For the Zoho CRM Audit tool · Last updated 17 July 2026
This policy explains what data the Zoho CRM Audit tool (“the tool”) collects when you connect your Zoho CRM, how we use it, who we share it with, and how long we keep it. The tool is operated by Limitless IT Consultancy (“we”, “us”), a Zoho Authorised Partner.
CRM data (read-only) — When you authorise the connection, we read — but never write to — your CRM’s configuration (modules, fields, users, profiles, automation) and record data in order to calculate your audit. We use Zoho’s official API and only ever read; we never create, edit or delete anything in your CRM.
Your contact details — The first name, last name and email address of the Zoho user who authorises the connection, so we can give you your report and discuss the results.
Your CRM users — To audit access and activity, your report includes the names, email addresses, roles and profiles of the users in your CRM, along with named breakdowns of who created or owns records.
Organisation details — Your CRM edition and the number of users in your organisation.
Marketing & device data — How you arrived at the tool (referring site / “source”), your device type (mobile, tablet or desktop) and any campaign tags in the link you followed (UTM source, medium, campaign, content and term).
We use the data above to:
Produce your audit — Analyse your CRM and generate your personalised health report.
Contact you — Send you your report and follow up about your results and relevant Limitless IT services.
Improve the tool — Understand which channels bring people to the tool and refine the audit.
We never change your CRM — The connection is read-only. We do not create, edit or delete anything in your Zoho CRM.
We delete your raw records — Your individual CRM records are processed only in memory while the audit runs (about 60 seconds) and are deleted the moment your report is generated. The report we store holds your audit findings, scores and counts and the user details described above — never copies of your customer or transaction records (your leads, contacts, deals and the like).
We don’t sell your data — We never sell or rent your personal data to anyone.
Raw CRM records — Held transiently during the audit only, then deleted immediately.
Your report — Stored securely and reachable through a private link with a built-in passcode, so you can revisit your results. You can ask us to delete it at any time, and we don’t keep it any longer than we need to support your enquiry.
Contact details & audit summary — Logged in our own CRM so we can follow up, and kept until you ask us to remove them (see your rights below).
We use a small number of trusted providers to run the tool. They process data on our behalf under their own security and privacy commitments:
Zoho — Your source CRM (read-only) and our own CRM / automation platform where we log your enquiry.
Vercel — Hosting and delivery of the web application.
Neon — The database that stores your generated report.
We do not share your data with advertising networks.
The tool uses only the cookies it needs to work:
Attribution cookie — Records your source, device type and campaign tags on your first visit, so your report can be attributed to the right channel.
Access cookie — Ties your generated report to your browser so you can view it.
We do not use third-party advertising or cross-site tracking cookies.
Under UK GDPR you can ask us to access, correct or delete your personal data, object to or restrict our use of it, or withdraw your consent at any time. To do so, contact us using the details below and we will respond within the timeframes the law requires.
Limitless IT Consultancy — email jake@limitlessitconsultancy.com for any question about this policy or your data.