SheetsmithCRM

Sheetsmith CRM — Terms of Service

Last updated: 19 September 2026

1. Who we are

Sheetsmith CRM ("the service") is provided by M Woodison, trading as Miso Developments ("we", "us"), 11 Cherry Rise, Flackwell Heath, Bucks, HP10 9PS, United Kingdom. Contact: support@sheetsmith.co.uk.

These terms are the agreement between us and the person or business that opens an account ("you"). The service is for business use. By creating an account you accept these terms and the Data Processing Agreement in Schedule 1.

2. The service

A simple online tool for keeping contacts, notes, follow-up tasks and a sales pipeline. We may add, change or remove features. We will not remove your ability to export your data.

We aim to keep the service available and your data safe, but we do not promise uninterrupted or error-free operation and there is no service level agreement. Keep your own exports of anything you could not afford to lose.

3. Your account

You need a valid email address. Keep your password secret; you are responsible for what happens under your login. Tell us straight away at support@sheetsmith.co.uk if you think someone else has access. One account is for one business.

4. Plans and payment

5. Your data

Everything you put into the service is yours. We claim no rights over it and we do not use it for anything except providing the service to you.

6. Acceptable use

Do not use the service to break the law; to store special-category data (such as health information), payment card numbers, passwords or government identifiers; to send spam; to attack, overload or probe the service; or to access anyone else's account or data. Do not resell the service. We may suspend an account that does any of these, and will tell you why.

You are responsible for having a lawful reason to hold the personal data you put into the service, and for telling your own contacts how you use their data.

7. If we ever close the service

We will give you at least 60 days' notice by email, keep export working for that whole period, and refund the unused part of any annual payment. After the closing date all customer data is deleted.

8. Our responsibility to you

We will provide the service with reasonable care and skill. Nothing in these terms limits liability that cannot legally be limited, including for death or personal injury caused by negligence, or for fraud.

Otherwise: we are not liable for loss of profit, business, goodwill or data, or for indirect losses; and our total liability in any 12-month period is limited to the greater of the fees you paid us in that period and £100.

9. Ending this agreement

You can stop at any time by deleting your account. We may end the agreement with 30 days' notice, or immediately if you seriously break these terms. When it ends, section 5 (deletion) applies.

10. Changes to these terms

We may update these terms. We will email you at least 30 days before a change that matters, and you can close your account if you do not accept it.

11. Law

These terms are governed by the law of England and Wales, and the courts of England and Wales have jurisdiction.

Schedule 1 — Data Processing Agreement

This schedule applies to personal data about other people (your contacts and clients) that you put into the service. For that data you are the controller and we are the processor under UK data protection law (UK GDPR and the Data Protection Act 2018).

What we process, and why. Subject matter: hosting your CRM records. Duration: for as long as your account exists. Nature and purpose: storage, retrieval, backup and display, only to provide the service to you. Types of data: names, company names, email addresses, phone numbers, tags, and whatever you write in notes, deals and tasks. Data subjects: your customers, prospects and other business contacts.

Our obligations. We will:

  1. process the data only on your documented instructions — which are these terms and what you do in the service — unless UK law requires otherwise, in which case we will tell you first if we are allowed to;
  2. make sure anyone we authorise to access the data is bound by confidentiality;
  3. keep appropriate security in place, including: encryption in transit and at rest; each account's records held under a key derived from its verified login, so one customer cannot address another's data; least-privilege access for our systems; point-in-time backups; and no third-party scripts in the application;
  4. use sub-processors only as listed below, give you at least 30 days' notice by email before adding or replacing one so that you can object (by closing your account), and hold each to data protection terms no less protective than these;
  5. help you respond to requests from individuals exercising their rights, mainly through the export and delete functions, and otherwise by email;
  6. tell you without undue delay, and within 48 hours of becoming aware, about a personal data breach affecting your data, with what we know about its nature, likely consequences and what we are doing about it;
  7. help you, where reasonable, with data protection impact assessments and with consulting the Information Commissioner's Office;
  8. delete your data when your account is deleted or this agreement ends (live data immediately, backups within 35 days), unless UK law requires us to keep it;
  9. give you the information you reasonably need to show that these obligations are met, and allow for an audit on reasonable notice, no more than once a year, at your cost.

Sub-processors.

Sub-processorWhat forWhere
Amazon Web Services EMEA SARLHosting, database, backups, login serviceLondon, United Kingdom

Stripe handles your payments as an independent controller and seller of record. It receives your billing details, never the contents of your CRM.

International transfers. Your CRM data is stored in the United Kingdom. We will not move it outside the UK without telling you in advance and putting in place a transfer mechanism that UK law recognises.