Privacy Policy

Last updated: 5 July 2026

CREO Systems ("CREO", "we", "us", "our") operates CREO Access, a subscription platform for recruitment professionals, accessible at access.creosystems.io. This policy explains what information we collect, how we use it, and the choices you have.

1. Information we collect

Account information. When you sign up, we collect your name, email address, and, if you sign in with Google, the basic profile information Google shares with us (name, email, profile picture).

Payment information. When you subscribe, payment is processed by Stripe. We do not store your card details ourselves; Stripe handles this in line with its own security standards. We retain a record of your subscription status, billing history, and transaction dates.

Usage information. We collect information about how you use CREO Access: which prompts, skills, workflows, and tutorials you view or save, and general activity such as login times. This helps us understand what's useful and improve the platform.

Content you submit. If you use the Prompt Generator or submit a content suggestion, we store what you enter so we can provide the feature and review suggestions.

Technical information. Standard technical data such as IP address, browser type, and device information, collected automatically for security and to keep the service running properly.

2. How we use your information

We use your information to:

  • Provide and maintain your account and subscription
  • Process payments and send billing communications
  • Improve CREO Access based on how it's actually used
  • Respond to support requests and content suggestions
  • Send you product updates and the Weekly AI Brief, if you have not opted out
  • Meet our legal and accounting obligations

We do not sell your personal information to third parties.

3. Who we share information with

We share information only where necessary to run the service:

  • Stripe, to process payments
  • Supabase, our database and authentication provider, which stores your account and usage data
  • Google, if you choose to sign in with Google
  • Any service provider bound by confidentiality obligations who helps us operate CREO Access

We do not share your personal data with third parties for their own marketing purposes.

4. Where your data is stored

Your data is stored using our infrastructure providers (including Supabase and associated cloud hosting), which may process data in regions outside your own country. Where this involves transferring data outside the UK or European Economic Area, we take reasonable steps to ensure an adequate level of protection is in place, in line with applicable data protection law.

5. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Request a copy of your data in a portable format
  • Withdraw consent where processing is based on consent
  • Complain to your local data protection authority

To exercise any of these rights, contact us at the email below. We will respond within the timeframe required by applicable law (for example, one month under UK/EU GDPR).

If you are in the UK or EEA, we process your data on the basis of contract necessity (to provide the service you've subscribed to), legitimate interests (to improve and secure the platform), and consent (for optional communications like the Weekly AI Brief).

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.

6. Data retention

We keep your account information for as long as your account is active. If you cancel your subscription, we retain basic account and billing records for as long as required for accounting and legal purposes, then delete or anonymise the rest. You can request earlier deletion by contacting us, subject to any legal retention requirements.

7. Security

We take reasonable technical and organisational measures to protect your information, including access controls and encrypted data transmission. No system is completely secure, and we cannot guarantee absolute security, but we work to protect your data appropriately for the sensitivity of what we hold.

8. Cookies

CREO Access uses essential cookies required for login and core functionality. We do not currently use third-party advertising or tracking cookies.

9. Children's privacy

CREO Access is a business tool intended for recruitment professionals and is not directed at children. We do not knowingly collect information from anyone under 16.

10. Changes to this policy

We may update this policy as the platform evolves. If we make material changes, we will notify subscribers by email or via a notice on the platform. The "last updated" date at the top reflects the most recent revision.

11. Contact us

If you have questions about this policy or want to exercise your data rights, contact us at:

hello@creosystems.io

CREO Systems
creosystems.io