
Acceptable Use Policy
HRR CRM · Version 2026-08-15 · Applies to everyone with an account
1. Purpose
HRR CRM holds two things of serious value: the personal data of our clients, and the commercial record of the business. Both can be damaged by ordinary carelessness, not only by bad intent. This policy sets out how to use the system so that neither happens.
It applies to the web app, the mobile app, and any data taken out of either. It sits alongside your employment terms and does not replace them; where this policy and your contract differ, the contract governs.
2. Your account
Your account is yours alone. Do not share your password, and do not let anyone else use the app while you are signed in — including a colleague “just to check something”. Everything done under your account is attributed to you, permanently. If someone else acts under your name, you carry it.
Lock your device. Keep whatever security settings the company requires enabled. If you think someone has accessed your account, or you have lost a device with the app on it, report it immediately — reporting fast is doing the right thing, and delay is what causes harm.
3. Client data is confidential
We hold names, phone numbers, email addresses, home addresses, PAN and GST numbers, financial information, property documents and recorded calls. Some of this would seriously harm a client if they lost control of it.
It is HRR’s commercial asset and it is the client’s personal data. You are trusted with it to do your job. It is not yours, and it does not travel with you.
Access only what you need. Do not look up records you have no business reason to see — not a colleague’s client, not a well-known name out of curiosity, not a property because you recognise the address. Every record you open is logged.
4. Copying and exporting
Exporting, printing, screenshotting or photographing data for a specific client you are working with is permitted only where your work genuinely requires it. Handle the copy as carefully as the original, and delete it once it has served its purpose.
Bulk export is prohibited outright. You must not extract, download, copy or assemble client data in bulk — client lists, contact exports, property databases, or any multi-record extract — under any circumstances. There is no authorisation process, because there is no business reason for an individual to hold a copy of HRR’s client database.
This includes:
- Downloading or exporting a list, search result or report containing client details
- Copying multiple records into a spreadsheet, document or notes app
- Photographing or screenshotting a list of clients
- Using any tool, script or automation to extract records at scale
- Assembling an extract gradually, one record at a time, to get around this rule
One file can expose thousands of clients at once, cannot be recalled, and is the form client data takes when it is sold, taken to a competitor, or lost with a laptop. A rule with exceptions is a rule that gets argued with; this one has none.
If you need data in bulk for a legitimate purpose — a report, an analysis, a mailing — ask for the output, not the data. The report can be produced within the system.
5. Prohibited
- Sharing client contact details outside HRR without authorisation
- Using client data for personal business, or any business other than HRR’s
- Passing client data to another agency, broker or developer
- Using HRR data to set up or assist a competing business
- Taking client data with you when you leave
- Attempting to bypass access restrictions, approvals or validation
- Uploading anything unlawful, or anything you have no right to share
6. Record honestly
Several records carry financial or legal weight. Entering them wrongly on purpose is misconduct, not a clerical slip.
Attendance — mark only your own, and only where you actually are. Do not ask a colleague to mark you in, and do not falsify your location by any means. The system checks your GPS position against your branch, but that check is a deterrent rather than a perfect control: we are relying on your honesty, not only on the software. If you are legitimately working away from the office, mark it as out of office with a genuine reason — that is what it is for, and it counts as a working day.
Commission confirmations must reflect what was actually agreed. Client verification must not be recorded for a client who did not complete it. Transaction status must not be advanced to a stage it has not reached to improve how a pipeline looks.
7. You are being logged
Stated plainly so nothing here is a surprise later:
- Every change you make is logged with your name and the time, permanently, and cannot be edited or deleted by anyone
- Every record you open leaves a trace
- Your attendance check-ins record your GPS location
- Calls through the company system are recorded
- Your activity is scored, and contributes to performance review
This is normal for a system holding client financial data. It exists to make records defensible and mistakes traceable — not to catch you out. Full detail is in the privacy notice.
8. Personal devices
Most people use the mobile app on a personally owned phone. That is permitted, on conditions. Lock the device. Keep the operating system reasonably up to date. Report a lost or stolen device immediately. Sign out and remove the app when you leave HRR.
Do not install the app on a rooted or jailbroken device — these defeat the protections the app relies on — nor on a shared device others can unlock, and do not back up CRM data to a personal cloud account.
9. External and AI tools
Do not paste client data into external tools HRR has not approved. This specifically includes public AI assistants such as ChatGPT, Gemini or Claude.
Pasting a client’s details into a public AI tool is a disclosure of personal data to a third party. It may be retained and it may be used to train a model. Legally it is the same as emailing it to a stranger — it just does not feel like it. This covers drafting a message about a named client, summarising call notes, cleaning up a contact spreadsheet, or translating a document containing client information.
If you want to use an AI tool for work, ask first. There may be an approved way to do what you want. The answer is not automatically no — but ask before, not after.
10. Client communications and WhatsApp
Use the company phone system and HRR email where you can. Calls through the company system are logged against the client record, which protects you as much as the client — it is evidence of what was said.
Client conversation on personal WhatsApp is common in this industry, and this policy does not pretend otherwise. But it is invisible to HRR, it leaves client data on your personal phone, and it does not transfer when you hand over a client or leave.
The conversation may live on WhatsApp; the record must live in the CRM. Record the substance of any material client conversation — what was agreed, quoted or committed to. Do not move a client relationship onto personal channels to keep it out of the system.
11. Company property and leaving
All data in HRR CRM — client records, listings, transaction history, commission records and the content you create at work — is the property of Hanu Reddy Realty. Your published realtor profile is yours to write, but HRR may edit or unpublish it.
When you leave, your access is revoked. Your historical records remain, attributed to you, as part of HRR’s business record. You must not retain copies of any HRR or client data, and you must remove the app from personal devices. Client relationships and contact details do not transfer with you. Confidentiality obligations continue after your employment ends.
12. If you make a mistake
You will occasionally get something wrong. What matters is what happens next. Fix it if you can, or ask an administrator. The audit trail records the correction, which protects you — it evidences that you found and fixed the error. Tell someone if client data left HRR.
A corrected mistake is not a disciplinary matter. A concealed one is. If people fear the audit trail they hide errors, and the data becomes untrustworthy for everyone. That is the outcome this policy is trying hardest to avoid.
13. Reporting
Tell someone if you suspect misuse of client data, have sent client information to the wrong person, have lost a device, think your account is compromised, or have seen information you should not have had access to.
Reports made in good faith will not be held against you — including where you are reporting your own mistake. We would rather hear about a problem in an hour than discover it in a month.
14. Consequences
Breaching this policy may result in your access being restricted or withdrawn, and in disciplinary action. Matters are assessed on the facts — whether it was deliberate, whether you reported it yourself and how promptly, what harm resulted, and whether there was any attempt at concealment. Self-reporting is treated as significant mitigation.
Where a disciplinary matter arises, you will be told in writing what you are alleged to have done, given a fair opportunity to respond, allowed to be accompanied by a colleague, shown the evidence relied upon, given the decision in writing, and given a right of appeal.
Serious breaches involving client personal data, falsified financial records, or use of HRR data for a competing business may also carry consequences for you personally, including under the Digital Personal Data Protection Act, 2023.
15. Questions
If you are unsure whether something is permitted, ask before doing it. Contact your branch head or the Grievance Officer at admin@hanureddyrealty.com. Nobody has ever been disciplined for asking.
