Privacy Policy
Last updated 2 August 2026
Please read this before you rely on it. This is a plain-English starting point, not legal advice. Crewly360 stores payslips and employment records, so have a solicitor or data-protection adviser review this against your actual processing before you take on customers.
This policy explains what personal data Crewly360 collects, why, and what rights you have. It covers both people who visit our website and people whose details are held inside a customer's workspace.
1. Who is responsible for your data
For our own website and account records, Crewly360 is the data controller. For information a customer puts into their workspace — their employees, contacts and deals — that customer is the controller and we are their processor: we act on their instructions and do not decide what happens to it.
2. What we collect
- Account details — name, work email, job title, organisation name, hashed password, and two-factor settings if you enable them.
- Usage and security records — sign-in times, IP address, browser, and an audit log of security-relevant actions such as role changes.
- Workspace content — whatever your organisation stores: contacts, deals, tasks, leave requests, employment records and uploaded payslips.
- Enquiries — if you use the contact form: your name, email, company, phone and message.
We do not use advertising trackers or third-party analytics cookies.
3. Why we process it, and our lawful basis
- To provide the Service — performance of our contract with you.
- To keep accounts secure — our legitimate interest in preventing unauthorised access. This covers the audit log and sign-in records.
- To answer enquiries — your consent, given when you tick the box on the contact form.
- To meet legal obligations — for example, retaining billing records.
4. Payslips and employment records
Payslips are sensitive, so they get stricter handling. They are stored in private cloud storage that is not publicly reachable, and every download is checked against the requester's identity — an employee can only ever retrieve their own. Administrators in your organisation can upload payslips and see the list; nobody at Crewly360 reads them in the course of normal operation.
5. How your data is separated from other customers
Every record carries the identifier of the organisation it belongs to, and every query is filtered by it automatically. The filter is designed to fail closed: if the system cannot establish which organisation a request belongs to, it returns nothing rather than everything. Attempts to write data across organisations are rejected outright.
6. Where it is stored
Data is hosted in the European Union on Google Cloud Platform. Where a sub-processor operates outside the EEA, transfers rely on Standard Contractual Clauses.
7. Who else touches it
- Google Cloud — hosting, database and file storage.
- Our email provider — delivery of verification, invitation and notification messages.
- Our payment provider — subscription billing, once paid plans are live. Card details go to them directly and never reach our servers.
We do not sell personal data, and we do not use it to train machine-learning models.
8. How long we keep it
- Workspace content — for as long as the workspace is open, then 30 days after closure before deletion.
- Security and audit logs — up to 12 months.
- Contact enquiries — up to 24 months, unless you ask us to delete sooner.
- Billing records — as long as tax law requires.
9. Your rights
Under the GDPR you can ask us to:
- give you a copy of your data, in a portable format;
- correct anything inaccurate;
- delete your data, where we have no overriding obligation to keep it;
- restrict or object to certain processing;
- withdraw consent, where consent is the basis we relied on.
If your details sit inside an employer's workspace, ask them first — they control that data, and we will help them respond. You can also complain to the Irish Data Protection Commission at dataprotection.ie.
10. Cookies
We set a session cookie to keep you signed in and a security token to protect forms against cross-site request forgery. Your light or dark theme choice is remembered in your browser's local storage. None of these track you across other websites.
11. Security incidents
If a breach affects your personal data and is likely to present a risk, we will notify the relevant supervisory authority within 72 hours of becoming aware, and tell affected customers without undue delay.
12. Changes
We will post any update here and change the date at the top. For material changes we will email workspace administrators.
13. How to contact us
To exercise any of the rights above, ask a question about this policy, or report a concern, email support@crewly360.com. We aim to respond within one month, as required under the GDPR.
If you are not satisfied with our response, you can complain to the Irish Data Protection Commission at dataprotection.ie.
Questions about this? Get in touch.