Legal
Privacy Policy
Your business data is yours. We process it to provide the Service, nothing more. We're EU-based and GDPR-compliant. This document explains exactly what we collect, why, and what rights you have over it.
1. Who We Are
Craft11 is operated by DotCom d.o.o., a company incorporated in Slovenia and operating since 2008 (dot-com.si). DotCom d.o.o. acts as the data controller for personal data processed through the Craft11 platform.
For GDPR purposes, DotCom d.o.o. in Slovenia serves as the EU establishment handling EU market activities including invoicing, support, and local compliance.
Privacy contact: privacy@craft11.com
2. What We Collect
Account information: Name, email address, company name, team size, and billing details provided during registration or payment.
Business data you enter ("Customer Data"): Client records, inquiries, offers, project details, invoices, notes, voice inputs, uploaded documents, and any other information you or your team enter into Craft11. This is your data and you own it entirely.
Usage data: How you use the platform, feature interactions, error logs, and performance data. Used to improve the Service and diagnose issues.
Technical data: IP address, browser type, device type, and session data. Used for security and service delivery.
Payment data: Processed by Stripe. We do not store full card details — Stripe handles payment security. We retain billing history and invoice records.
We do not collect or knowingly process data from individuals under 16.
3. Why We Process It (Legal Basis)
Contract performance: Providing, maintaining, and supporting the Service you've subscribed to.
Legitimate interests: Security, fraud prevention, system performance, improving the Service, and anonymized product analytics — where these don't override your rights.
Legal obligation: Retaining records required by applicable law, responding to lawful requests from authorities.
Consent: Where we rely on consent (e.g., marketing communications), you can withdraw it at any time.
4. How We Use Your Data
We use your data to:
- Provide and operate the Craft11 platform and all its features
- Process your subscription and manage billing via Stripe
- Power AI features (Stark, Spark Vault, AI Village) — grounded in your Company Data as the baseline, not general internet data
- Send service-related communications (account updates, security alerts, billing notices)
- Improve the platform through anonymized, aggregated analytics
- Maintain the security and integrity of the Service
- Comply with legal and regulatory obligations
We do not sell your personal data to third parties. We do not use your data for advertising.
5. AI Features and Your Data
Craft11's AI features (Stark, Spark Vault, AI Village, automated summaries, document ingestion) process your Customer Data to provide their functionality. A few important principles:
- Your data is the baseline. Stark answers from your company's own memory — your notes, your patterns, your history — not from generic internet knowledge. Your data drives the intelligence.
- Human judgment is always final. The system is designed so your raw human inputs remain the authoritative source of truth. You can review, edit, override, or revert any AI-generated content at any time. This is not a feature that can be turned off — it is the architecture.
- Anonymized improvement: We may use anonymized and aggregated data derived from Customer Data to improve AI models and platform performance. This derived data cannot be linked back to you or your business. EU/GDPR users may opt out by contacting privacy@craft11.com.
- No autonomous decisions: No AI-generated action in Craft11 reaches a client, commits to payment, or executes anything consequential without explicit human approval. The approval gates are structural, not optional settings.
6. Who We Share Your Data With
We do not sell or share your personal data except with:
- Stripe — payment processing. Governed by Stripe's own Privacy Policy.
- AI model providers — when you configure a provider (Claude/Anthropic, Grok/xAI, ChatGPT/OpenAI), your queries are processed by that provider under your own API key. Your API key and data interactions go directly to the provider you choose. Configure a local Ollama instance if you require zero external data transmission.
- Cloud infrastructure providers — hosting, storage, and delivery of the Service. Subject to appropriate data protection agreements.
- Legal authorities — when required by law, court order, or to protect rights and safety.
All third-party processors are bound by appropriate data processing agreements.
7. International Transfers
Craft11 is EU-based and processes data primarily within the EU. Some service components (cloud infrastructure, payment processing, AI model providers) may process data outside the EU/EEA. Where data is transferred internationally, it is safeguarded by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Addendum where applicable
- Other appropriate transfer mechanisms permitted under GDPR
You can request information about transfer safeguards by contacting privacy@craft11.com.
8. Your Rights (EU/GDPR)
If you are in the EU, EEA, UK, or Switzerland, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — limit how we process your data in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent, withdraw at any time
To exercise any of these rights, contact privacy@craft11.com. We will respond within one month (extendable to three months for complex requests). We may verify your identity before processing the request.
You also have the right to lodge a complaint with your national data protection authority. In Slovenia: Informacijski pooblaščenec (ip-rs.si).
9. Data Retention
We retain your Customer Data for as long as your subscription is active, plus any additional period required by law. After subscription termination:
- Active Customer Data is deleted or anonymized within 30 days
- Backup copies are retained for up to 90 days for disaster recovery, then deleted
- Billing records and legally required data are retained for the minimum period required by applicable law (typically 7–10 years for financial records under EU/Slovenian law)
- Anonymized aggregated data has no retention limit — it can no longer be linked to you
You can request a full export of your data in CSV/JSON format within 30 days of termination at no charge. Contact support@craft11.com.
10. Security
We implement reasonable administrative, technical, and physical safeguards to protect your data, including encryption at rest and in transit, access controls, and security monitoring. No system is completely secure. You are responsible for the security of your own account credentials.
Report security concerns to security@craft11.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification with at least 30 days' advance notice where practicable. The current version is always available at craft11.com/privacy. Continued use after changes constitute acceptance.
12. Contact
- Privacy and data protection: privacy@craft11.com
- General: support@craft11.com
- Legal: legal@craft11.com
- Operated by: DotCom d.o.o., Slovenia · dot-com.si