Compliance
Policies, notices and how we meet them
Crestlio holds some of the most sensitive records an employer keeps. Every policy below is authored and maintained by the app owner, and each one maps to a control that is actually enabled in the product rather than to an aspiration.
Privacy notice
Roles, data categories, lawful basis, retention, individual rights and transfers.
Terms of service
Subscription terms, data ownership, liability, termination and data return.
Data Processing Agreement & sub-processors
The versioned DPA, change history, and the full sub-processor register.
Cookie notice
The short list of strictly necessary and functional browser storage. No trackers.
Acceptable use policy
What must never be entered, how records must be written, and enforcement.
Security & trust
Tenant isolation, record integrity, least privilege and shared responsibility.
Vulnerability disclosure
Scope, safe harbour, and our acknowledgment and remediation timelines.
Accessibility statement
WCAG 2.2 AA target, measures taken, known limitations and how to report a barrier.
Document verification
Check an exported document's fingerprint, tenant and exporting user.
How each commitment is met in the product
- • Lawful basis and retention period are recorded per record type, per tenant, and enforced by a scheduled retention job
- • Access, correction and erasure requests are tracked end to end with due dates in Compliance → Data requests
- • Legal holds block automated purges until a release is approved by a legal reviewer
- • Every export is watermarked, hashed, signed and logged; audit-log exports require approval
- • Audit events and employee responses cannot be edited or deleted at the database privilege level
- • Incidents are triaged, assessed for notifiability, and evidenced through the incident workflow
What we do not claim
- • No SOC 2, ISO 27001, HIPAA or PCI certification is claimed or implied
- • No independent audit or penetration test result is published on this site
- • No accessibility conformance certificate has been issued by a third party
- • Compliance frameworks also depend on the customer's own organizational processes
Demonstration environment. All organization and people data shown in the product is fictional. Request the app owner’s current compliance documentation before relying on any framework claim.