Privacy Policy

Your privacy matters to us. Here's how we handle your data.

Last updated: April 29, 2026

Quick Summary

Data Stays Local

Your assessment data is stored in your browser. We don't have access to it.

Anonymous Analytics

We use analytics to improve the site. Data is anonymized and you can opt out.

Optional Email

We only collect your email if you choose to provide it. Never sold.

No Data Selling

We will never sell your personal data to third parties. Ever.

1. Who We Are

CRA Toolkit (cra-toolkit.com) is a free tool designed to help organizations understand and prepare for the EU Cyber Resilience Act (Regulation 2024/2847). We are committed to protecting your privacy and being transparent about our data practices.

Controller: Vritah Technologies LLP, 1196 Heera Garden, Pirangut, Mulshi, Pune, Maharashtra 412115, India. Contact: support@cra-toolkit.com. Full registration details are published in the Imprint.

EU Representative (Article 27 GDPR): Vritah Technologies is in the process of appointing an EU Representative as required by GDPR Article 27; full name and EU address will be published in the Imprint once the appointment is finalised. Until then, EU residents and supervisory authorities may contact us directly at support@cra-toolkit.com.

2. What Data We Collect

Data Stored in Your Browser (localStorage)

The following data is stored locally in your browser and never transmitted to our servers:

  • Assessment answers - Your responses to the CRA readiness assessment
  • Compliance tracking - Which requirements you've marked as complete
  • Preferences - Language, theme, and cookie consent choices

Optionally Provided Data

If you choose to provide it:

  • Email address - For accessing gated content or receiving updates. Stored securely in our database.
  • Feedback - When you submit feedback or report errors. May include optional email for follow-up.

Analytics Data

We use two analytics services to understand site usage:

  • Umami Analytics (consent-based) - Privacy-friendly analytics used only after you explicitly opt in to analytics cookies/settings.
  • Google Analytics (with consent) - If you accept analytics cookies, we additionally collect more detailed usage data via Google Analytics with IP anonymization enabled.

Analytics data is collected only if you consent via the cookie banner.

3. How We Use Your Data

  • Improve the toolkit - Analytics help us understand which features are useful and where users struggle
  • Send updates - If you provided your email, we may send CRA-related updates (you can unsubscribe anytime)
  • Respond to feedback - If you submitted feedback with an email, we may follow up

4. Cookies

We use the following types of cookies:

Type Purpose Consent Required
Essential Site functionality, language preference, consent choice No (strictly necessary)
Analytics (Google) Detailed site usage via Google Analytics Yes
Analytics (Umami) Privacy-friendly site analytics when analytics preference is enabled Yes

5. Third-Party Services

We use the following third-party services:

  • Umami Analytics - Analytics service loaded only with analytics consent. See: Umami Privacy Policy
  • Google Analytics - Web analytics (with IP anonymization, consent-based). See: Google Privacy Policy
  • Vercel - Hosting and analytics. See: Vercel Privacy Policy
  • Supabase - Database for storing emails and feedback. See: Supabase Privacy Policy
  • Resend - Email delivery service for transactional/opted-in updates.
  • Paddle - Merchant of record and payment processor for subscriptions and invoicing.
  • OpenAI, L.L.C. (GPT-5 Mini API, via OpenRouter, Inc.) - Primary AI inference provider for chatbot responses (United States). Chatbot prompts contain only CRA compliance questions; we do not send your name, email address, or other identifying personal data as part of these prompts. This is a paid commercial API — under OpenAI's API terms, inputs and outputs are not used to train their models by default, and logs are retained for a limited period only. OpenRouter routes the request but does not use commercial-tier traffic for training either. Transfer mechanism: EU Standard Contractual Clauses (2021/914). See OpenAI Privacy Policy and OpenRouter Privacy Policy.
  • Google LLC (Gemini API — Google AI Studio free tier) - Fallback AI inference provider, used only if the primary GPT-5 Mini provider is unavailable (United States). Important: This fallback tier is the free Google AI Studio tier. Under Google's terms for this tier, prompt content may be reviewed by Google and used to improve their AI models. Transfer mechanism: EU Standard Contractual Clauses (2021/914). See Google Privacy Policy.
  • Groq, Inc. - Second fallback AI inference provider, free tier (United States). Same prompt-content policy as Google's free tier. Transfer mechanism: EU Standard Contractual Clauses (2021/914).
  • Mistral AI SAS - Third fallback AI inference provider, free tier (France, within the EEA). Same prompt-content policy as Google's free tier.
  • Upstash, Inc. - Rate-limiting and cache infrastructure (United States). Only hashed client identifiers are stored. Transfer mechanism: EU Standard Contractual Clauses.

Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and apply supplementary measures including encryption in transit and at rest, in line with the EDPB recommendations following Schrems II. A full list of sub-processors and their transfer mechanisms is available on our Sub-processors page.

6. Lawful Basis for Processing

  • Consent (Art. 6(1)(a)): analytics, optional product updates, and non-essential tracking.
  • Contract (Art. 6(1)(b)): account creation, workspace access, and service delivery.
  • Legitimate interests (Art. 6(1)(f)): service security, abuse prevention, and reliability operations.

7. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right to access - Request a copy of data we hold about you
  • Right to rectification - Ask us to correct inaccurate data
  • Right to erasure - Request deletion of your data
  • Right to data portability - Receive your data in a portable format
  • Right to object - Object to processing of your data
  • Right to withdraw consent - Withdraw consent at any time (e.g., via cookie settings)

To exercise any of these rights, please contact us.

You also have the right to lodge a complaint with your local EU/EEA data protection authority.

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • HTTPS encryption for all data in transit
  • Secured database access with encrypted credentials
  • Sensitive data (assessments) stored locally in your browser, not on our servers
  • Data minimization - we only collect what we need

9. Data Retention

  • Browser data - Stored until you clear your browser data
  • Email addresses - Retained until you request deletion
  • Analytics data - Retained for 14 months (Google Analytics default)
  • Feedback - Retained for 2 years for product improvement
  • Account profile data - retained while your account remains active, then deleted or anonymized within a reasonable period.
  • Chat usage metadata - retained for quota, abuse prevention, and security operations for a limited period.

10. Children's Privacy

This website is not intended for children under 16. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via a notice on our website. The "Last updated" date at the top indicates when the policy was last revised.

12. Contact Us

If you have questions about this privacy policy or your data, please contact us:

← Back to Home