We do not intentionally collect special categories of personal data, and the Service is not directed at children under 16.
Enquiry and contact data. Name, email address, company name, topics of interest, monthly budget range, and message content, provided when you submit our contact form or otherwise reach out to us.
QA Maturity self-assessment data. When you start the QA Maturity self-assessment we receive your full name, company email, and company name via Web3Forms so we can follow up. Your answers, scores, and any PDF you download stay in your browser and are not sent to OpenCrevo or stored on our servers. We do not use this data for marketing lists or to train models.
Billing data. Where you enter a paid engagement with OpenCrevo, we process billing and transaction records (plan, amount, country, tax status) needed to operate that relationship. Payment details are collected by our payment or billing provider; we do not receive full card numbers.
Connected tool and engagement data. When an organization engages OpenCrevo for AI quality engineering, we may collect content and metadata from connected tools and systems to provide the Service: repository code and configuration, AI system settings, evaluation datasets, and quality metrics. We use this to deliver the insights and deliverables the Service provides (evaluation pipelines, quality agents, governance frameworks, evidence-cited findings, and recommended fixes). Source artifacts needed for a specific engagement are processed for the duration required to complete that work and are not retained beyond what the engagement requires; what we keep are the normalized findings (identifiers, severities, scores, code references cited as evidence, and suggested fixes) as agreed with the controller.
Connection credentials. The OAuth tokens, API keys, or access credentials you authorize when connecting a platform for an engagement, stored encrypted and scoped read-only by default (see Security below).
Usage data. Log data, device and browser type, and product interaction events, used for security, debugging, and improving the Service.