← Crystal Orion

Privacy Policy

This Privacy Policy explains how Crystal Orion LLP (“Company”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects personal data in connection with our website, business communications, mobile applications operated by us (“Company Apps”), and mobile app strategy and development services.

1. Scope

This policy applies when you visit our website, contact us, use a Company App, or engage us for professional services. It does not govern third-party websites, platforms, app stores, or services that we do not control.

2. Data Controller and Contact

Crystal Orion LLP is the data controller for personal data covered by this policy unless a contract states otherwise. Privacy requests may be sent to services@crystalorion.com.

3. Data We May Collect

4. Sources

We receive data directly from you, through meetings and communications, automatically through website or product technology, and from lawful public business sources or referrals.

5. How We Use Data

6. Legal Bases

Where applicable, processing relies on contract necessity, legitimate interests, consent, and legal obligations. The basis used depends on the context and the data involved.

7. Cookies and Similar Technologies

We may use cookies, local storage, analytics, logs, and similar technologies for essential functionality, security, diagnostics, and performance. Browser controls may limit cookies, although doing so can affect functionality.

8. Sharing and Disclosure

We may share data where reasonably necessary with hosting, analytics, security, communications, professional advisory, payment, and distribution providers; with project personnel under appropriate obligations; and with authorities where required by law or necessary to protect rights and safety. We do not sell personal data.

9. International Transfers

Data may be processed in jurisdictions where our team or providers operate. Where required, we use reasonable contractual and technical safeguards for cross-border transfers.

10. Retention

We keep personal data only as long as reasonably necessary for service delivery, security, dispute resolution, legal compliance, and legitimate business records. Periods vary by data category and legal requirements.

11. Security

We use reasonable administrative, organisational, and technical safeguards against unauthorised access, alteration, disclosure, loss, and misuse. No transmission or storage method can be guaranteed absolutely secure.

12. Your Rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing is based on consent. We may verify identity before acting on a request.

13. Marketing Communications

We may send communications relevant to an enquiry or engagement. You may opt out of non-essential promotional messages using the provided method or by contacting us.

14. Children

Our website and professional services are intended for business audiences and are not directed to children. We do not knowingly collect children’s personal data in violation of applicable law.

15. Third-Party Services

Links and integrations may lead to third-party services governed by their own privacy practices. We are not responsible for those practices.

16. Client and Product Data

For partner work, we process Client-provided data according to the contract, instructions, and law. Clients remain responsible for required rights, notices, and consents. For Company Apps, data may be processed to deliver features, provide support, secure accounts, improve quality, and comply with legal obligations.

17. Incident Response

We maintain processes to assess and respond to security incidents and will provide notifications where law or contract requires them.

18. Changes

We may update this policy for legal, technical, or operational reasons. The “Last updated” date identifies the latest revision.

19. Contact and Complaints

For privacy questions, rights requests, or complaints, email services@crystalorion.com. You may also have the right to complain to a competent data protection authority.