Effective Date: September 25, 2026
Last Updated: September 25, 2026
Key Points Summary:
- This Privacy Policy applies to users in the EU/EEA
- Data Controller: helpful bits GmbH, Südliche Münchner Straße 55, 82031 Grünwald, Germany
- Your recordings, screenshots, projects, and exported videos stay on your computer; videos are rendered on your computer
- AI requests go through our EU or US server when you are signed in, or directly to Google when you use your own Gemini API key without an account
- We process personal data with your consent (Art. 6(1)(a) GDPR) and for contract performance (Art. 6(1)(b) GDPR)
- Your app's screens are rebuilt by the coding agent you choose (Claude Code, Codex, or OpenCode), which runs under your own account with its provider. With your source approval, CrispDemo lets it read frames from your recordings and your screenshots on your computer; the agent sends them to its provider. CrispDemo does not send them to us or to Google
- Google receives only the finished video for review (unless you turn the review off), the narration text for Gemini text-to-speech, and the music brief for Google Lyria. Parts of your recordings can appear in the finished video
- You have these GDPR rights: access, rectification, erasure, portability, restriction, objection
- EU Supervisory Authority: Bavarian State Office for Data Protection Supervision (BayLDA)
1. Introduction and Scope
helpful bits GmbH ("CrispDemo," "we," "us," or "our") processes personal data under the General Data Protection Regulation (GDPR) and German data protection laws.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the CrispDemo desktop application (CrispDemo Studio), website, and related services (collectively, the "Service").
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
helpful bits GmbH
Südliche Münchner Straße 55, 82031 Grünwald, Germany
Email: privacy [at] crispdemo.com
Website: crispdemo.com
As the data controller, helpful bits GmbH determines the purposes and means of processing your personal data and is responsible for ensuring compliance with applicable data protection laws.
3. Territorial Scope and Location Information
This Privacy Policy applies to data subjects located in the European Union (EU) and European Economic Area (EEA). We derive your approximate country from your IP address to choose the server your desktop application uses and to show the legal documents for your region. We do not use device location services.
Users located outside the EU/EEA are subject to our U.S. Privacy Policy and are not covered by GDPR protections unless they are EU/EEA residents temporarily located elsewhere.
4. GDPR Definitions
For purposes of this Privacy Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"), as defined in Article 4(1) GDPR.
- "Processing" means any operation performed on personal data, including collection, recording, storage, use, disclosure, erasure, or destruction, as defined in Article 4(2) GDPR.
- "Controller" means the entity that determines the purposes and means of processing personal data (Article 4(7) GDPR) - in this case, helpful bits GmbH.
- "Processor" means an entity that processes personal data on behalf of the Controller (Article 4(8) GDPR).
- "Consent" means any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes (Article 4(11) GDPR).
- "Data Subject" means an identified or identifiable natural person to whom personal data relates.
5. Categories of Personal Data We Collect
5.1 Account and Authentication Data
- Email address and name: From the sign-in provider you choose (Google, GitHub, Microsoft, Apple, or OpenAI) through Auth0, for account creation, authentication, and communications
- Auth0 user ID and tokens: Your Auth0 identifier, sign-in tokens stored in your operating system's credential store, and an encrypted refresh token stored on our server
- Device identifier: A random ID created by the desktop application, to bind your sign-in to your device and for rate limiting
- Authentication state: Temporary session data for the sign-in flow
5.2 Usage, Billing, and Record-Keeping Data
- AI request records: For the video review, narration, and music requests made through our server: request and job IDs, device ID, stage, model, token counts, cost, status, and time
- Temporary request content: For narration and music requests through our server, the narration text or music brief until the request finishes, and the generated narration or music audio for up to 7 days
- Balance and billing data: Credit balance, top-up amounts and fees, free credits, transaction history, Stripe customer and charge IDs, and automatic top-up settings. Stripe collects your payment details, billing address, and any tax ID
- Audit log: A record of billing and account actions, such as payments, payment-method changes, and credit purchases
- Consent records: Which version of these documents you accepted or withdrew, when, and the IP address and user agent used
5.3 Content and Input Data
- Recordings and screenshots: The screen recordings and screenshots you add, and screen recordings you make in CrispDemo. They stay on your computer; CrispDemo does not change, move, or delete the files you add
- Microphone audio: Recorded with a screen recording only if you turn on the microphone. It stays in the recording file on your computer and is not sent to us or to Google
- Frames and screenshots your coding agent reads: With your source approval, still frames from your recordings and your screenshots, read on your computer by the coding agent you choose. CrispDemo does not send them to us or to Google
- Briefs, instructions, and chat messages: What you ask CrispDemo or your coding agent to make or change
- AI output: Rebuilt screens, story plans, scripts, narration, music, reviews, and rendered videos, stored in your project folders
5.4 Technical and Device Data
- Device information: Operating system, processor architecture, and application version, for example when the application checks for updates
- IP address: To choose a US or EU server, for security, rate limiting, and in server logs
- Server logs: IP address, requested address, response status, referrer, and user agent
- Local error log: Errors recorded by the desktop application on your computer. It is not sent to us
5.5 Communication Data
- Support correspondence: Email communications with customer support
- Feedback and surveys: Responses to feedback requests or user surveys
6. Legal Basis for Processing (Article 6 GDPR)
We process your personal data only when we have a valid legal basis under Article 6(1) GDPR:
6.1 Consent (Article 6(1)(a) GDPR)
We process certain data based on your explicit consent, including:
- Letting your coding agent read frames from your recordings and your screenshots, which you approve for each project's files
- Marketing communications (where applicable)
You may withdraw consent at any time: untick the source approval for a project, or contact us. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
6.2 Contract Performance (Article 6(1)(b) GDPR)
Processing is necessary to perform our contract with you (Terms of Service), including:
- Account creation and authentication
- Building, reviewing, and rendering the videos you request, including narration and music
- Selling credits, keeping your balance, and charging AI requests made through our server to it
- Providing customer support
6.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for our legitimate interests, provided these interests do not override your fundamental rights:
- Security and fraud prevention: Detecting and preventing unauthorized access, abuse, or fraudulent activity
- Service improvement: Analyzing usage patterns to enhance features and user experience
- Technical operations: Maintaining, troubleshooting, and optimizing the Service
- Business analytics: Understanding aggregate usage trends and business performance
You have the right to object to processing based on legitimate interests. See Section 15 for details.
6.4 Legal Obligations (Article 6(1)(c) GDPR)
Processing is necessary to comply with legal obligations, including:
- Tax and accounting requirements
- Response to lawful requests from authorities
- Data breach notification obligations
- Retention of data as required by law
7. Desktop Application Privacy
7.1 Local Data Storage
CrispDemo keeps the following on your computer:
- Project data: In a
.crispdemofolder inside each project folder you choose: screen recordings you make, frames taken from your sources, rebuilt screens, scripts, narration and music audio, copies of provider responses, your source approval, and rendered videos - Source references: File paths and media details of the recordings and screenshots you add. The files themselves stay where they are
- Application data: Preferences, a random device ID, and a local error log, in the application's data folder
- Credentials: Sign-in tokens and, if you add one, your Gemini API key, in your operating system's credential store (keychain)
7.2 Source Approval and What Leaves Your Computer
- Source approval: Before your coding agent builds a video from your sources, you tick a box that allows it to read your screenshots and frames from your recordings to rebuild their screens. The approval applies to the exact files attached to that project. If you change the files, you are asked again
- Frames go to your coding agent, not to us: The agent reads still frames and screenshots through CrispDemo tools on your computer and sends what it reads to its own provider, under your account with that provider (see Section 9.3). CrispDemo does not send your recordings, frames, or screenshots to our server or to Google, and the agent's tools do not give it the recording's audio track
- Narration and music: The narration text, language, and voice are sent to Gemini text-to-speech; a short music brief is sent to Google Lyria. If Lyria cannot create music, a music bed packaged with the application is used
- Video review: After a video is rendered, a reduced copy of it, including its sound, is sent to Gemini for review, together with the scene titles and narration text of its plan. Parts of your recordings and screenshots can appear in the finished video. This setting is on by default and you can turn it off in Settings
- Rendering and export: Videos are rendered on your computer and exported to your project folder
7.3 Service Account Data
When you are signed in, the following is stored on CrispDemo's server in your region (see Section 8.1):
- Account and authentication data
- Your balance, transaction history, and billing records
- AI request records and temporary request content
- The audit log and consent records
CrispDemo does not upload or sync your project folders or the original recordings and screenshots.
7.4 Other Network Requests
- Before you sign in, the application asks crispdemo.com (and, as a fallback, Cloudflare) for your country, derived from your IP address, to choose a US or EU server. North America uses the US server; other locations use the EU server
- The application checks crispdemo.com for updates, sending its version, platform, and processor architecture
- The application loads interface fonts from Google Fonts
- When you are signed in, the application loads the CrispDemo catalogue of video styles, devices, and motion presets from our server. A catalogue search sends your search text
7.5 Desktop Permissions
CrispDemo requests the following desktop OS permissions:
- File System Access: Required to read the recordings and screenshots you select and to store project data
- Screen Recording: Required when you record your screen in CrispDemo
- Microphone: Required only if you turn on the microphone for a screen recording
- Network Access: Required for the requests described in this section
You can manage permissions through your system settings at any time.
9. Google AI and Coding-Agent Processing
9.1 AI Processing and Data Flow
Your app's screens are rebuilt, and the story and script written, by the coding agent you choose (Section 9.3), not by Google. When you create or change a video, CrispDemo sends Google only: narration text, language, and voice for Gemini text-to-speech; a short music brief for Google Lyria; and, unless you turn it off, a reduced copy of the finished video with its sound, together with the scene titles and narration text of its plan, for review. Parts of your recordings and screenshots can appear in the finished video, so Google sees them as part of the video it reviews. CrispDemo does not send your recordings, frames, or screenshots to Google. This processing is based on contract performance (Article 6(1)(b) GDPR).
Through CrispDemo's server. When you are signed in and have not chosen your own key, requests go through our server in your region and are charged to your CrispDemo balance. The server keeps the narration text or music brief only until the request finishes, and the generated audio for up to 7 days so the application can collect it after an interruption. It keeps a record of each request (IDs, device ID, stage, model, usage, cost, and status). A video sent for review is held in a temporary file while it is forwarded; a large video may be uploaded to Google's file storage for the request and is deleted from it afterwards.
With your own Gemini API key. You can instead add your own Gemini API key, with or without a CrispDemo account. The key is stored in your operating system's credential store and requests go directly from your computer to Google. Google bills your key and Google's terms for your Google account apply to that use. We do not receive the request content.
9.2 Google
Purpose: Create narration and music, and review the finished video
Data processed: Narration text, music brief, and finished videos with their scene titles and narration text
Provider terms: Google's terms and privacy documentation applicable to the Gemini API govern provider-side processing and retention
Gemini API Additional Terms: https://ai.google.dev/gemini-api/terms
Google Privacy Policy: https://policies.google.com/privacy
9.3 Coding Agents in the Studio Chat
The Studio chat runs a coding agent on your computer: Claude Code, Codex, or OpenCode. It is your own tool: you choose it and sign in to it, you use it under your own account or provider settings with its vendor, and the vendor is responsible for its own processing under its terms. The agent rebuilds your app's screens and writes the story, script, and music brief. CrispDemo does not read, print, or store your agent sign-in credentials.
- The agent works through CrispDemo tools that run only on your computer. It can read the current project and your other CrispDemo projects, look up the CrispDemo catalogue, and, with your source approval, read frames from your recordings and your screenshots
- The agent sends what it reads, and your chat messages, to its model provider (for example Anthropic for Claude Code or OpenAI for Codex), under your agreement with that provider. CrispDemo does not transmit them
- OpenCode can use free models without an account. Some free models may use what you send them to improve the model. Connect your own provider in OpenCode to avoid this
- If you ask CrispDemo to install or sign in to an agent, it downloads the agent from its vendor and opens the vendor's own sign-in
9.4 Your Control
- CrispDemo's tools give your coding agent no frames from your sources until you give source approval for that project
- You can turn off the video review with Gemini in Settings
- You can use your own Gemini API key instead of our server, and remove it at any time
- You choose which coding agent to use, and which account or provider it uses
Consult Google's current documentation for provider-side data practices.
10. International Data Transfers
10.1 Transfers to Third Countries
Depending on our infrastructure and Google's processing configuration, analysis data may be processed outside the EU/EEA. Such locations may not provide an equivalent level of data protection to the EU.
10.2 Transfer Mechanisms
Where Chapter V GDPR applies, the transfer mechanism depends on the provider, service configuration, and processing location. Safeguards may include:
- Standard Contractual Clauses (SCCs): The European Commission's Standard Contractual Clauses (Decision 2021/914) where applicable to the provider relationship
- Adequacy Decisions: We transfer data to countries with adequacy decisions where available
- Supplementary Measures: Technical and organizational measures appropriate to the transfer and processing risk
10.3 U.S. Data Privacy Framework
A provider may rely on the EU-U.S. Data Privacy Framework where it is certified and the framework applies to the relevant processing. Contact us for information about the mechanism applicable to a specific transfer.
10.4 Your Rights Regarding International Transfers
You have the right to:
- Request information about international transfers of your data
- Obtain a copy of the appropriate safeguards (SCCs) we use
- Object to specific international transfers (subject to contract performance requirements)
To exercise these rights, contact us at privacy [at] crispdemo.com.
11. Data Retention Periods
We retain personal data only as long as necessary for the purposes for which it was collected or as required by law (Article 5(1)(e) GDPR - storage limitation principle).
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account data (email, name, Auth0 user ID) | Until you delete your account; deleted immediately when you do | Contract performance |
| Authentication tokens | Access tokens expire after 7 days and are removed from your computer when you sign out. The encrypted refresh token on our server is kept with your account and deleted when you delete your account | Contract performance |
| Source references and project data (recordings, frames, rebuilt screens, audio, videos) | Stored on your computer until you delete them | Contract performance |
| Usage statistics and AI request records | 12 months, or until you delete your account, whichever is sooner | Legitimate interest |
| Request content on our server (narration text, music brief, generated audio, videos sent for review) | Narration text and music brief until the request finishes; generated audio up to 7 days; a video sent for review only while it is forwarded. Deleted immediately when you delete your account. Provider-side retention follows Google's current terms | Contract performance |
| Consent records (which terms and privacy version you accepted, when, IP address and browser/app details) | While your account exists and 3 years after deletion, as proof of consent | Legal obligation, legitimate interest |
| Support correspondence | 3 years after last contact | Legitimate interest |
| Billing records (payments, balance changes, billing audit log) | 10 years (HGB §257, AO §147). After account deletion they are linked only to a random account ID, not to your name or email | Legal obligation |
| Server logs | 90 days | Legitimate interest |
| Local error log (on your computer) | Latest 2,000 entries | Legitimate interest |
| Marketing consent records | 3 years after withdrawal | Legal obligation |
You can delete your account in the CrispDemo app under Settings > Account > Delete account. Deletion takes effect immediately. Signing in again later creates a new, empty account.
When you delete your account, we keep the Stripe customer ID and billing records described above for the legal retention period. Stripe keeps your payment and invoice records under its own obligations. Your CrispDemo sign-in is provided by Auth0; deleting your CrispDemo account removes your Auth0 user ID from our systems, but does not delete your Auth0 login.
The US and EU servers each keep their own accounts. Deleting your account in the app removes only the account on the server the app uses. If you also created an account on the other server, contact us at privacy [at] crispdemo.com and we'll delete it.
Deleting your account does not delete project data on your computer or data handled by a provider under its applicable terms.
For personal data held by us and subject to a stated retention period, we delete or anonymize it after that period, subject to legal or operational exceptions described in this policy.
12. Security Measures
12.1 Technical and Organizational Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR:
Technical Measures
- Encryption in transit: TLS 1.2 or 1.3 for connections to our servers
- Encryption at rest: Sign-in refresh tokens are stored with AES-256 encryption; credentials on your computer are kept in your operating system's credential store
- Secure authentication: OAuth 2.0 with PKCE, token rotation, and secure token storage
- Access controls: Role-based access control (RBAC) for backend systems
- Network security: Firewalls, intrusion detection, and DDoS protection
- Secure development: Code reviews, security testing, and vulnerability scanning
- Data minimization: Local-first architecture minimizes server-side data storage
Organizational Measures
- Data protection by design: Privacy considerations integrated into product development
- Data protection by default: Privacy-friendly default settings
- Staff training: Regular data protection training for employees
- Confidentiality agreements: All employees sign confidentiality and data protection agreements
- Incident response plan: Documented procedures for data breach response
- Regular audits: Periodic security audits and assessments
- Vendor management: Due diligence on all processors and subprocessors
12.2 Your Security Responsibilities
You are responsible for:
- Maintaining the confidentiality of your account credentials
- Using strong, unique passwords
- Keeping your computer and application updated
- Reporting any security concerns or unauthorized access
13. Your GDPR Rights
As a data subject under GDPR, you have the following rights regarding your personal data:
13.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether we process your personal data and, if so, access to the data and information about the processing, including:
- Purposes of processing
- Categories of personal data
- Recipients or categories of recipients
- Retention periods
- Your other GDPR rights
- The source of data not collected from you
- Existence of automated decision-making, including profiling
You can request a copy of your data by contacting privacy [at] crispdemo.com.
13.2 Right to Rectification (Article 16 GDPR)
You have the right to obtain correction of inaccurate personal data and to have incomplete personal data completed. Your name and email address come from the sign-in provider you use; you can change them there or ask us to correct them.
13.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
You have the right to request deletion of your personal data when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Erasure is required to comply with a legal obligation
You can delete your account in the CrispDemo app under Settings > Account > Delete account, or ask us to delete your account and associated data by contacting us. Note that we may retain certain data as required by law (e.g., tax records). Project data on your computer is under your control and you can delete it at any time.
13.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request restriction of processing when:
- You contest the accuracy of the data (during verification)
- Processing is unlawful and you oppose erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing (pending verification of legitimate grounds)
13.5 Right to Data Portability (Article 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON) and to transmit it to another controller when:
- Processing is based on consent or contract performance
- Processing is carried out by automated means
You may request a copy of personal data held by us by contacting privacy [at] crispdemo.com. External source videos remain under your control at their original file paths.
13.6 Right to Object (Article 21 GDPR)
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
For direct marketing, you have an absolute right to object at any time.
13.7 Right Not to be Subject to Automated Decision-Making (Article 22 GDPR)
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you. AI processing is conducted at your explicit request for specific tasks.
13.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on consent, you have the right to withdraw consent at any time, for example by unticking the source approval for a project or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
13.9 How to Exercise Your Rights
To exercise any of these rights, you may:
- Use the controls in the application: source approval for each project, the video review setting, your own Gemini API key, and your choice of coding agent
- Email us at privacy [at] crispdemo.com
- Send a written request to helpful bits GmbH, Südliche Münchner Straße 55, 82031 Grünwald, Germany
We will respond to your request within one month. In complex cases, we may extend this by two additional months, and we will inform you of any such extension.
We may request additional information to verify your identity before fulfilling your request. Requests are generally free of charge, but we may charge a reasonable fee for manifestly unfounded or excessive requests.
15. Detailed Legal Basis for Processing Activities
This table provides a detailed overview of our processing activities and their legal basis:
| Processing Activity | Data Categories | Legal Basis (Art. 6 GDPR) | Purpose |
|---|---|---|---|
| Account creation and authentication | Email, OAuth tokens, device ID | 6(1)(b) Contract | Provide access to Service |
| Narration, music, and video review with Google | Narration text, music brief, finished videos with their scene titles and narration text | 6(1)(b) Contract | Create narration and music, review the video |
| Letting your coding agent read your sources | Frames from your recordings and your screenshots (with source approval), read on your computer | 6(1)(a) Consent | Let the coding agent you choose rebuild your app's screens |
| Screen recording | Screen recording and, if you turn it on, microphone audio, stored on your computer | 6(1)(b) Contract | Record the app you want to show |
| Source and project management | File paths and media details of your sources, project files on your computer | 6(1)(b) Contract | Keep your sources and projects together |
| AI request and usage records | Request IDs, device ID, model, token counts, cost, status | 6(1)(b) Contract 6(1)(f) Legitimate interest | Charge your balance, prevent duplicate charges, reliability |
| Credit purchases and balance | Balance, top-ups, fees, transaction history, Stripe references | 6(1)(b) Contract 6(1)(c) Legal obligation | Sell credits and maintain required accounting records |
| Server logs and audit log | IP address, user agent, requested address, billing and account actions | 6(1)(f) Legitimate interest | Troubleshooting, security, accounting |
| Customer support | Email, support correspondence | 6(1)(b) Contract 6(1)(f) Legitimate interest | Respond to inquiries, resolve issues |
| Security and fraud prevention | IP address, device ID, access logs | 6(1)(f) Legitimate interest | Protect Service and users from abuse |
| Legal compliance (tax records) | Billing records, invoices | 6(1)(c) Legal obligation | Comply with tax law (AO §147) |
| Marketing communications (opt-in) | Email, communication preferences | 6(1)(a) Consent | Send product updates and offers |
17. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16 without parental consent.
Users aged 16-17 may use the Service with parental consent and supervision. Parents or legal guardians may exercise GDPR rights on behalf of minors.
If we become aware that we have collected personal data from a child under 16 without proper parental consent, we will take steps to delete such information promptly.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website and in the app
- Sending an email notification to your registered email address
- Displaying an in-app notification upon next login
For material changes that require consent under GDPR (e.g., new processing purposes), we will obtain your explicit consent before implementing the changes.
The "Last Updated" date at the top of this policy indicates when it was last revised. We encourage you to review this Privacy Policy periodically.
19. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
helpful bits GmbH
Südliche Münchner Straße 55, 82031 Grünwald, Germany
Privacy Inquiries: privacy [at] crispdemo.com
Data Protection Officer: dpo [at] crispdemo.com
General Contact: legal [at] crispdemo.com
Website: crispdemo.com
We aim to respond to all privacy inquiries within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
20. Data Breach Notification
20.1 Notification to Supervisory Authority
In the event of a personal data breach, we will notify the competent supervisory authority (BayLDA) within 72 hours of becoming aware of the breach, as required by Article 33 GDPR, unless the breach is unlikely to result in a risk to your rights and freedoms.
20.2 Notification to Data Subjects
If a data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by Article 34 GDPR. The notification will include:
- The nature of the personal data breach
- The likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact information for further inquiries
20.3 Breach Response Measures
We maintain an incident response plan that includes:
- Immediate containment and mitigation procedures
- Forensic investigation to determine breach scope and impact
- Notification to affected parties and authorities
- Implementation of remedial measures to prevent recurrence
- Documentation of all breach-related activities
21. California Privacy Rights (CPRA) - For California Residents
Note: This section applies only to California residents who may be using the Service. EU/EEA residents should refer to the GDPR provisions above.
21.1 CPRA Rights
If you are a California resident, you have the following rights under the California Privacy Rights Act (CPRA):
- Right to Know: Request information about categories and specific pieces of personal information we collect
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of sale or sharing of personal information (we do not sell personal information)
- Right to Limit Use of Sensitive Personal Information: Limit use of sensitive personal information
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising CPRA rights
21.2 Notice of Collection
We collect the categories of personal information described in Section 5 of this Privacy Policy for the purposes described in Section 6 and Section 15.
21.3 No Sale or Sharing
We do not sell or share (for cross-context behavioral advertising) personal information as defined by the CPRA.
21.4 Exercising CPRA Rights
To exercise your CPRA rights, contact us at privacy [at] crispdemo.com.
22. Additional Provisions
22.1 Data Protection Officer
We have appointed a Data Protection Officer (DPO) who can be reached at dpo [at] crispdemo.com.
22.2 Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
22.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you of any such transfer and any choices you may have regarding your data.
22.4 Legal Disclosures
We may disclose personal data when required by law, court order, or legal process, or to protect our rights, property, or safety, or the rights, property, or safety of others.
22.5 Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) as required by Article 35 GDPR for processing activities that are likely to result in high risks to your rights and freedoms.
23. Effective Date and Governing Version
This Privacy Policy is effective as of September 25, 2026. If there are any conflicts between different language versions of this Privacy Policy, the English version shall prevail to the extent permitted by law.
Previous versions of this Privacy Policy are available upon request by contacting privacy [at] crispdemo.com.
This Privacy Policy is written under:
- General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679
- German Federal Data Protection Act (BDSG)
- German Telecommunications-Telemedia Data Protection Act (TDDDG)
- California Privacy Rights Act (CPRA) - for California residents
Last updated: September 25, 2026 | Effective: September 25, 2026
© 2026 helpful bits GmbH. All rights reserved.