Privacy Policy
The short version
- This website sets no cookies and runs no analytics or advertising trackers. That is why there is no cookie banner: there is nothing to consent to.
- The only personal data we collect is what you send us yourself (through the contact form, by email or on social media), plus the technical server logs any website produces.
- We use it for one thing: to reply to you and, if you want, to work together. We do not sell it, share it for advertising, or use it to train AI models.
- Your data is stored with Google (Firebase / Google Workspace) under EU-approved safeguards. We keep contact-form messages for up to 24 months.
- You can ask us at any time what we hold about you, and have it corrected or deleted: info@crosstech.solutions.
This policy explains how CrossTech handles personal data when you visit crosstech.solutions, contact us, or interact with us on social media. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and the Dutch implementing act (UAVG), the UK GDPR, South Africa's Protection of Personal Information Act (POPIA), the comprehensive privacy laws of US states such as the California Consumer Privacy Act (CCPA/CPRA), and Canada's PIPEDA and Quebec's Law 25. Where those laws give you different rights, the region-specific sections below apply to you.
Data we process on behalf of clients inside the software we build for them is governed by the contract and data processing agreement for that project, not by this policy.
Contents
- Who we are
- What we collect and why
- Cookies, trackers and browser storage
- Who we share data with
- International transfers
- How long we keep data
- How we protect it
- AI and automated decisions
- Your rights
- EU / EEA / UK visitors
- South Africa (POPIA)
- United States
- Canada
- Children
- Social media and third-party sites
- Our mobile applications
- Changes to this policy
- Contact
1. Who we are
CrossTech Solutions ("CrossTech", "we", "us") is an AI-first software studio. We are the controller (GDPR) and responsible party (POPIA) for the personal data described in this policy.
CrossTech Solutions B.V. is in incorporation under Dutch law. Until that registration is complete, the studio is operated by its founder as a sole trader, who is the controller in the meantime and is bound by this policy in the same way; once the B.V. is incorporated it becomes the controller and we will update this page, including our company registration number and VAT ID. Because we also operate in South Africa, this policy is written to comply with POPIA as well.
Contact for anything privacy-related: info@crosstech.solutions (subject line "Privacy request"). We have not appointed a statutory Data Protection Officer, because our processing does not require one; the founder acts as our privacy contact and as our POPIA Information Officer.
2. What we collect and why
We collect as little as we can. Everything we process about website visitors is in this table.
| When | Data | Purpose | Legal basis (GDPR / POPIA) | Kept for |
|---|---|---|---|---|
| You use the contact form | Name, email address, subject, message, time of submission, a random reference number we generate for your message, and our internal handling status (whether we have replied). Your message also triggers a notification email to our own mailbox | To read and answer your message, send you an automatic confirmation with your reference number, and follow up on a potential project | Our legitimate interest in answering enquiries and following up (Art. 6(1)(f) GDPR; POPIA s11(1)(f)); where you are yourself the prospective contracting party, steps at your request before entering a contract (Art. 6(1)(b) GDPR; POPIA s11(1)(b)) | Up to 24 months after we receive it; longer only while we are still in contact or start working together (then under the project contract) |
| You email us or message us on social media | Whatever you choose to include, your address or handle, and the conversation history | To answer you and keep track of what we agreed | As above | As above |
| You visit any page | IP address, browser type, requested page, date/time and referrer, recorded in the hosting provider's server logs | To serve the pages, keep the site secure, and detect abuse or attacks | Legitimate interest in running a secure website (Art. 6(1)(f) GDPR; POPIA s11(1)(f)) | Held by the hosting provider (Google Firebase) for a few months, then deleted. We do not look at these logs unless we are investigating a security problem |
| You use the self-check tool | Nothing. Your answers are computed in your browser and never sent to us | — | — | — |
Providing your details is voluntary. If you prefer not to fill in the form, you can simply email us; if you send nothing, the only consequence is that we cannot reply to you. We never ask for, and you should not send us, sensitive ("special category") data such as health, religious or biometric information through the contact form.
We do not buy data about you, enrich your details from third-party sources, or build marketing profiles. We do not currently send newsletters or marketing emails; if you ask us for a proposal, we will only email you about that request. If we ever start sending marketing messages, we will do so only with your prior consent (or to existing clients about similar services, where the law allows), every message will identify us and contain an unsubscribe link, and we will act on unsubscribe requests within 10 business days.
3. Cookies, trackers and browser storage
This website does not set cookies of any kind: no analytics cookies, no advertising cookies, no "functional" cookies and no third-party pixels. We do not use Google Analytics, Meta Pixel, LinkedIn Insight, session recording or fingerprinting. Because nothing is stored on or read from your device to track you, the EU ePrivacy rules and the Dutch Telecommunications Act do not require a consent banner, and we do not show one.
Two technical notes, in the interest of full transparency:
- The contact page loads Google's Firebase library so your message can be delivered to our database. That library is used strictly to send your message; it is not used to identify or track you across sites.
- Fonts, stylesheets, scripts and images are served from our own domain. Since September 2026 our web fonts are self-hosted, so no request is sent to Google Fonts when you load a page.
Do Not Track and Global Privacy Control. We do not track visitors or sell or share personal data, so a "Do Not Track" or Global Privacy Control signal from your browser changes nothing: you are already treated as opted out.
If we ever introduce analytics or other technologies that store information on your device, we will update this section first and, where the law requires it, ask for your consent before they run.
4. Who we share data with
We never sell personal data, share it for cross-context behavioural advertising, or give it to data brokers. We share it only with service providers that process it on our instructions (processors / operators), and only as far as needed to run the website and answer you:
| Provider | What they do for us | Location | Safeguards |
|---|---|---|---|
| Google LLC / Google Ireland Ltd — Firebase Hosting, Cloud Firestore, Cloud Functions | Serve the website, store contact-form messages, run the process that emails you a confirmation and notifies us | Google Cloud data centres; may include the United States | Firebase Data Processing and Security Terms (incl. EU Standard Contractual Clauses); Google LLC is certified under the EU–US Data Privacy Framework |
| Google Workspace (Gmail) | Our email; every message you send us and our replies pass through it | As above | Google Workspace Data Processing Addendum (incl. EU Standard Contractual Clauses); Data Privacy Framework as above |
We may also disclose personal data if the law requires it (for example a valid order from a court or supervisory authority), to protect our rights or safety, or as part of a merger, sale or restructuring of the business (including the transfer to CrossTech Solutions B.V. once incorporated), in which case this policy will continue to apply. We will update this table before adding any new provider.
5. International transfers
We work from the European Union and South Africa; our providers store data in Google Cloud regions that may include the United States. Whenever personal data leaves the EU/EEA, the UK or South Africa, we rely on recognised safeguards: for Google, the EU Standard Contractual Clauses built into its data processing terms and, for Google LLC, its certification under the EU–US Data Privacy Framework (and the UK and Swiss extensions). Transfers out of South Africa are made under section 72 of POPIA, on the basis that the recipient is bound by contractual terms that give a substantially similar level of protection. You can ask us for a copy of the relevant safeguards.
6. How long we keep data
- Contact-form messages and email: up to 24 months after we receive them, then deleted (longer only while we are still in contact). If your enquiry turns into a project, the correspondence becomes part of the project file and is kept for the duration of the engagement plus the statutory retention period for business records (generally 7 years).
- Server logs: retained by our hosting provider for a few months and then automatically deleted; we keep no copy.
- Legal claims: we may keep specific data for longer where we need it to establish, exercise or defend a legal claim.
7. How we protect it
All pages and form submissions are served over HTTPS. Contact-form messages go into a database that is configured so that the public internet can only write a validated message and can never read, change or delete one; only our own authenticated systems (the process that sends you the confirmation) and the founder can read them. We keep the amount of data, the number of systems and the number of people with access as small as possible. No system is perfectly secure, so if we ever discover a breach affecting your data we will notify the competent supervisory authority where the law requires it (within 72 hours under the GDPR; as soon as reasonably possible under POPIA) and inform you without undue delay where the breach is likely to put you at high risk.
8. AI and automated decisions
We build AI systems for clients, so we want to be explicit about how AI touches your data on this site: it doesn't.
- No decision that affects you is made automatically. Your message is read and answered by a person.
- The automatic confirmation email is a fixed template that quotes your message back to you; it involves no AI.
- We do not use your messages or data to train, fine-tune or evaluate AI models, and we do not pass them to AI providers.
- If we ever use AI tooling to help draft replies, a person will still review every reply, and we will say so here.
9. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you and receive a copy;
- Correct anything that is inaccurate or incomplete;
- Delete your data ("right to be forgotten");
- Restrict or object to processing based on our legitimate interests;
- Receive the data you gave us in a portable, machine-readable format;
- Withdraw consent at any time, where processing is based on consent (this does not affect what was done before you withdrew);
- Complain to a supervisory authority (see the regional sections below).
How to exercise them. Email info@crosstech.solutions with the subject "Privacy request" and tell us what you would like us to do. Write from the email address you used to contact us; if you cannot, we may ask for reasonable proof that you are the person concerned. You may use an authorised agent, provided the agent can show your written permission. Requests are free of charge unless they are clearly excessive. We answer within one month, or within any shorter deadline that your local law sets. For unusually complex requests the GDPR lets us take up to two further months; if we need that, we will tell you within the first month and explain why. We do not discriminate against anyone for exercising their rights. If we refuse a request, we will explain why and how to appeal: reply to our decision and it will be reviewed again, and you may also complain to your supervisory authority.
10. Visitors in the EU / EEA and the United Kingdom
The GDPR (and, for UK visitors, the UK GDPR and Data Protection Act 2018) applies to everything in this policy. Our legal bases are listed in section 2. Where we rely on legitimate interests, we have checked that they are not overridden by your interests and rights; you may object at any time and we will stop unless we can show compelling legitimate grounds. The competent supervisory authority for us is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also complain to the authority in the country where you live or work; UK visitors may contact the Information Commissioner's Office (ico.org.uk). We have not appointed a UK representative, because our processing of UK visitors' data is occasional and low-risk (Article 27(2)(a) UK GDPR).
11. South Africa (POPIA)
CrossTech is a responsible party under the Protection of Personal Information Act 4 of 2013. In addition to the rights above, you may object to processing on reasonable grounds under section 11(3), and object at any time to direct marketing (section 69; see section 2 on how we handle marketing). Your information is stored outside South Africa with the providers listed in section 4, under the safeguards described in section 5. Our Information Officer can be reached at info@crosstech.solutions. Requests for access to records under the Promotion of Access to Information Act (PAIA) may be addressed to the Information Officer at the same address. Complaints may be lodged with the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001; inforegulator.org.za; enquiries@inforegulator.org.za.
12. United States
CrossTech is a small business based outside the United States and does not meet the revenue or consumer-volume thresholds of the California Consumer Privacy Act (as amended by the CPRA) or of the other US state privacy laws. We nonetheless extend the same rights to all US residents voluntarily, and we make the disclosures those laws expect:
- Notice at collection. The categories of personal information we collect (identifiers and the contents of your message; internet activity in server logs), the purposes, and the retention periods are set out in section 2.
- We do not sell or share personal information (as those terms are defined in the CCPA), have not done so in the preceding 12 months, and do not use it for targeted advertising or profiling that produces legal or similarly significant effects. We do not knowingly collect personal information of anyone under 16. For that reason there is no "Do Not Sell or Share My Personal Information" link: there is nothing to opt out of.
- Sensitive personal information. We do not collect it and do not use any personal information to infer characteristics about you.
- Your rights to know, access, correct, delete, obtain a portable copy, and to appeal a denied request are described in section 9. We honour Global Privacy Control signals by design, since we never sell or share data.
- If you are dissatisfied with how we handled an appeal, you may contact your State Attorney General.
13. Canada
For visitors in Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, including Quebec's Act respecting the protection of personal information in the private sector (Law 25). Our privacy contact named in section 1 is the person in charge of the protection of personal information. Your data may be stored and processed outside Canada and Quebec (see section 5) and may be subject to the laws of those jurisdictions; we rely on the contractual safeguards described in section 5. We do not use technology that identifies, locates or profiles you, so there are no such functions to switch off. Any commercial electronic message we send complies with Canada's Anti-Spam Legislation: it identifies us and lets you unsubscribe, and we act on unsubscribe requests within 10 business days. You may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information.
14. Children
This website and our services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.
15. Social media and third-party sites
We have profiles on X, LinkedIn and GitHub. When you interact with us there, the platform processes your data under its own privacy policy, and we see what the platform shows us (public profile, messages you send us, and aggregated page statistics). For the statistics LinkedIn provides about our company page ("Page Insights"), LinkedIn and CrossTech are joint controllers under LinkedIn's Page Insights Joint Controller Addendum; LinkedIn is responsible for handling your rights in relation to that data. Links from our site to other websites are provided for convenience; we are not responsible for their privacy practices. Our GitHub repositories, including the open-source Swing MCP project, are hosted by GitHub, Inc. under its terms.
16. Our mobile applications
Where a mobile application published by CrossTech is still available in an app store, this policy applies to it as well. Those applications collect no personal data other than crash reports when the app crashes (device model, operating-system version, app version and time of the crash), delivered to us through the app platform's crash-reporting facility, used solely to diagnose and fix the problem, and not linked to your identity.
17. Changes to this policy
We will update this policy whenever our practices change, and always before we start any new processing that is not covered here. The version number and effective date at the top tell you when it last changed, and the version history at the bottom of this page summarises what changed. Earlier versions are available on request.
18. Contact
Questions, requests or complaints about privacy: info@crosstech.solutions. We would rather hear from you first, but you can always go directly to the supervisory authority for your region listed above.
Version history: v2.0 (1 September 2026) — complete rewrite covering the website, GDPR/UAVG, POPIA, US state laws and Canadian law; no-cookie statement; AI statement; self-hosted fonts. v1.0 (1 January 2023) — mobile-app crash-report policy, now section 16.