CRIS INDUSTRIES

CRIS FRONTDESK PILOT · TEST

Privacy Policy

Data practices for the restricted CRIS FrontDesk Pilot.

1. Contact and legal status

For questions, access or deletion requests, contact industriescris@gmail.com. The dedicated account is owner-controlled. The operator and controller of this informational website and the owner test is Cristofer Garcia Almoril, operating under CRIS Industries, a venture in development. The service address is provided only in the Impressum. A separate controller/processor arrangement is required before onboarding any real customer business.

2. Information pages and application are separate

These static information pages use locally bundled images, styles and scripts. They include no analytics, advertising, tracking pixels, customer forms or payment processing, and set no application session cookie. The prepared public website uses Cloudflare Pages for delivery. When the site is publicly deployed, Cloudflare receives IP addresses, request time, requested URLs, browser/connection details and related security data needed to deliver and protect the site. The release remains pending owner approval at the time of preparation. No FrontDesk database or OAuth credential is included in this static package.

Legal grounds, hosting and contact

For website delivery and proportionate security, the legal basis is Article 6(1)(f) GDPR: the legitimate interest in providing a functional, secure informational website. Enquiries sent voluntarily by email are processed to answer them under Article 6(1)(b) GDPR when related to requested pre-contractual steps, or Article 6(1)(f) for other correspondence. This website has no contact form. Sending an email is your choice and uses your email provider and the dedicated Gmail service.

Cloudflare, Inc. supplies the hosting infrastructure. Its international processing is described in its Privacy Policy and Data Processing Addendum, including applicable transfer safeguards. No exclusive processing in Germany or the EU is promised. This package does not enable analytics or retain a separate application log of website visitors. Provider security records follow the provider's applicable retention rules; a zero-retention claim is not made. Email correspondence is retained for the enquiry and any applicable legal retention obligations, then deleted; no marketing list is created.

For this operator you can raise privacy concerns with the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI), or another competent supervisory authority. You may contact the controller using the email above. The owner-only application test is separate from the public informational site; no visitor records are sent into that local test.

3. Application data and purposes

The local application stores account and session records, business profiles, approved FAQs, service schedules, enquiries, contact methods, case status, appointment proposals, provider event references and operational audit records. Their purpose is authentication, answering approved questions, managing requests, resolving problems and preventing abuse. Current testing uses synthetic enquiry data; real customer use is not activated.

Google sign-in requests openid, email and profile. The authentication library may receive and store your name, email address, profile image URL and provider account/token information to establish and maintain the session. Session cookies are HttpOnly and SameSite. OAuth identity data is not commercial-demand evidence.

4. Dedicated Google Calendar

Separate authorization requests openid, email and https://www.googleapis.com/auth/calendar.app.created. Identity is checked against the dedicated CRIS account before calendar creation. This permits secondary calendars created by the application, not general access to personal calendars. The adapter checks time-slot availability and writes a generic event summary, start/end time, timezone and generated event ID to the dedicated calendar. It does not add attendees, customer names or contact details to events and uses sendUpdates=none. A successful authorization alone does not prove that a calendar or event was created.

5. Optional Gmail — disconnected

The implemented adapter requests identity plus gmail.readonly and gmail.send only with separate consent for the dedicated mailbox. These are mailbox-wide scopes, not per-message permissions. When enabled, a manual inbox check can retrieve up to ten unread inbox messages as full message payloads. The current case parser stores sender, subject, message/thread identifiers and loop-suppression status rather than message bodies or attachments. Message content may therefore be received transiently by the server. Outgoing handoff notices contain a case identifier, not customer details, and require an expressly approved recipient. No unsolicited outreach or marketing is authorized.

6. Use, sharing and Google data restrictions

Google data is used only to provide the disclosed sign-in, dedicated-calendar and optional mailbox functions. It is not sold, used for advertising, transferred to data brokers or used to train generalized AI models. No Google or real-customer personal data is sent to external AI. Any Google-data transfer or human access must follow the Google API Services User Data Policy, including its Limited Use requirements, and be limited to permitted service, security, legal or specifically authorized support purposes.

Authorized operators may review relevant cases to provide support. Google processes the account authorization and enabled API requests. Cloudflare Workers/D1/Turnstile and Workers AI are planned adapters, not active processors of real-customer records in this pilot. Any activation requires an updated notice covering the actual recipients, processing locations and applicable international-transfer safeguards. No EU-only hosting or zero provider retention is claimed.

7. Storage, retention and deletion

Application records currently reside in local SQLite storage. Dedicated Calendar/Gmail connection tokens are encrypted at rest using the server session secret; the existing authentication library stores its own account/token records in the protected local database. Local OAuth client configuration is private and excluded from deployment artifacts. These controls do not claim encryption of the entire database.

Case retention is configurable from 1 to 90 days, with cleanup while the local service runs. Account, profile and connection records remain until administrative removal or reconnection. Rate-limit counters and operational records support abuse prevention and diagnosis; there is not yet a verified universal automatic deletion period for every non-case record. Local database backups and downloaded exports are separate copies and may outlive case deletion; they require separate controlled removal. These retention gaps must be resolved for real-customer operation.

The workspace can export cases, preview a validated restoration and delete case records. This does not delete Google events, account/profile records or downloaded backups. Request those additional removals through the dedicated contact. Revoke Google access in Google Account connections; revocation does not itself erase previously stored records or calendar events.

8. Your choices and rights

Google permissions are optional; disconnected Calendar leaves appointment requests for manual review. Do not submit sensitive information or real customer data during synthetic testing. Where applicable, you may request access, correction, erasure, restriction or portability, object to processing, withdraw consent and complain to a competent supervisory authority. A business-specific legal basis and data processing arrangement must be established before activating real-customer processing; OAuth permission is not a substitute for a GDPR legal basis. No legally significant decision is made solely by this prototype.