Privacy Policy

Last updated: 29 June 2026

This Privacy Policy explains how Resonance Dynamics Pty Ltd (“Toshi”, “we”, “us”) collects, uses, stores, and protects information in connection with Toshi (the “Service”), the sales-intelligence and CRM application available at toshicrm.com. By using the Service you agree to the practices described here.

1. Information we collect

  • Account information — your name, email address, organization name, and authentication details when you sign up (including via Google Sign-In).
  • Content you provide — sales-call transcripts, prospect and contact records, notes, messages, documents, and other CRM data you or your team add to the Service.
  • Integration data — data we access on your behalf when you connect a third-party account (for example, Google), as described in “Google user data” below.
  • Usage and device data — log data, IP address, browser type, and product usage events used to operate, secure, and improve the Service.
  • Cookies — strictly necessary cookies for authentication and session management.

2. Google user data we access

If you choose to connect your Google account, Toshi requests access to the following Google user data, and uses it only to provide features you have enabled:

  • Gmail messages and metadata — to detect replies from your prospects so the Service can automatically pause or update follow-up sequences, surface the conversation in the relevant prospect record, and keep your pipeline accurate. We read only what is necessary to provide these features and do not display unrelated mailbox content.
  • Google Calendar events — to read your availability and write booked meetings, so the Service can schedule calls, offer booking times to prospects, and reflect upcoming meetings on prospect records.

You can revoke Toshi’s access at any time from your Google Account permissions page or from within the Service’s integration settings.

3. Limited Use of Google user data

Toshi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, Toshi does not sell Google user data, and does not transfer it to others except as necessary to provide or improve the user-facing features described above, to comply with applicable law, or as part of a merger or acquisition (with notice). We do not use Google user data for advertising, and we do not allow humans to read it except where you give explicit consent, where it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymized.

4. How we use information

  • To provide, operate, maintain, and secure the Service.
  • To power product features — analyzing transcripts, drafting follow-ups, syncing email and calendar activity, and generating sales intelligence.
  • To communicate with you about your account, support requests, and service updates.
  • To monitor, debug, and improve the Service in a manner consistent with this policy.
  • To comply with legal obligations and enforce our terms.

5. How we store and secure your data

Data is hosted with reputable cloud infrastructure providers and stored in managed, access-controlled databases. We use encryption in transit (TLS) and apply encryption at rest for sensitive fields such as integration secrets. Access to production data is restricted to authorized personnel and protected by role-based access controls. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard safeguards.

6. Third parties and sub-processors

We share data only with service providers that help us run the Service, under contractual confidentiality and data-protection obligations. These may include cloud hosting and database providers, email and SMS delivery providers, AI/LLM processing providers, payment processing providers, and Google (for the integrations you enable). We do not sell your personal information or your Google user data.

7. Data retention

We retain your information for as long as your account is active or as needed to provide the Service, and thereafter only as required to comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your data as described below; connected-integration data is removed when you disconnect the integration or close your account, subject to backup-rotation timelines.

8. Your rights and choices

  • Access, correct, or export the personal data we hold about you.
  • Request deletion of your account and associated data.
  • Revoke third-party integration access (including Google) at any time.
  • Depending on your location, you may have additional rights under laws such as the GDPR or CCPA.

To exercise any of these rights, contact us at the address below and we will respond within a reasonable timeframe.

9. Children’s privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by additional notice. Your continued use of the Service after an update constitutes acceptance of the revised policy.

11. Contact us

Questions or requests regarding this policy or your data can be sent to Toshi at privacy@toshicrm.com.