SeyleaseCRM-AUA-v1.0

Privacy & data governance

CRM Privacy & Data Handling Notice

This notice explains how personal and business information is handled in the Seylease Sales CRM. It is an internal operational notice for authorised CRM users and complements Seylease's approved privacy, compliance and records-management policies.

1. Who operates this CRM

Leasing Company (Seychelles) Limited (Seylease) operates this CRM for authorised business development, sales follow-up, application pipeline management, management reporting and related internal controls.

Seylease is a regulated financial institution. CRM use must therefore remain consistent with applicable Seychelles law, Seylease internal policies and relevant regulatory requirements.

2. Information recorded

The CRM may contain:

  • CRM user identity, role and account status.
  • Target organisation information and business contact details.
  • Details of serious individual leads where consent has been confirmed.
  • Sales interactions, outcomes, follow-ups, opportunities and application-stage information.
  • Management guidance, approved sales reference material and brochure-location records.
  • Security, access and audit records generated by use of the CRM.

3. Purpose and data-minimisation

Information must be recorded only where it is relevant to a legitimate Seylease business purpose. Users should keep records accurate, factual and proportionate, and should not enter unnecessary personal or sensitive information into free-text notes.

The CRM is a sales outreach and opportunity-management system. It is not an approved repository for identity documents, bank statements, salary slips, detailed credit files, AML/KYC evidence or similar sensitive financial documentation unless Seylease expressly authorises that use and appropriate controls are implemented.

4. Access and confidentiality

Access is restricted to authorised Seylease users and is controlled by role. Users may access information only to the extent required for their duties and must not disclose, copy or export CRM information for unauthorised purposes.

5. Serious lead consent

A serious individual lead must not be created unless the person has agreed to Seylease recording their details for legitimate sales follow-up. The CRM records that consent confirmation as part of the lead record.

6. Service providers and hosting

Seylease may use approved technology service providers to host and operate the CRM, including the database/authentication and application-hosting services configured for this system. Where processing occurs outside Seychelles, Seylease should apply its approved legal, contractual and security safeguards as required by applicable law and policy.

7. Retention, correction and deletion

CRM records are retained in accordance with Seylease's approved records-retention schedule and applicable legal or regulatory requirements. No fixed retention period is stated here because requirements can differ by record type.

Requests to correct, access or otherwise address personal information should be referred through Seylease's designated privacy/compliance process. Records must not be deleted merely to remove legitimate audit or business history.

8. Data protection principles

CRM users are expected to support the principles reflected in the Seychelles Data Protection Act, 2023, including fair and lawful handling, purpose limitation, data minimisation, accuracy, security and appropriate retention of personal data.

Internal control notice

This page is an operational CRM control baseline. It does not replace any approved customer-facing privacy notice, employment confidentiality obligation or formal Seylease compliance policy.