Privacy Policy
This Privacy Policy explains how Crystal Orion LLP (“Company”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects personal data in connection with our website, business communications, mobile applications operated by us (“Company Apps”), and mobile app strategy and development services.
1. Scope
This policy applies when you visit our website, contact us, use a Company App, or engage us for professional services. It does not govern third-party websites, platforms, app stores, or services that we do not control.
2. Data Controller and Contact
Crystal Orion LLP is the data controller for personal data covered by this policy unless a contract states otherwise. Privacy requests may be sent to services@crystalorion.com.
3. Data We May Collect
- Identification and contact data, such as name, business email, company, role, country, and communication preferences.
- Enquiry and project data, including requirements, budget, timing, documents, and messages.
- Technical and usage data, including IP address, browser, device, pages viewed, referral source, and approximate location derived from IP.
- Company App data, such as feature usage, app events, diagnostics, crash logs, versions, and device identifiers where needed.
- Contract and transaction data, including proposal details, billing contacts, invoices, and payment status.
- Support and communication records.
4. Sources
We receive data directly from you, through meetings and communications, automatically through website or product technology, and from lawful public business sources or referrals.
5. How We Use Data
- Respond to enquiries and prepare proposals.
- Operate, secure, maintain, and improve Company Apps.
- Deliver and manage contracted services.
- Provide project, operational, and support communications.
- Analyse performance and improve service quality.
- Maintain legal, accounting, and audit records.
- Prevent and investigate fraud, misuse, and security incidents.
6. Legal Bases
Where applicable, processing relies on contract necessity, legitimate interests, consent, and legal obligations. The basis used depends on the context and the data involved.
7. Cookies and Similar Technologies
We may use cookies, local storage, analytics, logs, and similar technologies for essential functionality, security, diagnostics, and performance. Browser controls may limit cookies, although doing so can affect functionality.
8. Sharing and Disclosure
We may share data where reasonably necessary with hosting, analytics, security, communications, professional advisory, payment, and distribution providers; with project personnel under appropriate obligations; and with authorities where required by law or necessary to protect rights and safety. We do not sell personal data.
9. International Transfers
Data may be processed in jurisdictions where our team or providers operate. Where required, we use reasonable contractual and technical safeguards for cross-border transfers.
10. Retention
We keep personal data only as long as reasonably necessary for service delivery, security, dispute resolution, legal compliance, and legitimate business records. Periods vary by data category and legal requirements.
11. Security
We use reasonable administrative, organisational, and technical safeguards against unauthorised access, alteration, disclosure, loss, and misuse. No transmission or storage method can be guaranteed absolutely secure.
12. Your Rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing is based on consent. We may verify identity before acting on a request.
13. Marketing Communications
We may send communications relevant to an enquiry or engagement. You may opt out of non-essential promotional messages using the provided method or by contacting us.
14. Children
Our website and professional services are intended for business audiences and are not directed to children. We do not knowingly collect children’s personal data in violation of applicable law.
15. Third-Party Services
Links and integrations may lead to third-party services governed by their own privacy practices. We are not responsible for those practices.
16. Client and Product Data
For partner work, we process Client-provided data according to the contract, instructions, and law. Clients remain responsible for required rights, notices, and consents. For Company Apps, data may be processed to deliver features, provide support, secure accounts, improve quality, and comply with legal obligations.
17. Incident Response
We maintain processes to assess and respond to security incidents and will provide notifications where law or contract requires them.
18. Changes
We may update this policy for legal, technical, or operational reasons. The “Last updated” date identifies the latest revision.
19. Contact and Complaints
For privacy questions, rights requests, or complaints, email services@crystalorion.com. You may also have the right to complain to a competent data protection authority.