Crakd.ai
  • Home
  • Opera AI
    Automation Apps Dashboards Bank Reconciliation GoCardless Procurement
  • Sentinel
  • How it Works
  • Pricing
See it in Action Book a Demo
Legal

Privacy Policy

Crakd Limited — crakd.ai
Effective date: 22 April 2026 · Last updated: 22 April 2026

1. Who We Are

Crakd Limited ("Crakd", "we", "us", "our") is a company registered in England and Wales under company number 16339368, with its registered office at 70 Home Park Road, London, England, SW19 7HN.

We provide workflow automation applications for businesses using Pegasus Opera accounting software. This Privacy Policy explains how we collect, use, store, and protect personal data when you:

  • visit our website at crakd.ai;
  • use our applications and cloud platform ("Service"); or
  • contact us for sales, support, or general enquiries.

For questions about this policy, contact us at support@crakd.ai.

2. What Data We Collect

2.1. Website Visitors

When you visit crakd.ai, we may collect:

  • Usage data — pages visited, time on site, referral source, browser type, device type, and IP address (collected via analytics tools)
  • Contact form data — name, email address, company name, phone number, and any message you submit
  • Cookie data — see our Cookie section (clause 8) for details

2.2. Prospective Customers

When you request a demo, download materials, or engage with our sales process, we collect:

  • Name, job title, email address, phone number
  • Company name and size
  • Opera version and environment details (where relevant to scoping)

2.3. Subscribers and Users

When your organisation subscribes to the Service, we collect and process:

  • Account data — name, email address, job title, company name, and login credentials for each User
  • Billing data — company name, billing address, VAT number (where applicable). Payment details (bank account/sort code) are collected and held by GoCardless, not by Crakd.
  • Operational data — data transmitted through the Crakd Gateway from your Opera database for the purpose of providing the Service. This may include supplier names, customer names, contact email addresses, invoice references, and transaction data.
  • Support data — correspondence, support tickets, and related information submitted to support@crakd.ai
  • Usage data — how Users interact with the Apps (feature usage, session data, error logs)

2.4. Supplier and Customer Contacts

Where the Service processes data from your Opera system, it may handle personal data of your suppliers' and customers' contact persons (names, email addresses, business phone numbers). This data is processed on your behalf — see clause 5.

3. How We Use Your Data

We use personal data for the following purposes:

PurposeLawful Basis (UK GDPR)
Providing and operating the ServicePerformance of a contract (Art. 6(1)(b))
Creating and managing User accountsPerformance of a contract
Processing payments and invoicingPerformance of a contract
Sending service-related communications (onboarding, updates, downtime notices)Performance of a contract
Providing application supportPerformance of a contract
Responding to enquiries and demo requestsLegitimate interests (Art. 6(1)(f)) — responding to your request
Improving the Service (analytics, bug fixes, performance)Legitimate interests — product improvement
Sending marketing communications (only with consent)Consent (Art. 6(1)(a))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))
Protecting against fraud, misuse, and security threatsLegitimate interests — security

4. Marketing Communications

4.1. We will only send you marketing emails if you have given your explicit consent or if you are an existing customer and the communications relate to similar products and services (in accordance with the Privacy and Electronic Communications Regulations 2003).

4.2. Every marketing email includes an unsubscribe link. You can opt out at any time by clicking the link or emailing support@crakd.ai.

4.3. We do not sell, rent, or share your personal data with third parties for their marketing purposes.

5. When We Process Data on Your Behalf

5.1. Where your organisation subscribes to the Service, Crakd acts as a data processor in respect of the operational data transmitted from your Opera database via the Crakd Gateway.

5.2. Your organisation is the data controller for this data. We process it solely on your instructions for the purpose of delivering the Service.

5.3. This processing is governed by our Data Processing Agreement, available on request from support@crakd.ai.

5.4. Crakd does not store your financial data beyond what is required for operational processing. Your financial data resides in your own Opera database and is accessed on demand via the Gateway.

6. Who We Share Data With

We may share personal data with:

  • GoCardless — to process Direct Debit payments. GoCardless acts as an independent controller for payment data. See their privacy policy at gocardless.com/legal/privacy.
  • Hosting and infrastructure providers — who host the Crakd cloud platform. These providers act as sub-processors under our DPA.
  • Authorised resellers and channel partners — only where your subscription was arranged through a partner, and only to the extent necessary to manage the relationship.
  • Professional advisers — legal, accounting, and insurance advisers, where necessary.
  • Law enforcement or regulators — where required by law, regulation, or court order.

We do not sell personal data. We do not share personal data for advertising purposes.

7. Data Retention

Data TypeRetention Period
Website analytics26 months
Contact form submissions24 months from last interaction, or until you ask us to delete
Prospective customer data24 months from last interaction
Subscriber account dataDuration of Subscription + 12 months
Billing records and invoices7 years (legal/accounting requirement)
Operational data (via Gateway)Not retained — accessed on demand from your Opera database
Support correspondenceDuration of Subscription + 12 months

After the applicable retention period, personal data is securely deleted or anonymised.

8. Cookies

8.1. Our website uses cookies to improve your experience and help us understand how the site is used.

Strictly Necessary Cookies — required for the website to function. Cannot be disabled.

Analytics Cookies — help us understand how visitors use the site (e.g., pages visited, time on site). We use these to improve our content and user experience.

Marketing Cookies — used to track the effectiveness of our marketing. Only set with your consent.

8.2. On your first visit, you will be presented with a cookie consent banner. You can manage your preferences at any time through the cookie settings on our website.

8.3. You can also control cookies through your browser settings. Disabling certain cookies may affect the functionality of the website.

9. Data Security

9.1. We take the security of your data seriously and implement appropriate technical and organisational measures, including:

  • Encryption of data in transit (TLS)
  • Access controls and role-based permissions
  • Regular security reviews and vulnerability assessments
  • Staff training on data protection and security
  • Incident response procedures

9.2. While we take all reasonable precautions, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

10. International Transfers

10.1. We primarily process and store personal data within the United Kingdom.

10.2. Where data is transferred outside the UK (for example, through infrastructure providers), we ensure appropriate safeguards are in place in accordance with UK GDPR, such as the UK International Data Transfer Agreement.

11. Your Rights

Under UK data protection law, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your data (subject to legal retention requirements)
  • Restriction — request that we limit how we use your data
  • Portability — request your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests or for marketing purposes
  • Withdraw consent — where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at support@crakd.ai. We will respond within one month.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

12. Children

Our Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or through a notice on our website.

The "Last updated" date at the top of this policy indicates when it was most recently revised.

14. Contact Us

If you have any questions about this Privacy Policy or how we handle your data:

Crakd Limited

70 Home Park Road, London, England, SW19 7HN

Email: support@crakd.ai

Company number: 16339368

Crakd.ai

Modern automation apps for Pegasus Opera. Built by the team behind Intsys UK, Cloudsis and SystemsCloud.

Platform

  • Apps
  • Dashboards
  • Bank Reconciliation
  • GoCardless
  • How it Works

Solutions

  • Opera AI
  • Sentinel
  • Halo ITSM

Contact

  • hello@crakd.ai
  • Pricing
  • LinkedIn

© 2026 Crakd.ai. All rights reserved. Privacy · Terms · DPA