This page is maintained by the app owner and describes how Crestlio handles employment records. It is app-owned editable content, not an independent certification or legal advice.
The employer that subscribes to Crestlio is the controller of the employment records held in its tenant. Crestlio operates as a processor and acts only on documented instructions from that employer.
Crestlio is designed to hold the minimum needed to document a development process:
Crestlio has no field for special-category data. Health information, union membership, religious or political opinions, biometric identifiers, and government identity numbers must not be entered into free-text fields.
Records are processed for the controller's legitimate interest in documenting performance development and for compliance with its own record-keeping obligations. Crestlio does not sell data, does not use customer content for advertising, and does not train models on customer content.
Crestlio makes no employment decision and produces no score, ranking, or recommendation about a person. Optional writing assistance only flags vague or unmeasurable wording; every determination is written and approved by an authorized person.
Each tenant configures retention per record type, with a default of seven years after employment ends and ten years for audit history. A legal hold blocks deletion of everything in its scope until released. Employee responses and acknowledgments are never deletable by managers or administrators.
Access, correction, restriction, objection, portability, and erasure requests are handled by the employer as controller. Crestlio supports the employer with export and correction tooling and records every export in the audit log. Employees should raise requests with their employer's People & Culture or privacy contact.
Hosting, database, and authentication are provided by the platform infrastructure that runs this application. A current sub-processor list and transfer terms are provided by the app owner on request and form part of the data processing agreement.
Suspected vulnerabilities or incidents should be reported to the app owner's security contact. Confirmed incidents affecting customer content are notified to the controller without undue delay so the controller can meet its own notification deadlines.
Demonstration environment. All organization and people data shown in the product is fictional. Contact the app owner for the data processing agreement, sub-processor list, and jurisdiction-specific terms before entering real employee data.