CORPILUS

Privacy Policy

Last updated: September 13, 2026

1. Controller and contact

This policy explains how we process personal data on corpilus.com, in price quote requests, in the contact form and when providing the Corpilus service. We follow Regulation (EU) 2016/679 (GDPR), Slovak Act No. 18/2018 Coll. on the protection of personal data, and the rules on storing information on a user’s device.

  • Controller: CREBISO | corp.systems s.r.o., registered in the Slovak Republic
  • Product: Corpilus
  • Email for all matters, including data protection: info@crebiso.com

Full company details (company ID, VAT ID, registered office) are available on request at info@crebiso.com.

2. Roles in processing

  • We are the controller for the corpilus.com website, price quote requests, the contact form, communication with customers and invoicing.
  • We are the processor for data a customer processes in the Corpilus service (for example documents in the knowledge base, text checked before it is sent to an AI model, or events from protecting the customer’s website). The customer is the controller of that data, and we process it on the customer’s instructions.
  • If you are an employee of a customer, or a visitor to a website protected by Corpilus Shield, please contact that organisation first with questions about that data.
  • The Corpilus Privacy browser extension has its own privacy policy at corpilus.com/privacy-extension.

3. Categories of data

Depending on how you get in touch with us, we process the following data:

  • Price quote request: company name, country, number of employees, full name, work email, phone (optional), the packages you are interested in, number of people and domains, preferred deployment, an additional message and your confirmation of consent.
  • Contact form: name, email, company name, subject, message and page language. We check the message for spam automatically and store the result of that check with it. If sending fails, the form offers to open your email app instead.
  • Technical data when you visit the website: IP address, browser and device type, the page requested and the time of the request. The Corpilus Shield protection widget on this website also sends technical data about the request and about behaviour on the page, so its security can be assessed (see the Cookie Policy).
  • Website usage data, only if you consent: which pages you visit, how you got to the website and basic technical data about your browser and device, collected by Google Analytics (see the Cookie Policy).
  • Communication and the contractual relationship: emails we exchange, the customer’s contact persons and billing details.
  • Customer data in the service: content a customer puts into the service or processes through it, and users’ login details. For this data we are the processor (section 2).

4. Purposes and legal bases (Art. 6 GDPR)

  • Preparing a price quote at your request: we use the data from the form to prepare the quote and reply to you.
  • Replying to a contact form message or an email: we use the data to answer your question.
  • Providing the service, support and customer communication: performance of a contract (Art. 6(1)(b)).
  • Invoicing and accounting: legal obligation (Art. 6(1)(c)).
  • Protecting the website and forms against misuse, spam and automated attacks, including the Corpilus Shield widget: legitimate interest (Art. 6(1)(f)).
  • Remembering your language and display settings: strictly necessary to provide the feature you asked for.
  • Measuring how the website is used, with Google Analytics: your consent (Art. 6(1)(a)), given in the cookie settings. We do not use this data for advertising profiles, and no other marketing tools are in use.

Corpilus Shield assesses requests automatically and may block a suspicious one, such as a form submission. If you think this happened to you by mistake, write to info@crebiso.com.

Where processing is based on consent, you can withdraw it at any time: for analytics with the “Cookie settings” button on the website, otherwise by email. Withdrawal does not affect processing carried out before it.

5. Retention

  • Price quote requests and contact form messages: as long as needed to handle them and for the business communication that follows. If no contract results, we delete the data once it is no longer needed, or earlier at your request.
  • Data about customers and their contact persons: for the term of the contract and afterwards to the extent needed to establish or defend legal claims.
  • Invoicing and accounting records: for the period set by tax and accounting law.
  • Customer data in the service: according to the contract with the customer and its instructions; after the contract ends, according to the Terms of Service.
  • Technical and security records: only as long as needed to protect the website and the service and to investigate incidents.
  • Website usage data (with your consent): the Google Analytics cookies last 13 months, and the data in Google Analytics is kept for 14 months at most.
  • Data stored in your browser: see the Cookie Policy.

6. Recipients

We do not sell data or give it to third parties for their own marketing. Recipients can only be:

  • Technical service providers who help us operate the service.
  • Google (Google Fonts): the website loads fonts from Google’s servers, so your browser passes your IP address and basic browser information to Google when it does so.
  • Google Ireland Limited (Google Analytics): only if you consent to analytics in the cookie settings; it receives the website usage data described above.
  • The model provider the customer chooses, for example OpenAI, Anthropic or Google, if the customer enables cloud models in the service. Before sending, recognised sensitive data is replaced with placeholders according to the customer’s settings. With local models, no data is sent to a model provider.
  • Security events from this website’s protection may be assessed by an AI model according to the operator’s settings, including a cloud provider; secret keys and passwords are removed before sending.
  • Public authorities, where the law requires it.

7. Transfers outside the European Economic Area

We host the website and the service we operate on infrastructure in the EU. Data may reach countries outside the European Economic Area (for example the USA), for instance when fonts are loaded from Google Fonts, when you consent to Google Analytics and the data is also processed by Google LLC in the USA under the EU–US Data Privacy Framework, when technical service providers process data for us, when a customer enables cloud models from providers based outside the EEA, or when security events from this website’s protection are assessed by an AI model according to the operator’s settings, including a cloud provider; secret keys and passwords are removed before sending.

In those cases we rely on GDPR safeguards:

  • an adequacy decision of the European Commission where one exists, including the EU–US Data Privacy Framework for certified recipients;
  • standard contractual clauses approved by the European Commission;
  • supplementary measures where needed, in particular replacing sensitive data with placeholders before it is sent to a model.

8. Security measures

  • Encryption of communication between the browser, applications and the service (TLS).
  • Encryption of AI model API keys before they are stored.
  • Access control based on roles and permissions.
  • Regular backups and operational monitoring.
  • Hosting in the EU; in a deployment on the customer’s premises, operation on the customer’s own infrastructure.

No measure provides absolute protection. If we become aware of a personal data breach, we follow the GDPR, including notifying the supervisory authority and the people affected where the law requires it.

9. Your rights

Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict processing, to data portability, to object to processing based on legitimate interest, and to withdraw consent at any time. Consent to analytics is withdrawn with the “Cookie settings” button — the round button at the bottom left of the page or the link in the footer.

You can exercise your rights by email at info@crebiso.com. We will reply without undue delay and within one month at the latest; in complex cases we may extend this period as the GDPR allows and will let you know.

Where the data is processed by us as a processor for a customer, we will pass your request to that customer and help it respond.

You can also lodge a complaint with a supervisory authority. In Slovakia this is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, www.dataprotection.gov.sk.

10. Cookies and browser storage

The website stores in your browser what it needs to remember your language, your cookie choice and the security of the website. Only with your consent does it also keep your display settings between visits and set the Google Analytics cookies. You choose in the cookie settings (the “Cookie settings” button) and can change your choice at any time.

The full list, with purpose and storage period, is in the Cookie Policy at corpilus.com/cookies.

11. Changes to this policy

We may update this policy for legal, operational or product reasons. Each time, we update the date at the top of the page. We inform customers of material changes in advance.

If a change would mean new processing based on consent, such as adding marketing tools, we will ask for consent before it starts.

12. Contact

Send questions, comments or requests about this policy to info@crebiso.com.

Controller: CREBISO | corp.systems s.r.o. (product: Corpilus). Full company details (company ID, VAT ID, registered office) are available on request.

The terms for using the service are in the Terms of Service at corpilus.com/terms.