA compliance of third-party services and is not responsible for processing performed independently by those providers outside Onpipeline’s controlled environment.
Individuals may exercise the privacy rights provided by the legal framework applicable to the relevant processing. Depending on that framework, such rights may include:
Where Personal Data must be retained for legal, regulatory, accounting, security, dispute-resolution or similar purposes, such data will be retained only for the relevant purpose and for the period required or permitted for that purpose.
Privacy requests may be submitted to: privacy@onpipeline.com – Onpipeline may request information reasonably necessary to verify the identity of the requester and to process the request in accordance with the relevant legal framework.
Onpipeline undertakes to maintain the security of all data gathered using technical and organisational tools. The safety measures are aimed at reducing to the minimum the risk of destruction or loss of data and the risk of unauthorised access, and they include the possibility of limiting access to the data to authorised Onpipeline personnel alone. Onpipeline employees acknowledge that they are bound by standards of data security and data confidentiality.
All data is held only for a period of time strictly necessary for the purposes for which the data was gathered. Without prejudice to the right to immediately block the use of data for commercial and marketing purposes, it may prove necessary to hold the data for a further period of time for purposes of satisfying legal provisions or for accounting and administrative purposes.
Upon termination of the Service, “data collected and entered by Clients” is deleted from active systems within 30 days from the effective date of termination. Residual copies may be retained in encrypted and access-restricted backup systems for a limited period of up to 180 days, after which they are permanently deleted or irreversibly overwritten.
In the future, modifications to this Privacy Policy may be introduced for purposes of ensuring ongoing compliance with applicable legal rules. We invite Users to carefully read the rules applied by ourselves for the gathering and processing of personal data.
For questions regarding this Privacy Notice or our privacy practices, please contact:
privacy@onpipeline.com
Onpipeline Limited
The Black Church, St. Mary’s Place
Dublin 7 (Ireland), Reg. No. 679560
Last update: June 4, 2026
Cookies are fragments of text sent by a server to a client (browser) and then sent back by the client to the server whenever the client accesses the same server. Cookies are used for authentication and tracking of sessions and for memorising specific information related to users who access the server. Data obtained from cookies are utilised by Onpipeline itself or by companies that collaborate with us in order to ensure simpler access to the Service, easier navigation on the site, marketing purposes and purposes instrumental to the service. The user may always decide whether or not to accept the cookies of a particular website. These rules are defined autonomously by the User at browser level.
Please see the below list of sub-processors that we engaged with, the country they operate from, and the service(s) they provide.
| Sub-Processor | Country | Service | Sub-Processor Measures |
| Amazon Web Services | Ireland | Cloud Service Provider | Shared Responsibility Model |
| Mailchimp | United States | Email Marketing Provider | Privacy Policy |
| SendGrid | United States | Email Marketing Provider | Privacy Policy |
We adopt the latest technologies, practices and architecture available. We keep all our tools and services under the same roof by utilizing a market-leader in cloud computing. Amazon Web Services(AWS) provides our Engineers the flexibility and capacity to rapidly deploy and scale services on-demand. We look after your data on the cloud by implementing a number of security controls, while AWS protects your data on the cloud. They do this through physical security in their data centers.
We’ve built both internal and external security checkpoints into the application’s development pipeline. Our Engineering ensure that our coding guidelines are followed and maintained. We validate our deployments with regular ongoing assessments.
We have a long term vision for our application security that is continuously evolving, we build new features for our product and we identify reasonable opportunities to fand maintain a conscious security mindset.
Information Security Policy is the overarching collection of policies implemented to ensure the confidentiality, integrity, and availability of the data we store. Our policies ensure that we provide all our team members with the necessary practices to build upon the strong foundations of their security onboarding. We utilize these policies daily.
Switching CRM? Save 75% on migration