CRAYS Franchise / Privacy

Privacy

This pre-release notice maps the processing contexts expected around CRAYS.pro without presenting an unconfirmed controller, legal basis, retention period, recipient or transfer mechanism as final.

Controller confirmation outstanding

Controller identity, address, privacy contact and the production processing register require legal confirmation before release.

01

Controller and privacy contact

Confirmation required

TBD — LEGAL CONFIRMATION REQUIRED. The future CRAYS.pro controller, address, privacy contact and any representative or data-protection contact must be confirmed from the approved legal record. No Gym, venture or Association identity is substituted.

02

Public browsing and security

Scope boundary

A production public site may need to process request and security data required to deliver and protect the service, such as route, time, response and security-event information. Exact fields, legal basis, recipients and retention remain subject to the confirmed production architecture and legal review.

03

Contact preview

Scope boundary

The current CRAYS.pro Contact preview keeps a draft in the open page only for local review. It does not send or store the submitted content. A later sender, destination, retention rule and privacy notice require their own approval before transmission is enabled.

04

Account and authentication

Scope boundary

The target CRAYS.pro account journey may process the minimum identifiers, authentication state and security/session data needed for sign-in and account protection. Authentication does not grant a business relationship, role or record scope. Exact production purposes and provider disclosures remain later-gated.

05

Portal and relationship records

Scope boundary

Property, Candidate, Deal, Funding, Investor, Vendor and Team contexts remain separate relationship scopes. CRAYS authorises every private view separately for the approved relationship and scope. Public browsing, account creation or login alone does not expose private records, documents, notes or evidence.

06

Property and Deal evidence

Scope boundary

Public summaries and public-safe intake are distinct from private Property Opportunity, Deal Package and diligence evidence. Private material is released only to an authorised relationship and purpose. It is not made public, merged across relationships or reused automatically.

07

Venture processing stays separate

Scope boundary

Coffee, Retail, Gym and Clubs keep venture-specific customer journeys, purposes and applicable notices. A future shared application target or CRAYS.pro login does not silently combine customer histories, memberships, bookings, purchases, hospitality records or permissions across ventures.

08

Storage and optional technologies

Confirmation required

TBD — PRODUCTION INVENTORY REQUIRED. Necessary session, security or journey-state storage and any optional analytics or marketing technologies must be inventoried by purpose. Optional technology may not be represented as active or consented until the approved production inventory and consent path permit it.

09

Recipients and transfers

Confirmation required

TBD — PROCESSOR AND TRANSFER REVIEW REQUIRED. No speculative provider list is published here. Production recipients, processors, international-transfer locations and safeguards must match the verified deployment and approved contracts before release.

10

Retention and deletion

Confirmation required

TBD — PURPOSE-SPECIFIC SCHEDULE REQUIRED. Each processing context needs a verified retention trigger, period and deletion or anonymisation rule. Evidence that remains lawfully retained does not become current, complete, transferable or public.

11

Rights and complaints

Confirmation required

TBD — LEGAL REVIEW REQUIRED. Applicable data-subject rights, identity-verification safeguards, complaint authority and response channel will be stated for the confirmed controller and jurisdiction before release.

Public-safe next step

Raise a privacy or security concern

Use the dedicated public-safe Contact purpose and name the affected page or journey. Never include passwords, recovery codes, private keys, bank details, identity documents or private Property or Deal evidence.

Open privacy Contact