CCrevly
ProductPlatformsPlansCommon questionsStudios
Login
Menu
  • Product
  • Platforms
  • Plans
  • Common questions
  • Studios
Login
Privacy

Privacy notice

This notice explains how personal data is processed when you visit, register for and use the Crevly SaaS application.

Effective from: 1 October 2026 · Version 2.0

Expired
This is an earlier version and is no longer in force.
01

Controller and contact

The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

SK Medien. Email: info@sk-medien.biz

Full provider details are set out in the legal notice.

No data protection officer has been appointed. Please direct privacy enquiries to the email address above.

02

Crevly's role regarding tenant data

For registration, contract administration, billing, security and operation of the website, the provider processes data as a controller in its own right.

Where studios or creators record, import or synchronise third-party personal data in a workspace through platform connectors, the Crevly customer generally acts as controller and the provider as processor. A data processing agreement, including the sub-processors engaged, must be concluded before productive use. The customer is responsible in particular for the legal basis, transparency towards data subjects and the permissibility of the import.

03

Website access and technical logs

When the site is accessed, technically necessary connection data is processed, in particular IP address, timestamp, requested URL, referrer, browser and device details, response status as well as security and error events. This serves delivery, stability, abuse prevention and fault analysis.

The legal basis is Art. 6(1)(f) GDPR; the legitimate interests are secure and uninterrupted operation and the prevention of attacks. Where processing is necessary to enter into or perform a contract, Art. 6(1)(b) GDPR applies in addition.

Access logs are created by the hosting provider and deleted in accordance with its practice, typically after a few days to weeks. Longer retention occurs only where a security incident requires it.

04

Account, authentication and communication

On registration and account use we process in particular username, name, email address, optionally a telephone number, preferred language, password hash, roles, tenant assignment, email verification status, sign-in timestamps, session data as well as data relating to invitations and password resets.

This processing is necessary for account creation, authentication, permission management and performance of the contract (Art. 6(1)(b) GDPR). Security-related logs are additionally processed on the basis of Art. 6(1)(f) GDPR. Contractual and service emails form part of the service; marketing is sent only on a separate legal basis.

Passwords are stored exclusively as a hash with a random salt (scrypt); the plaintext entry is not retained.

05

Workspace, creator and business data

Depending on use, we process tenant and creator master data, platform accounts and external identifiers, encrypted credentials or tokens, imported raw data, earnings, payouts, fees, currencies, revenue shares, time entries, goals, bookings, notes, reports, exports, import and synchronisation status as well as audit data.

Processing of our own contractual data takes place under Art. 6(1)(b) GDPR. For third-party data entered by the customer, the legal basis follows the customer's instructions and responsibility. Credentials and tokens are used solely to set up and run the connection chosen by the customer.

Platform credentials are stored encrypted (AES-256-GCM). Decryption is bound to the tenant, the individual record and an unlocked context.

06

Platform connectors and data sources

Crevly processes data from manual entry, CSV imports and — once activated by the customer — from connected platforms via interfaces or portal automation. This may also involve cookies, tokens or credentials for the third-party system. Which data is retrieved depends on the connector, the permissions granted and the period selected.

Retrieval is not performed automatically on a schedule; it is triggered.

The customer must be entitled to connect and retrieve data and must observe the terms of the platform concerned. Third-party platforms process data on their own responsibility. Crevly is neither affiliated with those platforms nor responsible for their privacy practices unless expressly stated.

07

Billing and Stripe

For plans, trials, subscriptions and invoices we process the plan, add-ons, billing interval, status, amounts, currency, invoice and transaction references as well as the customer and invoicing data required. Payments are handled by Stripe. Complete card or bank details are not stored on Crevly systems.

The following is transmitted to Stripe: email address and display name, an internal user and tenant identifier, and the plan, billing interval and add-ons purchased.

If you choose a paid plan before registering or signing in, we store this plan intention (plan and add-ons) on your account so that we can offer it to you for explicit confirmation after email confirmation – on another device too. It triggers nothing by itself and is deleted once a subscription exists, when you decide against it, or after 14 days at the latest.

The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for records subject to commercial and tax retention duties. For customers outside North and South America the contracting entity is Stripe Payments Europe, Limited, established in Ireland. Stripe may process certain data as a controller in its own right; the Stripe notices shown at payment apply in addition.

08

Support

For support enquiries we process contact details, the content and time of the enquiry as well as any attachments and technical information voluntarily provided. The legal basis is Art. 6(1)(b) or (f) GDPR depending on the matter. Our legitimate interest lies in handling enquiries and improving the service.

Support cases are deleted once they are no longer required for handling and no contractual or evidentiary obligations stand in the way.

09

Cookies and local storage

Crevly uses strictly necessary session and security mechanisms only. An authentication cookie, a CSRF protection cookie and a language preference cookie are set. In addition, the application stores in the browser's local storage the sign-in context, the active workspace and a display preference for the booking calendar. A complete overview with the purpose, duration and legal basis of each individual entry is available under "Cookies and storage".

The legal basis for accessing the terminal equipment is section 25(2) no. 2 TDDDG; the subsequent processing takes place under Art. 6(1)(b) and (f) GDPR.

Non-essential analytics, marketing or personalisation technologies are used only with prior consent. No such services are currently in use, and no third-party content is embedded.

Own usage measurement: To understand whether Crevly actually helps in daily work, we record individual usage events on our own servers, without third parties and without storing anything on your device: on the home, studio, pricing and registration pages and the "Trust and data handling" page the page view with language, a coarse device class, the name of a referring external website and campaign codes from the address (utm parameters); in the product registration, email confirmation, saving, importing or syncing revenue data, opening reports and subscription steps. A visit receives a random identifier that is passed in the address when you click another link on our website (parameter "vid") and is linked to the account if you then register. No cookies are set and nothing is stored in the browser for this. Revenue amounts, prices, credentials, content, IP addresses and the full browser identifier are not recorded. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is improving the service based on actual use. You may object at any time (section 15); your account is then excluded from the measurement.

Browser settings can delete or block cookies; without the necessary cookies, signing in is not possible.

10

Recipients and processors

Access is granted only to authorised internal personnel and to the service providers required. Data may also be transmitted to connected platforms on the customer's instruction and to authorities or advisers where there is a legal obligation or for the defence of legal claims.

The following are engaged:

  • Hosting, computing and database: DreamHost (contracting entity based in the United States)
  • Email delivery: Plus Five Five, Inc. (Resend), San Francisco, United States
  • Payment processing: Stripe Payments Europe, Limited, Ireland

No third-party error or log aggregation takes place. No content delivery network, external fonts or third-party support tools are used.

Service providers are bound under data protection law where they act as processors.

11

International transfers

Hosting and email delivery are provided by companies whose contracting entities are established in the United States. The actual place of processing at the hosting provider is not contractually limited to any one country and has not yet been conclusively determined. The transfer is based on appropriate safeguards under Art. 46 GDPR:

  • DreamHost: EU Standard Contractual Clauses
  • Plus Five Five, Inc. (Resend): certification under the EU-US Data Privacy Framework and, in

addition, EU Standard Contractual Clauses

The contracting entity for payment processing is established in Ireland and therefore within the European Economic Area; onward transfers to group companies outside the EEA are governed by Stripe's contractual framework.

A copy of the safeguards can be requested via the contact address in section 1.

12

Retention and deletion

We store data only for as long as it is required for the respective purpose. Account data and active workspace content are stored for the term of the contract.

After the contract ends, data is retained for 30 days and then deleted. This period exists solely so that an accidental cancellation or a failed payment can be reversed. No export facility is provided.

Commercial and tax records are retained in line with statutory periods and are excluded from deletion. Invoice data is additionally held by the payment provider and is not removed by deletion within Crevly.

Logs of business operations are deleted after 365 days. Usage events (section 9) are deleted 13 months after they occur. Tokens and temporary authentication data are removed once they expire or have been used.

13

Obligation to provide data

The fields marked as mandatory are required for registration, conclusion of the contract or use of the respective function. Without this data, the account or function cannot be provided. Optional profile details and non-essential consents are voluntary and may be refused or withdrawn without disadvantage to the core service.

14

Automated decision-making

There is no solely automated decision-making producing legal or similarly significant effects within the meaning of Art. 22 GDPR. Analyses, categorisations and revenue calculations serve presentation and support; business decisions are made by the customer.

15

Rights of data subjects

Subject to the statutory conditions, data subjects have the right to access, rectification, erasure, restriction of processing, data portability and objection. Consent given may be withdrawn at any time with effect for the future.

Where processing is based on Art. 6(1)(f) GDPR, an objection may be raised on grounds relating to the particular situation. Requests should be directed to the contact address in section 1. Where a request concerns data entered by a Crevly customer acting as controller, it should be addressed to that customer in the first instance.

16

Right to lodge a complaint, and security

Data subjects have the right to lodge a complaint with a data protection supervisory authority, in particular at their habitual residence, place of work or the place of the alleged infringement.

The competent supervisory authority for the provider is: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany, telephone +49 30 13889-0, https://www.datenschutz-berlin.de

We apply appropriate technical and organisational measures, in particular access restrictions, tenant separation, encrypted transport only, protected password storage, encryption of connector credentials, protection against cross-site request forgery, rate limiting of sign-in attempts and logging. No procedure, however, offers absolute security.

17

Changes to this notice

We update this privacy notice when functions, service providers or the legal position change. Each version carries a version identifier and an effective date; earlier versions remain available. We will give notice of material changes in an appropriate manner.

Earlier versions

  • Go to the version currently in force
  • Version 1.0 · 16 September 2026
Back to registration
Crevly

SK Medien

info@sk-medien.biz

Product

  • Features
  • Pricing
  • For studios

Legal

  • Legal notice
  • Privacy
  • Terms of service
  • Cookies
  • Trust and data

Small business under section 19 of the German VAT Act — the prices shown are final prices with no value added tax.