CRAnotify Documentation

Personal data and retention

CRAnotify processes little personal data, but it processes it in a delicate context: non-public reports, decisions with legal effect, evidence meant to last. This page explains what is kept, for how long, and how data-subject rights are exercised.

What data

CategoryContentWhere it comes from
UsersName, email address, role, password digest, active sessions.Sign-up, invitation, single sign-on.
OrganisationLegal name, VAT number, registered office, certified mail, recipient code, escalation addresses.Company data.
ReportsText, product indicated, reporter's contact (optional), attachments.Public form, manual entry.
RegistryActs performed, with author and moment.Use of the application.
BillingTax data and accounting documents.Subscription.

Data resides in the European Union and is separated per organisation: no other organisation's data enters your views, your search results or your integrity chain.

Exercising rights

From Account area › Legal three actions are available, each recorded and confirmed by email:

ExportPrepares the account data in JSON. It is also directly downloadable as a file from the account area.
DeletionStarts a deletion request. What can be deleted is deleted; what must remain by law is identified.
Breach noticeThe path by which we inform you of an event that may have involved your personal data.

What remains after a deletion

The activity registry and the filing receipts are not deleted on request: they are documentation of regulatory compliance with their own retention period. Deleting them would destroy the evidence that an obligation was discharged — to the detriment, first of all, of the organisation itself.

So what remains is: the registry rows (including author and moment), the receipts issued by the platform, and accounting documents for the period prescribed by tax law. Account data not needed for those purposes is removed.

Retention period

A case dossier is kept for the period that allows the compliance to be documented in an inspection. When expiry approaches, an alert tells the contact and the administrators: that is the moment to decide whether to archive externally the evidence you want to keep longer.

Good practice. Do not rely on a single custodian. When a case closes, export the registry and the dossier and keep them with the product's conformity documentation.

Reporters' data

The reporter's contact address is optional and is used only for the acknowledgement and the response. An anonymous report carries no identifying data. Handle attachments with care: they may contain third-party personal data the reporter included without thinking — if it is not needed for the assessment, do not replicate it into the notification.

Suppliers involved

To run the service we rely on suppliers for transactional email, hosting infrastructure, payments and error monitoring. The current list, with roles and legal bases, is in the privacy notice. Application errors are collected without request bodies, cookies or authentication headers, and users appear there with an identifier, organisation and role — never with an email address.

Use of artificial intelligence

The CRA assistant sends the model the text you provide and the context of the page you are working on, not the whole registry or product records. It takes no decision with legal effect and every output is a draft to review. The full position is at https://cranotify.eu/ia.

Contact

For personal-data requests: privacy@cranotify.eu. For everything else, support.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu