Current as of January 5, 2026

Privacy Notice

Welcome, and thank you for your interest in Pipedrive (“Pipedrive,” “we,” or “us”), our website at https://www.pipedrive.com and all related websites (the “Website”), the Pipedrive Services and Platform, any other services we provide, and any activities we carry out where a link to this Privacy Notice is displayed, as well as all communications with individuals through written or oral means, such as email or phone (collectively, “Pipedrive Operations”).

This Privacy Notice describes the information we gather on or through the Website, the Platform, the Pipedrive Services, or otherwise through Pipedrive Operations, how we use and disclose such information, and the steps we take to protect such information.

If you are a California consumer please review Section 11 “Your California Privacy Rights” of this Privacy Notice.

To understand what cookies we use, please review our Cookie Notice, available at https://www.pipedrive.com/en/cookie-notice;

This Privacy Notice is incorporated into and is subject to the Pipedrive Terms of Service, available at https://www.pipedrive.com/en/terms-of-service;

The addresses of our offices, where Pipedrive, Inc. and our affiliates are located, can be found here: https://www.pipedrive.com/en/about.


1. DEFINITIONS

Capitalized terms used but not defined in this Privacy Notice have the meaning given to them in the Pipedrive Terms of Service, available at https://www.pipedrive.com/en/terms-of-service.

“Personal Data” means any information relating to an identified or identifiable natural person, or as the term or its material equivalent (e.g., “Personal Information”) are defined under applicable law.

“Public Area” means the area of the Website that can be accessed by both Users and Visitors without needing to log in.

“Restricted Area” or “Platform” means the area of the Website that can be accessed only by Users and where access requires logging in.

“Visitor” means an individual other than a User who uses the Public Area but has no access to the Restricted Area.


2. ROLES & RESPONSIBILITIES

This section outlines Pipedrive's roles and responsibilities concerning the processing of Personal Data.

2.1 Pipedrive as a Data Controller

This Privacy Notice describes Pipedrive's practices when we act as a data controller. As a data controller, we determine the purposes and means of processing your Personal Data. This includes information collected directly from you, such as when you sign up for an Account, register for events, participate in research sessions, or interact otherwise with us. It also covers information collected automatically, such as through cookies and tracking technologies, and information we receive from third parties. Our responsibilities include ensuring the lawfulness, fairness, and transparency of data processing and taking reasonable and appropriate measures designed to safeguard your rights as a data subject.

2.2 Pipedrive as a Data Processor

If you are a Client and want to understand our data processing practices when we act as a data processor, please refer to our Data Processing Addendum (the “DPA”), available at https://www.pipedrive.com/en/privacy/dpa. The DPA provides detailed information about our obligations when processing Personal Data on behalf of our Clients. This includes processing Personal Data contained within Client Data according to the Client's instructions, ensuring data security, and assisting Clients in fulfilling their data protection obligations. We do not own, control, or direct the use of Personal Data contained within Client Data. Only the Client or User has the right to access, retrieve, and direct the use of such Personal Data.

If you are a data subject seeking to exercise your rights (such as access, rectification, deletion, etc.) regarding Personal Data processed by a Pipedrive Client (that we process as a data processor on behalf of our Client) within the Pipedrive Services, please contact the Client directly. The Client, as the data controller, is responsible for handling such requests according to applicable data protection laws and regulations. Pipedrive processes Client Data solely on behalf of our Clients and according to their instructions. We are largely unaware of the specific data stored by Clients and do not directly access such data, except as necessary to provide the Pipedrive Services or otherwise permitted by the Terms.

For any questions or further clarification on these roles, please contact us at [email protected].


3. THE INFORMATION WE COLLECT

We collect different types of information from or through Pipedrive Operations (e.g., through the Website and Platform), including through the methods summarized below.

3.1 Information You Provide Directly to Pipedrive

  • Account signup: When you sign up for an Account to access Pipedrive Services, we ask for information, like your name, contact number, business email address, company name and country, to complete the Account signup process. You may also provide us with more information, such as your photo, time zone and language, but we don’t require that information to sign up for an Account.

  • Event registrations and other form submissions: We record information that you submit when you (i) register for any event, including webinars or seminars, (ii) subscribe to our newsletter or any other mailing list, (iii) submit a form in order to download any product, whitepaper or other materials, (iv) participate in contests, research, or respond to surveys, or (v) contact Pipedrive for any purpose.

  • Payment processing: When you buy something from us, we ask you to provide your name, contact information, credit card information or other payment account information. When you submit your card information, we store the name and address of the cardholder, the expiration date and the last four digits of the credit card number. We do not store the actual credit card number. For quick processing of future payments, if you have given us your approval, we may store your credit card information or other payment information in an encrypted format in the secured servers of our payment service providers.

  • Testimonials: When you authorize us to post testimonials about Pipedrive Operations, we may include your name and other Personal Data in the testimonial. You will be given an opportunity to review and approve the testimonial before we post it. If you wish to update or delete your testimonial, you can contact us at [email protected]. Others may also have access to testimonials and may have the ability to share it with third parties. You understand that, even after removal, copies of testimonials may remain viewable in cached and archived pages and may have been copied or stored by Internet archives and others.

  • Interactions with Pipedrive: We may record, analyze and use your interactions with us, including, for example, email, telephone and chat conversations with our sales and customer support professionals, to respond to you and to assist you, to manage our relationship, and to improve our interactions with you and others.

3.2 Automatically Collected Information

  • Information from browsers, devices and servers: When you visit our Website, we collect information that web browsers, mobile devices and servers make available, such as the internet protocol (IP) address, media access control (MAC) address, browser type, language preference, time zone, referring URL, screen resolution, date and time of access, operating system, mobile device manufacturer and mobile network information. We include these in our log files to understand more about visitors to our Website and accommodate our Website to the visitors.

  • Information from cookies and tracking technologies: We use temporary and permanent cookies to identify Visitors and Users and to enhance user experience by collecting information including, for example, when and how they visit the Website and how popular particular Website pages are, to provide you with customized advertising and for other purposes as described herein. We embed unique identifiers in our downloadable products to track usage of the products. We also use cookies, beacons, tags, scripts, and other similar technologies to identify Visitors and Users, track Website navigation and search queries, gather demographic information about Visitors and Users, understand email campaign effectiveness and target Visitor and User engagement. We also use session recording cookies to better understand interactions on the Public Area and improve our services. You can learn more about the cookies used on our Website and change your cookie settings in our Cookie Notice available at https://www.pipedrive.com/en/cookie-notice. Changing your cookie preferences in one browser will not necessarily carry over to other browsers or devices, so you may need to adjust your preferences each time you get a new device, install a new browser, upgrade an existing browser, or alter or delete a browser’s cookie file. If you have questions regarding the specific information about you that we process or retain, as well as your choices regarding our collection and use practices, please contact us using the information listed below.

  • Information from application logs and mobile analytics: We collect information about your and your end-users’ use of Pipedrive Operations from application logs and in-house usage analytics tools and use it to understand how your use and needs can improve Pipedrive Operations. This information includes clicks, scrolls, features accessed, access time and frequency, errors generated, performance data, storage utilized, user settings and configurations, and devices used to access Pipedrive Operations and their approximate locations.

3.3 Information We Collect from Third Parties

  • Signups using federated authentication service providers: You may be able to log in to the Pipedrive Services using supported federated authentication service providers, such as Google. These services will authenticate your identity and give you the option to share certain Personal Data with us, such as your name and email address. You should check your privacy settings on each integrated service to understand what information that integrated service makes available to us and make changes as appropriate. This Privacy Notice does not apply to such integrated service providers’ collection or use of your Personal Data. Please review each integrated service’s terms of use and privacy notices carefully before using their services and connecting to Pipedrive Services.

  • Referrals: If someone has referred Pipedrive Services to you through any of our referral programs, that person/entity may have provided us with your name, email address, and other Personal Data. You may contact us at [email protected] to request that we remove your information from our database. If you provide us with information about another person, or if another person/entity gives us your information, we will only use that information for the specific reason for which it was provided to us, unless we have a legal basis to process it for other purposes.

  • Information from our resellers, partners and service providers: If you contact any of our resellers, partners or service providers or otherwise express interest in Pipedrive Operations to them (e.g., by filling out a form and opting in to be contacted by Pipedrive), the resellers, partners or service providers may pass your name, email address, company name and other information to Pipedrive. If you register for or attend an event that Pipedrive sponsors, the event organizer may share your information with us. Pipedrive may also receive information about you from review sites if you comment on any review of Pipedrive Operations and from other third party service providers we engage to market Pipedrive.

  • Information we collect and process when you integrate Pipedrive Services with third parties: You or other Users may connect third party integrations to your Pipedrive Account, which may ask for certain permissions to access or send information to or from your Pipedrive Account. It is your responsibility to review any third party integrations you or other Users authorize. We may collect information about the types of integrations you use in your Pipedrive Account. Any permission(s) granted by you or other Users grant these third parties access to your information, which may include (but is not limited to) granting third party applications access to view, store, and/or modify the Client Data on your Pipedrive Account. We are not responsible for the practices of third party integrations and this Privacy Notice (or the Terms in general) do not apply to such third parties’ collection or use of Personal Data, so please carefully review the permissions you grant to third party applications. For more information on integrations with third party providers, please see https://support.pipedrive.com/en/article/pipedrive-marketplace-apps-integrations.

  • Information from social media sites and other publicly available sources: When you provide feedback or reviews about Pipedrive Operations, interact, or engage with us on marketplaces, review sites or social media sites, such as Facebook, X (Twitter), LinkedIn and Instagram through posts, comments, questions and other interactions, we may collect such publicly available information, including profile information, to allow us to connect with you, improve Pipedrive Operations, better understand reactions and issues, or to reproduce and publish your feedback on our Website. We must tell you that once collected, this information may remain with us even if you delete it from these sites. Pipedrive may also add and update information about you from other publicly available sources.

  • Analytics providers: When we procure services from third party analytics service providers, we may receive clicks, scrolls, features accessed, access time and frequency, errors generated, performance data, storage utilized, user settings and configurations, and devices used to access and their approximate locations. We use such information to improve and enhance the Pipedrive Operations.

  • Advertising networks: When we procure marketing and advertising services, we may receive information page visits, clicks, scrolls, features accessed, preferences, products or services that may be of interest to you and activity across your Internet usage. Our third party service providers use this information to provide more tailored, relevant and targeted advertising to you with respect to products and services that may be of interest to you.

  • Information from commercial data enrichment services: We may obtain information about you from commercial data enrichment services and trusted third-party providers. These may combine web-sourced data, vendor partnerships, and contributory networks to supply professional contact details (such as, business email addresses and phone numbers), firmographic information (such as company name, size, and industry classification), and other business intelligence data. We use this information to maintain the accuracy of our records, better understand your business needs, and improve the Pipedrive Operations.

3.4 No Sensitive Personal Data

We do not knowingly collect “sensitive” or “special” categories of Personal Data as such may be defined by applicable data privacy laws.


4. HOW WE USE THE INFORMATION WE COLLECT

We use the information that we collect in a variety of ways to provide Pipedrive Operations and operate our business, including the following:

4.1 Operations

We use the information to operate, maintain, enhance, and provide all features of the Pipedrive Operations, such as:

  • To set up and maintain your Account and to do all other things required for providing Pipedrive Operations, such as enabling collaboration, providing Website and email hosting, and backing up and restoring your data in accordance with Pipedrive’s backup and disaster recovery policies;

  • To provide customer support;

  • To manage our relationship with you;

  • To detect and prevent fraudulent transactions and other illegal activities, report spam, and protect the rights and interests of Pipedrive, its Clients and Users, third parties, and the public.

4.2 Improvements

We use the information to improve Pipedrive Operations, such as:

  • To understand how Clients and Users use the Pipedrive Services, to monitor and prevent problems, and to improve the Pipedrive Services;

  • To analyze and improve our interactions with Clients and Users;

  • To analyze trends, administer our Website, and track Visitor navigations on our Website to understand what Visitors are looking for and to better help them.

If this purpose requires Pipedrive to process Personal Data within Client Data, the data will only be used in anonymized or aggregated form.

4.3 Communications

We use the information to communicate with you, such as:

  • To communicate with you (such as through email) about products and materials that you have downloaded and Pipedrive Services that you have signed up for, changes to the Terms, the list of Sub-processors, or other important notices;

  • To send you marketing communications via email, SMS, WhatsApp, the Platform or other means about our business, products, Pipedrive Services and Operations, and other programs and information that may be of interest to you. In order to provide you with a personalized experience, these communications may be tailored to your preferences based on, for example, inferences we make using your visits to the Pipedrive Operations or the links you click on in our emails. Please note that pixel tags, cookies and other online trackers may be used within emails to track your interactions with those websites and when emails are opened, where allowed;

  • To ask you to participate in surveys, research sessions, or to solicit feedback on Pipedrive Operations.

4.4 Analytics; Personalization; Advertising

We use the information for analytics, such as:

  • To update, expand and analyze our records, identify new customers, and provide products and services that may be of interest to you;

  • To monitor and improve marketing campaigns and make suggestions relevant to the User. This includes (i) retargeting Users interested in Pipedrive Operations, (ii) identifying and engaging new audiences similar to our high-value Clients, and (iii) ensuring that Clients who have completed actions like purchases do not receive irrelevant advertisements.

4.5 Quality Assurance

We use the information for quality assurance, such as:

  • To perform quality assurance and to assist with fraud identification;

  • To assist our customer relationship representatives, we use tools to monitor and record certain user experience information, including, without limitation, customer service interactions and information resulting from such calls.

4.6 Lawful Processes

We use the information for lawful processes, such as:

  • In accordance with and in response to regulatory authorities, courts with competent jurisdiction, valid law enforcement requests, governmental agency requests, emergency services, and other necessary third parties for legal, protection, security, and safety purposes (e.g., to protect the safety of our employees, agents, and Clients, or any other person);

  • To enforce our agreements, policies, and Terms, to bring legal action and/or to protect our operations and assets.

4.7 Legal Bases for Processing Personal Data (for United Kingdom and European Economic Area and Other Relevant Jurisdictions)

If you are an individual in the United Kingdom, the European Economic Area (EEA), or in another relevant jurisdiction, we collect and process your Personal Data only where we have a legal basis or bases for doing so under applicable laws and regulations. The legal bases depend on the processing activity. We process your Personal Data only where:

  • We need it to operate and provide you with Pipedrive Operations, including any customer support and personalized features;

  • It satisfies a legitimate interest of Pipedrive (which is not overridden by your data protection interests and rights), such as to protect the safety and security of Pipedrive Operations and Users, for research and development, to provide information to you about Pipedrive Operations that we believe you and your organization may find useful, to monitor and improve marketing campaigns and to protect our legal rights and interests;

  • You give us consent to do so for a specific purpose; or

  • We need to comply with a legal obligation.

Where we rely on legitimate interests to process your Personal Data, you can object to that processing as described in Section 10 “Your Rights and Choices” of this Privacy Notice. In response to your objection, we will stop processing your information for the relevant purposes unless we have compelling grounds in the circumstances or the processing is necessary in the context of legal claims. Pipedrive may also process your Personal Data for direct marketing purposes and you have a right to object to Pipedrive’s use of your Personal Data for this purpose at any time.

Where we rely on consent to process your Personal Data, you can withdraw consent at any time as described in Section 10 “Your Rights and Choices” of this Privacy Notice

4.8 How We Use AI and ML

We use artificial intelligence and machine learning (together – the “AI”) to improve Pipedrive Operations, enhance security, and automate certain processes. AI may help analyze data, including Pipedrive communications with Clients and Users, detect patterns, make predictions, provide recommendations and create AI-generated responses or other content for the purposes and pursuant to the legal bases described in Section 4 “How We Use the Information We Collect” of this Privacy Notice.

However, we do not carry out fully automated decision-making that can produce legal or similarly significant effects as defined under applicable law (for example, as defined in Article 22 of the GDPR or applicable U.S. state data protection laws). Where AI is involved in decision-making, we ensure appropriate safeguards are in place that are designed to minimize risk to you, including human review, where necessary. If a feature involves direct interaction exclusively with an AI, we may disclose this through clear visual indicators, such as labels, flags, or notices, so you understand you are not interacting with a human.

We may also use third-party AI services to support these activities.

Our AI processing evolves over time, and we remain committed to transparency. If our use of AI changes significantly, we will update this Privacy Notice accordingly, as described in Section 13 “Changes and Updates to This Privacy Notice”.

4.9 Additional Limits on Use of Your Google User Data

Notwithstanding anything else in this Privacy Notice, if you provide Pipedrive access to your Google data (e.g., when you enable the email sync feature with your Google account), Pipedrive’s use of that data will be subject to these additional restrictions:

  • Pipedrive will only use access to read, write, modify or control Gmail message bodies (including attachments), metadata, headers, and settings to provide a web email client that allows Users to compose, send, read, and process emails and will not transfer this Gmail data to others unless doing so is necessary to provide and improve these features, comply with applicable law, or as part of a merger, acquisition, or sale of assets.

  • Pipedrive will not use this Gmail data for serving advertisements.

  • Pipedrive will not allow humans to read this data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes, such as investigating abuse, to comply with applicable law, or for Pipedrive’s internal operations and when used for internal operations, only when the data have been aggregated and anonymized.

Pipedrive’s use of information received and Pipedrive’s transfer of information to any other app from Google APIs will adhere to Google API Services User Data Policy available at https://developers.google.com/terms/api-services-user-data-policy#additional_requirements_for_specific_api_scopes, including the Limited Use requirements.


5. TO WHOM WE DISCLOSE INFORMATION

Except as described in this Privacy Notice, we will not intentionally disclose the Personal Data that we process to third parties without the consent of the applicable data subject. We may disclose Personal Data under the following circumstances:

5.1 Unrestricted Information

Any information you voluntarily choose to include in a Public Area of the Pipedrive Services or Website, such as a public profile page, will be available to anyone with access to that content. For example, we make available various community forums and self-help support materials, as well as blogs and other means for you to post information. This information you post is publicly-available information that you choose to disclose, and it may be read, collected, and processed by others who visit the Website. Except for your username (which may be your real name) and the details that you choose to include in your profile, the categories of data disclosed in these circumstances will depend on what information you choose to provide. Your posts and certain profile information may remain even after you terminate your Pipedrive Account. We urge you to consider the sensitivity of any information you may disclose in this way. We will correct or delete any information you have posted on the Website if you so request, as described in Section 10 "Your Rights and Choices" of this Privacy Notice. You understand that, even after removal, copies of information you provide in Public Areas may remain viewable in cached and archived pages and may have been copied or stored by Internet archives and others. In some cases, we may not be able to remove your information, in which case we will let you know if we are unable to and why.

5.2 Other Users in Your Company Account

Information about your use of the Pipedrive Services is available to the Administrator(s) of your Pipedrive Account and, depending on the settings chosen by the Account Users, also to other Users for the purposes of providing the Pipedrive Services.

Please note that while Administrator(s) have overall control, individual Users control the visibility of their synced emails and activities. Each User is responsible for the contents of their Mail tab and synced activities. For additional information on how to set up email visibility, please check the following article: https://support.pipedrive.com/en/article/how-can-i-view-or-adjust-email-visibility. For additional information on how to set up calendar sync, please check the following article: https://support.pipedrive.com/en/article/calendar-sync.

When using the Team Inbox option, only Users with relevant permission settings have the ability to set up and adjust the visibility settings for emails synced in Team Inbox. For additional information on Team Inbox, please check the following article: https://support.pipedrive.com/en/article/team-inbox.

5.3 Service Providers

We work with third party service providers who provide development, hosting, storage, system administration, customer relationship management, maintenance, security and fraud detection, marketing, analytics, and other services for us. These third parties may have access to or otherwise process Personal Data as part of providing those services for us. We limit the information provided to these service providers to that which is reasonably necessary for them to perform their functions, and our contracts with them require them to maintain the confidentiality of such information.

5.4 Social Media

Pipedrive’s Website may use third party social media features, such as the Facebook “like” button, LinkedIn and X (Twitter) sharing features, and other similar widgets (the “Social Media Features”). You may be given the option by such Social Media Features to post information about your activities on the Website to a profile page of yours that is provided by a third party social media network in order to share content with others within your network. Social Media Features are either hosted by the respective social media network, or hosted directly on our Website. To the extent the Social Media Features are hosted by the respective social media networks and you click through to these from our Website, the latter may receive information showing that you have visited our Website. If you are logged in to your social media account, it is possible that the respective social media network can link your visit to our Website with your social media profile. Your interactions with Social Media Features are not governed by this Privacy Notice, but are governed by the privacy notices (and any other applicable terms) of the respective companies that provide the relevant Social Media Features.

5.5 Advertising and Marketing

We partner with third party ad networks to display advertising on our Website or to manage our advertising on other sites. Our ad network partners use cookies, web beacons, and data we share with them to collect information about your activities on our Website and other websites and provide you with targeted advertising based on your interests. If you wish not to have your information used for the purpose of serving you targeted ads, you may opt out by using these services on the following websites: https://optout.networkadvertising.org/ or https://optout.aboutads.info/ (or if located in the European Union, by clicking here: http://www.youronlinechoices.eu/). Please note this does not opt you out of being served advertising - you will continue to receive generic ads. Please refer to Section 10.2 “Opting Out” of this Privacy Notice for detailed instructions about opting out of specific data processing activities. Please remember that changing your settings with individual web browsers or ad networks will not necessarily carry over to other browsers or ad networks.

5.6 Partners

We may share your Personal Data with trusted partners where we have an appropriate legal basis for such sharing, including where necessary for our legitimate business interests, with your consent or as otherwise permitted by applicable law or contract.

For example, we may share data with trusted partners to contact you about products or services that are complimentary to Pipedrive Services. When you engage with these partners, a partner will provide a link to the partner’s privacy notice so you can learn about their personal data processing practices. For more information on our partner program, see https://www.pipedrive.com/en/partner. If you do not want us to share your Personal Data with these companies, please contact our partners’ team at [email protected].

In addition, we may share limited identifiers (such as email addresses or other unique identifiers, which may be hashed or pseudonymized where possible) together with related event information (for example, sign-up or click timestamps) with certain strategic partners. This sharing is carried out solely for the purposes of verifying attribution, reconciling usage or calculating revenue share in connection with our partnership programs.

5.7 Non-Personally Identifiable Information

We may make certain anonymous, aggregated, or otherwise non-personally-identifiable information available to third parties for various purposes, including (i) compliance with various reporting obligations, (ii) for business or marketing purposes, or (iii) to assist such parties in understanding our Clients’, Users’ and Visitors’ interests, habits, and usage patterns for certain programs, content, services, and/or functionality available through Pipedrive Operations.

5.8 Law Enforcement, Legal Process and Compliance

We may disclose Personal Data or other information if required to do so by applicable law or when we believe in good faith that such disclosure is necessary to: (i) comply with applicable laws, legal obligations, court orders, subpoenas, warrants, or other legal process; (ii) cooperate with law enforcement or other governmental agencies; (iii) prevent fraud, abuse, or unlawful activity; (iv) protect the security and integrity of Pipedrive Operations, systems, or infrastructure; (v) enforce our agreements and safeguard our legal rights or property; or (vi) investigate, respond to, or defend against claims, allegations, or liability affecting us or others. We may make such disclosures without prior notice to you, as we determine in our sole discretion.

5.9 Change of Ownership

Any Personal Data we process may be disclosed and otherwise transferred to an acquirer, successor or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, as well as in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.


6. DATA SECURITY

At Pipedrive, we take data security very seriously. We have taken steps to implement appropriate administrative, technical, and physical safeguards designed to prevent unauthorized access, use, modification, disclosure or destruction of the information you entrust to us. These measures have been audited against industry standards. However, no security system is perfect, and due to the inherent nature of the Internet, we cannot guarantee that data, including Personal Data, is absolutely safe from intrusion or other unauthorized access by others.

You are responsible for protecting your password(s) and other authentication factors and maintaining the security of your devices.

To learn more about current practices, auditors’ certifications and policies regarding the security and confidentiality of Pipedrive Operations, please visit our Trust Center at https://www.pipedrive.com/en/trust-center;


If you believe your Personal Data has been compromised, please contact us as set forth in Section 16 “How to Contact Us” of this Privacy Notice. If we learn of a security breach, we will inform you and the authorities of the occurrence of the breach as necessary in accordance with applicable law.


7. INTERNATIONAL DATA TRANSFERS

Pipedrive may transfer your Personal Data to countries other than the one in which you live, including transfers to the U.S. To the extent that Personal Data is transferred abroad, Pipedrive will ensure compliance with the requirements of the applicable laws in line with Pipedrive’s obligations.

In particular, we offer the following safeguards if Pipedrive transfers Personal Data from jurisdictions with differing data protection laws:

  • Standard Contractual Clauses: Pipedrive uses Standard Contractual Clauses approved by the European Commission (and the equivalent standard contractual clauses for the UK, where appropriate) for transfers to countries not subject to an adequacy decision by the European Commission or your local legislature and/or regulator.

  • Data Privacy Framework (DPF): Pipedrive participates in and complies with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF (the “DPF”) set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Data of individuals in the European Union and the UK. Pipedrive Inc. has been certified by the Department of Commerce that it adheres to the DPF Principles. In the context of an onward transfer, Pipedrive is responsible for the processing of Personal Data it receives under the DPF Principles and subsequently transfers to a third party acting as an agent on our behalf. Pipedrive will remain liable under the DPF Principles if our agent processes your Personal Data in a manner inconsistent with the DPF Principles, unless Pipedrive is not responsible for the event giving rise to the damage. If there is any conflict between the terms in this Privacy Notice and the DPF Principles, the DPF Principles shall govern. To learn more about the DPF and to view our certification, please visit the DPF website at https://www.dataprivacyframework.gov/s/.

For information about sharing your Personal Data, onward transfers, and your choices to opt out, please see Sections 5 “To Whom We Disclose Information” and 10.2 “Opting Out” of this Privacy Notice.

In compliance with the DPF Principles, Pipedrive commits to resolving complaints about our collection or use of your Personal Data. EU and UK individuals with inquiries or complaints regarding our DPF policy should first contact Pipedrive’s Data Protection Officer at [email protected]. Pipedrive has further committed to cooperate with the panel established by the data protection authorities concerning unresolved DPF complaints concerning human resources data and non-human resources data transferred from the EU and the UK. Please visit https://www.edpb.europa.eu/about-edpb/about-edpb/members_en to access the relevant contact details of EU (and EEA) data protection authorities and https://ico.org.uk/make-a-complaint/ to access the relevant contact details of the UK Information Commissioner’s Office (the “ICO”). If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims when other dispute resolution procedures have been exhausted. See https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction for more information on the arbitration procedure.

In any matters relating to DPF, Pipedrive Inc. is subject to the investigatory and enforcement powers of the Federal Trade Commission (the “FTC”).


8. MINORS AND CHILDREN’S PRIVACY

Protecting the privacy of children is especially important. Pipedrive Operations are not directed to nor intended for children under the age of 18, and we do not knowingly collect Personal Data from children under the age of 18. If you are under 18 years of age, then please do not use or access the Pipedrive Operations at any time or in any manner. If we learn that Personal Data has been collected on the Pipedrive Operations from persons under 18 years of age and without verifiable parental consent, then appropriate steps will be taken that are designed to delete this information. If you are a parent or guardian and discover that your child under 18 years of age has obtained an Account on the Pipedrive Services, then you may alert us at [email protected] and request that we delete that child’s Personal Data from our systems.


9. DATA ACCURACY AND RETENTION

Information you provide to us should be relevant to the purposes for which it is to be used, and, to the extent necessary for those purposes, should be accurate, complete, and up to date.

We retain information about you for as long as it is reasonably necessary for the purposes specified in this Privacy Notice. When we no longer have a legitimate need to process your Personal Data, we will delete or anonymize your information from our active databases. We will also securely store the information and isolate it from further processing on backup discs until deletion is possible. When determining the length of time to retain information about you, we consider various criteria, including whether we need the information to continue to provide you Pipedrive Operations, comply with our legal obligations, resolve a dispute, enforce our contractual arrangements, prevent harm, promote safety, security and integrity, or protect ourselves or others.


10. YOUR RIGHTS AND CHOICES

10.1 Your Rights

Some U.S. states (for example, California, Colorado, Connecticut, Delaware, Texas, and Virginia) and other jurisdictions (for example, the United Kingdom, European Union, and Brazil) provide certain rights and options to individuals. Depending on the laws applicable to our processing of Personal Data about you and the location in which you reside, you may have the ability to exercise the rights listed below. Subject to foregoing and all application limitations, exemptions, or exceptions to these rights, you may have the right to:

  • Right to confirm and access: You have the right to confirm whether we process Personal Data about you and to know which Personal Data we hold about you (if any).

  • Right to data rectification: You have the right to require corrections to your Personal Data in case it is inaccurate or incomplete.

  • Right to data deletion: You have the right to request the deletion of your Personal Data.

  • Right to restriction of processing: You have the right to request to restrict the use of your Personal Data.

  • Right to data portability: You have the right to transfer your Personal Data that we process about you to a third party in a structured, commonly used and machine-readable format.

  • Right to object: You have the right to object to the use of your Personal Data in certain circumstances, such as when the processing is based on legitimate interest and in the use for direct marketing.

  • Right to Opt Out of Selling and Targeted Advertising: You may have the right to opt out of (i) the sale of your Personal Data; and/or (ii) the processing of your Personal Data for targeted advertising purposes. Exercise this right by using the Global Privacy Control as noted in the Section 12 “Do Not Track (DNT) Request & Global Privacy Controls” section below or via the following form.

  • Right to complain: You have the right to complain to the appropriate regulatory or government authority (including, for example, supervisory authority, state attorney general) if you have any grievance against the way we collect, use or share your Personal Data. For European Economic Area, the contact details of supervisory authorities are available here: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en and of the UK ICO here: https://ico.org.uk/make-a-complaint/.

We do not use your Personal Data in furtherance of automated profiling decisions that produce a legal or similarly significant effect. We do not discriminate against individuals for exercising the rights granted to them under applicable law and that are applicable to our processing of Personal Data.

To exercise your rights, you may contact us as set forth in Section 16 “How to Contact Us” or use the methods set forth in Section 13 “Exercise Your Rights” below. Additionally:

  • You may update, correct, or delete your Account information and preferences at any time by accessing your Account settings page on the Pipedrive Services. Please note that while any changes you make will be reflected in active databases instantly or within a reasonable period of time, we may retain all information you submit for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so.

  • You may decline to share certain Personal Data with us, in which case we may not be able to provide to you some of the features and functionality of the Pipedrive Operations.

  • You can choose not to provide optional profile information, such as your photo. You can also delete or change your optional profile information from your Account settings page.

  • You can always choose not to fill in non-mandatory fields when you submit any form linked to our Website.

10.2 Opting Out

We do not sell your Personal Data as the concept of “selling” is traditionally understood as being the exchange of something for money. However, we do “sell” Personal Data and/or use certain categories of Personal Data for “targeted advertising” purposes (as such concepts are defined under U.S. state privacy laws) and, in the preceding 12 months, we have sold and/or used for targeted advertising the following categories of Personal Data:


Category of Personal Information

Categories of Purposes

Categories of Recipients

Identifiers

  • Analytics; Personalization; Advertising (as defined in Section 4.4 above)

  • Specifically, for analytical and targeted advertising purposes (including, without limitation, cross-contextual behavioral advertising)

  • Advertising and Marketing Partners

  • Specifically, analytics, marketing, advertising, and remarketing partners and services providers

Internet or other similar network activity

Inferences


You may have the right to opt out of the selling and targeted advertising as described herein. You may exercise this right to opt out by utilizing the Global Privacy Control as mentioned in Section 12 “Do Not Track (DNT) Request & Global Privacy Controls” section below, or by clicking the “Cookie Settings” or “Your Privacy Choices” option in the footer of the Website and changing your cookie settings as described on that webpage. If you have any questions, concerns, or would like more information on our ability to opt out, you can contact us by emailing: [email protected].

In addition to the above, and to comply with data protection regulations, Pipedrive provides you with the following options to opt out of different data processing activities:

  • WhatsApp Business: You can opt out of receiving messages via WhatsApp Business in the “Marketing preferences” tab on the Pipedrive Services.

  • Commercial communications: You may opt out of receiving newsletters and other non-essential messages by using the “Unsubscribe” function included in all such messages or by sending an email to the address provided in Section 16 “How to Contact Us”. Please note that you will continue to receive essential notices and emails, such as Account notification emails (password change, renewal reminders, etc.), security incident alerts, security and privacy update notifications, and other essential transactional and payment-related emails. Users can view and modify settings relating to the nature of promotional communications they receive from us by accessing the “Marketing and communications preferences” tab on the Pipedrive Services.

  • Cookies: You can change your cookie settings by clicking on the “Cookies Settings” link at the bottom of our Website and selecting your preferences on that page. Or via the “Customize Settings” link available on our Cookie Notice page: https://www.pipedrive.com/en/cookie-notice.

  • Navigation information: You may opt out from the collection of navigation information about your visit to the Website by Google Analytics by using the Google Analytics Opt-out feature available at https://tools.google.com/dlpage/gaoptout. You can disable browser cookies before visiting our Website. However, if you do so, you may not be able to use certain Website features properly.

Lastly, you can always opt out of certain communications by reaching out to [email protected].


11. YOUR CALIFORNIA PRIVACY RIGHTS

If you are a California consumer, then under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (the “CCPA”), you may have certain rights to understand and request that we disclose details about how we handle your Personal Data. To learn more about how we collect, use, disclose, and share your Personal Data, please see below.

11.1 Categories of Personal Data Collected

In the preceding 12 months, we have collected the following categories of Personal Data about California consumers. We may collect this Personal Data directly from you, from third parties, and from your interactions with us. For additional details about the Personal Data that we collect and the sources from which we collect this Personal Data, please review Section 3 “The Information We Collect” of this Privacy Notice. The Personal Data categories are:

  • Identifiers, such as name, email address, address, and phone number;

  • Commercial information, such as records of products or services purchased and other transactional data;

  • Internet or other network or device activity details, such as technical data about your use of Pipedrive Operations, metadata associated with your interactions with our emails (e.g., whether and when an email is opened), collected for analytics and performance measurement;

  • Geolocation data, such as your approximate location based on IP address;

  • Financial information, such as payment information or financial account numbers in the process of providing you with a subscription;

  • Other Personal Data, in instances when you interact with us online, by phone or email in the context of receiving help through our support channels; participate in customer surveys or contests; or otherwise in providing the Pipedrive Operations;

  • Inferences drawn from any of the above information.

We may retain this Personal Data for as long as is needed for the purpose(s) for which it was collected and no longer than is relevant and reasonably necessary. Our retention periods vary based on business, legal, and regulatory needs.

11.2 Business and Commercial Purposes for Collection; Disclosures for a Business Purpose

We may collect all of the above categories of Personal Data to run our business and carry out our day-to-day activities, as described in Section 4 “How We Use the Information We Collect” of this Privacy Notice. In the preceding 12 months, we have disclosed each of these categories of Personal Data with our service providers for various business purposes, as described in Section 5 “To Whom We Disclose Information” of this Privacy Notice.

11.3 Categories of Personal Data Sold or Shared for Cross-Context Behavioral Advertising

In the preceding 12 months, we have disclosed some of the above categories of Personal Data to third party advertising partners, such as in connection with our use of tracking technologies for cross-context behavioral advertising or by providing lists of email addresses for potential customers, so that we can reach you across the web with advertisements for our products and services. This may be considered “sharing” or a “sale” under the CCPA. You can read more about our sharing and sales activities in Section 10.2 “Opting Out”. Pipedrive does not have actual knowledge that it sells or shares the Personal Data of California consumers under 16 years of age.

11.4 Your Rights

In addition to those rights set forth in Section 10 “Your Rights and Choices” of this Privacy Notice above, the CCPA may also grant you certain additional rights regarding the Personal Data we collect about you:

  • Right to Know: You have the right to request to know (i) the categories of Personal Data collected, disclosed, sold and/or shared; (ii) the categories of sources from which the Personal Data was collected; (iii) the business or commercial purpose for collecting, selling, and/or sharing Personal Data; (iv) the categories of third parties with whom we disclosed, sold, and/or shared Personal Data; and (v) the specific pieces of Personal Data we have collected about you.

  • Right to Non-Discrimination for the Exercise of Your Privacy Rights: You have the right not to receive discriminatory treatment by us for the exercise of your privacy rights conferred by the CCPA.

To exercise this right, use the methods set forth in Section 13 “Exercise Your Rights” of this Privacy Notice below.


12. DO NOT TRACK (DNT) REQUESTS & GLOBAL PRIVACY CONTROLS

Some browsers offer a “Do Not Track” (DNT) feature that signals your preference not to be tracked online. Currently, there is no consistent industry standard for how websites should respond to DNT signals, so we do not take action in response to DNT settings.

That said, we do respect other privacy controls and choices, such as cookie consent mechanisms and browser-level settings where applicable. We are committed to protecting your privacy and comply with relevant applicable privacy regulations. For example, our website recognizes the Global Privacy Control (GPC) signal which enables you to opt-out of certain uses or disclosures of information about you. If you notify us of your preference through GPC, we will honor your request only for the browser or device that sends the GPC signal. To learn more about Global Privacy Control, you can visit https://globalprivacycontrol.org/.

You can also manage your advertising preferences through the following industry tools:

Please note that these opt-outs are browser and device-specific. If you clear your cookies, or switch browsers or devices, you may need to opt out again.


13. EXERCISE YOUR RIGHTS

If you need this Privacy Notice in an alternative format due to a disability, please contact us at [email protected].

If this Privacy Notice expressly stated above that you have certain rights, or applicable law grants you certain rights as it relates to the information we collect about you, you may exercise any of these rights by contacting us using the information provided below. You may submit a request to us by:

Emailing: [email protected]

Visiting: Privacy Preferences, available here

Or by following the opt out methods and processes identified above. For clarity, to exercise your rights to opt out of targeted advertising, or the “selling” or “sharing” of personal information about you, you must follow the instructions provided under the Section 10.2 “Opt Out” of this Privacy Notice noted above.

Additionally, you may have the right to appeal our decision regarding a request related to these rights by contacting us using the information provided below. If the appeal is denied, you may submit a complaint to the applicable government regulator or authority in the jurisdiction in which you are located (for example, the state Attorney General in the state in which you reside). When you submit a request or an appeal, we will limit our collection of information about you to only what is necessary to securely fulfil your request or process your appeal. Making a request or appeal does not require you to create an account with us.

To verify certain requests - for example, requests to know, access, delete, or correct - we may need to collect additional information to verify your identity and the request before providing a substantive response to the request. Some jurisdictions, depending on your location, permit you to authorize an agent to make requests on your behalf to exercise your rights. If you have a registered agent to act on your behalf, we have the right to authenticate such agent’s authority to act.


14. THIRD PARTY WEBSITES; LINKS AND EMBEDDED CONTENT

We may provide links to third party websites or platforms. If you follow links to sites or platforms that we do not control and are not affiliated with, you should review the applicable privacy notice and other terms. We are not responsible for the privacy or security of, or information found on, these sites or platforms.

Information you provide on public or semi-public venues, such as third party social networking platforms, may also be viewable by other Users and Visitors and/or users of those third party platforms without limitation as to its use. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owner or operators.

The Pipedrive Operations may also incorporate features, add-ons, portals, and content including feeds, scripts embedded in the Website’s code, and visible content (e.g., videos), provided by third parties. In some cases, those third parties collect data about how you interact with their content. Our Website may also use YouTube to make content in video format available to you. By accessing a part of the Services where videos are available, watching an embedded video, or otherwise interacting with any content made available through YouTube, you signify your agreement with YouTube’s terms and conditions, available at https://www.youtube.com/static?template=terms. YouTube collects and otherwise has access to usage data (e.g., what videos you accessed and watched) through videos embedded in the Website as further described in YouTube’s Privacy Notice, available at https://policies.google.com/privacy?hl=en. YouTube adheres to Google's privacy policies and principles, part of that allows you to control certain privacy settings and which data are collected.


15. CHANGES AND UPDATES TO THIS PRIVACY NOTICE

Please review this page periodically to stay informed about any updates to this Privacy Notice, which we may revise from time to time. If we make changes, we will post the updated Privacy Notice on our Website and indicate the date of the latest revision. For substantial changes, we will notify you via the Pipedrive Services or by email. Your continued use of the Pipedrive Services after the updated Privacy Notice takes effect means you have read, understood and agreed to the current version.


16. HOW TO CONTACT US

Please contact us with any questions or comments about this Privacy Notice, your Personal Data, your rights, your consent choices, or our data processing practices by email at [email protected].

If you have any concerns or complaints about this Privacy Notice or our data processing practices, you may contact Pipedrive’s Data Protection Officer by email at [email protected].