09/07/26
Privacy Policy
Privacy Policy
Last updated: July 9, 2026
CryviTis Platform — www.cryvitis.com. This Policy describes how CryviTis FZE collects, uses, stores, shares and protects your personal data.
This Privacy Policy (the "Policy") describes the practices of CryviTis FZE ("CryviTis", "we") regarding the collection, use, storage, sharing, disclosure, transfer and protection of the personal data of users ("you", "User") of the platform accessible via www.cryvitis.com, its subdomains, applications and associated services (the "Platform").
By accessing the Platform, creating an account, using our services or providing us with personal information, you acknowledge that you have read, understood and accepted the practices described here.
This Policy forms an integral part of the GTUS. In the event of conflict, this Policy prevails with respect to the processing of personal data.
Article 1 – Data controller and contacts
1.1. Controller identity
The controller of the data collected via the Platform is CryviTis FZE (Free Zone Establishment — FZE), Ajman Free Zone, Building C, United Arab Emirates, license No. 36268. Contact: assistance@cryvitis.com.
1.2. Representative in the European Union
In accordance with Article 27 GDPR, CryviTis, whose head office is outside the EU, will appoint a representative in a Member State. Their details will be published on the Platform and in this Policy upon effective appointment.
Article 2 – Applicable legal framework
CryviTis processes data in accordance with applicable regulations, in particular:
European Union / EEA
Regulation (EU) 2016/679 (GDPR)
Directive 2002/58/EC (ePrivacy), as transposed
Regulation (EU) 2022/2065 (Digital Services Act)
France
Law No. 78-17 of 6 January 1978 (Data Protection Act), as amended
Ordinance No. 2018-1125 of 12 December 2018
Belgium
Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data
Switzerland
Federal Act of 25 September 2020 on Data Protection (FADP, in force 1 September 2023)
Data Protection Ordinance (DPO)
United Arab Emirates
Federal Decree-Law No. 45 of 2021 (PDPL)
Cabinet Decision No. 57 of 2024 (PDPL Executive Regulations)
Other jurisdictions: where Users reside in countries with applicable laws (in particular the California CCPA, Virginia VCDPA, Brazilian LGPD), CryviTis endeavours to comply with the applicable provisions.
2.2. Hierarchy of norms
In the event of conflict between this Policy and the mandatory requirements of a regulation applicable to a User, those requirements prevail for that User.
Article 3 – Definitions
Sensitive data / special categories: data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic or biometric data (for unique identification), health, or sex life/orientation.
Consent: a freely given, specific, informed and unambiguous indication by which you accept the processing of your data.
Cookies: small text files stored on your device during browsing.
Personal data: any information relating to an identified or identifiable natural person (directly or indirectly).
Aggregated data: data combined with that of other Users, no longer allowing individual identification.
Anonymised data: data irreversibly processed so that the person is no longer identifiable.
Pseudonymised data: data that cannot be attributed to a person without separately kept additional information.
Data subject: the natural person whose data is processed.
Controller / Processor / Recipient / Third party: within the meaning of the GDPR.
Profiling: automated processing to evaluate personal aspects (behaviour, preferences, reliability, location, etc.).
Tracking technologies: cookies, pixels, tags, scripts, device identifiers, local/session storage, IndexedDB, fingerprinting, etc.
Processing: any operation on data (collection, storage, consultation, disclosure, erasure, etc.).
Transfer: disclosure of data to a recipient located in a third country or an international organisation.
Data breach: a security breach leading to unauthorised destruction, loss, alteration, disclosure or access.
User / Client / Professional: within the meaning of the GTUS.
Article 4 – Personal data collected
4.1. Collection principles
We collect data (a) directly from you, (b) automatically during use, (c) from third-party sources. We apply data minimisation; however, operating a matchmaking platform requires collecting many categories for operation, transaction security, fraud prevention and legal obligations.
4.2.1. Registration and account data (all Users)
Last name, first name(s) required — identification, billing, KYC
Date of birth required — age verification, KYC
Email required — communication, authentication, notifications
Primary phone required — verification, communication, security · secondary optional
Password required · Security question optional
Country of residence required — compliance, tax · Postal address, postcode, city required — billing, location
Language, time zone optional · Profile photo, biography optional · Notification preferences optional
Additional data (Professionals)
Company name, legal form, registration number required — identification, KYB · VAT number activity-based · incorporation date, NAF/NACE code optional · sector required
Registered office address required · correspondence address optional
Bank details (holder, IBAN, BIC/SWIFT, bank, country) required — payouts
Activity description, areas of expertise, indicative rates required · experience, diplomas, languages, availability, web/LinkedIn links optional
Professional liability insurance (insurer, policy no., expiry) activity-based · professional body, approvals activity-based
4.2.2. Identity verification (KYC/KYB)
KYC: ID document (both sides) and document photo, extracted data (name, date of birth, document number and dates, authority), verification result, metadata (date, IP, device) — kept for account duration + 5 years.
KYB: registration extract (< 3 months), articles of association, proof of business address, extracted data (company name, office, directors, capital…), validation result via official APIs (INSEE, VIES, BCE) — kept for account duration + 5 years.
Verification is carried out internally by CryviTis: automated checks followed by a systematic manual review by our team after each automatic approval. No external KYC provider is used.
KYC verification currently involves no selfie and no biometric data processing (no facial template or liveness detection). Should such processing be introduced in the future, it would be subject to your prior explicit consent and this Policy would be updated.
4.2.3. Services and Orders
Service publication (title, description, category, pricing, timeframes, prerequisites, FAQ, portfolio, media, keywords, availability, cancellation policy); Orders (Service and options, brief and instructions, provided documents, timestamp, amount, billing currency, billing data — identity, full postal address, individual/business status, intra-community VAT number where applicable —, transaction reference and unique engagement reference “CRY-…”); Bookings (slots, appointment dates and times, Client's and Professional's time zones).
4.2.4. Communications
Messages between Users (content, attachments, status) — 3 years after last exchange + 2 years archived
Support (subject, content, history), complaints, reports — 5 years · support calls (recording if consented) — 5 years
CryviTis emails (delivered/opened/clicked status), chat — 3 years · reviews — account duration + 5 years · testimonials — until consent withdrawal
Messages may be subject to automated analysis to detect circumvention of the Platform, illegal content, spam and fraud, with possible human review. By using messaging, you consent to this analysis. CryviTis does not use these communications for third-party targeted advertising and does not sell them.
4.2.5. Payment data
CryviTis collects: method, last 4 card digits, card type, expiry date, issuing country, billing address, transaction history, invoices. Stripe (PSP) processes sensitive data (full card number, CVV, 3D Secure, IP, device fingerprint, fraud data). CryviTis neither stores nor accesses card numbers or security codes (Stripe, PCI-DSS Level 1 — stripe.com/privacy). Direct Client↔Professional payments via Stripe Connect; CryviTis does not hold the funds.
4.2.6. Disputes
Reason, evidence, arguments, history, decision and reasoning, financial data (amounts, refunds).
4.2.7. Programmes and promotions
Referral Programme: referral code, name and email of invited persons, referrer/invitee relationship, validation status (signed up, active, validated), rewards, commission reductions and cashback. Invited persons are informed of the origin of the invitation and of the processing of their data upon first contact and may object to it. Also: satisfaction surveys, contests, beta tests, webinars.
4.2.8. Other data you provide
Forum content, optional survey responses, support exchanges, suggestions, imported content (with authorisation).
4.2.9. AI Profile and Smart Matching (Professionals)
Answers to the "AI Profile" questionnaire (skills, specialisms, working methods, client preferences) and matching scores generated by the Smart Matching algorithm. These data are used exclusively to improve the relevance of matches (see Article 13.3).
4.3. Data collected automatically
4.3.1. Technical and connection: IP address (public/local), browser (type, version, language, configuration, user-agent), OS, device (type, make/model, resolution, orientation, DPI, identifier), network (type, carrier, speed), date/time and time zone, referrer (source URL, UTM).
4.3.2. Navigation and use: pages visited, order and time spent, clicks, scrolling, searches, filters, results viewed, favourites, comparisons, cart abandonment, conversion path, sessions, frequency, features used, errors, performance.
4.3.3. Geolocation: by IP (country/region/city, legitimate interest, no consent); precise GPS (latitude/longitude, explicit consent required, for optional features); by WiFi (per device settings). Refusing GPS does not prevent use of the Platform.
4.3.4. Device fingerprinting: canvas, WebGL, audio, fonts, plugins, screen, timezone/language, platform, cores/memory, touch support — used for security and fraud prevention (multiple accounts, unauthorised access).
4.3.5. Logging: authentication and security — 12 months; errors — 6 months; HTTP access — 12 months; transactions — 10 years; moderation — 5 years.
4.4. Third-party sources
Business verification: INSEE/Sirene API (FR), VIES (EU, VAT validity), BCE (BE), local registers (CH, UAE)
Host Wix: analytics, performance, security, forms
Stripe: transaction status, fraud alerts, chargebacks
Connected services (with your consent): Google Calendar and Outlook calendars via read-only iCal URL (busy/free events, availability), Discord (ID, servers, voice activity), Google Meet and Microsoft Teams (session links and IDs), social login (name, email, photo, ID)
Public sources: official registers, public LinkedIn profiles, professional websites, directories, press — to verify, enrich (where applicable) and detect fraud
Other Users: reports, reviews, information shared in messages, recommendations
4.5. Data we do not collect
CryviTis does not intentionally collect sensitive data (racial/ethnic origin, political opinions, religious/philosophical beliefs, trade-union membership, genetic or health data, sex life/orientation), minors' data, criminal records (except voluntary disclosure in proceedings) or social security numbers (except where required for tax compliance). Any such data received in error will be deleted as soon as possible, unless legally required to be kept.
Article 5 – Purposes and legal bases
5.1.1. Performance of the contract (Art. 6.1.b GDPR)
Account creation and management; connecting Clients/Professionals; Order processing; invoice generation (self-billing mandate); transactional communications; Virtual Office (Discord); Dispute handling; support; payment facilitation (Stripe Connect); Commission invoicing (multi-currency); Subscription management; booking and time-zone management; organisation of video conferencing sessions (generation of Discord, Google Meet, Microsoft Teams links); management of the Referral Programme (referrer rewards).
5.1.2. Legal obligations (Art. 6.1.c GDPR)
KYC/KYB verification (Directive (EU) 2015/849 AML/CFT); retention of invoices and accounting records; responses to requisitions; tax filings; DSA compliance; retention of connection data; anti-money-laundering and counter-terrorism-financing.
5.1.3. Legitimate interest (Art. 6.1.f GDPR)
Fraud prevention and detection; detection of Platform circumvention; securing access; improving the Platform; statistics and analyses (aggregated/anonymised data); non-transactional service communications (opt-out); protection of CryviTis's rights; research and development; abuse prevention; algorithmic matching (Smart Matching — Article 13.3); processing of invited persons' data under the Referral Programme (information upon first contact, objection possible).
Right to object: you may object to processing based on legitimate interest (assistance@cryvitis.com). CryviTis may refuse where compelling legitimate grounds prevail, or for the defence of legal claims.
5.1.4. Consent (Art. 6.1.a GDPR)
Newsletter and marketing communications (opt-in box); analytics and marketing cookies (banner); precise geolocation (device settings); surveys; testimonials; connection of an external calendar via iCal URL (read-only synchronisation, can be disabled at any time); sharing with marketing partners (opt-in). Withdrawable at any time, without retroactive effect on the lawfulness of prior processing.
5.2. Artificial intelligence and machine learning
CryviTis may use AI/ML for: fraud detection (scoring), message analysis (NLP), identity verification (document analysis), recommendations, ranking of results, algorithmic matching (Smart Matching — Article 13.3), spam detection, automatic categorisation — with human intervention for decisive cases.
No decision producing significant legal effects (suspension, withholding of funds, verification refusal) is taken in a fully automated manner without the possibility of human intervention. You may request human intervention, express your view and contest. CryviTis does not use your data to train generative AI models intended for external uses.
Article 6 – Cookies and tracking technologies
6.1. Management by the host
The Platform is hosted by Wix, which handles the technical management of cookies. See the Wix cookie policy and the Wix privacy policy.
6.3. Technologies used
HTTP cookies, Local Storage, Session Storage, IndexedDB, web beacons, tags, mobile SDKs, fingerprinting.
6.4.1. Strictly necessary cookies
Essential to operation (e.g. XSRF-TOKEN, svSession, consent-policy, smSession, TS*, fedops…). Legal basis: legitimate interest. Cannot be disabled.
6.4.2. Functionality cookies
Preference storage (language, currency, timezone, wixLanguage — 12 months). Legal basis: consent.
6.4.3. Analytics and performance cookies
Google Analytics (_ga, gid, gat — up to 2 years), Wix _wixAB3 (A/B testing). Legal basis: consent. IP anonymisation enabled; see Google.
6.4.4. Marketing and advertising cookies
_fbp (Facebook), Google/DoubleClick (IDE, NID, conversion tracking). Legal basis: consent.
6.5. Managing your preferences
A consent banner (first visit) lets you accept, reject non-essential cookies, or customise by category; only strictly necessary cookies are active by default. Change via "Manage my cookies". You can also configure your browser (Chrome, Firefox, Safari, Edge). The Platform honours Do Not Track (DNT) and Global Privacy Control (GPC) signals: if GPC is active, marketing cookies are disabled and no data is shared for targeted advertising.
6.6. Durations
Session (browser close); persistent: max 13 months (CNIL recommendations); cookie consent: 6 months then renewed.
Article 7 – Data sharing and disclosure
7.1. Between Users
Professional profiles (public): name/company name, photo, description, expertise, declared experience and qualifications, Services (title, description, prices), reviews and ratings, badges, response rate and time, registration date, number of Orders, languages.
After a paid Order: the Client receives the Professional's name, professional email and phone, address and VAT number (billing); the Professional receives the Client's name, email, phone, billing address, brief and documents.
Anti-circumvention protection: personal contact details are shared only after confirmation of a paid Order via the Platform.
7.2. Processors
Our processors act on instruction, are bound by confidentiality, security measures, no unauthorised sub-processing, and deletion/return at the end of the contract. Identity verification (KYC) is carried out internally by CryviTis and does not involve any dedicated processor.
Wix.com Ltd. | Hosting, CMS, emails · all data · Israel, EU, USA · adequacy (Israel), SCC (USA) |
Stripe Inc. | Payments · payment data, identity · USA · SCC |
Brevo (Sendinblue) | Transactional & marketing emails · email, name, Order · France · native GDPR |
Google LLC | Analytics, Google Meet, Google Calendar (iCal) · analytics data, session links, busy/free events · USA · SCC |
Discord Inc. | Virtual Office, video conferencing · ID, session links and IDs · USA · SCC |
Microsoft Corp. | Teams (video conferencing), Outlook Calendar (iCal) · session links, busy/free events · USA · SCC |
Amazon Web Services | Cloud infrastructure (via Wix) · all data (encrypted) · EU, USA · SCC |
Cloudflare Inc. | CDN, security · technical data · USA · SCC |
Our processors may use sub-processors. Any addition involving significant processing triggers a Policy update; Professionals who have signed a DPA are notified with a 30-day objection period.
7.3. Authorities and legal obligations
CryviTis may disclose data to judicial authorities, police, tax administration, financial-intelligence units (AML/CFT suspicion reports), regulators (CNIL, APD…), DSA coordinators. Procedure: verification of the authority's legality and competence, strictly necessary disclosure, notification of the User unless legally prohibited.
7.4. Restructuring
In the event of merger, acquisition, asset transfer or similar operation, your data may be transferred to the acquirer; you will be informed beforehand and may exercise your rights during that period.
7.5. Partners
Subject to your explicit consent: marketing partners (email, preferences — opt-in), content partners, academic partners (anonymised data). CryviTis does not intentionally sell your personal data to third parties.
7.6. Aggregated / anonymised data
CryviTis may share market statistics, benchmark data, research or report data that does not allow your identification — outside the scope of this Policy.
Article 8 – International transfers
8.1. Data location
Data is mainly stored in the EU (Wix servers). Some processing involves transfers outside the EEA.
8.2. Countries and safeguards
European Union | Wix (EU), Brevo · GDPR (native protection) |
Israel | Wix (head office) · European Commission adequacy decision |
Switzerland | some clients · adequacy decision |
United States | Stripe, Google, Microsoft, Discord, Cloudflare · SCC 2021/914 + supplementary measures |
United Arab Emirates | CryviTis (head office) · SCC + supplementary measures |
8.3. Safeguard mechanisms
Adequacy decisions for certain countries. Standard Contractual Clauses (SCC) — Implementing Decision (EU) 2021/914 — for others. Supplementary measures (following Schrems II, EDPB recommendations): encryption in transit (TLS) and at rest (AES-256), pseudonymisation, minimisation, access compartmentalisation; Transfer Impact Assessment (TIA); commitments to notify and challenge excessive government access requests.
8.4. Risk assessment (USA)
CryviTis has assessed transfers to the USA (FISA 702, EO 12333), taking into account Executive Order 14086 and the Data Privacy Framework. Residual risks are considered acceptable given the measures in place and the nature of the data.
Article 9 – Retention periods
9.1. Principles
Data is kept for as long as necessary for the purposes or in accordance with legal obligations, then deleted or anonymised. CryviTis applies three levels: active base, intermediate archiving (legal obligations / litigation), deletion or anonymisation.
9.2. Periods by category
Account / Pro profile | contractual relationship + 5 years → deletion |
KYC (documents) | relationship + 5 years (AML/CFT) → deletion |
Transactions | 3 years + 7 years (tax) → deletion |
Invoices / accounting | 3 years + 10 years (legal) → deletion |
Payment (excl. card no.) | 13 months + 7 years (litigation) → deletion |
User messages | 3 years + 2 years → deletion |
Disputes | duration of Dispute + 5 years → deletion |
Support | 3 years + 2 years → deletion |
Reviews | Service presence + 5 years → deletion |
Connection / security logs | 12 months → anonymisation / deletion |
Transaction logs | 10 years → deletion |
Analytics | 26 months → anonymisation |
Prospecting (consent) | 3 years after last contact → deletion |
Cookie consent | 6 months → renewal |
DSA reports | 6 months + 5 years (DSA) → deletion |
Referral (codes, invitees, rewards) | duration of the relationship + 12 months → deletion |
AI Profile / matching scores | account duration + 12 months → deletion or anonymisation |
External calendar (iCal, busy/free) | until synchronisation is disconnected → deletion |
Video session links | Order duration + 12 months → deletion |
9.4. Inactive accounts
No login or transaction for 36 months: reminder email 30 days before, reactivation possible by login, then deletion (excluding legally retained data).
9.5–9.6. After deletion
Some data is kept per intermediate archiving (tax, accounting, AML/CFT, litigation). Residual copies may temporarily remain: backups (max 30 days), logs (per periods), caches (max 48h). CryviTis does not guarantee deletion of data copied by other Users.
Article 10 – Data security
CryviTis implements appropriate technical and organisational measures.
Technical measures
Encryption: in transit (TLS/HTTPS), at rest (AES-256), KYC data (PII with separate keys), payments (Stripe tokenisation/PCI-DSS), backups (AES-256)
Access control: 2FA available and recommended, least privilege, role separation, entitlement reviews, logging of sensitive access
Infrastructure: certified Wix hosting, DDoS protection (Cloudflare), web application firewall (WAF), intrusion detection, daily backups (30 days), multi-zone redundancy
Application security: anti-CSRF, anti-XSS (sanitisation, CSP), parameterised queries (anti-SQL-injection), rate limiting, session management
Organisational measures
Formalised security policy, confidentiality clauses, incident management, periodic audits and penetration tests, vulnerability monitoring
Payments: handled by Stripe (PCI-DSS Level 1). CryviTis stores no full card data.
No absolute guarantee. No method of transmission or storage is completely secure. In the event of a breach, CryviTis will comply with its notification obligations (Section 14).
Article 11 – Your rights
11.1. Rights (GDPR)
Access (Art. 15) — confirmation and copy of your data
Rectification (Art. 16) — correct/complete
Erasure (Art. 17) — "right to be forgotten", in certain circumstances
Restriction (Art. 18) · Portability (Art. 20, JSON/CSV format) · Objection (Art. 21)
Withdrawal of consent (Art. 7) · Not to be subject to automated decisions (Art. 22)
Post-mortem directives (French law)
Erasure limits: does not apply where processing is necessary for freedom of expression, compliance with a legal obligation, or the establishment/exercise/defence of legal claims. Automated decisions: you may obtain human intervention, express your view and contest.
11.3. Exercising your rights
Contact assistance@cryvitis.com stating your identity, the right(s) exercised and relevant information (an ID may be requested). Deadline: response within one month (extendable by two months if complex). Free, except for manifestly unfounded or excessive requests (reasonable fee or refusal possible).
11.4. Limitations
Exercise may be limited by legal retention obligations, the defence of legal claims, the protection of others' rights, or public-interest grounds; where applicable, the reasons will be communicated to you.
11.5. Complaint to an authority
France — CNIL | cnil.fr · 3 Place de Fontenoy, 75007 Paris |
Belgium — APD | autoriteprotectiondonnees.be · Rue de la Presse 35, 1000 Brussels |
Switzerland — FDPIC | edoeb.admin.ch · Feldeggweg 1, 3003 Bern |
You may lodge a complaint with the authority of your place of residence, work, or the place of the alleged breach.
Article 12 – Jurisdiction-specific rights
12.1. European Union
The rights in Section 11 apply fully (GDPR).
12.2. Switzerland (FADP)
Access, rectification, objection, erasure, portability. Authority: FDPIC.
12.3. United Arab Emirates (PDPL)
Access, rectification, restriction, objection to automated processing, withdrawal of consent, complaint to the UAE Data Office.
12.4. United States — California (CCPA/CPRA)
Right to know, delete, correct, opt out of "sale"/"sharing", limit sensitive data, non-discrimination. CryviTis does not "sell" or "share" (as defined by the CCPA) your data.
12.5. Brazil (LGPD)
Confirmation, access, correction, anonymisation/blocking/deletion, portability, deletion of consent-based data, information on sharing, withdrawal of consent.
Article 13 – Automated decisions and profiling
13.1. Automated processing
Fraud detection (temporary blocking, verification); automatic KYC verification (registration/VAT); identity verification (document analysis); message filtering; circumvention detection; ranking of results; recommendations; algorithmic matching (Smart Matching — 13.3); automatic moderation. Human intervention: yes for all decisive cases (ranking and recommendations have no significant impact).
13.2. Algorithm logic
Ranking of results: relevance, rating and number of reviews, response rate and time, completion rate, recency, profile completeness, badges, geo/language match. No "pay-to-rank". Fraud detection: consistency of information, history, device fingerprint and behaviour, transaction characteristics, known patterns, Stripe Radar.
Safeguard: no fully automated decision producing significant legal effects (suspension, withholding of funds, KYC refusal, sanctions). You may obtain an explanation, human intervention, express your view and contest.
13.3. Smart Matching (algorithmic matching)
When a Client expresses a need, a matching algorithm ("Smart Matching") calculates a compatibility score between that need and the registered Professionals.
General logic: matching the Client's declared needs with the skills and information declared by Professionals.
Categories of data used: answers to the "AI Profile" questionnaire, areas of expertise, languages, availability, activity history on the Platform (ratings, response rate, completed assignments).
Effects: Smart Matching produces only indicative suggestions presented to the Client. It produces no decision with legal effects or similarly significant effects within the meaning of Article 22 GDPR: it does not exclude any Professional from standard search and the directory, does not determine prices or access to services, and the Client remains entirely free in their choice.
Your rights: obtain explanations about a suggestion, request human intervention, express your view, contest a result and object to profiling related to Smart Matching (assistance@cryvitis.com). Professionals who exercise this right remain visible via standard search and the directory.
13.4. Profiling
To personalise the experience, prevent fraud (scoring), improve matching (Smart Matching — 13.3), improve services (aggregated analyses) and targeted marketing (with consent). You have a right to object to profiling, in particular for direct marketing purposes.
Article 14 – Data breach notification
14.1. Definition
A security breach leading to unauthorised destruction, loss, alteration, disclosure or access to personal data.
14.2. Notification to authorities
CryviTis notifies the competent authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to your rights and freedoms (reasons for delay given where applicable).
14.3. Notification to data subjects
In the event of high risk, you are informed as soon as possible: nature of the breach, DPO contact, likely consequences, measures taken, recommendations. Exceptions: encrypted/unintelligible data, subsequent measures eliminating the risk, or disproportionate effort (public notification then made).
14.4. Documentation
Every breach is documented (facts, effects, measures) and made available to authorities on request.
Article 15 – Minors
The Platform is restricted to adults (18 years minimum, or the local age of majority if higher). CryviTis does not knowingly collect minors' data. Parents or guardians: if your child has provided us with data without your consent, contact assistance@cryvitis.com; we will delete it as soon as possible. If we discover such data, we delete it and close the relevant account.
Article 16 – Links to third-party sites
The Platform may contain links to third-party sites, provided for your convenience, without endorsement or control by CryviTis. We are not responsible for their practices; review their policies before providing them with data. Main services: Stripe, Google, Discord, Wix.
Article 17 – Changes to the Policy
CryviTis may amend the Policy to reflect its practices, services, technologies or legal requirements. Minor changes (corrections, clarifications, similar processors): effective on publication. Substantial changes (new purposes, categories, recipients, retention, or affecting your rights): notified 30 days before taking effect, by email and a notice on the Platform, with the date at the top updated. Continued use constitutes acceptance; otherwise, stop using the Platform and close your account before the effective date.
Article 18 – Miscellaneous provisions
Entirety: this Policy, together with the GTUS, constitutes the entire agreement on data processing. Severability: an invalid provision does not affect the others. No waiver: not exercising a right is not a waiver. Language: drafted in French; in the event of translation divergence, the French version prevails. Governing law: the law of the United Arab Emirates, subject to the mandatory provisions applicable to Users (in particular the GDPR for EU residents).
Article 19 – Contact
For any question or to exercise your rights: assistance@cryvitis.com.
Controller | CryviTis FZE — Ajman Free Zone, Building C, United Arab Emirates — License 36268 |
Website |
CryviTis FZE — Ajman Free Zone, Building C, United Arab Emirates — License: 36268To exercise your rights / questions: assistance@cryvitis.com
.png)