1. What this policy covers
This policy explains what personal information Cremit Inc. collects, what we do with it, who else sees it, and how we protect it. It covers our website, our marketing, and the Cremit non-human identity security platform, together, the Services.
It covers information we decide the use of ourselves: what we collect from website visitors, prospective customers and account administrators. In privacy law we are a controller for that information.
It does not cover the personal data sitting inside Customer Data, what our customers put into the Services. There we are a processor, acting on the customer's instructions. Their own privacy notice and their Data Processing Addendum with us govern that, not this page.
2. What we collect
2.1 What you give us
- Account details: your name, work email, company, role, and a password we store hashed rather than in the clear.
- Billing details: our payment provider handles the card. We keep the invoice and transaction record; we never hold the full card number.
- Anything you write to us: emails, support tickets, contact forms, demo requests.
- Event and webinar sign-ups: whatever you fill in on the form.
2.2 What we collect as you browse
- Usage: which pages you looked at, which features you used, where you came from, what you clicked, roughly how long you stayed.
- Device and logs: IP address, browser, operating system, device identifiers, timestamps.
- Cookies and similar technology: our Cookie Policy lists them one by one.
2.3 What we get from other companies
Partners and service providers sometimes send us information, business details from B2B data providers, or traffic figures from acquisition platforms. We do not buy personal information about individual consumers.
3. What we do with it
We use personal information to:
- run the Services, keep them secure, maintain them and improve them;
- set up and manage accounts, and answer you when you ask for help;
- send you messages about your account, security and billing;
- send marketing where the law allows it, and you can opt out of that at any time;
- spot, prevent and investigate fraud, abuse and breaches of our Terms;
- meet legal obligations and enforce our agreements;
- analyse how the Services get used, so we know what to build next.
Where the GDPR applies, we rely on one of four legal bases: performing our contract with you; our legitimate interests, such as securing the Services or marketing directly to business contacts; your consent, where consent is what the law requires; and compliance with legal obligations.
5. Companies that help us
We keep this list short on purpose. These are the categories of company that handle data on our behalf:
- Cloud hosting and infrastructure (AWS, Vercel): running the Services and this website.
- Content management (Sanity): the blog, docs and marketing content.
- CRM (Attio): handling sales enquiries and demo requests.
- Email and support: sending transactional and marketing email, and running support tickets.
- Analytics (Google Analytics 4, Ahrefs Analytics, Apollo.io Website Tracker, Vercel Analytics), understanding traffic so we can improve what we publish. These load only if you turn on analytics cookies.
- Advertising and retargeting (Meta Pixel and LinkedIn Insight Tag, delivered through Google Tag Manager), measuring campaigns and reaching visitors again on those platforms. These load only if you turn on advertising cookies, which are off unless you switch them on.
- Scheduling (Calendly): booking demos and meetings.
- Status page (Instatus): publishing service status.
Ask us for the current named list and we will send it. Each of these companies is bound by obligations at least as protective as the ones in this policy, and by our DPA where one applies.
6. Where the data goes
We are based in the Republic of Korea. We and the companies in Section 5 may process personal data in countries other than the one you live in, including the United States and the European Economic Area.
For data leaving the EEA, the UK or Switzerland, we use the safeguards the law provides, the European Commission's Standard Contractual Clauses, the UK's International Data Transfer Addendum, or another mechanism that applies. For data moving to or from Korea, we follow PIPA's cross-border transfer requirements.
7. How long we keep it
We keep personal information for as long as the purpose behind it lasts, running the Services, meeting legal and accounting duties, resolving disputes, enforcing our agreements. In practice:
- Account data: while the account is open, and up to 3 years after it closes, longer only if the law says so.
- Billing records: up to 5 years from the transaction, longer where tax or accounting law requires.
- Support tickets and correspondence: up to 3 years after the matter is resolved.
- Web analytics and cookie data: up to 26 months.
- Security logs: up to 1 year, longer if an investigation needs them.
After that we delete or anonymise it. Two things slow this down: backups, which expire on their own schedule and cannot be edited row by row, and legal holds, which we have to honour.
8. How we protect it
We encrypt personal information in transit with TLS 1.2 or better, and at rest. Access is role-based, so people reach only what their job needs. We log and monitor, we run due diligence on vendors before they touch anything, and we train staff on security.
No system is perfectly secure, and we would rather say so than imply otherwise. If we learn of an incident affecting your personal data, we will tell you as the law requires.
9. What you can ask us to do
Depending on where you live, you can ask us to:
- show you the personal information we hold about you;
- correct it where it is wrong or incomplete;
- delete it;
- stop or limit certain uses of it;
- hand it over in a portable form;
- act on a withdrawal of consent, which does not make what we did beforehand unlawful.
You can also complain to a data protection authority. We would rather you came to us first, but the right is yours either way.
To exercise any of these, write to security@cremit.io. We reply within the time the law allows. For marketing email, the unsubscribe link in any message works immediately.
10. Where you live
10.1 European Economic Area, UK and Switzerland
Cremit is the controller for the personal data covered by this policy. Section 9 lists the rights the GDPR and UK GDPR give you, and you can complain to your national data protection authority.
10.2 Republic of Korea
Under Korea's Personal Information Protection Act, Cremit is the 개인정보처리자. You can ask to see your information, correct it, delete it, or have processing suspended, as Section 9 describes. Send enquiries, complaints and damage-relief requests to the privacy officer in Section 13.
10.3 California
California residents have the rights in Section 9 under the CCPA and CPRA. We do not sell personal information, and we do not knowingly "share" it for cross-context behavioural advertising as the CPRA defines that term.
11. Children
The Services are for business users who have reached the age of majority where they live. We do not knowingly collect personal information from anyone under 16. If you think a child has given us something, write to security@cremit.io and we will delete it.
12. When this policy changes
We update this policy from time to time. When a change matters, we tell you before it takes effect, by email or in the product. The "Last reviewed" date at the top of this page is always the date of the version you are reading.
13. Contact
Questions, concerns or requests about any of this go here: