1. Who we are
Metrik Sales is the organization responsible for operating the Responsible User Management integration published on the Kommo Marketplace.
Data Protection Officer contact channel: contato@metriksales.com.
2. What this policy covers
Integration has two parts, and both are covered by this policy:
- The widget, which runs within the Kommo interface, in the browser of those using CRM.
- The server, maintained by us, which saves the configuration and decides the distributions.
This policy does not cover Kommo. Kommo's processing of your data is governed by its own privacy policy, and installing the integration does not change that relationship.
3. Our roles
For data entered in Kommo, the contracting organization generally acts as controller, while Metrik Sales processes the data needed to operate the integration according to its instructions.
Metrik Sales acts as controller for processing related to service administration, security, support, subscriptions and communications about the integration.
3.1 Legal bases
Depending on the purpose, processing may rely on performance of a contract, compliance with legal or regulatory obligations, and legitimate interests, with due regard for data-subject rights.
4. What data do we deal with?
4.1 Kommo account data
Numeric account identifier, subdomain, time zone and the distribution configuration defined in the integration.
Purpose: identify the account to which each configuration belongs and apply the chosen rules.
4.2 Account user data
Numeric identifier of each user in Kommo and, for each:
- Time clock record: start and end date and time.
- Declared work schedule: time ranges for each day of the week.
- Participation in distribution and the assigned percentage slice.
- Permissions: if the person can strike his own point, declare his own working hours and enter or leave the distribution.
We do not keep Kommo users' registration data, such as name, photo, telephone number or password, in our database, except for information provided directly by the administrator for support, subscription and authorized communications.
There is one exception that is not our storage, but written in your account: the field Assigned user, described in section 5, receives the name of the person chosen by the widget. It stays on the lead card, inside Kommo, under your control.
Purpose: determine who is eligible to receive a lead when it arrives.
4.3 Access credentials to your account
We save the access and renewal tokens (OAuth 2.0) issued by Kommo when integration is installed.
Credentials are stored securely and used exclusively to let the integration access the Kommo API on behalf of the authorized account.
4.4 Leads, contacts and businesses data
When an assignment occurs, we record the entity's numeric identifier, who received it, through which mechanism and when.
When acceptance-based distribution is enabled, the integration stores a snapshot of up to three fields that your account administrator chose to display in the offer, together with their values. If a name, telephone number or another field is selected, its value remains in our database while the offer exists and in its history.
This choice is yours: without any selected field, the offer is anonymous and only announces “New lead”. Nothing but the chosen fields is stored. We don't copy the lead, we don't read conversations and we don't keep attachments.
4.5 Technical records
Installation attempts — subdomain, result and error message — and server operating logs used to diagnose failures.
5. What integration writes in your account
To keep the assignment report inside Kommo, the integration creates and fills five custom lead fields, recording how and why the lead was assigned. These fields belong to your account, remain after uninstallation and can be removed at any time.
The integration also changes the responsible user for leads, contacts, companies and tasks according to your configuration.
6. What we don't do
- We do not use cookies or equivalent tracking technologies.
- We do not use widget data for behavioral advertising.
- We do not sell or rent personal data.
- We do not use your data to train artificial intelligence models.
8. Where the data is
Data is processed through cloud infrastructure and service providers required to operate the integration. Processing may involve storage or access from other countries.
Where an international transfer occurs, Metrik Sales will adopt the safeguards required by applicable law.
9. How long do we keep it?
Data is retained for as long as necessary to provide the service, fulfill the purposes described in this policy, meet legal obligations and establish or defend rights.
After uninstalling or a valid deletion request, data will be deleted or anonymized according to internal procedures and applicable legal requirements. Certain records may be retained where legally required or legitimately necessary.
10. With whom we share
We do not sell personal data or share it for advertising purposes.
Data may be processed by infrastructure and service providers hired to operate the integration, subject to confidentiality and data-protection obligations, or disclosed when required by law.
11. Security
- Communications and access credentials are protected using security measures appropriate to the processing.
- Requests, permissions and access are authenticated and validated before processing.
- Infrastructure and data access is restricted to authorized people who need it to perform their duties.
If an incident may cause relevant risk or harm, Metrik Sales will take the measures required by law, including notifying the controller, the competent authority and data subjects where applicable.
12. Your rights
In accordance with LGPD Art. 18, you may request:
- Confirmation treatment and access to data.
- Correction incomplete, inaccurate or outdated data.
- Anonymisation, blocking or elimination of unnecessary data or processed in breach of the law.
- Data portability to another provider.
- Deletion of data processed on the basis of consent.
- Information About who we share data with.
- Withdrawal of consent.
To exercise any right, write to contato@metriksales.com. Requests will be answered within the time limits established by applicable law.
If the request involves lead or contact data from your account, send it to the Kommo account holder. In this relationship, we act as processor and follow the controller's instructions.
13. Data from children and adolescents
The integration is a business tool and is not directed at people under 18. The contracting organization is responsible for ensuring an appropriate legal basis when processing children's or adolescents' data in Kommo.
14. Changes in this policy
We can update this document. When a change is relevant, we will notify you through the integration support channels before its entry into force. The date at the top indicates the last revision.
15. Contact
Support: contato@metriksales.com
Data Protection Officer contact channel: contato@metriksales.com
