creno.
Draft pending legal review. This text is not final and should not be treated as binding.

Data Processing Addendum

For customers subject to a law requiring a data processing agreement with their vendors.

Last updated: July 29, 2026

1. Purpose and roles

This addendum applies when you (the "customer") use Créno to collect personal data from your own visitors (name, email, phone, booking notes). In that context, you're the party responsible for that data, and Solution Lancée acts as a processor on your behalf. This addendum supplements, rather than replaces, our Privacy Policy, which instead governs our direct relationship with you as a customer.

2. Description of processing

We process your visitors' personal data solely to provide the service: displaying your availability, creating bookings, and sending the associated confirmation or reminder emails. The nature of processing is shaped by your own configuration (calendars, service menus); we don't use it for any other purpose.

3. Customer instructions

We process this data only on your documented instructions, meaning those given through your use of the service, subject to applicable law. If an instruction appears to us to violate the law, we'll tell you before carrying it out.

4. Confidentiality

Personnel with access to this data are bound by confidentiality obligations and only access it to the extent necessary to provide or support the service.

5. Sub-processors

We use sub-processors to provide the service: Cloudflare (infrastructure, bot protection), Resend (transactional email delivery), Stripe (payment processing), and our cloud hosting provider. We'll notify you of any material change to this list. These providers only receive the data strictly necessary for their function.

6. Security measures

Data is encrypted in transit (TLS). Passwords are hashed, never stored in plaintext. Access to a customer's data is scoped by that customer's own API key. Administrative actions are logged. We apply least-privilege access internally.

7. Assistance with requests

If one of your visitors exercises an access, correction, or deletion right with you, we'll reasonably assist you in responding, including by giving you the means to correct or delete the relevant data within the service.

8. Breach notification

In the event of a security incident affecting personal data processed on your behalf, we'll notify you without undue delay, and no later than 72 hours after becoming aware of it, with whatever details are available at that time.

9. Deletion or return of data

On termination of your account, your visitors' personal data is deleted within a reasonable period, except where retention is legally required. You may request an export of your data before your account is closed.

10. International transfers

Some of our sub-processors (Section 5) process data outside Canada. We ensure appropriate safeguards govern those transfers, consistent with applicable law.

11. Term

This addendum remains in effect for as long as you use the service, as governed by our Terms of Service.

12. Governing law

This addendum is governed by the laws of the Province of Québec and applicable federal laws of Canada.

13. Contact us

Questions about this addendum or how your data is processed? Write to us at contact@crenoapp.com.