GDPR
Last updated: July 26, 2026
Crewio handles conversations, and conversations are personal data. We built the product with that in mind rather than bolting compliance on afterwards. This page summarizes how; the details live in the Privacy Policy.
Data stays in the EU
Production servers and object storage run at Hetzner in Falkenstein, Germany. Workspace content, including mirrored Telegram conversations, is stored there. Where a subprocessor operates outside the EU (see the list in the Privacy Policy), transfers rely on standard contractual clauses or an equivalent mechanism.
Clear roles
For account and billing data, CherryIT is the controller. For workspace content, the workspace owner is the controller and we process it on their instructions. You choose which chats the mirror sees; excluded chats are never stored.
Deletion is real and immediate
Deleting a workspace deletes its content at that moment, mirrored conversations included. We have no interest in accumulating phone numbers or message archives that no customer is paying us to keep. Residual copies in encrypted backups expire on a rolling basis shortly after.
Data subject requests
Access, export, correction, deletion and objection requests go to hello@crewio.xyz; we answer within 30 days. Requests from people whose data appears inside a customer's workspace are routed to that workspace owner, who is the controller for it.
Data processing agreement
If your company needs a signed DPA covering our processing of your workspace data, email hello@crewio.xyz and we will arrange it.
Minimal by design
- No advertising trackers or analytics cookies on the website.
- No selling of personal data, ever.
- Card data never touches our servers; Paddle handles payment as merchant of record.
- AI requests are processed to answer you, not to train models.