Privacy notice
This notice explains how personal data is processed when you visit, register for and use the Crevly SaaS application.
Effective from: 16 September 2026 · Version 1.0
Controller and contact
The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
SK Medien. Email: info@sk-medien.biz
Full provider details are set out in the legal notice.
No data protection officer has been appointed. Please direct privacy enquiries to the email address above.
Crevly's role regarding tenant data
For registration, contract administration, billing, security and operation of the website, the provider processes data as a controller in its own right.
Where studios or creators record, import or synchronise third-party personal data in a workspace through platform connectors, the Crevly customer generally acts as controller and the provider as processor. A data processing agreement, including the sub-processors engaged, must be concluded before productive use. The customer is responsible in particular for the legal basis, transparency towards data subjects and the permissibility of the import.
Website access and technical logs
When the site is accessed, technically necessary connection data is processed, in particular IP address, timestamp, requested URL, referrer, browser and device details, response status as well as security and error events. This serves delivery, stability, abuse prevention and fault analysis.
The legal basis is Art. 6(1)(f) GDPR; the legitimate interests are secure and uninterrupted operation and the prevention of attacks. Where processing is necessary to enter into or perform a contract, Art. 6(1)(b) GDPR applies in addition.
Access logs are created by the hosting provider and deleted in accordance with its practice, typically after a few days to weeks. Longer retention occurs only where a security incident requires it.
Account, authentication and communication
On registration and account use we process in particular username, name, email address, optionally a telephone number, preferred language, password hash, roles, tenant assignment, email verification status, sign-in timestamps, session data as well as data relating to invitations and password resets.
This processing is necessary for account creation, authentication, permission management and performance of the contract (Art. 6(1)(b) GDPR). Security-related logs are additionally processed on the basis of Art. 6(1)(f) GDPR. Contractual and service emails form part of the service; marketing is sent only on a separate legal basis.
Passwords are stored exclusively as a hash with a random salt (scrypt); the plaintext entry is not retained.
Workspace, creator and business data
Depending on use, we process tenant and creator master data, platform accounts and external identifiers, encrypted credentials or tokens, imported raw data, earnings, payouts, fees, currencies, revenue shares, time entries, goals, bookings, notes, reports, exports, import and synchronisation status as well as audit data.
Processing of our own contractual data takes place under Art. 6(1)(b) GDPR. For third-party data entered by the customer, the legal basis follows the customer's instructions and responsibility. Credentials and tokens are used solely to set up and run the connection chosen by the customer.
Platform credentials are stored encrypted (AES-256-GCM). Decryption is bound to the tenant, the individual record and an unlocked context.
Platform connectors and data sources
Crevly processes data from manual entry, CSV imports and — once activated by the customer — from connected platforms via interfaces or portal automation. This may also involve cookies, tokens or credentials for the third-party system. Which data is retrieved depends on the connector, the permissions granted and the period selected.
Retrieval is not performed automatically on a schedule; it is triggered.
The customer must be entitled to connect and retrieve data and must observe the terms of the platform concerned. Third-party platforms process data on their own responsibility. Crevly is neither affiliated with those platforms nor responsible for their privacy practices unless expressly stated.
Billing and Stripe
For plans, trials, subscriptions and invoices we process the plan, add-ons, billing interval, status, amounts, currency, invoice and transaction references as well as the customer and invoicing data required. Payments are handled by Stripe. Complete card or bank details are not stored on Crevly systems.
The following is transmitted to Stripe: email address and display name, an internal user and tenant identifier, and the plan, billing interval and add-ons purchased.
The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for records subject to commercial and tax retention duties. For customers outside North and South America the contracting entity is Stripe Payments Europe, Limited, established in Ireland. Stripe may process certain data as a controller in its own right; the Stripe notices shown at payment apply in addition.
Support
For support enquiries we process contact details, the content and time of the enquiry as well as any attachments and technical information voluntarily provided. The legal basis is Art. 6(1)(b) or (f) GDPR depending on the matter. Our legitimate interest lies in handling enquiries and improving the service.
Support cases are deleted once they are no longer required for handling and no contractual or evidentiary obligations stand in the way.
Cookies and local storage
Crevly uses strictly necessary session and security mechanisms only. An authentication cookie, a CSRF protection cookie and a language preference cookie are set. In addition, the application stores in the browser's local storage the sign-in context, the active workspace, a selected plan intention and a display preference for the booking calendar.
The legal basis for accessing the terminal equipment is section 25(2) no. 2 TDDDG; the subsequent processing takes place under Art. 6(1)(b) and (f) GDPR.
Non-essential analytics, marketing or personalisation technologies are used only with prior consent. No such services are currently in use, and no third-party content is embedded.
From 1 October 2026, Crevly carries out its own usage measurement – without third parties and without storing anything on your device. The details are set out in version 2.0 of this notice, which takes effect on that day and can already be read. Until then we only record registration, email confirmation and subscription steps (checkout started or completed, add-ons booked, plan changes and cancellations) as events, with plan and add-on codes and without amounts. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is improving the service. The events are deleted after 13 months; you may object at any time (section 15).
Browser settings can delete or block cookies; without the necessary cookies, signing in is not possible.
Recipients and processors
Access is granted only to authorised internal personnel and to the service providers required. Data may also be transmitted to connected platforms on the customer's instruction and to authorities or advisers where there is a legal obligation or for the defence of legal claims.
The following are engaged:
- Hosting, computing and database: DreamHost (contracting entity based in the United States)
- Email delivery: Plus Five Five, Inc. (Resend), San Francisco, United States
- Payment processing: Stripe Payments Europe, Limited, Ireland
No third-party error or log aggregation takes place. No content delivery network, external fonts or third-party support tools are used.
Service providers are bound under data protection law where they act as processors.
International transfers
Hosting and email delivery are provided by companies whose contracting entities are established in the United States. The actual place of processing at the hosting provider is not contractually limited to any one country and has not yet been conclusively determined. The transfer is based on appropriate safeguards under Art. 46 GDPR:
- DreamHost: EU Standard Contractual Clauses
- Plus Five Five, Inc. (Resend): certification under the EU-US Data Privacy Framework and, in
addition, EU Standard Contractual Clauses
The contracting entity for payment processing is established in Ireland and therefore within the European Economic Area; onward transfers to group companies outside the EEA are governed by Stripe's contractual framework.
A copy of the safeguards can be requested via the contact address in section 1.
Retention and deletion
We store data only for as long as it is required for the respective purpose. Account data and active workspace content are stored for the term of the contract.
After the contract ends, data is retained for 30 days and then deleted. This period exists solely so that an accidental cancellation or a failed payment can be reversed. No export facility is provided.
Commercial and tax records are retained in line with statutory periods and are excluded from deletion. Invoice data is additionally held by the payment provider and is not removed by deletion within Crevly.
Logs of business operations are deleted after 365 days. Tokens and temporary authentication data are removed once they expire or have been used.
Obligation to provide data
The fields marked as mandatory are required for registration, conclusion of the contract or use of the respective function. Without this data, the account or function cannot be provided. Optional profile details and non-essential consents are voluntary and may be refused or withdrawn without disadvantage to the core service.
Automated decision-making
There is no solely automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR. Analyses, categorisations and revenue calculations serve presentation and support; business decisions are made by the customer.
Rights of data subjects
Subject to the statutory conditions, data subjects have the right to access, rectification, erasure, restriction of processing, data portability and objection. Consent given may be withdrawn at any time with effect for the future.
Where processing is based on Art. 6(1)(f) GDPR, an objection may be raised on grounds relating to the particular situation. Requests should be directed to the contact address in section 1. Where a request concerns data entered by a Crevly customer acting as controller, it should be addressed to that customer in the first instance.
Right to lodge a complaint, and security
Data subjects have the right to lodge a complaint with a data protection supervisory authority, in particular at their habitual residence, place of work or the place of the alleged infringement.
The competent supervisory authority for the provider is: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany, telephone +49 30 13889-0, https://www.datenschutz-berlin.de
We apply appropriate technical and organisational measures, in particular access restrictions, tenant separation, encrypted transport only, protected password storage, encryption of connector credentials, protection against cross-site request forgery, rate limiting of sign-in attempts and logging. No procedure, however, offers absolute security.
Changes to this notice
We update this privacy notice when functions, service providers or the legal position change. Each version carries a version identifier and an effective date; earlier versions remain available. We will give notice of material changes in an appropriate manner.