top of page

Politique de confidentialité

09/07/26

Privacy Policy

Privacy Policy

Last updated: July 9, 2026

CryviTis Platform — www.cryvitis.com. This Policy describes how CryviTis FZE collects, uses, stores, shares and protects your personal data.

This Privacy Policy (the "Policy") describes the practices of CryviTis FZE ("CryviTis", "we") regarding the collection, use, storage, sharing, disclosure, transfer and protection of the personal data of users ("you", "User") of the platform accessible via www.cryvitis.com, its subdomains, applications and associated services (the "Platform").

By accessing the Platform, creating an account, using our services or providing us with personal information, you acknowledge that you have read, understood and accepted the practices described here.

This Policy forms an integral part of the GTUS. In the event of conflict, this Policy prevails with respect to the processing of personal data.

Article 1 – Data controller and contacts

1.1. Controller identity

The controller of the data collected via the Platform is CryviTis FZE (Free Zone Establishment — FZE), Ajman Free Zone, Building C, United Arab Emirates, license No. 36268. Contact: assistance@cryvitis.com.

1.2. Representative in the European Union

In accordance with Article 27 GDPR, CryviTis, whose head office is outside the EU, will appoint a representative in a Member State. Their details will be published on the Platform and in this Policy upon effective appointment.

Article 2 – Applicable legal framework

CryviTis processes data in accordance with applicable regulations, in particular:

European Union / EEA

  • Regulation (EU) 2016/679 (GDPR)

  • Directive 2002/58/EC (ePrivacy), as transposed

  • Regulation (EU) 2022/2065 (Digital Services Act)

France

  • Law No. 78-17 of 6 January 1978 (Data Protection Act), as amended

  • Ordinance No. 2018-1125 of 12 December 2018

Belgium

  • Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data

Switzerland

  • Federal Act of 25 September 2020 on Data Protection (FADP, in force 1 September 2023)

  • Data Protection Ordinance (DPO)

United Arab Emirates

  • Federal Decree-Law No. 45 of 2021 (PDPL)

  • Cabinet Decision No. 57 of 2024 (PDPL Executive Regulations)

Other jurisdictions: where Users reside in countries with applicable laws (in particular the California CCPA, Virginia VCDPA, Brazilian LGPD), CryviTis endeavours to comply with the applicable provisions.

2.2. Hierarchy of norms

In the event of conflict between this Policy and the mandatory requirements of a regulation applicable to a User, those requirements prevail for that User.

Article 3 – Definitions

  • Sensitive data / special categories: data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic or biometric data (for unique identification), health, or sex life/orientation.

  • Consent: a freely given, specific, informed and unambiguous indication by which you accept the processing of your data.

  • Cookies: small text files stored on your device during browsing.

  • Personal data: any information relating to an identified or identifiable natural person (directly or indirectly).

  • Aggregated data: data combined with that of other Users, no longer allowing individual identification.

  • Anonymised data: data irreversibly processed so that the person is no longer identifiable.

  • Pseudonymised data: data that cannot be attributed to a person without separately kept additional information.

  • Data subject: the natural person whose data is processed.

  • Controller / Processor / Recipient / Third party: within the meaning of the GDPR.

  • Profiling: automated processing to evaluate personal aspects (behaviour, preferences, reliability, location, etc.).

  • Tracking technologies: cookies, pixels, tags, scripts, device identifiers, local/session storage, IndexedDB, fingerprinting, etc.

  • Processing: any operation on data (collection, storage, consultation, disclosure, erasure, etc.).

  • Transfer: disclosure of data to a recipient located in a third country or an international organisation.

  • Data breach: a security breach leading to unauthorised destruction, loss, alteration, disclosure or access.

  • User / Client / Professional: within the meaning of the GTUS.

Article 4 – Personal data collected

4.1. Collection principles

We collect data (a) directly from you, (b) automatically during use, (c) from third-party sources. We apply data minimisation; however, operating a matchmaking platform requires collecting many categories for operation, transaction security, fraud prevention and legal obligations.

4.2.1. Registration and account data (all Users)

  • Last name, first name(s) required — identification, billing, KYC

  • Date of birth required — age verification, KYC

  • Email required — communication, authentication, notifications

  • Primary phone required — verification, communication, security · secondary optional

  • Password required · Security question optional

  • Country of residence required — compliance, tax · Postal address, postcode, city required — billing, location

  • Language, time zone optional · Profile photo, biography optional · Notification preferences optional

Additional data (Professionals)

  • Company name, legal form, registration number required — identification, KYB · VAT number activity-based · incorporation date, NAF/NACE code optional · sector required

  • Registered office address required · correspondence address optional

  • Bank details (holder, IBAN, BIC/SWIFT, bank, country) required — payouts

  • Activity description, areas of expertise, indicative rates required · experience, diplomas, languages, availability, web/LinkedIn links optional

  • Professional liability insurance (insurer, policy no., expiry) activity-based · professional body, approvals activity-based

4.2.2. Identity verification (KYC/KYB)

KYC: ID document (both sides) and document photo, extracted data (name, date of birth, document number and dates, authority), verification result, metadata (date, IP, device) — kept for account duration + 5 years.

KYB: registration extract (< 3 months), articles of association, proof of business address, extracted data (company name, office, directors, capital…), validation result via official APIs (INSEE, VIES, BCE) — kept for account duration + 5 years.

Verification is carried out internally by CryviTis: automated checks followed by a systematic manual review by our team after each automatic approval. No external KYC provider is used.

KYC verification currently involves no selfie and no biometric data processing (no facial template or liveness detection). Should such processing be introduced in the future, it would be subject to your prior explicit consent and this Policy would be updated.

4.2.3. Services and Orders

Service publication (title, description, category, pricing, timeframes, prerequisites, FAQ, portfolio, media, keywords, availability, cancellation policy); Orders (Service and options, brief and instructions, provided documents, timestamp, amount, billing currency, billing data — identity, full postal address, individual/business status, intra-community VAT number where applicable —, transaction reference and unique engagement reference “CRY-…”); Bookings (slots, appointment dates and times, Client's and Professional's time zones).

4.2.4. Communications

  • Messages between Users (content, attachments, status) — 3 years after last exchange + 2 years archived

  • Support (subject, content, history), complaints, reports — 5 years · support calls (recording if consented) — 5 years

  • CryviTis emails (delivered/opened/clicked status), chat — 3 years · reviews — account duration + 5 years · testimonials — until consent withdrawal

Messages may be subject to automated analysis to detect circumvention of the Platform, illegal content, spam and fraud, with possible human review. By using messaging, you consent to this analysis. CryviTis does not use these communications for third-party targeted advertising and does not sell them.

4.2.5. Payment data

CryviTis collects: method, last 4 card digits, card type, expiry date, issuing country, billing address, transaction history, invoices. Stripe (PSP) processes sensitive data (full card number, CVV, 3D Secure, IP, device fingerprint, fraud data). CryviTis neither stores nor accesses card numbers or security codes (Stripe, PCI-DSS Level 1 — stripe.com/privacy). Direct Client↔Professional payments via Stripe Connect; CryviTis does not hold the funds.

4.2.6. Disputes

Reason, evidence, arguments, history, decision and reasoning, financial data (amounts, refunds).

4.2.7. Programmes and promotions

Referral Programme: referral code, name and email of invited persons, referrer/invitee relationship, validation status (signed up, active, validated), rewards, commission reductions and cashback. Invited persons are informed of the origin of the invitation and of the processing of their data upon first contact and may object to it. Also: satisfaction surveys, contests, beta tests, webinars.

4.2.8. Other data you provide

Forum content, optional survey responses, support exchanges, suggestions, imported content (with authorisation).

4.2.9. AI Profile and Smart Matching (Professionals)

Answers to the "AI Profile" questionnaire (skills, specialisms, working methods, client preferences) and matching scores generated by the Smart Matching algorithm. These data are used exclusively to improve the relevance of matches (see Article 13.3).

4.3. Data collected automatically

4.3.1. Technical and connection: IP address (public/local), browser (type, version, language, configuration, user-agent), OS, device (type, make/model, resolution, orientation, DPI, identifier), network (type, carrier, speed), date/time and time zone, referrer (source URL, UTM).

4.3.2. Navigation and use: pages visited, order and time spent, clicks, scrolling, searches, filters, results viewed, favourites, comparisons, cart abandonment, conversion path, sessions, frequency, features used, errors, performance.

4.3.3. Geolocation: by IP (country/region/city, legitimate interest, no consent); precise GPS (latitude/longitude, explicit consent required, for optional features); by WiFi (per device settings). Refusing GPS does not prevent use of the Platform.

4.3.4. Device fingerprinting: canvas, WebGL, audio, fonts, plugins, screen, timezone/language, platform, cores/memory, touch support — used for security and fraud prevention (multiple accounts, unauthorised access).

4.3.5. Logging: authentication and security — 12 months; errors — 6 months; HTTP access — 12 months; transactions — 10 years; moderation — 5 years.

4.4. Third-party sources

  • Business verification: INSEE/Sirene API (FR), VIES (EU, VAT validity), BCE (BE), local registers (CH, UAE)

  • Host Wix: analytics, performance, security, forms

  • Stripe: transaction status, fraud alerts, chargebacks

  • Connected services (with your consent): Google Calendar and Outlook calendars via read-only iCal URL (busy/free events, availability), Discord (ID, servers, voice activity), Google Meet and Microsoft Teams (session links and IDs), social login (name, email, photo, ID)

  • Public sources: official registers, public LinkedIn profiles, professional websites, directories, press — to verify, enrich (where applicable) and detect fraud

  • Other Users: reports, reviews, information shared in messages, recommendations

4.5. Data we do not collect

CryviTis does not intentionally collect sensitive data (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic or health data, sex life/orientation), minors' data, criminal records (except voluntary disclosure in proceedings) or social security numbers (except where required for tax compliance). Any such data received in error will be deleted as soon as possible, unless legally required to be kept.

Article 5 – Purposes and legal bases

5.1.1. Performance of the contract (Art. 6.1.b GDPR)

Account creation and management; connecting Clients/Professionals; Order processing; invoice generation (self-billing mandate); transactional communications; Virtual Office (Discord); Dispute handling; support; payment facilitation (Stripe Connect); Commission invoicing (multi-currency); Subscription management; booking and time-zone management; organisation of video conferencing sessions (generation of Discord, Google Meet, Microsoft Teams links); management of the Referral Programme (referrer rewards).

5.1.2. Legal obligations (Art. 6.1.c GDPR)

KYC/KYB verification (Directive (EU) 2015/849 AML/CFT); retention of invoices and accounting records; responses to requisitions; tax filings; DSA compliance; retention of connection data; anti-money-laundering and counter-terrorism-financing.

5.1.3. Legitimate interest (Art. 6.1.f GDPR)

Fraud prevention and detection; detection of Platform circumvention; securing access; improving the Platform; statistics and analyses (aggregated/anonymised data); non-transactional service communications (opt-out); protection of CryviTis's rights; research and development; abuse prevention; algorithmic matching (Smart Matching — Article 13.3); processing of invited persons' data under the Referral Programme (information upon first contact, objection possible).

Right to object: you may object to processing based on legitimate interest (assistance@cryvitis.com). CryviTis may refuse where compelling legitimate grounds prevail, or for the defence of legal claims.

5.1.4. Consent (Art. 6.1.a GDPR)

Newsletter and marketing communications (opt-in box); analytics and marketing cookies (banner); precise geolocation (device settings); surveys; testimonials; connection of an external calendar via iCal URL (read-only synchronisation, can be disabled at any time); sharing with marketing partners (opt-in). Withdrawable at any time, without retroactive effect on the lawfulness of prior processing.

5.2. Artificial intelligence and machine learning

CryviTis may use AI/ML for: fraud detection (scoring), message analysis (NLP), identity verification (document analysis), recommendations, ranking of results, algorithmic matching (Smart Matching — Article 13.3), spam detection, automatic categorisation — with human intervention for decisive cases.

No decision producing significant legal effects (suspension, withholding of funds, verification refusal) is taken in a fully automated manner without the possibility of human intervention. You may request human intervention, express your view and contest. CryviTis does not use your data to train generative AI models intended for external uses.

Article 6 – Cookies and tracking technologies

6.1. Management by the host

The Platform is hosted by Wix, which handles the technical management of cookies. See the Wix cookie policy and the Wix privacy policy.

6.3. Technologies used

HTTP cookies, Local Storage, Session Storage, IndexedDB, web beacons, tags, mobile SDKs, fingerprinting.

6.4.1. Strictly necessary cookies

Essential to operation (e.g. XSRF-TOKEN, svSession, consent-policy, smSession, TS*, fedops…). Legal basis: legitimate interest. Cannot be disabled.

6.4.2. Functionality cookies

Preference storage (language, currency, timezone, wixLanguage — 12 months). Legal basis: consent.

6.4.3. Analytics and performance cookies

Google Analytics (_ga, gid, gat — up to 2 years), Wix _wixAB3 (A/B testing). Legal basis: consent. IP anonymisation enabled; see Google.

6.4.4. Marketing and advertising cookies

_fbp (Facebook), Google/DoubleClick (IDE, NID, conversion tracking). Legal basis: consent.

6.5. Managing your preferences

A consent banner (first visit) lets you accept, reject non-essential cookies, or customise by category; only strictly necessary cookies are active by default. Change via "Manage my cookies". You can also configure your browser (Chrome, Firefox, Safari, Edge). The Platform honours Do Not Track (DNT) and Global Privacy Control (GPC) signals: if GPC is active, marketing cookies are disabled and no data is shared for targeted advertising.

6.6. Durations

Session (browser close); persistent: max 13 months (CNIL recommendations); cookie consent: 6 months then renewed.

Article 7 – Data sharing and disclosure

7.1. Between Users

Professional profiles (public): name/company name, photo, description, expertise, declared experience and qualifications, Services (title, description, prices), reviews and ratings, badges, response rate and time, registration date, number of Orders, languages.

After a paid Order: the Client receives the Professional's name, professional email and phone, address and VAT number (billing); the Professional receives the Client's name, email, phone, billing address, brief and documents.

Anti-circumvention protection: personal contact details are shared only after confirmation of a paid Order via the Platform.

7.2. Processors

Our processors act on instruction, are bound by confidentiality, security measures, no unauthorised sub-processing, and deletion/return at the end of the contract. Identity verification (KYC) is carried out internally by CryviTis and does not involve any dedicated processor.

Wix.com Ltd.

Hosting, CMS, emails · all data · Israel, EU, USA · adequacy (Israel), SCC (USA)

Stripe Inc.

Payments · payment data, identity · USA · SCC

Brevo (Sendinblue)

Transactional & marketing emails · email, name, Order · France · native GDPR

Google LLC

Analytics, Google Meet, Google Calendar (iCal) · analytics data, session links, busy/free events · USA · SCC

Discord Inc.

Virtual Office, video conferencing · ID, session links and IDs · USA · SCC

Microsoft Corp.

Teams (video conferencing), Outlook Calendar (iCal) · session links, busy/free events · USA · SCC

Amazon Web Services

Cloud infrastructure (via Wix) · all data (encrypted) · EU, USA · SCC

Cloudflare Inc.

CDN, security · technical data · USA · SCC

Our processors may use sub-processors. Any addition involving significant processing triggers a Policy update; Professionals who have signed a DPA are notified with a 30-day objection period.

7.3. Authorities and legal obligations

CryviTis may disclose data to judicial authorities, police, tax administration, financial-intelligence units (AML/CFT suspicion reports), regulators (CNIL, APD…), DSA coordinators. Procedure: verification of the authority's legality and competence, strictly necessary disclosure, notification of the User unless legally prohibited.

7.4. Restructuring

In the event of merger, acquisition, asset transfer or similar operation, your data may be transferred to the acquirer; you will be informed beforehand and may exercise your rights during that period.

7.5. Partners

Subject to your explicit consent: marketing partners (email, preferences — opt-in), content partners, academic partners (anonymised data). CryviTis does not intentionally sell your personal data to third parties.

7.6. Aggregated / anonymised data

CryviTis may share market statistics, benchmark data, research or report data that does not allow your identification — outside the scope of this Policy.

Article 8 – International transfers

8.1. Data location

Data is mainly stored in the EU (Wix servers). Some processing involves transfers outside the EEA.

8.2. Countries and safeguards

European Union

Wix (EU), Brevo · GDPR (native protection)

Israel

Wix (head office) · European Commission adequacy decision

Switzerland

some clients · adequacy decision

United States

Stripe, Google, Microsoft, Discord, Cloudflare · SCC 2021/914 + supplementary measures

United Arab Emirates

CryviTis (head office) · SCC + supplementary measures

8.3. Safeguard mechanisms

Adequacy decisions for certain countries. Standard Contractual Clauses (SCC) — Implementing Decision (EU) 2021/914 — for others. Supplementary measures (following Schrems II, EDPB recommendations): encryption in transit (TLS) and at rest (AES-256), pseudonymisation, minimisation, access compartmentalisation; Transfer Impact Assessment (TIA); commitments to notify and challenge excessive government access requests.

8.4. Risk assessment (USA)

CryviTis has assessed transfers to the USA (FISA 702, EO 12333), taking into account Executive Order 14086 and the Data Privacy Framework. Residual risks are considered acceptable given the measures in place and the nature of the data.

Article 9 – Retention periods

9.1. Principles

Data is kept for as long as necessary for the purposes or in accordance with legal obligations, then deleted or anonymised. CryviTis applies three levels: active base, intermediate archiving (legal obligations / litigation), deletion or anonymisation.

9.2. Periods by category

Account / Pro profile

contractual relationship + 5 years → deletion

KYC (documents)

relationship + 5 years (AML/CFT) → deletion

Transactions

3 years + 7 years (tax) → deletion

Invoices / accounting

3 years + 10 years (legal) → deletion

Payment (excl. card no.)

13 months + 7 years (litigation) → deletion

User messages

3 years + 2 years → deletion

Disputes

duration of Dispute + 5 years → deletion

Support

3 years + 2 years → deletion

Reviews

Service presence + 5 years → deletion

Connection / security logs

12 months → anonymisation / deletion

Transaction logs

10 years → deletion

Analytics

26 months → anonymisation

Prospecting (consent)

3 years after last contact → deletion

Cookie consent

6 months → renewal

DSA reports

6 months + 5 years (DSA) → deletion

Referral (codes, invitees, rewards)

duration of the relationship + 12 months → deletion

AI Profile / matching scores

account duration + 12 months → deletion or anonymisation

External calendar (iCal, busy/free)

until synchronisation is disconnected → deletion

Video session links

Order duration + 12 months → deletion

9.4. Inactive accounts

No login or transaction for 36 months: reminder email 30 days before, reactivation possible by login, then deletion (excluding legally retained data).

9.5–9.6. After deletion

Some data is kept per intermediate archiving (tax, accounting, AML/CFT, litigation). Residual copies may temporarily remain: backups (max 30 days), logs (per periods), caches (max 48h). CryviTis does not guarantee deletion of data copied by other Users.

Article 10 – Data security

CryviTis implements appropriate technical and organisational measures.

Technical measures

  • Encryption: in transit (TLS/HTTPS), at rest (AES-256), KYC data (PII with separate keys), payments (Stripe tokenisation/PCI-DSS), backups (AES-256)

  • Access control: 2FA available and recommended, least privilege, role separation, entitlement reviews, logging of sensitive access

  • Infrastructure: certified Wix hosting, DDoS protection (Cloudflare), web application firewall (WAF), intrusion detection, daily backups (30 days), multi-zone redundancy

  • Application security: anti-CSRF, anti-XSS (sanitisation, CSP), parameterised queries (anti-SQL-injection), rate limiting, session management

Organisational measures

  • Formalised security policy, confidentiality clauses, incident management, periodic audits and penetration tests, vulnerability monitoring

Payments: handled by Stripe (PCI-DSS Level 1). CryviTis stores no full card data.

No absolute guarantee. No method of transmission or storage is completely secure. In the event of a breach, CryviTis will comply with its notification obligations (Section 14).

Article 11 – Your rights

11.1. Rights (GDPR)

  • Access (Art. 15) — confirmation and copy of your data

  • Rectification (Art. 16) — correct/complete

  • Erasure (Art. 17) — "right to be forgotten", in certain circumstances

  • Restriction (Art. 18) · Portability (Art. 20, JSON/CSV format) · Objection (Art. 21)

  • Withdrawal of consent (Art. 7) · Not to be subject to automated decisions (Art. 22)

  • Post-mortem directives (French law)

Erasure limits: does not apply where processing is necessary for freedom of expression, compliance with a legal obligation, or the establishment/exercise/defence of legal claims. Automated decisions: you may obtain human intervention, express your view and contest.

11.3. Exercising your rights

Contact assistance@cryvitis.com stating your identity, the right(s) exercised and relevant information (an ID may be requested). Deadline: response within one month (extendable by two months if complex). Free, except for manifestly unfounded or excessive requests (reasonable fee or refusal possible).

11.4. Limitations

Exercise may be limited by legal retention obligations, the defence of legal claims, the protection of others' rights, or public-interest grounds; where applicable, the reasons will be communicated to you.

11.5. Complaint to an authority

France — CNIL

cnil.fr · 3 Place de Fontenoy, 75007 Paris

Belgium — APD

autoriteprotectiondonnees.be · Rue de la Presse 35, 1000 Brussels

Switzerland — FDPIC

edoeb.admin.ch · Feldeggweg 1, 3003 Bern

You may lodge a complaint with the authority of your place of residence, work, or the place of the alleged breach.

Article 12 – Jurisdiction-specific rights

12.1. European Union

The rights in Section 11 apply fully (GDPR).

12.2. Switzerland (FADP)

Access, rectification, objection, erasure, portability. Authority: FDPIC.

12.3. United Arab Emirates (PDPL)

Access, rectification, restriction, objection to automated processing, withdrawal of consent, complaint to the UAE Data Office.

12.4. United States — California (CCPA/CPRA)

Right to know, delete, correct, opt out of "sale"/"sharing", limit sensitive data, non-discrimination. CryviTis does not "sell" or "share" (as defined by the CCPA) your data.

12.5. Brazil (LGPD)

Confirmation, access, correction, anonymisation/blocking/deletion, portability, deletion of consent-based data, information on sharing, withdrawal of consent.

Article 13 – Automated decisions and profiling

13.1. Automated processing

Fraud detection (temporary blocking, verification); automatic KYC verification (registration/VAT); identity verification (document analysis); message filtering; circumvention detection; ranking of results; recommendations; algorithmic matching (Smart Matching — 13.3); automatic moderation. Human intervention: yes for all decisive cases (ranking and recommendations have no significant impact).

13.2. Algorithm logic

Ranking of results: relevance, rating and number of reviews, response rate and time, completion rate, recency, profile completeness, badges, geo/language match. No "pay-to-rank". Fraud detection: consistency of information, history, device fingerprint and behaviour, transaction characteristics, known patterns, Stripe Radar.

Safeguard: no fully automated decision producing significant legal effects (suspension, withholding of funds, KYC refusal, sanctions). You may obtain an explanation, human intervention, express your view and contest.

13.3. Smart Matching (algorithmic matching)

When a Client expresses a need, a matching algorithm ("Smart Matching") calculates a compatibility score between that need and the registered Professionals.

  • General logic: matching the Client's declared needs with the skills and information declared by Professionals.

  • Categories of data used: answers to the "AI Profile" questionnaire, areas of expertise, languages, availability, activity history on the Platform (ratings, response rate, completed assignments).

  • Effects: Smart Matching produces only indicative suggestions presented to the Client. It produces no decision with legal effects or similarly significant effects within the meaning of Article 22 GDPR: it does not exclude any Professional from standard search and the directory, does not determine prices or access to services, and the Client remains entirely free in their choice.

  • Your rights: obtain explanations about a suggestion, request human intervention, express your view, contest a result and object to profiling related to Smart Matching (assistance@cryvitis.com). Professionals who exercise this right remain visible via standard search and the directory.

13.4. Profiling

To personalise the experience, prevent fraud (scoring), improve matching (Smart Matching — 13.3), improve services (aggregated analyses) and targeted marketing (with consent). You have a right to object to profiling, in particular for direct marketing purposes.

Article 14 – Data breach notification

14.1. Definition

A security breach leading to unauthorised destruction, loss, alteration, disclosure or access to personal data.

14.2. Notification to authorities

CryviTis notifies the competent authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to your rights and freedoms (reasons for delay given where applicable).

14.3. Notification to data subjects

In the event of high risk, you are informed as soon as possible: nature of the breach, DPO contact, likely consequences, measures taken, recommendations. Exceptions: encrypted/unintelligible data, subsequent measures eliminating the risk, or disproportionate effort (public notification then made).

14.4. Documentation

Every breach is documented (facts, effects, measures) and made available to authorities on request.

Article 15 – Minors

The Platform is restricted to adults (18 years minimum, or the local age of majority if higher). CryviTis does not knowingly collect minors' data. Parents or guardians: if your child has provided us with data without your consent, contact assistance@cryvitis.com; we will delete it as soon as possible. If we discover such data, we delete it and close the relevant account.

Article 16 – Links to third-party sites

The Platform may contain links to third-party sites, provided for your convenience, without endorsement or control by CryviTis. We are not responsible for their practices; review their policies before providing them with data. Main services: Stripe, Google, Discord, Wix.

Article 17 – Changes to the Policy

CryviTis may amend the Policy to reflect its practices, services, technologies or legal requirements. Minor changes (corrections, clarifications, similar processors): effective on publication. Substantial changes (new purposes, categories, recipients, retention, or affecting your rights): notified 30 days before taking effect, by email and a notice on the Platform, with the date at the top updated. Continued use constitutes acceptance; otherwise, stop using the Platform and close your account before the effective date.

Article 18 – Miscellaneous provisions

Entirety: this Policy, together with the GTUS, constitutes the entire agreement on data processing. Severability: an invalid provision does not affect the others. No waiver: not exercising a right is not a waiver. Language: drafted in French; in the event of translation divergence, the French version prevails. Governing law: the law of the United Arab Emirates, subject to the mandatory provisions applicable to Users (in particular the GDPR for EU residents).

Article 19 – Contact

For any question or to exercise your rights: assistance@cryvitis.com.

Controller

CryviTis FZE — Ajman Free Zone, Building C, United Arab Emirates — License 36268

Website

CryviTis FZE — Ajman Free Zone, Building C, United Arab Emirates — License: 36268To exercise your rights / questions: assistance@cryvitis.com

bottom of page