Legal

GDPR Statement

Last updated: May 23, 2026

CrowdNod is committed to compliance with the EU General Data Protection Regulation (GDPR) and equivalent privacy laws (UK GDPR, CCPA). This statement summarizes how we handle personal data of EU/UK residents and the rights you can exercise.

1. Roles

  • For your account data (you, the customer): we are the data controller.
  • For testimonials submitted through your forms: you are the controller, and we are the processor acting on your instructions.

By using the Service to collect testimonials, you confirm you have a lawful basis (typically consent or legitimate interest) to process those submitters' data.

2. Legal Basis for Processing

  • Contract— processing necessary to provide the Service you signed up for.
  • Legitimate interest— product analytics, fraud prevention, security.
  • Consent— optional marketing emails (you can opt out at any time).
  • Legal obligation— tax records, responding to law-enforcement requests where legally required.

3. Your Rights as a Data Subject

  • Access— receive a copy of your personal data.
  • Rectification— correct inaccurate or incomplete data.
  • Erasure— request deletion (“right to be forgotten”).
  • Restriction— pause processing in certain cases.
  • Portability— export your data in CSV or JSON format.
  • Objection— object to processing based on legitimate interest.
  • Complaint— lodge a complaint with your national data protection authority.

Account owners can export and delete their data directly from the dashboard settings page. For all other requests, email support@crowdnod.com. We respond to verified requests within 30 days.

4. Sub-processors

We use the following GDPR-compliant sub-processors:

  • Supabase— database, auth, storage. Standard Contractual Clauses in place.
  • Stripe— payment processing. Self-certified under EU-US Data Privacy Framework.
  • Resend— transactional email delivery.
  • OpenRouter— AI processing (US-based).
  • Vercel— hosting and CDN.

We will notify customers via email at least 30 days before adding or replacing any sub-processor.

5. International Data Transfers

Where personal data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses approved by the European Commission. You can request a copy of the applicable SCCs by emailing support@crowdnod.com.

6. Data Breach Notification

In the event of a personal data breach affecting EU/UK residents, we will notify the relevant supervisory authority within 72 hours of becoming aware and notify affected customers without undue delay.

7. Data Protection Officer

For privacy and data protection inquiries, contact us at support@crowdnod.com with the subject line “Data Protection”.

See also our Privacy Policy and Terms of Service.