Skip to main content

Privacy Policy

Effective date: September 3, 2026

This Privacy Policy explains how OpenCrevo OÜ, headquartered in Estonia ("OpenCrevo", "we", "us"), collects and processes personal data in connection with OpenCrevo, including opencrevo.com, the OpenCrevo website, our products and platforms, and related services (the "Service").

Contact for privacy matters: dpo@opencrevo.com

1. Our two roles

We process personal data in two distinct capacities:

  • As a controller for data about visitors to our website and the people who contact us, start the QA Maturity self-assessment, or administer a relationship with OpenCrevo (e.g. your name, email, company, and enquiry details).
  • As a processor for data in the systems, repositories, and services a customer's organization connects that we analyze or quality-engineer on the customer's behalf (e.g. code authored by a team, commit metadata, AI system configuration, and evaluation artifacts). For this data, the organization that engages OpenCrevo is the controller, and we process it under their instructions and our Data Processing Agreement (available on request).

If you are a team member with questions about how data from your organization's connected tools or AI systems is handled, please contact your organization's OpenCrevo administrator first; we will assist them in responding.

2. Data we collect

We do not intentionally collect special categories of personal data, and the Service is not directed at children under 16.

Enquiry and contact data. Name, email address, company name, topics of interest, monthly budget range, and message content, provided when you submit our contact form or otherwise reach out to us.

QA Maturity self-assessment data. When you start the QA Maturity self-assessment we receive your full name, company email, and company name via Web3Forms so we can follow up. Your answers, scores, and any PDF you download stay in your browser and are not sent to OpenCrevo or stored on our servers. We do not use this data for marketing lists or to train models.

Billing data. Where you enter a paid engagement with OpenCrevo, we process billing and transaction records (plan, amount, country, tax status) needed to operate that relationship. Payment details are collected by our payment or billing provider; we do not receive full card numbers.

Connected tool and engagement data. When an organization engages OpenCrevo for AI quality engineering, we may collect content and metadata from connected tools and systems to provide the Service: repository code and configuration, AI system settings, evaluation datasets, and quality metrics. We use this to deliver the insights and deliverables the Service provides (evaluation pipelines, quality agents, governance frameworks, evidence-cited findings, and recommended fixes). Source artifacts needed for a specific engagement are processed for the duration required to complete that work and are not retained beyond what the engagement requires; what we keep are the normalized findings (identifiers, severities, scores, code references cited as evidence, and suggested fixes) as agreed with the controller.

Connection credentials. The OAuth tokens, API keys, or access credentials you authorize when connecting a platform for an engagement, stored encrypted and scoped read-only by default (see Security below).

Usage data. Log data, device and browser type, and product interaction events, used for security, debugging, and improving the Service.

3. Purposes and legal bases

We process personal data to: provide and operate the Service (performance of contract, or the controller's instructions for engagement data); receive QA Maturity self-assessment lead details so we can follow up (consent, given when you submit the assessment form and withdrawable anytime); bill and manage commercial relationships where applicable (contract, legal obligation); secure the Service and prevent abuse (legitimate interests); improve the Service using aggregated, de-identified data (legitimate interests); measure how visitors use our website (consent, given via the cookie banner and withdrawable anytime); send service communications (contract) and, with your consent where required, product news (consent, withdrawable anytime).

4. Sharing and subprocessors

We do not sell personal data. We share data only with:

  • Google Cloud (EU tenant): website hosting, content delivery, automatic git-based deployment, privacy-friendly web analytics, contact form and QA Maturity lead delivery to hello@opencrevo.com, and font delivery for opencrevo.com, consolidated on Google Cloud infrastructure in the European Union.
  • Service providers for email delivery, bound by data processing terms.
  • Authorities where required by law, and successors in the event of a merger or acquisition (with notice).

We do not use your code or data to train third-party models for unrelated purposes. A current subprocessor list is available on request at dpo@opencrevo.com.

5. International transfers

We operate globally and store data on cloud infrastructure. Where personal data subject to GDPR or UK GDPR is transferred internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum.

6. Retention

Enquiry data submitted via our contact form is kept for as long as needed to respond and manage the relationship, then deleted or anonymized within 90 days of closure unless a longer period is required by law or an active engagement. QA Maturity lead emails (name, company email, company name) are deleted or anonymized within 90 days of receipt, or sooner if you send a verified deletion request to the contact below. Assessment answers and PDFs are generated in your browser only and are not stored by OpenCrevo. Connection credentials are deleted when you disconnect the relevant integration or the engagement ends. Engagement findings and reports are kept while the relationship remains active and are deleted within 90 days after engagement termination or a verified deletion request from the controller. Billing records are retained as required by tax and accounting law. Backups roll off within 35 days.

7. Security

We follow SOC 2-aligned security practices, including encryption in transit (TLS) and at rest, least-privilege access controls, audit logging, and periodic access reviews. Connection credentials are protected with industry-standard encryption; API keys and similar secrets are stored using secure hashing where applicable. Engagement work runs in isolated environments where practicable, and results are written to tenant-isolated storage protected by access controls. No system is perfectly secure; we will notify affected customers of a personal data breach without undue delay and in accordance with applicable law.

8. Your rights

Depending on your location (including under GDPR and UK GDPR), you may have rights to access, correct, delete, or receive a copy of your personal data, restrict or object to processing, and withdraw consent. To exercise them, email dpo@opencrevo.com. If we process your data as a processor for your organization, we will refer your request to them and assist. You may also lodge a complaint with your local data protection authority. You can additionally disconnect any connected platform at any time, which revokes our access and deletes the stored credential.

9. Cookies and analytics

Strictly necessary storage. The website stores your cookie-consent choices in your browser's local storage. The QA Maturity self-assessment stores your name, company, draft answers, question order, and which aspects you have completed in local storage and a first-party cookie on this site so you can refresh, go back, or return later and continue toward the Maturity Assessment Report. That progress data is not sent to OpenCrevo servers (only the lead form submission is emailed via Web3Forms). It expires after 90 days or when you clear site data.

Analytics. We use Vercel Web Analytics, a cookieless analytics tool that measures aggregate page views and traffic trends without setting cookies or tracking you across other sites. In line with our cookie banner, it only runs after you accept non-essential tracking, and stops immediately if you withdraw consent.

Marketing: only with your consent. Our cookie banner allows you to accept or deny non-essential cookies. Marketing and ad-measurement tools are off by default and are not currently loaded; if we adopt any, they will run only if you have enabled the relevant consent.

Withdrawing consent. You can change your choices at any time by clearing your browser local storage for this site or contacting us at the email above. Disabling consent stops any optional tracking we may introduce in the future.

10. Changes

We may update this policy from time to time. Material changes will be notified by email or in-app notice before they take effect. The effective date above always reflects the current version.

11. Contact

OpenCrevo OÜ (Estonia)

Email: dpo@opencrevo.com