CREVORO
Jak to działaCo dla Ciebie zrobimyCiągły rozwójCennikAffiliateSpace
Rozpocznij projekt
← Wróć do CREVOROWszystkie dokumenty prawne
CREVORO LEGAL

Prywatność

This Privacy Policy explains how Synaria Ltd processes personal data when you use CREVORO, including account, project, support, security and integration data.

Ostatnia aktualizacja: 2 października 2026Pytania prawne i dotyczące prywatności: hello@crevoro.com
Pełna treść prawna jest obecnie dostępna w języku angielskim. W zakresie dozwolonym prawem wiążąca jest wersja angielska.

Spis treści

  1. Who is responsible for your data
  2. Personal data we process
  3. Why we process data and our lawful bases
  4. Project data and automated development systems
  5. Service providers and recipients
  6. International data transfers
  7. How long we keep data
  8. Security
  9. Your data-protection rights
  10. Cookies and local storage
  11. Children
  12. Complaints and supervisory authorities
  13. Changes to this Policy

1. Who is responsible for your data

Synaria Ltd, Company No. 16911551, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, is the controller for personal data used to operate CREVORO accounts, billing, support, security, communications and the CREVORO service itself.

For personal data that a customer places in a CREVORO project and processes on behalf of its own customers, staff or other individuals, the CREVORO customer is normally the controller and Synaria Ltd acts as processor. The Data Processing Addendum applies to that processing.

European Union representation: Synaria klub, z.s., IČO 24094412, Děčínská 552/1, Střížkov, 180 00 Praha 8, Czech Republic, acts as CREVORO’s European Union representative and EU compliance contact. Synaria Ltd remains the relevant controller or processor and remains responsible for its obligations.

2. Personal data we process

Depending on how you use CREVORO, we may process the following categories of data:

  • account and identity data, such as name, email address, organisation and account identifiers;
  • authentication and security data, such as session identifiers, access records, login events, IP address and security logs;
  • project data, including briefs, prompts, uploaded files, logos, images, source material, project configuration and technical metadata;
  • integration data, including domain information, connection identifiers and encrypted credentials or OAuth tokens where you choose to connect a service;
  • payment and billing metadata where paid features or Stripe-connected payments are enabled; full card details are handled by the payment provider, not by CREVORO;
  • support and communication data, including messages and emails you exchange with us;
  • usage and diagnostic data necessary to operate, secure and troubleshoot the platform.

3. Why we process data and our lawful bases

We process data to provide and administer the service, authenticate users, create and maintain projects, provide support, secure the platform, prevent abuse, manage billing, comply with legal duties and communicate important service information.

Our lawful bases under UK GDPR, and EU GDPR where applicable, are primarily performance of a contract, compliance with legal obligations and our legitimate interests in operating, securing and improving CREVORO. Where the law requires consent, for example for non-essential cookies or optional marketing, we rely on consent and you can withdraw it.

4. Project data and automated development systems

To build and maintain a project, CREVORO can process project instructions, selected files, code, technical context and other project material through automated development and AI-assisted systems used to deliver the service.

We limit this processing to what is reasonably necessary for the requested task. Do not include sensitive personal data in project instructions unless it is necessary, lawful and appropriate for the project. If you use CREVORO to process special-category or criminal-offence data on behalf of others, you are responsible for ensuring an appropriate legal basis and safeguards.

5. Service providers and recipients

We may use service providers for infrastructure, hosting, security, email, business communications, payment processing, automated development/inference and customer-selected integrations. Examples include DeepSeek as the current primary automated development/inference provider, Google Workspace/Gmail for CREVORO business email and Stripe where payment functionality is enabled.

Providers receive only the information reasonably required for their role and are subject to contractual, technical or account-level controls appropriate to the service. We do not sell personal data.

6. International data transfers

CREVORO is operated by a UK company and some providers or project integrations may process data in the United Kingdom, European Economic Area or other countries.

Where a restricted international transfer requires a safeguard, we use an applicable lawful transfer mechanism, such as an adequacy decision, the UK International Data Transfer Agreement or Addendum, Standard Contractual Clauses, or another mechanism permitted by applicable data-protection law.

7. How long we keep data

We keep personal data only for as long as needed for the purpose for which it was collected, taking into account account status, project lifecycle, security, dispute handling, backup cycles and legal obligations.

Account and project data is generally kept while the account or project is active and for a limited period afterwards where needed for recovery, security, claims or legal compliance. Security and operational logs are kept for a proportionate period. Billing, tax and accounting records may be retained for the period required by law, which can be up to six years or longer in specific circumstances.

8. Security

CREVORO uses technical and organisational controls designed to protect data, including access controls, role separation, encrypted transport, restricted administrative access, audit logging and isolation of build/deployment operations. Sensitive credentials stored by CREVORO are encrypted where the relevant integration supports server-side storage.

No system is completely secure. If we become aware of a personal-data breach, we will investigate and make notifications required by applicable law.

9. Your data-protection rights

Depending on the law and the context, you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing is based on consent.

To exercise a right, contact hello@crevoro.com. We may need to verify your identity. If your request concerns data controlled by one of our customers inside that customer’s project, we may direct the request to that customer or assist them as processor.

10. Cookies and local storage

CREVORO uses first-party cookies for language preference, authentication, account security and short-lived federation where needed. We do not currently use advertising or behavioural-analytics cookies on the public CREVORO website.

Details, purposes and current durations are described in the Cookie Policy. If we introduce non-essential cookies, we will provide the consent controls required by applicable law before setting them.

11. Children

CREVORO accounts are not intended for children. If we learn that we have collected personal data from a child as an account holder without an appropriate legal basis or authorisation, we will take reasonable steps to delete it.

12. Complaints and supervisory authorities

Please contact us first at hello@crevoro.com so we can investigate your concern. You also have the right to complain to the UK Information Commissioner’s Office (ICO). If EU GDPR applies to your processing, you may also have the right to complain to the competent supervisory authority in the EEA country where you live or work.

13. Changes to this Policy

We may update this Privacy Policy when the service, law or our data practices change. Material changes will be communicated through the service, by email or another reasonable method where required.

Powiązane dokumenty

Polityka cookiesDPAWarunki usługi

EU Representative · GDPR Article 27

Synaria klub, z.s.Czech ID No.: 24094412Děčínská 552/1Střížkov, 180 00 Praha 8Czech Republic

European Union contact point for data subjects and supervisory authorities on EU GDPR matters. Synaria Ltd remains the relevant controller or processor.

Operator

Synaria LtdCompany No.: 1691155171–75 Shelton Street, Covent Garden,London WC2H 9JQ, United Kingdomhello@crevoro.com

Integracja platformy w UE i compliance

Synaria klub, z.s.IČO: 24094412Děčínská 552/1Střížkov, 180 00 Praha 8, Czech Republic
CREVORO

Ty prowadzisz firmę. CREVORO zajmuje się technologią.

CennikAffiliateSpaceWarunki usługiPrywatnośćPolityka cookiesZwroty i anulowanieReport contentSecurityLegalKontakt

Operator

Synaria LtdCompany No.: 1691155171–75 Shelton Street, Covent Garden,London WC2H 9JQ, United Kingdomhello@crevoro.com

Integracja platformy w UE i compliance

Synaria klub, z.s.IČO: 24094412Děčínská 552/1Střížkov, 180 00 Praha 8, Czech Republic

© 2026 CREVORO · crevoro.com · Wszelkie prawa zastrzeżone.