← Back to CrewzyC Crewzy
⚠️ Working draft — not legal advice. Scaffolded from Crewzy's actual data practices as a starting point. Have it reviewed by legal counsel and complete every [[placeholder]] before publishing.

Privacy Policy

Last updated: [[date]]

1. Who we are & our two roles

Crewzy is a multi-tenant HR and workforce platform operated by [[legal entity name]],[[registered address]] ("Crewzy", "we", "us"). Our role under data-protection law depends on whose data it is:

  • Controller — for the data of the person who signs up and administers an account (name, work email, company, billing). This policy governs that relationship.
  • Processor — for the personal data of a customer's employees, which we process on the customer's instructions. There, the customer company is the controller and our handling is governed by our Terms and our Data Processing Agreement ([[DPA link]]).

2. Personal data we collect

Account & company

Name, work email, hashed password, company name, phone number, and assigned role.

Employee records (processed for our customers)

Name, email, phone, department, job role, employee code, start date and onboarding status.

Employee documents & compliance

Documents your team uploads — which may include identity documents, work permits and other records. Some of this may be sensitive / special-category data (e.g. immigration status), which we store with additional safeguards and expiry tracking. Files are held in Amazon S3 and served via short-lived, signed links.

Operational data

Timesheets (hours, projects, notes), leave requests and balances, expense claims and receipts, and invoices and client details.

Security & audit logs

To keep the platform safe and auditable, we record actions taken in the product together with the acting user's email, IP address, browser user-agent and a timestamp.

Approximate location

We detect your region and currency from your IP address (via network headers and the third-party service ipapi.co) to show the right pricing and defaults. We do not use it to pinpoint you.

3. How we use personal data

  • To provide, secure and support the service and authenticate users.
  • To route approvals and send transactional notifications (e.g. onboarding, reminders).
  • To track document expiry and compliance for our customers.
  • To power optional AI features when a customer enables them (see §6).
  • To bill for paid plans and prevent abuse.

4. Legal bases (where GDPR/UK GDPR applies)

Depending on the processing, we rely on contract (to deliver the service), legitimate interests (security, product improvement, fraud prevention), legal obligation, and consent where required. For employee data we act on the customer's documented instructions. [[confirm bases with counsel]]

5. Sub-processors & third parties

We use a small set of vetted providers to run the service:

  • Amazon Web Services (AWS) — hosting and encrypted document/receipt/invoice storage (region: eu-west-2).
  • ipapi.co — IP-based region/currency detection.
  • AI provider[[OpenAI and/or AWS Bedrock]], used only for optional AI features (see §6).
  • Slack — for the optional Slack integration (Slack user/team identifiers and the email used to link accounts).
  • Email delivery[[email provider]], for transactional messages.
  • Payments[[payment processor]], for paid plans; we do not store full card numbers.

A current list of sub-processors is available on request. [[or link a sub-processor page]]

6. AI features

When a customer enables the AI assistant or AI document parsing, the relevant content is sent to our AI provider to generate a response. [[State whether the provider retains or trains on this data — confirm from your provider's DPA; disclose plainly.]] AI features are optional and can be left off.

7. How we protect your data

We use multi-tenant isolation, encryption in transit and at rest, hashed passwords, role-based access control with least privilege, separation-of-duties on approvals, a full audit trail, email verification and multi-factor authentication. See our Security page for detail.

8. Data retention

We keep personal data for as long as an account is active and as needed to provide the service, then delete or anonymise it within [[retention period]] of account closure, unless a longer period is required by law. Audit logs are retained for [[audit retention period]]. Customers can request export or deletion of their tenant data.

9. International transfers

Data is primarily processed in the EU (AWS eu-west-2). Where we or our sub-processors transfer data across borders (for example for customers or providers outside the EEA/UK), we use appropriate safeguards such as Standard Contractual Clauses. [[confirm mechanisms]]

10. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. If you are an employee of a Crewzy customer, please contact that customer (the controller) first; we will assist them. To exercise rights or ask questions, contact [[privacy contact / DPO email]]. You may also complain to your local supervisory authority.

11. Cookies & local storage

We use strictly-necessary cookies and browser storage to keep you signed in and to run the app (session and authentication tokens), plus IP-based region detection. We do not use advertising cookies. [[Add analytics/marketing cookies here only if you actually use them.]]

12. Children

Crewzy is a workplace tool intended for business use and is not directed to children.

13. Changes to this policy

We may update this policy; we'll revise the "last updated" date and, for material changes, notify account admins.

14. Contact

Questions about this policy or your data: [[privacy@crewzy.io / DPO details]].