Privacy Policy
Last updated: June 8, 2025Seidor Analytics North América Corp (“Seidor Analytics”, “we”, “our”, or “us”) operates Crestone, a multi-tenant data integration platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Crestone.
1 Introduction
Seidor Analytics, S.L. is the data controller responsible for the personal data processed through the Crestone platform (“Platform”). Crestone is a B2B Software-as-a-Service (SaaS) solution that enables enterprise customers to extract data from source systems (including SAP, ABAP-based systems, and other enterprise applications) and load it into cloud data warehouses and storage destinations.
This Privacy Policy applies to all users of the Platform, including administrators, operators, and any individual whose personal data is processed in connection with their use of Crestone. By accessing or using Crestone, you agree to the collection and use of information as described in this policy.
This policy does not govern the business data that customers extract, transform, and load through Crestone - that data remains the property and responsibility of the customer. Our Data Processing Addendum (DPA) covers the processing of any personal data contained within customer-controlled datasets.
2 Information We Collect
2.1 Account and Registration Data
When you register for Crestone or are invited to a workspace, we collect your full name, email address, company or organization name, and your role within the organization. This information is required to create and manage your account.
2.2 Usage and Activity Data
We collect information about how you use the Platform, including:
- Data integration jobs and extraction nodes you create and configure
- Execution history, scheduling settings, and job status events
- Source and destination system connections you configure (system type, host addresses, and connection metadata - not your system credentials, which are stored encrypted)
- Workspace and tenant configuration actions
- Feature interactions and navigation patterns within the Platform UI
2.3 Technical and Device Data
When you access the Platform, we automatically collect certain technical information:
- IP address and approximate geographic location
- Browser type, version, and operating system
- Session tokens and authentication events (managed via Supabase Auth)
- Request timestamps and HTTP response codes
2.4 Integration Metadata
Crestone processes metadata about your data pipelines - such as table names, column schemas, record counts, and data formats - in order to operate the Platform. We do not access, store, or process the business content (the actual rows of data) being transferred through your pipelines beyond what is strictly necessary for the in-transit extraction and load operation. Credentials for third-party systems are stored encrypted using AES-256 encryption and are never stored in plain text.
3 How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provision, operate, and maintain your Crestone account and workspaces, and to execute your data integration jobs.
- Authentication and Security: To verify your identity on each request (via JWT tokens validated against Supabase), detect unauthorized access, and prevent fraud or abuse.
- Customer Support: To respond to your inquiries, troubleshoot issues, and provide technical assistance.
- Product Improvement: To analyze usage patterns in aggregate to improve Platform features, performance, and reliability.
- Communications: To send you service notifications, security alerts, product updates, and, where you have consented, marketing communications. You may opt out of marketing emails at any time.
- Billing and Administration: To manage subscriptions, process payments, and enforce usage limits or plan entitlements.
- Legal Compliance: To comply with applicable laws, respond to lawful requests from public authorities, and enforce our Terms of Service.
4 Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We may share your information only in the following circumstances:
4.1 Sub-processors and Service Providers
We engage trusted third-party providers who process data on our behalf to operate the Platform. These include:
- Supabase - authentication, user management, and relational database hosting
- Amazon Web Services (AWS) - cloud infrastructure and object storage
- Microsoft Azure - cloud infrastructure and Azure Storage / Fabric OneLake destinations
- Google Cloud Platform (GCP) - cloud infrastructure and BigQuery / GCS destinations
- Apache Kafka (managed) - real-time data streaming infrastructure for pipeline execution
All sub-processors are contractually bound to process data only as instructed, implement appropriate security measures, and comply with applicable data protection laws.
4.2 Within Your Organization
Within the Platform, data is shared among users who belong to the same tenant and workspace as configured by your organization’s administrator. Workspace administrators control user access and permissions.
4.3 Legal Requirements
We may disclose your information if required to do so by law or in response to a valid legal request (such as a court order or government subpoena). Where permitted, we will notify you of such requests.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, personal data may be transferred as part of that transaction. We will notify affected users before personal data is transferred and becomes subject to a different privacy policy.
5 Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with the Platform. If you request account deletion or your subscription is terminated, we will delete or anonymize your personal data within 90 days, except where we are required to retain it longer for legal, tax, or regulatory purposes (typically up to 7 years for billing records).
Execution logs, job run histories, and pipeline audit records may be retained for up to 12 months from the date of creation to support debugging, support requests, and compliance audits.
Aggregated and anonymized usage statistics that cannot be linked back to an individual may be retained indefinitely for product analytics purposes.
6 Security
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, loss, or alteration:
- Encryption in transit: All data transmitted between your browser and the Platform is encrypted using TLS 1.2 or higher.
- Encryption at rest: Third-party system credentials stored in Crestone are encrypted with AES-256 before being written to the database. Encryption keys are managed separately from the data they protect.
- Authentication: Every API request is authenticated via short-lived JWT tokens (max 3-hour lifetime) issued by Supabase Auth. Multi-Factor Authentication (MFA) is available and recommended for all users.
- Access controls: Access to production systems is restricted to authorized personnel on a need-to-know basis.
- Multi-tenancy isolation: All data is scoped to a tenant and workspace. Cross-tenant data access is architecturally prevented.
Despite these measures, no system is completely secure. If you believe your account has been compromised, please contact us immediately at support@crestone.io.
7 International Data Transfers
Seidor Analytics North América Corp is established in the United States. Where personal data is transferred to sub-processors located outside the EEA (for example, to cloud infrastructure providers in the United States), we ensure that appropriate safeguards are in place, including:
- European Commission adequacy decisions (where the destination country has been deemed adequate)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules or other approved transfer mechanisms where applicable
You may request a copy of the relevant transfer safeguards by contacting us at the address below.
8 Your Rights
8.1 EU / EEA Users (GDPR)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”): Request deletion of your personal data, subject to legal retention obligations.
- Right to restriction of processing: Request that we limit how we use your data in certain circumstances.
- Right to data portability: Receive your personal data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: Where processing is based on your consent, withdraw it at any time without affecting the lawfulness of prior processing.
You also have the right to lodge a complaint with your local supervisory authority. In the US, you may contact the Federal Trade Commission (FTC) at www.ftc.gov.
8.2 California Users (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you additional rights, including the right to know what personal information we collect and how we use it, the right to delete your personal information, the right to correct inaccurate personal information, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as defined under the CCPA.
To exercise any of your rights, please contact us at support@crestone.io. We will respond within 30 days (or as required by applicable law).
9 Cookies and Tracking
Crestone uses a minimal set of cookies and local storage mechanisms strictly necessary to operate the Platform:
- Session cookies: Used to maintain your authenticated session after login. These are short-lived and expire when you close your browser or after a maximum of 3 hours of inactivity.
- Preference storage: Used to remember UI preferences (such as workspace selection or theme) across sessions.
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics scripts that identify individuals. We do not sell data derived from cookies to any third party.
Strictly necessary cookies cannot be disabled as they are essential for the Platform to function. You may clear all cookies at any time through your browser settings, which will require you to log in again.
10 Children’s Privacy
The Crestone Platform is intended solely for use by business professionals and enterprise customers. It is not directed at, and we do not knowingly collect personal data from, individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will take steps to delete such information promptly. Please contact us if you believe we may have collected data from a minor.
11 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by:
- Posting the updated policy on this page with a revised “Last updated” date
- Sending an email notification to the address associated with your account
- Displaying a prominent notice within the Platform on your next login
Your continued use of Crestone after any changes take effect constitutes your acceptance of the updated policy. We encourage you to review this page periodically.
12 Contact Us**
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact our Privacy team:
Seidor Analytics North América Corp
Privacy & Data Protection
Email: support@crestone.io
Security issues: support@crestone.io