Privacy Policy
Last updated 24 July 2026 · Version 0.1 (draft)
This policy explains what personal data CRCX handles, why, and the choices you have. We keep the core stack in the European Union and collect as little as the service needs.
| Name | Function | Location | Data processed |
|---|
Who we are and how to contact us
CRCX BV is the controller for personal data described in this policy, except where we act as a processor for a client as set out below. You can reach us at hello@crcx.eu.
- Controller: CRCX BV
- Registered address: {{TO CONFIRM: registered address}}
- Company number: {{TO CONFIRM: KvK number}}
- Privacy contact: {{TO CONFIRM: DPO or privacy contact}}
What data we collect
We split this by context, because the marketing site, scheduling a meeting, an app account, and the client platform each involve different data.
- Marketing site: privacy first, cookieless analytics with no cross site tracking, so we collect minimal data and do not build a profile of you.
- Scheduling a meeting: when you book through our scheduler, Cal.com, we and Cal.com collect the details you enter such as name, email, and meeting notes, plus technical data such as IP address and timezone, to arrange the meeting. Cal.com processes this as {{TO CONFIRM: processor under a DPA / its role}} in {{TO CONFIRM: data region}}.
- App account: email, authentication data, and product event data generated as you use the app.
- Webinar registration: when you register for a live session, we collect your email, an optional name, your consent, and a timestamp, to register you and send the joining details. This is stored in our own EU infrastructure ({{TO CONFIRM: Supabase, Frankfurt}}).
- Client platform: identity and access data processed on behalf of the client, where CRCX acts as processor and not controller.
Purposes and lawful bases
We use personal data only for clear purposes, each with a lawful basis under the GDPR.
- To run and secure the marketing site: our legitimate interest in a working, safe site.
- To arrange meetings you request: to take steps at your request before any contract, and our legitimate interest in responding to enquiries.
- To provide the app and client platform: performance of a contract with you or your organisation.
- To meet legal obligations and protect our rights: compliance and legitimate interest.
Controller and processor
For the marketing site, scheduling, and app accounts, CRCX is the controller. For identity and access data handled through the client platform, CRCX is a processor acting on documented instructions from the client, who remains the controller. The terms of that processing are set in the agreement with the client.
Where your data is processed
We keep the core stack in the European Union as part of our sovereignty commitment. International transfers outside the EU: {{TO CONFIRM: none outside the EU, otherwise list transfers and safeguards}}.
Sub-processors
We use a small set of vetted providers to run the service. The current list, with each provider's function and region, is at /legal/subprocessors.
How long we keep data
We keep personal data only as long as needed for the purpose it was collected for, or as required by law. Retention periods: {{TO CONFIRM: retention periods per data category}}.
How we protect data
We apply technical and organisational measures appropriate to the risk, including access control, encryption in transit, logging, and least privilege. No system is perfect, so we also plan for detection and response.
Your rights
Under the GDPR you can exercise the following rights over your personal data.
- Access: ask for a copy of the data we hold about you.
- Rectification: ask us to correct data that is wrong or incomplete.
- Erasure: ask us to delete data where the law allows.
- Portability: receive certain data in a portable format.
- Objection and restriction: object to or limit certain processing.
To exercise any of these, email hello@crcx.eu. Where CRCX acts as a processor for a client, we will pass your request to that client. You also have the right to lodge a complaint with a supervisory authority: {{TO CONFIRM: competent supervisory authority}}.
Cookies
The marketing site is cookieless, and the app uses only essential first party cookies for the login session. Full detail, including the Cal.com scheduler, is in our Cookie Policy at /legal/cookies.
Data Processing Agreement
A Data Processing Agreement is available to clients on request via hello@crcx.eu.
Changes to this policy
We may update this policy as the service changes. We will revise the last updated date above, and for material changes we will take reasonable steps to let affected people know.
Contact
Questions about this policy or your data can go to hello@crcx.eu.