Privacy Policy
GDPR & data protection - marketing site, client portal & setter workspace · Last updated: September 17, 2026
Who & what
Data Controller
The data controller for personal data collected through crescosystem.com, the client portal at portal.crescosystem.com and the setter workspace at setter.crescosystem.com is:
- Company: CRESCO System - Maximilian Faust
- Representative: Max Faust
- Address: 59 rue de Ponthieu, Bureau 326, 75008 Paris, France
- Email: contact@crescosystem.com
Data We Collect - Marketing Site
Contact / discovery form:
- First and last name
- Professional email address
- Phone number (optional, with country code)
- Business name (optional)
- Business type
- Selected package (Audit / Systems Build / Partnership / undecided)
- Description of your problem or project
- Preferred time slot for a discovery call
Advertising attribution (only with your consent):
- The click identifier assigned by the advertising platform (
gclid,gbraid,wbraid) and any UTM campaign parameters present in the address you arrived on - These are held in your browser's sessionStorage for the visit, and attached to your enquiry so we can tell which campaign produced it
- If you decline advertising cookies, nothing is stored and nothing is attached. The form works identically either way
Referral code (only if you arrived on a referral link):
- If the address you arrived on carried a
refparameter, that code is held in your browser's sessionStorage for the visit and attached to your enquiry, so that the person who sent you to us is credited for it - It identifies them, not you. It reaches no advertising network, and it is kept whether or not you allow advertising cookies - declining them should not cost somebody else their fee
Technical data:
- Your IP address, processed to rate-limit our forms and block automated abuse. It is held for a short window against the form endpoint and is never attached to your enquiry
- Standard server logs generated by our host
Our typefaces, stylesheets, scripts and images are all served from our own domain, including the photographs on client testimonials, which we fetch from Notion server-side rather than letting your browser request them. Loading a page of this site contacts no third party. The only exception is the Google Ads tag, and only if you have allowed it.
We do not run a website analytics product. There is no Google Analytics, no heatmap tool and no visitor-profiling script on this site. The only third-party tag is the Google Ads conversion tag described above, and it does not load unless you allow it.
Data We Collect - Client Portal
Project data:
- Project name and associated phases
- Milestones, deliverables, and progress statuses
- Planned start and end dates
- Project updates, recaps, and communications
Billing data:
- Invoice and quote amounts, numbers, and payment statuses
- Stripe payment and subscription references (for monthly retainers)
- Transaction history
- Your billing details as they appear on issued documents, including any intra-community VAT number
Agreements and electronic signature:
- The name you type as signer, and your email address
- The signature you draw, embedded into the signed document
- The exact timestamp, and a cryptographic fingerprint (SHA-256) of the document you signed
- The IP address you signed from and your browser user-agent
- The resulting signed PDF
This exists for one reason: under the EU eIDAS regulation an electronic signature is only worth something if it can be evidenced. Your name, your signature, the timestamp and the document fingerprint are written onto a certificate page appended to the signed PDF, and that PDF is kept. Your IP address and user-agent are not printed on the document. They are captured at the moment of signature and sent to us in the internal notification that tells us you signed, and they appear in our server logs; we do not copy them into any other record. The signing screen tells you this before you sign.
WhatsApp notifications (only if you ask for them):
- Your mobile number
- The record of your consent: that you gave it, exactly when, on which screen, and which version of the wording you were shown
- The details that go into each message - your first name, and whichever of these the notice is about: a document number, an amount, a date, your project name, the title of an update, or the time of a booked call
- The access code that opens your portal, or the link to the document being sent, carried by the button on the message. It is the same code your email already contains
This is off unless you turn it on. There is a separate tick box when you sign your agreement, and it is deliberately not part of the agreement itself - consent bundled into a document you have to sign would not be a free choice. You can turn it off again at any time from your portal, or by replying STOP to any message, and it takes effect immediately. Everything you would have received on WhatsApp keeps arriving by email either way. We never send marketing this way.
If you reply to one of these messages we keep no record of what you wrote. The reply is checked for opt-out words such as STOP, forwarded to us so that a person sees it, and then dropped - it is never written to our systems, our client records or our logs, and we store no WhatsApp conversation, thread or history. The forwarded copy arrives in our own WhatsApp inbox and stays there like any other message somebody has sent us.
Credential handover (secure links):
- When a project requires you to hand over an access credential, we send a single-use link. The value is encrypted in your browser with a key that lives in the link fragment and is never transmitted to us
- Our server stores the ciphertext and the bookkeeping around it - the initialisation vector, a hash of the optional password if one was set, the hint we wrote to say which value we are asking for, whether the link is us sending you something or asking you for something, how many failed password attempts it has had, the email address of whoever on our side created it, and the timestamps. It stores nothing that can turn the ciphertext back into the value. We cannot read it, and neither can our hosting or database providers
- It expires automatically after 24 hours, is destroyed the moment it is read once, and self-destructs after a small number of failed password attempts
Feedback and testimonials:
- Your name, agency, project, a rating, and any written comment you choose to give
- Whether you agreed to that comment being published. Publication is a decision we take case by case; we do not publish a named testimonial you did not agree to, and you can withdraw that agreement at any time by writing to us
Session data:
- Your project code is stored exclusively in the browser's sessionStorage
- It is automatically cleared when the tab or browser is closed
- There is no server-side session and no login cookie: the portal issues no session token at all
- It is removed from the URL immediately after validation, leaving no trace in browser history
Data We Collect - Setter Application & Setter Workspace
crescosystem.com/setter carries a job advert and a timed application, open to anyone. setter.crescosystem.com is the private workspace used by the setters we have taken on. They are two different surfaces and they collect different things.
The application:
- Your name, your WhatsApp number and your email address. At least one of the last two is required, because there has to be a way to tell you the outcome
- Your Telegram handle and your country, if you give them
- Where you heard about the role
- Your answers: your experience, the agencies you researched and what told you their size, the opening message you wrote, and your replies to the objections
- How long the task took you. It is recorded, not enforced - running over does not disqualify anyone
- Your IP address, for the rate limit on the form. It is never attached to your application
The application does not ask you to create a login, and no password is collected there.
The workspace, once you are working with us:
- A handle you choose and a password. We store a scrypt hash of the password with a salt of its own, never the password itself, together with the date it was set. It cannot be read back, by us or by anyone who obtained the database
- A single-use reset code, when you ask for one. It expires after 72 hours and is destroyed by the request that spends it
- A login cookie (
cresco_setter): HttpOnly, signed with a server key, valid for 30 days. It carries your handle, the id of your row and the moment it expires, and nothing else - Your shifts: clock-in, clock-out and break minutes
- What you log each day: targets added, messages opened, replies, qualified conversations, calls booked, and anything you write in the note or the weekly reflection
- Your payout method and payout details, and a dated record of every change you make to them
- The prospects you work and the calls you book: the account or agency, the channel, the stage, your notes, and - for a booked call - the prospect's name, handle, email and the problem they named
The login is rate-limited twice, by IP address and by IP address and handle together, so neither a broad password grind nor a focused one on a single account is practical. A wrong handle and a wrong password give the same answer, so the login cannot be used to find out who has an account.
How & why we process it
Purposes of Processing
The data we collect is used to:
- Process and respond to discovery requests, and to set up the video call you booked
- Manage the client relationship and project follow-up via the portal
- Issue quotes, agreements, invoices, and credit notes, and process payments and retainers
- Establish that an agreement was signed, by whom, and when
- Receive credentials you need to give us, without them ever sitting readable in an inbox or a chat
- Keep our forms usable by blocking automated abuse
- Measure which advertising campaigns produce enquiries (only with your consent)
- Credit the person who referred an enquiry, where one did
- Publish a testimonial, where you explicitly agreed to it
- Send the same transactional notices over WhatsApp, to clients who asked for them (only with your consent), and hold the evidence that the consent was given
- Assess an application for a setter role and tell the applicant the outcome
- Run the setter workspace: logging in, shifts, daily activity, prospect follow-up, booked calls, and payouts
Legal Basis
- Legitimate interest: responding to inbound enquiries, managing the commercial relationship, securing our forms against abuse, evidencing a signature, and keeping the record that a consent was given for as long as it could be questioned
- Contract performance, and steps taken at your request before a contract (Article 6(1)(b)): client project management, portal access, agreements, invoicing and retainer subscriptions; and, on the setter side, assessing an application and running the engagement that follows, payouts included
- Legal obligation: retention of accounting and tax records, and electronic invoicing obligations
- Consent (Article 6(1)(a)): advertising cookies and click-identifier attribution; publication of a named testimonial; and WhatsApp notifications, which are off for everyone until a client switches them on and are never used for marketing. Each of these can be withdrawn at any time, by the routes set out under Your Rights below, and withdrawing one does not make anything done beforehand unlawful
Data Processors & Third Parties
Your data may be shared with the following sub-processors, strictly within the scope of service delivery and of running our own business. This list names every provider we send your data to, and it is complete as at the date at the top of this page - if a provider is not named here, we do not send it your data.
Each of these providers runs on infrastructure of its own, engaged by them and not by us: Notion, for example, keeps files uploaded to it in Amazon S3. Those suppliers are covered by our contract with the provider rather than listed here one by one, and we have no separate relationship with them. Where such a file would otherwise be fetched by your browser - a testimonial photograph is the only case - we fetch it server-side and serve it from our own domain instead, so your IP address never reaches that supplier.
- Notion Labs, Inc. (United States) - leads, clients, projects, agreements, quotes, invoices, and feedback records; the storage of any photograph supplied with a testimonial; and, on the setter side, applications and everything the setter workspace records
- Stripe, Inc. (United States / Ireland) - payment processing, subscriptions, and transaction history. PCI-DSS Level 1 certified. We never see or store your full card number
- Cloudflare, Inc. (R2 object storage) - signed agreement PDFs, signature images, and invoice PDFs
- Google LLC (United States) - Google Drive, which holds the agreement documents we prepare and export; and the Google Ads conversion tag, which loads only if you allow advertising cookies
- Microsoft Corporation (United States / EU) - creates the Teams meeting for a booked discovery call. Your name and the enquiry you wrote go into that calendar entry; your email address is deliberately not added as an attendee
- Resend, Inc. (United States) - transactional email delivery (booking confirmations, invoices, project updates)
- Meta Platforms Ireland Limited (Ireland / United States) - delivery of the same transactional notices over WhatsApp, to clients who have asked for them. Receives your phone number, the contents of the notice being sent, and the access code or document link that the message’s button opens - the same code your email already carries. Used only if you tick the WhatsApp box when you sign, and never for marketing
- Loom, Inc. (United States, an Atlassian company) - where a project update comes with a recorded walkthrough, the recording is hosted there and the update carries a link to it. The portal does not embed the player: nothing is requested from Loom until you click the link, and from that click you are on Loom’s own site, where their privacy policy governs the visit
- Anthropic PBC (United States; EU representative Anthropic Ireland, Limited, Dublin) - the AI assistant we use to run our own business. It reads our internal record of the work - your project file, our correspondence with you, notes from a call, a quote or an invoice - so that we can draft, summarise and organise from it. That means your name, your business email, and what we are doing for you. Model training is switched off on our account: nothing in those records is used to improve an AI model. Credentials you send us never go there, and neither does anything from inside a client’s own systems
- Upstash, Inc. - short-lived storage of IP addresses for rate limiting on the public forms, the portal and the setter login, and of the encrypted credential blobs described above
- Vercel Inc. - website and portal hosting and encrypted data transmission (340 Pine Street Suite 701, San Francisco, CA 94104, USA)
No data is sold, rented, or transferred to third parties for their own commercial purposes.
Security Measures (Client Portal)
The following technical measures are in place to protect data accessed via the client portal:
- Random project codes: access codes are randomly generated in the format
CM-XXXX-XXXX, with no link to personal information - No stored passwords: portal authentication relies solely on project codes - the portal has no password database at all (the setter workspace, a separate application for our own team, does; it is described above)
- Ephemeral sessions: all session data is cleared when the browser is closed, and no server-side session is created
- HTTPS only: all data is transmitted over TLS-encrypted connections
- URL sanitisation: the project code is removed from the URL immediately after validation to prevent exposure in history or server logs
- End-to-end encrypted credential handover: credentials you send us are encrypted in your browser; the decryption key never reaches our servers
- Rate limiting: the public forms and the sensitive endpoints - enquiries, portal access validation, agreement signing and credential links - are rate-limited to make brute-force and scraping impractical
- Unguessable document links: quotes and secure links are reachable only through a long random token
Storage & your rights
Retention Periods
- Lead data: 2 years from the last point of contact
- Advertising attribution: the click identifier we keep ourselves stays in your browser for the visit only. Google's own advertising cookie, which its tag sets once you switch that category on, lasts about 90 days - withdrawing your consent in the banner deletes it, and so does clearing your browser data. Where attribution is attached to an enquiry it follows the lead retention above
- Project data (portal): retained for the duration of the engagement and for 5 years after its close (French accounting requirement)
- Signed agreements (the PDF, including the certificate page carrying your signature, the timestamp and the document fingerprint): duration of the engagement plus 5 years, matching the general limitation period under Article 2224 of the French Civil Code, so that a signature can still be evidenced for as long as it can still be disputed
- The IP address and user-agent captured at signature: kept only in the internal notification email we receive and in short-lived server logs. They are never printed on the document and never shared
- Payment and invoicing data: 10 years (French legal requirement - Article L.123-22 et seq. of the Commercial Code)
- Credentials sent through a secure link: a maximum of 24 hours, and destroyed immediately on first read
- IP addresses used for rate limiting: the length of the rate-limit window only, measured in minutes or hours. No longer-term analytics record of them is kept
- Feedback and testimonials: until you withdraw your agreement to publication
- Your WhatsApp number and consent record: these are deliberately not deleted when you switch the notifications off. Switching off flips the consent to no and records where the withdrawal came from and when; your number, and the record that you had consented and to which wording, stay on your client record. Erasing them at the moment of an opt-out would destroy the only evidence that the consent ever existed, which is the single thing that record is for. They are erased with the rest of your client record when its retention period above ends, and you can ask for the number to be removed sooner
- Session data (portal): duration of the browser session only - no server-side retention
- Setter applications that do not lead to an engagement: deleted once we decide not to go ahead, and at the latest 7 days after that decision
- Setter workspace records (shifts, activity logs, prospects, bookings, payout details): duration of the engagement and 5 years after it ends, on the same accounting and limitation grounds as the client records above. The password hash and any unused reset code are cleared when the engagement ends; the login session expires 30 days after the last login in any case
Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the following rights:
- Right of access: obtain a copy of the data held about you
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: request deletion of your data ("right to be forgotten")
- Right to portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on your particular situation
- Right to restriction: request a temporary suspension of processing
- Right to withdraw consent: as easily as you gave it, and for each consent separately - see below
Withdrawing a consent:
- Advertising cookies and click-identifier attribution: change your choice at any time from the cookie banner at the bottom of every page
- WhatsApp notifications: two routes, both of which take effect immediately and neither of which needs to go through us. Turn the switch off in your portal, or reply STOP to any message we sent you. Nothing else changes: everything you would have received on WhatsApp keeps arriving by email
- Publication of a named testimonial: write to us and it comes down
Withdrawing a consent does not make what was done beforehand unlawful, and it costs you nothing else - no feature of the portal depends on any of these.
Records we are legally required to keep - signed agreements, invoices, accounting entries - cannot be erased before their retention period expires. The WhatsApp consent record is kept on the same principle, as the retention list above sets out. Everything else can be erased.
To exercise any of these rights, contact us at: contact@crescosystem.com
You also have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr
Cookies
crescosystem.com sets two categories of cookie and equivalent browser storage, and you can review or change your choice at any time from the cookie banner at the bottom of every page. Two more apply elsewhere: one on the client portal, and one on the setter workspace - which runs this same banner, so the two categories above, the Google Ads tag included, apply there as well.
- Essential - required for the site to function and for abuse prevention. These cannot be disabled
- Advertising & conversion measurement - the Google Ads tag, and the click identifier described above. Off unless you switch it on. Nothing is loaded or stored until you do
- Payments (Stripe) - set on the client portal at portal.crescosystem.com when you open a payment form, to process the payment and detect fraud. They have no switch here because this banner does not run on the portal domain, and an invoice cannot be paid without them
- Setter login (essential) - one cookie set at setter.crescosystem.com when a setter logs in, so that they stay logged in for 30 days. It is HttpOnly, signed, carries a handle, a row id and its own expiry, and measures nothing. There is no switch for it because without it there is no login
Declining a non-essential category has no effect on your access to the site, the form, or the portal.
International Transfers
Several of our sub-processors are established in the United States. WhatsApp messages are delivered through Meta’s Irish entity, which transfers to the United States. These transfers are governed by Standard Contractual Clauses approved by the European Commission and, where the provider is certified, by the EU-US Data Privacy Framework.
The transfer to Anthropic runs on the Standard Contractual Clauses incorporated in their Data Processing Addendum. Anthropic is not certified under the EU-US Data Privacy Framework and we do not rely on it for them.
Updates to This Policy
CRESCO System - Maximilian Faust reserves the right to update this privacy policy at any time. Changes take effect upon publication on this page. We encourage you to review this page periodically.