Cryovo Privacy Policy
Effective: September 21, 2026
Cryovo ("we," "us," "our," or "Cryovo") operates a cold-chain and F-gas compliance platform. This policy explains what we collect, why, and your rights.This is a first-draft template — please have it reviewed by counsel before relying on it.
1. Who we are and our role
Cryovo is a data processor for the business data you and your organization (the controller) upload — temperature readings, equipment records, compliance reports, and traceability lots — and a data controllerfor the account, billing, and usage data needed to run the service. As a B2B tool, most of the data you process relates to your facility and products, not private individuals.
2. Information we collect
- Account data: name, email, company, role (for e-signatures).
- Business data you provide: equipment, temperature logs (CSV/API), traceability lots, compliance records.
- Usage & technical: IP address, browser/device, pages visited, session data — to operate and secure the service.
- Billing data: processed by our payment provider (Stripe). We do not store full card numbers.
3. How we use it
- Provide and secure the platform (excursion detection, audit records, reports).
- Send transactional and, with your consent, promotional communications.
- Comply with legal obligations and respond to lawful requests.
- Improve the product using aggregate, non-identifying data.
4. Legal basis (EEA/UK)
Where applicable, we rely on: contract performance (providing the service you asked for), legitimate interests (securing and improving the service), consent (marketing, optional cookies), and legal obligation.
5. Cookies & consent
We use strictly-necessary cookies (e.g. session/auth) and, where you switch it on, optional analytics. We seek your consent before setting non-essential cookies or running analytics; you can decline and still use the core service.
6. Sharing
We share data only with: our hosting and payment providers (Supabase, Vercel, Stripe) necessary to operate the service, and where required by law. We do not sell personal data.
7. Retention & security
We keep account records for as long as your account is active or as needed for legal/contractual purposes, then delete or anonymize. We use encryption in transit and industry-standard access controls; we do not claim a specific certification (e.g. SOC 2) unless separately obtained.
8. Your rights (GDPR / CCPA / other)
You may request access, correction, deletion (erasure), portability, and — where processing is based on consent — withdrawal of consent. For DSARs and account deletion, use the in-app controls or contact us; we respond within the legally required timeframe.
9. Contact
Privacy questions, DSARs, or a DPA request: contact us via the address on our contact page. A Data Processing Agreement is available here: View the DPA.