Privacy Policy
LAST UPDATED: 14 August 2025
This policy explains how Crisod collects, uses and protects information, including the infrastructure and system data used to build your financial resilience model.
Information collected
We collect information you provide directly, such as your name, work email, company, industry, country and details submitted through our forms. We also collect information generated through your use of the platform.
Infrastructure data
To build a model of your financial infrastructure, Crisod processes information you provide or connect about your systems, accounts, APIs, permissions, dependencies and financial workflows. You control what infrastructure information is shared with Crisod.
System metadata
We may collect metadata describing the structure and relationships of connected systems — such as system names, dependency relationships, permission scopes and configuration attributes — rather than the underlying transactional or customer data held within those systems.
Security telemetry
Where applicable, we may collect technical telemetry related to platform usage and security — such as access logs, authentication events and simulation activity — to operate and secure the platform.
AI processing
Crisod uses AI models to analyze infrastructure and dependency data and to generate simulation scenarios and findings. AI outputs are generated from the information you provide and are intended to support your own analysis, not to serve as a final determination of risk.
Data usage
We use collected information to provide and improve the platform, generate your infrastructure model and simulations, communicate with you, and maintain the security of our systems.
Data sharing
We do not sell personal information or infrastructure data. We may share information with service providers who support our operation of the platform, under obligations consistent with this policy, or where required by law.
Third-party services
We may rely on third-party infrastructure and service providers to operate Crisod, including hosting and processing services. These providers process data on our behalf and are not authorized to use it for their own independent purposes.
Security
We apply technical and organizational measures designed to protect the information we process, including infrastructure and simulation data. No system can be guaranteed to be completely secure.
Retention
We retain information for as long as needed to provide the platform and for legitimate business or legal purposes, after which it is deleted or de-identified in accordance with our internal retention practices.
International transfers
Information we process may be transferred to and processed in countries other than your own. Where this occurs, we take steps intended to ensure the information continues to receive an appropriate level of protection.
User rights
Depending on your location, you may have rights to access, correct, delete or restrict the use of your personal information. To exercise these rights, contact us using the details below.
Changes
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page.
Contact
Questions about this policy can be sent to privacy@crisod.com.