Drive Innovation with SIX Customer Relation Management
Compliance should strengthen customer relationships—not slow them down
Customer relationship management has changed.
A CRM system is no longer simply a digital address book where salespeople store names, telephone numbers, and meeting notes. Modern companies need to manage the entire relationship: from the first website enquiry to qualification, quotation, order, delivery, customer service, complaint handling, and repeat business.
At the same time, every stage creates data, responsibilities, and regulatory risks.
A new lead may provide personal information through a website form. A salesperson may record calls and emails. Marketing teams may want to send newsletters. A customer may request access to their data. A quality manager may need proof that a complaint was investigated. An auditor may ask who changed a record, when it was changed, and why.
When this information is distributed across spreadsheets, inboxes, messaging applications, and separate business systems, companies lose more than efficiency. They lose control.
SIX Customer Relation Management brings customer information, sales activities, documents, operational processes, and compliance controls into one connected environment. It helps businesses work faster while maintaining the structured evidence increasingly expected by customers, auditors, regulators, and management.
Compliance is therefore not an obstacle to innovation. When it is built into everyday processes, compliance creates clearer data, more reliable decisions, better service, and stronger customer trust.
One customer relationship from first contact to repeat business
SIX CRM manages the complete customer journey:
Lead capture → Qualification → Opportunity → Offer → Order → Delivery → Service → Repeat business
Each stage remains connected to the same customer or lead record. This prevents the relationship from being broken into separate pieces as it moves between marketing, sales, operations, finance, delivery, and support.
A lead can enter SIX CRM through a website form, email, telephone call, trade fair, referral, campaign, imported list, or manual entry. The source can be recorded so the company knows where the lead came from and which campaigns generate valuable opportunities.
The lead can then be assigned to a responsible employee, sales team, branch, territory, or business unit. Qualification fields help the team record the customer’s needs, expected value, decision timeline, industry, preferred products, risks, and next action.
Once qualified, the lead can move into the opportunity pipeline. Activities such as calls, meetings, tasks, demonstrations, emails, notes, and follow-up deadlines remain attached to the relationship. Management can see where opportunities are slowing down and which actions are required.
When the customer is ready, the same information supports the preparation of an offer, proposal, estimate, or contract. Accepted offers can become orders without repeatedly entering the same customer, product, price, tax, and delivery information.
The relationship continues after the sale. Orders connect with inventory, purchasing, manufacturing, delivery, invoicing, service tickets, field service, and reporting. The sales team can therefore see more than what a customer promised to buy. It can see what was ordered, delivered, invoiced, returned, serviced, or reported as a problem.
This creates a complete and practical customer history.
One complete customer record
The central customer record gives authorised users a controlled view of the relationship. Depending on the company’s configuration and the employee’s permissions, it may contain:
- Company and contact information
- Billing and delivery addresses
- Contact persons and organisational roles
- Lead source and marketing campaign
- Customer type, industry, territory, and classification
- Assigned sales representative or account manager
- Calls, meetings, emails, notes, and tasks
- Opportunities and their current pipeline stages
- Offers, proposals, estimates, and contracts
- Orders, deliveries, invoices, and payments
- Products, equipment, vehicles, or other customer-owned assets
- Support cases, complaints, repairs, and service history
- Consent, communication preferences, and objections
- Documents and signed acknowledgements
- Data-retention status and compliance actions
- Record history and relevant audit information
The purpose is not to collect as much customer data as possible. The purpose is to maintain the right information for a defined business reason.
This distinction matters under the GDPR. The European Commission identifies purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability as core principles of personal-data processing. A company must not only follow these principles—it must also be able to demonstrate that it follows them. European Commission: Principles of the GDPR
SIX CRM supports this approach by allowing customer information to be structured, classified, protected, reviewed, and connected to an identifiable business process.
GDPR management inside everyday CRM work
A CRM contains personal data. Names, business email addresses, telephone numbers, correspondence, meeting notes, buying preferences, and account activity may all relate to identifiable individuals.
GDPR management should therefore not exist only in a policy document stored somewhere outside the CRM. It must influence how employees collect, use, share, retain, and delete customer information.
Recording the purpose and lawful basis
Different processing activities may rely on different lawful bases.
Data needed to prepare or perform a contract may be processed differently from information used for newsletters, lead scoring, surveys, or long-term marketing. Consent is not automatically the correct legal basis for every activity, and one general consent checkbox should not be used to cover unrelated purposes.
A compliance-aware CRM configuration can record:
- The purpose of processing
- The applicable lawful basis
- When and how information was collected
- The source of the data
- Which privacy notice was presented
- The version of that privacy notice
- Whether consent was requested
- The date and method of consent
- Consent withdrawal
- Objections to direct marketing
- Permitted communication channels
- Retention or review dates
This creates evidence behind the status displayed in the CRM. Instead of showing only “marketing allowed,” the system can explain why the communication is permitted and when that permission was recorded.
Managing marketing preferences
Direct marketing requires particular care.
A contact may agree to receive email newsletters but not telephone marketing. Another person may be contacted about an existing contract but may have objected to promotional communication. Purchased contact lists introduce additional risks because the organisation must be able to demonstrate that the data was obtained lawfully and may be used for the intended advertising purpose.
The European Commission states that organisations using acquired marketing databases must confirm that the information was collected in compliance with the GDPR, keep the database current, respect objections, and follow the applicable ePrivacy rules for communications such as email. European Commission: Legal grounds for processing data
SIX CRM can support separate preferences for different channels and purposes. Marketing lists can then be built from eligible contacts instead of exporting every email address into an uncontrolled spreadsheet.
This reduces the likelihood of contacting someone who has withdrawn consent or objected to marketing.
Supporting data-subject requests
Individuals may have rights to information, access, rectification, erasure, restriction, portability, objection, and protection from certain decisions based solely on automated processing. These rights do not apply identically in every situation, but organisations need processes for receiving, evaluating, completing, and documenting requests. European Data Protection Board: Respect individuals’ rights
SIX can manage a data-subject request as a controlled workflow:
- The request is registered and assigned a unique reference.
- The identity of the requester is verified according to company procedure.
- A responsible privacy employee or data protection officer is assigned.
- Relevant customer records, documents, activities, and connected transactions are identified.
- The applicable right and legal exceptions are evaluated.
- Processing can be restricted while the request is under review.
- Required information can be collected for review and export.
- Corrections, deletions, or restrictions are recorded.
- The response and completion date are documented.
- Evidence of the completed process is retained according to policy.
This is much more reliable than asking employees to search through email accounts, local documents, CRM exports, accounting records, and support systems independently.
Because SIX connects CRM with operational modules, the company can identify related information without assuming that every record may simply be deleted. An invoice may be subject to legal retention requirements even when marketing data is no longer required. A warranty record may need to remain available for the warranty period. A legal dispute may justify preserving specific documents.
The system supports the process. The responsible organisation still determines the legal basis, exceptions, retention requirements, and final action.
Retention and controlled deletion
Keeping every lead forever is not a safe retention policy.
The European Commission explains that personal data should be kept for the shortest period necessary, while also considering legal obligations such as tax, labour, anti-fraud, or warranty requirements. Organisations should establish limits for deleting or reviewing stored information. European Commission: GDPR storage limitation
SIX can apply different retention rules to different types of information:
| Information type | Possible control |
|---|---|
| Unqualified website lead | Review or deletion after a defined inactivity period |
| Active sales opportunity | Retain while the opportunity remains active |
| Lost opportunity | Review after a company-defined period |
| Marketing consent evidence | Retain while relevant to demonstrate the communication status |
| Customer contract | Retain according to contractual and legal requirements |
| Invoice and tax record | Retain according to applicable accounting and tax law |
| Complaint or warranty case | Retain according to warranty, quality, and legal-defence requirements |
| Support ticket | Retain according to service, security, and contractual policy |
The important point is that one retention period should not be applied blindly to every record.
SIX can calculate review dates, identify inactive records, create approval tasks, restrict use, anonymise information where appropriate, or place records into a controlled deletion process. This makes retention an operational routine rather than an occasional manual cleanup.
ISO 9001: turning customer relationships into a quality process
ISO 9001 is not an EU law, and using CRM software does not create ISO 9001 certification. It is a voluntary quality-management standard that organisations can use to structure and improve their processes.
ISO describes important ISO 9001 elements as customer focus, process management, risk-based thinking, documented information, performance evaluation, and continual improvement. Certification, when pursued, requires assessment by an independent certification body. ISO: ISO 9001 explained
SIX CRM can provide operational evidence for these principles.
Understanding customer requirements
Customer requirements can be recorded from the first enquiry and carried into the opportunity, quotation, contract, order, production process, delivery, and service case.
This reduces the risk of requirements being lost when responsibility moves from sales to another department.
Important customer needs may include:
- Product specifications
- Quantities and tolerances
- Delivery expectations
- Required certificates
- Packaging requirements
- Service-level commitments
- Communication responsibilities
- Approval procedures
- Quality requirements
- Regulatory or industry conditions
Changes can be documented rather than communicated only through informal messages.
Complaint and nonconformity management
A customer complaint should not disappear after someone replies to the email.
SIX can connect a complaint to the customer, product, order, delivery, invoice, asset, employee, supplier, or production batch involved. The organisation can then record:
- Complaint category
- Severity and business impact
- Responsible owner
- Immediate containment action
- Investigation
- Root cause
- Corrective action
- Deadline
- Verification of effectiveness
- Customer response
- Final approval and closure
Repeated complaints can be analysed by product, supplier, employee, location, cause, or process. This turns customer feedback into measurable quality improvement.
Customer satisfaction and continual improvement
SIX can combine direct and indirect indicators of customer satisfaction, including:
- Survey responses
- Complaint frequency
- Response times
- Repeat-order rate
- Customer retention
- Delivery performance
- Return rate
- Service resolution time
- Contract renewals
- Opportunity win rate
- Customer profitability
Management can review these indicators through dashboards and scheduled reports. Actions agreed during management reviews can be assigned, monitored, and verified inside the same business platform.
ISO/IEC 27001: protecting customer and commercial information
CRM information has commercial value. It may include customer contacts, contracts, negotiated prices, correspondence, support history, forecasts, sales strategies, and personal data.
ISO/IEC 27001:2022 defines requirements for an Information Security Management System. It uses a risk-management approach that considers people, processes, policies, and technology—not only technical security tools. ISO: ISO/IEC 27001 and the ISO/IEC 27000 family
SIX can support an information-security framework through:
- Role-based access permissions
- Separation of responsibilities
- Controlled access to sensitive records
- User and permission administration
- Authentication controls
- Logging of important activities
- Document access management
- Backup and recovery procedures
- Data-export controls
- Incident and corrective-action workflows
- Periodic access reviews
- Supplier and integration records
- Change and approval histories
A sales employee may need access to assigned leads but not to every financial record. A support technician may need a customer’s service history but not commercial margins. A manager may require aggregated reporting without unrestricted access to every personal note.
Access should follow job responsibilities and the need-to-know principle.
SIX provides the technical and operational structure for this separation. The organisation remains responsible for defining roles, approving access, reviewing permissions, training employees, and managing risks.
ISO/IEC 27701: connecting privacy governance with CRM operations
ISO/IEC 27701:2025 specifies requirements and guidance for establishing, maintaining, and continually improving a Privacy Information Management System. It is intended for organisations acting as controllers or processors of personally identifiable information and is designed to support accountability and evidence-based privacy management. ISO: ISO/IEC 27701:2025
For CRM operations, this can mean maintaining structured information about:
- Categories of personal data
- Processing purposes
- Controller and processor responsibilities
- Data sources
- Recipients and integrations
- Retention requirements
- Data-subject rights
- Privacy risks
- Incidents
- Corrective measures
- Applicable policies
- Evidence of approvals and reviews
The benefit of connecting these controls with SIX CRM is practical: privacy governance becomes linked to the real customer processes where personal data is created and used.
A privacy register should not describe a process that employees do not actually follow. SIX helps reduce that gap by making privacy steps part of the operational workflow.
NIS2 and customer-data resilience
The NIS2 Directive does not apply equally to every company. Its scope depends on factors such as sector, size, criticality, and national implementation. Organisations should therefore determine applicability with qualified legal and cybersecurity advice.
For entities within scope, NIS2 places greater emphasis on cybersecurity risk management, incident handling, business continuity, supply-chain security, access control, and management responsibility.
Even where a company is not directly subject to NIS2, customers and larger business partners may request stronger security evidence from suppliers.
A connected SIX environment can support resilience by keeping customer processes structured and recoverable. Incident records can identify affected customers, responsible teams, systems, integrations, contractual obligations, and follow-up actions. Tasks can be assigned and escalated, while management receives current information about operational impact.
The CRM therefore becomes part of business continuity—not merely part of sales.
Compliance across connected EU-focused modules
The strongest advantage of SIX CRM is that it does not end when an opportunity becomes an order.
Contract and document management
Offers, contracts, privacy notices, data-processing agreements, acknowledgements, and customer correspondence can be connected to the relevant customer and transaction.
Document templates help standardise required information. Version control and approval processes help ensure that employees use the correct document. Electronic-signature integrations can support documented acceptance where applicable.
Sales, invoicing, and financial records
Customer details can flow from the CRM into quotations, orders, deliveries, and invoices. This reduces repeated entry and inconsistent master data.
It also allows personal information to be treated differently according to context. A marketing lead, active customer, invoice recipient, and former contact may require different purposes and retention rules.
Inventory and product traceability
CRM records can connect customers to delivered products, serial numbers, batches, warranties, or installed assets.
If a defect, recall, or safety issue occurs, the company can identify which customers received the affected product. Service and communication activities can then be documented against the same record.
Field service and support
Customer requests can become service tickets, appointments, or field-service assignments. Technicians can receive the information needed for the job without unrestricted access to the complete commercial record.
Work performed, used parts, time, customer approval, signatures, and follow-up actions can be returned to the central customer history.
Tasks, projects, and corrective actions
Compliance creates responsibilities. Someone must review a request, approve a document, investigate a complaint, complete an access review, or respond to an incident.
SIX converts these responsibilities into assigned tasks with owners, deadlines, status, escalation, and evidence of completion.
Business intelligence
Dashboards can show:
- Open and overdue data-subject requests
- Records approaching retention review
- Marketing contacts without a documented communication basis
- Unresolved complaints
- Corrective actions past their deadlines
- Customer satisfaction indicators
- Access-review status
- Security or privacy incidents
- Expiring contracts and agreements
- Pipeline value and conversion
- Sales and service performance
This gives management real-time visibility into both commercial activity and control effectiveness.
Responsible use of AI in CRM
AI can help sales and service teams summarise correspondence, classify leads, suggest follow-up actions, identify duplicate records, draft replies, detect unusual patterns, or estimate opportunity probability.
However, AI should support employees—not silently make every customer decision.
The GDPR includes rights related to decisions based solely on automated processing in qualifying circumstances. The European Data Protection Board lists protection from certain solely automated decisions among the rights organisations must be prepared to address. EDPB: Data-subject rights
SIX can therefore use AI within a controlled process:
- AI-generated content is identified as a suggestion.
- Employees can review and correct the result.
- Sensitive actions can require human approval.
- The data used by the AI can be restricted according to purpose and role.
- Important actions can be logged.
- Model and configuration choices can be governed centrally.
- Automated scoring should be explainable enough for responsible business use.
- AI output should not override contractual, legal, or quality controls.
This approach brings innovation into the CRM without turning customer relationships over to an uncontrolled algorithm.
Cloud agility without losing control
A cloud-based SIX deployment allows authorised teams to work with current customer information across offices, branches, warehouses, production sites, and service locations.
Changes become visible without waiting for spreadsheet consolidation. A salesperson can see whether an order was delivered. A support employee can see the relevant product and service history. Management can review the pipeline and unresolved customer issues. Compliance teams can monitor retention, rights requests, and overdue actions.
This real-time visibility supports faster decisions, but agility does not mean unrestricted access.
Cloud architecture must still be supported by appropriate security, access control, backup, recovery, contractual, and data-governance measures. The correct configuration depends on the organisation, its processing activities, legal requirements, customer commitments, and risk assessment.
What SIX CRM changes in daily work
Without an integrated CRM, employees often ask:
- Who last spoke with this customer?
- Was the offer approved?
- Which privacy notice did the contact receive?
- Can we send this person a marketing email?
- What did the customer originally request?
- Was the complaint investigated?
- Which products were delivered?
- When does the contract expire?
- Who changed this record?
- Is this information still needed?
- What should happen next?
With SIX, the answer is not hidden across several inboxes and spreadsheets. It becomes part of one controlled customer process.
That produces practical benefits:
- Faster response times
- Fewer lost leads
- More consistent follow-up
- Better-quality customer data
- Reduced duplicate work
- Stronger control over personal information
- More reliable audit evidence
- Clear ownership and deadlines
- Better cooperation between departments
- Improved customer service
- More informed management decisions
- Stronger customer confidence
Compliance does not come from software alone
No CRM platform can automatically make an organisation GDPR-, ISO-, or NIS2-compliant.
Compliance depends on the organisation’s purpose, policies, risk assessment, legal interpretation, employee behaviour, contracts, technical environment, and ongoing management.
SIX provides the structure to turn those requirements into real processes.
It helps organisations define responsibilities, control access, connect records, document decisions, manage deadlines, preserve evidence, monitor performance, and improve over time. That makes compliance easier to operate and easier to demonstrate.
The difference is important.
A policy explains what should happen. A connected business-management system helps ensure that it actually happens.
Modern customer relationships need connected control
Customers expect fast answers, personalised service, secure handling of their information, and consistent quality. Regulators expect accountability. Auditors expect evidence. Management expects accurate and timely information.
These expectations cannot be met reliably through disconnected spreadsheets and informal communication.
SIX Customer Relation Management connects customer engagement with sales, contracts, orders, delivery, finance, service, quality, privacy, security, and business intelligence.
The result is a CRM that does more than help companies sell.
It helps them build customer relationships that are efficient, transparent, secure, measurable, and ready for the realities of doing business in the European Union.
Modernise customer relations. Build compliance into the process. Turn trusted data into better business decisions with SIX CRM.


