Data processing addendum
1. Who is who
The customer (the hotel or business) decides what is watched, which zones are drawn, who receives alerts and what the results are used for: it is the controller. Cravero Robotics LLC processes that data only on the customer's instructions and to provide the service: it is the processor. This addendum is part of the Terms of service and prevails over them on anything concerning personal data.
2. What is processed, and for how long
Account and venue-team data (name, email, mobile, role, dated SMS consent); venue events and times with no identity of any person; the text a guest writes if they scan the QR, with their room if given; wait snapshots; and technical operation logs. Raw measurement detail is kept for about 45 days and snapshots for about 30; after that they delete automatically and a historical summary with no images remains. When the service ends, customer data is deleted within 30 days, except what the law requires us to keep.
3. Instructions and limits
We do not use customer data for advertising, do not sell it, do not rent it, and do not train our own or third-party models on it. We process it only to provide, support, bill and improve the service in aggregate form, identifying no business and no person. If an instruction from the customer appears unlawful to us, we say so before carrying it out.
4. Sub-processors
We use providers for cloud hosting, image analysis, SMS delivery, email delivery, payment processing and encrypted backup. Each receives the minimum necessary, is contractually bound to an equivalent level of protection, and may not use the data for anything else. The current list is provided on request; we give notice before adding a new sub-processor and the customer may object on reasonable grounds.
5. Security
Data travels encrypted; the server sits in a cloud with restricted, key-based access; backups are stored encrypted off the server and their restoration is tested periodically. Cravero staff access is the minimum necessary and is logged. Minimization applies throughout: what is not needed is not kept.
6. Breaches
If a security breach affects the customer's personal data, we notify the customer without undue delay and no later than 72 hours after we become aware of it, with what we know: what happened, who is affected, what we are doing and what we recommend. We assist the customer with any notifications the law requires of it.
7. Individual rights and audit
If a person exercises a right of access, correction or deletion with the customer, we help it respond within the legal deadlines, at no charge. Once a year the customer may request reasonable information evidencing compliance with this addendum; on-site audits are arranged in advance and may not compromise the security of other customers.
8. Where the data lives and what happens at the end
Data is processed and stored in the United States. When the service ends, the customer may request an exportable copy of its data within 30 days; after that it is deleted per section 2. This addendum remains in force for as long as we process customer data.
Terms of service · Privacy policy · SMS terms · Data addendum · 📄 PDF
Cravero Robotics LLC · Kenilworth, New Jersey · hello@craverorobotics.com