Privacy Policy
Crado builds engineering decision infrastructure for regulated hardware. This policy explains, in plain terms, what information we handle, why, and the choices you have.
Introduction
This policy applies to the Crado website, our early access and pilot programs, and the Crado platform (together, the “Services”). It is written to be readable, not to bury the important parts in legal language.
Crado is operated by Crado Ltd (“Crado”, “we”, “us”). If you access Crado through your employer under an enterprise agreement, that agreement and your organisation’s own privacy notices may also apply, and in some cases your organisation, not Crado, acts as the controller of the data processed in your deployment.
Information we collect
Information you provide
When you request a pilot, join the waitlist, contact us, or correspond with our team, we collect what you choose to share, typically your name, work email, company, role, and the contents of your message.
Usage information
When you visit our website we may collect basic, aggregated technical information such as pages viewed, approximate region, referring source, browser type, and device information. We use this to understand interest and improve the site.
Cookies
Our marketing site aims to use only essential cookies needed for it to function, plus privacy-respecting analytics where applicable. We do not use advertising cookies. You can control cookies through your browser settings.
Engineering data in the platform
When Crado is deployed for an enterprise customer, the platform processes engineering and certification data, for example requirements, specifications, test reports, and engineering changes. How that data is handled is described under “Engineering documents and AI processing” and “Deployment, security and data residency” below.
How we use information
We use the information you provide to respond to enquiries, evaluate and operate pilots and the early access program, provide and support the Services, keep them secure, meet legal obligations, and improve our product and communications.
We do not sell personal information, and we do not share it with third parties for their own advertising.
Engineering documents and AI processing
This section is the part engineering and certification teams care about most, so we have tried to be precise.
We do not train foundation models on your documents
Crado does not use customer engineering documents to train foundation models. Uploaded compliance artefacts and engineering documents are processed only to perform the verification and analysis workflows you ask Crado to run.
Your data stays under your control
Customer data remains under customer control. Engineering documents are treated as confidential and are accessible within your deployment according to the access controls you configure.
How AI is used
Where Crado uses AI, it is used to read and structure engineering documents. Regulatory conclusions are produced by a deterministic verification engine that references the underlying sources, rather than being generated freely by a language model. Outputs are intended to assist engineering judgement, not replace it.
Deployment, security and data residency
We aim to apply appropriate technical and organisational measures to protect information, including encryption in transit, role-based access controls, and audit logging within the platform. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Enterprise deployments
Enterprise customers can deploy Crado on-premise or within their own private cloud. In these deployments, engineering data is processed inside the customer’s environment, and Crado is designed so that this data does not leave the customer’s network.
On-premise and air-gapped
For on-premise and air-gapped deployments, customer engineering data remains within the customer’s infrastructure and is not transmitted to Crado.
Cloud deployments
For cloud or managed deployments, data is processed using the providers and regions agreed with the customer, subject to the relevant order or agreement.
Data residency
Where applicable, we work with enterprise customers to meet data residency requirements as part of their deployment and agreement.
Data retention
We aim to keep personal information only for as long as needed for the purposes described in this policy, or as required to meet legal, accounting, or reporting obligations. Retention of engineering data within a deployment is governed by the relevant customer agreement and the customer’s own configuration.
You can ask us to delete the personal information you have shared with us, subject to any legal obligations we may have to retain it.
Third-party providers
We use a limited set of trusted service providers to operate our business, for example hosting, infrastructure, email, scheduling, and analytics. These providers process information on our behalf under appropriate agreements and only for the purposes we specify.
We aim to choose providers that maintain appropriate security practices, and we limit what we share to what each provider needs to perform its function.
International transfers
We are based in the United Kingdom and may process information in the UK, the European Economic Area, the United States, or other locations where we or our providers operate. When we transfer personal information across borders, we aim to use appropriate safeguards, such as recognised adequacy decisions or standard contractual clauses, when applicable.
Your privacy rights
Depending on where you live, you may have rights over your personal information. We aim to honour valid requests in line with applicable law.
UK and EU (UK GDPR / EU GDPR)
If you are in the UK or the EU, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. You may also lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office).
California (CCPA/CPRA)
If you are a California resident, you may have the right to know what personal information we collect, to request access or deletion, and to not be discriminated against for exercising your rights. We do not sell personal information.
To make a request, email hello@crado.io. We may need to verify your identity before responding. Where Crado processes data on behalf of an enterprise customer, we will direct relevant requests to that customer.
Children’s privacy
Crado is a business product intended for organisations and professionals. It is not directed to children, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, provide additional notice. Continued use of the Services after an update means you accept the revised policy.
Contact us
If you have questions about this policy or how we handle information, email hello@crado.io. You can also write to us at Crado Ltd, London, United Kingdom.