GDPR Data Processing Statement

Last updated: July 3, 2026

CrossKit complies with the EU General Data Protection Regulation (GDPR). We do NOT sell your personal data.

1. Data Controller

CrossKit (operated by CrossKit Technology) acts as the data controller for personal data processed through this website. We are responsible for ensuring your data is processed in accordance with GDPR.

2. Legal Basis for Processing

We process your personal data based on:

  • Consent: When you register, subscribe, or use optional features
  • Contract: To provide the services you requested
  • Legitimate Interest: To improve our services and ensure security
  • Legal Obligation: To comply with applicable laws

3. Categories of Personal Data

  • Identification data (name, username, email)
  • Account credentials (hashed passwords)
  • Usage data (tool usage, query history, archived keywords)
  • Payment data (processed by PayPal/Creem, not stored by us)
  • Technical data (IP address, browser type, device info)

4. Your GDPR Rights

  • Right of Access (Article 15): Request a copy of your personal data
  • Right to Rectification (Article 16): Correct inaccurate data
  • Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing (Article 18): Limit how we use your data
  • Right to Data Portability (Article 20): Receive your data in a structured format
  • Right to Object (Article 21): Object to processing based on legitimate interest
  • Right to Withdraw Consent (Article 7): Withdraw consent at any time

5. Data Retention

We retain personal data only as long as necessary: active account data is kept while your account is active; archived tool data is retained for 90 days after account deletion; batch task logs are retained for 30 days; payment records are retained per legal requirements.

6. Data Transfer Outside EEA

Your data may be transferred to and processed in countries outside the European Economic Area. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions.

7. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and affected individuals without undue delay.

8. How to Exercise Your Rights

To exercise any of your GDPR rights, contact us at support@crosskit.top. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

Data Non-Sale Commitment: CrossKit will never sell your personal data to any third party. All collected data is used solely for providing and improving our services.