Privacy notice

This page is maintained by the app owner and describes how Crestlio handles employment records. It is app-owned editable content, not an independent certification or legal advice.

Roles under data protection law

The employer that subscribes to Crestlio is the controller of the employment records held in its tenant. Crestlio operates as a processor and acts only on documented instructions from that employer.

Categories of personal data

Crestlio is designed to hold the minimum needed to document a development process:

  • Identity and work context: name, work email, job title, department, location, reporting line
  • Development records: plans, expectations, action items, meeting notes, dated observations
  • Employee voice: responses and comments written by the employee
  • Acknowledgments: the exact wording shown, the timestamp, and the acknowledging account
  • Security telemetry: audit events recording actor, action, previous and new values, and reason

Data we ask controllers not to enter

Crestlio has no field for special-category data. Health information, union membership, religious or political opinions, biometric identifiers, and government identity numbers must not be entered into free-text fields.

Lawful basis and purpose limitation

Records are processed for the controller's legitimate interest in documenting performance development and for compliance with its own record-keeping obligations. Crestlio does not sell data, does not use customer content for advertising, and does not train models on customer content.

Automated decision-making

Crestlio makes no employment decision and produces no score, ranking, or recommendation about a person. Optional writing assistance only flags vague or unmeasurable wording; every determination is written and approved by an authorized person.

Retention and deletion

Each tenant configures retention per record type, with a default of seven years after employment ends and ten years for audit history. A legal hold blocks deletion of everything in its scope until released. Employee responses and acknowledgments are never deletable by managers or administrators.

Individual rights

Access, correction, restriction, objection, portability, and erasure requests are handled by the employer as controller. Crestlio supports the employer with export and correction tooling and records every export in the audit log. Employees should raise requests with their employer's People & Culture or privacy contact.

International transfers and sub-processors

Hosting, database, and authentication are provided by the platform infrastructure that runs this application. A current sub-processor list and transfer terms are provided by the app owner on request and form part of the data processing agreement.

Security contact and incident reporting

Suspected vulnerabilities or incidents should be reported to the app owner's security contact. Confirmed incidents affecting customer content are notified to the controller without undue delay so the controller can meet its own notification deadlines.

Demonstration environment. All organization and people data shown in the product is fictional. Contact the app owner for the data processing agreement, sub-processor list, and jurisdiction-specific terms before entering real employee data.