Credocent

Last updated ยท 2026-08-19

Privacy policy

How Credocent handles personal data for customers, their employees and visitors to this website.

1. Who is responsible

Credocent provides an AI assistant that answers employee questions from the customer's own documents.

For this website and for our own customer accounts we are the data controller. For the documents and questions inside a customer workspace we act as a data processor on behalf of the customer company.

2. What we process

Account data: name, work email, company, role and login metadata.

Usage data: questions asked, answers given, documents uploaded, and technical logs needed to run and secure the service.

Billing data: company details, plan and invoice history.

3. Why we process it

To deliver the service under our agreement with the customer, to invoice, to keep the service secure, and to comply with the law.

We do not sell personal data and we do not use customer documents to train AI models.

4. Where data is stored

Data is stored and processed in the EU/EEA. Each customer workspace is isolated at the database level so one company can never read another company's content.

5. Sub-processors

We use a small number of vetted providers for hosting, AI inference and transactional email. The current list is published on the security page and customers are notified before it changes.

6. How long we keep data

Content is kept for as long as the customer's account is active. After termination it is deleted within 30 days, except where law requires us to keep accounting records.

An administrator can delete documents, employees or the entire workspace at any time from the admin area.

7. Your rights

You may request access, correction, deletion, restriction, objection and data portability.

If you are an employee of a customer company, contact your employer first; we will assist them as their processor. You can also complain to your national data protection authority.

8. Cookies and local storage

We only use strictly necessary storage: a login session cookie and a local storage entry that remembers your chosen language.

We do not use advertising cookies, tracking pixels or third-party analytics, so no cookie consent banner is required. If that ever changes, we will ask for your consent first.

9. Security

Data is encrypted in transit and at rest, access is role based, and every request is checked against the workspace it belongs to.

10. Contact

Privacy questions and data subject requests can be sent to our contact address below.

Back to home