Tool Documents

Customer Relationship Management

A CRM accumulates two things that make it the hardest tool to leave: years of relationship history, and personal data about people who are not your employees.

Reviewed August 9, 2026. Legal points are summaries of published provisions, not advice. For a related operational perspective, Monitask also publishes a reference on workforce analytics software.

What varies structurally

The object model. Contact, company, deal, and how they relate. Whether a person can belong to two companies, whether a deal can have several contacts, whether relationships are typed — these determine what you can represent and no feature fixes a model that does not fit.

Where activity lives. Emails, calls and meetings either attached to records or held in a separate log. (A helpdesk makes the same claim on the same conversations.) This is the substance of a CRM and it is the part most likely to be lost in export.

For broader context, see monday.com.

Pipeline flexibility. One pipeline or several, and whether stages can differ by product line or team.

And the automation boundary. What the tool does by itself — sequences, scoring, assignment — which is configuration that will not transfer.

Why switching cost is highest here

History has no substitute. A four-year record of who said what to whom is not reconstructible, and unlike project data it does not become irrelevant.

Email integration is deep. A CRM connected to mailboxes has synchronisation state, threading and permissions that a data export does not describe.

And adoption is fragile. Sales teams abandon a CRM that is worse than the last one within weeks, which makes a migration a change-management project rather than a data one.

Price the switching cost at purchase, because in this category it exceeds the licence by more than anywhere else.

The data protection dimension

A CRM holds personal data about people who never agreed to be in it.

A lawful basis is required for holding contact data about prospects, and legitimate interests with a documented assessment is the usual route in the EU.

Data subject rights apply to them. Access, rectification, erasure and objection requests can come from anybody in the database, and the practical question is whether the tool can find and export one person's records across contacts, activities, notes and email history.

Ask that directly: can you produce everything held about one named individual, and can you delete it. A CRM that cannot is a compliance problem the moment somebody asks.

And the subprocessor question is sharper here — enrichment services, email delivery and analytics all see contact data.

What to check in this category specifically

Export completeness for activity history, tested during the trial with real emails attached.

Whether email sync is one-way or two-way, and what happens to synced mail if you leave.

Per-individual retrieval and deletion.

Retention rules — whether records of people you never did business with expire, or accumulate indefinitely.

And what the next tier gates, because CRMs place reporting, permissions and API limits at tier boundaries more aggressively than most categories.

The short version