1 · Introduction and Scope

This Privacy Policy explains how CRAVEWORKS LLC, a professional services company focused on computer integrated systems design and related services, handles personal information that it obtains through its public website at www.craworks.lat, through its project and support correspondence, and through the delivery of its services to studios, marketing teams and other business clients. The company name CRAVEWORKS LLC and the developer name CraveWorks are used in this document to describe the same United States company. We wrote this policy to be plain, honest and complete. We believe that good privacy practice is like good brickwork: laid one clear course at a time, with every joint accounted for and nothing hidden below the surface.

This policy covers information that can identify a person, either on its own or when combined with other details that we hold. If you contact us through the site, email us, call us, place an enquiry, apply to work with us, or become a business contact during a project, this policy tells you what we do with the details you provide. It also describes the choices you have and the rights you can exercise. Reading this policy before you share information is wise, because it describes the whole journey of your data from the moment it enters our office to the moment it is securely deleted.

2 · Who We Are

We are CRAVEWORKS LLC, a limited liability company registered in the United States. Our postal address is CRAVEWORKS LLC, 7488 N Adobe Ln, Tooele - 84074-8965, United States (US). The company builds content production systems, digital asset management, studio workflow platforms, campaign operations systems, brand governance and delivery automation for creative studios and marketing organizations. As the developer behind this service, CraveWorks operates the website and the underlying systems. When this policy says we, our or us, it means CRAVEWORKS LLC and its staff.

Because we serve professional and scientific clients, most information we touch belongs to businesses rather than individuals. Even so, a business record often contains a person name, a work email or a phone number, which makes the record personal data under many laws. We treat those records with the same care as personal data, because a professional contact is still a person with privacy protections.

3 · Information We Collect

The information we collect falls into a few clear groups. First, information you give us directly: your name, your email address, your message text when you write through the contact form, your phone number when you call, your position and company when you introduce yourself, and any project brief or document you choose to send us. Second, information we obtain during a working engagement: names of your team members, roles, content calendars, approval lists, asset libraries and the operational data that flows through the systems we build. Third, technical information collected automatically when you visit the site.

The automatic group includes your IP address, browser type, device type, the pages you view, the time you visit, the rough geographic region of your connection and the site that referred you. We keep this information brief and we do not use it to build a profile of you as an individual; we use it to keep the service reliable, to measure which pages are useful and to detect abuse. In every case we limit collection to what a reasonable person would expect, and we never go mining for more than the task needs.

4 · Privacy for Children

The services of CRAVEWORKS LLC are directed at professional and adult audiences. We do not knowingly collect information from children, and the website is not designed to attract anyone under the age of sixteen. If you believe that a child has sent us personal information without the consent of a parent or guardian, contact us at the address given in the final section and we will delete the record promptly if we can verify that it belongs to a child.

Under the laws of many regions, including the standard protections for children in the United States and Europe, content that is meant for children must carry extra safeguards and parental consent paths. Because none of our professional material is directed at minors, we rely on the simple rule that no child data should reach us in the first place. We review this position regularly and would never launch a service aimed at young audiences without first building a separate, stricter consent system.

5 · How We Use Information

We use personal information for the narrow, clear purposes you would expect from a professional services firm. We use your contact details to reply to your enquiry, to schedule and run a scoping call, to prepare a proposal, to agree a service agreement, and to keep you informed as your project moves through the cast, dry, load, fire and ship stages of our process. Within an active engagement, we use your team data to build the system you asked for, to migrate assets, to set approval paths and to provide support after launch.

We also use limited personal information to send you service notices, to maintain the security of our systems, to keep records that tax or other law requires, to defend or bring a legal claim, and to understand in broad terms how visitors use our site. We do not use your information for purposes that a reasonable person would not expect. If a new purpose arises later, we will describe it here and, where the law demands it, ask for fresh consent rather than quietly repurposing what you already shared.

6 · Lawful Bases for Processing

Where data protection law requires a stated legal basis, our bases are those of a normal professional services firm. When you ask us to quote for work or to deliver a service, we process the details needed to take steps at your request before entering, and then to perform, a contract with your organisation. When you browse the public site, we rely on legitimate interest in keeping the site working and safe, balanced carefully against your interests and rights, which we never allow to be outweighed lightly.

When you subscribe to our newsletter or where a particular course of processing rests on your consent, we rely on that consent and make it as easy to withdraw as to give. We also rely on legal obligation where we must keep records or respond to a lawful demand. Our policy is to name the basis at the time and to record it, so that no processing ever drifts into a grey zone where neither you nor we can say why it happens.

7 · Cookies and Tracking

Our website uses very few cookies. A small number of files may be stored on your device to keep the site working, to remember whether you opened the mobile menu, or to make the scroll and reveal behaviour smooth. These functional cookies do not track you across other websites. Where we measure traffic, we prefer techniques that avoid identifying you as a person and we keep any measurement window short.

We do not sell your browsing activity, and we do not join your website visits to a personal profile built from other sources. If we ever introduce a tool that sets advertising or cross-site cookies, we will update this section, name the partners, and offer you an obvious refusal path. Until then, the honest summary is simple: when you visit this site, we take the smallest useful technical measure, not the largest available.

8 · Information We Share

We share personal information in only a handful of circumstances, and we are deliberately slow to add more. We share with our own team members who need the record to do their job. We share with the limited service providers named in the next section who help us host the site, run the software and communicate with you. We share within a collaboration when a business client asks us to connect a partner, an agency or a contractor to the project, and only to the extent that join is genuinely needed.

We share where the law requires it, as described in the section on government demands. And we share in the event of a business sale, as described in the mergers section. We never sell your personal information to data brokers, we never trade contact lists, and we never publish a client record for marketing. When a colleague at a client organisation writes to us, we do not hand that colleague email to anyone outside the work you asked for.

9 · Our Service Providers

To run a modern service we rely on a small set of behind-the-scenes suppliers: a website host that stores the public files, a domain registrar for the craworks.lat address, an email provider that carries messages to and from the mailbox, and project software that holds the boards, approvals and calendars we configure for clients. Each of these providers processes data only on our instruction and only for the purpose of the service we buy.

We choose providers that have sound security and that respect data protection law. Where a provider sits outside the region of the data, we take one of the approved safeguards described in the international transfers section. We review the provider list whenever we renew a contract, and we keep this policy truthful: if the list changes in a way that affects you, we say so.

10 · Data Retention

We do not keep personal information longer than we need it. An enquiry with no contract behind it is kept only for the time needed to reply and, if you might come back, a short window to avoid asking twice for the same detail. Website logs are shortened and then deleted on a regular cycle. Contact details for an active account are kept for the life of the relationship and for a reasonable tail afterwards so that support and invoices can be completed honestly.

Records that must survive under tax, accounting or contract law are kept for the period those rules require, and not a day more. When a client project ends and no legal duty remains, we delete or return the operational data according to the written handover agreement. Our retention times are written into our internal schedule, reviewed each year, and applied by a named owner, so deletion does not depend on a tired memory of what used to be true.

11 · Security of Your Data

Protecting the data we handle is central to the work we sell, because much of that data belongs to your content operation itself. We protect it by restricting access to named staff, by using strong, unique credentials and two-factor checks on the systems we control, by encrypting data in transit and at rest across the channels we run, and by keeping the number of people who can reach a record as small as the task allows.

We keep software current, back up the systems we run, test our recovery, and train the team in the dull but vital habits that stop a breech before it starts: no shared passwords, no secrets pasted into public threads, no customer files left on a personal machine. No organisation can promise an absolute zero of risk, so we promise instead an honest standard: defence that is proportionate to the value of what we hold, reviewed and tested, and a fast, straight answer if something does slip. That record is kept in the breach section below.

12 · Data Breach Response

If we discover a security incident that risks your personal information, we will act quickly. We will contain the problem, remove the cause where we can, preserve evidence, and work out what was exposed and to whom it might matter. If the law requires notice, we will give it without the delay that lawyers enjoy and governments dislike: we will tell the affected regulator and the affected people in the time the rule sets out.

Where a breach touches a specific business client, we will tell that client directly and frankly, naming what happened, what we fixed and what they should watch for, rather than hiding behind a vague statement written to limit blame. We keep an incident log and we learn from each event by tightening the very measure that failed. A breach is a serious failure of the trust we earn, and our response aims to repair trust through honest, complete, timely communication.

13 · International Transfers

CRAVEWORKS LLC is a United States company, and the data you send normally stays within the United States. If a tool we use, or a client project, requires data to move across a border, we do it only where the destination offers an adequate level of protection under the law that governs your data, or where we have put a recognised safeguard such as a set of standard contractual clauses in place.

We never move data across a border merely to avoid a local law, and never to gain a commercial advantage over your privacy. When a transfer happens, the same promises in this policy follow the data. You can ask us how a particular transfer is safeguarded, and we will give you a plain answer pointing to the clause or adequacy decision rather than a paragraph of fine print.

14 · Your Privacy Rights

Depending on where you live, the law gives you some of the following rights over the personal data we hold about you. You may have a right to access the information we hold about you, to correct a mistake, to delete it, to limit or object to certain processing, to request a portable copy, and to withdraw a consent you gave earlier. You also have a right not to be treated worse for the exercise of these rights.

To make a request, write to us at the address in the final section and tell us clearly what you want. We will verify your identity with the care such a request deserves, and we will answer within the time your local law allows, normally thirty days. We will honour the request unless a separate law or a genuine need to defend a claim prevents it, and where we refuse we will say why in plain terms and tell you how to challenge the refusal.

15 · Choices and Opt-Outs

You can always refuse to give us personal information, and you can always withdraw it later. If you only want to browse the public site, you never have to share a name or an email. If you send a note and later change your mind about being contacted, write to us or use the unsubscribe link in any marketing mail and we will stop. Because our work is usually contractual, some data is needed to keep the service running, and there we will explain what happens if you ask us to pause it.

Opting out of marketing never removes the data we need to provide a service you bought or to meet the law. We separate the two firmly in our systems, so a person who says no to a newsletter does not suddenly lose access to the support they paid for, and a person who wants no further marketing is never re-added by a different campaign list. Your choices are respected across the whole office, not just in the corner that received the request.

16 · California Privacy Rights

If you live in California, the consumer privacy law there gives residents specific rights: to know what personal information a business holds, to see the categories and purposes involved, to ask for deletion, to opt out of any sale or sharing of personal information, and to correct inaccuracies. We do not sell personal information in the ordinary sense, and we do not share it for advertising targeting. If that ever changes, this section will name the categories involved and give you a clear way to say no.

Residents of California also have a right not to be discriminated against for exercising these rights. You can make a request through the contact details in the final section, and a designated member of our small team handles each request carefully and without penalty. Where a request needs extra verification because it touches sensitive data, we will ask only for what is needed to be sure that the request truly comes from you.

17 · Do Not Track

Some browsers send a signal called Do Not Track that tells a website not to follow the reader across the web. Because we already collect only the brief technical data described in the cookies section, and because we do not follow you across third-party sites, our service can offer you the same modest behaviour whether or not your browser raises that flag. We never change our treatment of your information in response to a Do Not Track signal, because there is nothing greater to turn off.

If we later add a feature that would make a Do Not Track signal meaningful, we will honour it and will say so here. Until that day, the truthful position stands: the invisibility you might seek from a tracking flag is already the default of this site, because we ask so little of your visit in the first place.

18 · Third-Party Links

The website may point to other sites, for example the platforms where our clients publish content or the pages of the tools we recommend. Once you leave craworks.lat, this policy stops, and the privacy rules of the destination apply instead. We do not control those sites, and we encourage you to read their own policies before you share anything with them. A link from us is a sign that we find the site useful, not a claim that we answer for its privacy behaviour.

Because some of our client work involves connecting content platforms, we sometimes need to share a technical key or a workspace address with a third party as part of the service you asked for. In those cases we limit what we share to the minimum needed, and the third party remains bound by its own terms and by our instruction. Any such connection is named in the proposal so that you never discover an outside party in your data by surprise.

19 · Client Work and Employer Assets

When we build a production system for a studio or marketing team, we act under a contract with that organisation. The names, calendars, approvals and assets we touch during the work belong to the client business, and we generally treat them as that business data rather than as the personal records of any single staff member. If one employee or contractor in the operation asks us for a right over that shared data, we will look first to the client who signed the agreement.

This is not a way to dodge a genuine personal right. Where information is truly about an individual, even inside a business system, we will help that individual make a request to the data controller, normally the client. And in every case we keep confidential the content of a client project: we never reuse your content plans, your asset library or your approval patterns for another customer, and we never cite your internal numbers in public marketing without clear written permission.

20 · Applicant and Staff Data

If you apply to work with CRAVEWORKS LLC, we need the information a fair hiring decision asks for: your name, contact details, work history, and the evidence of skill you choose to include. We use that information to assess your application, to arrange interviews and to comply with employment law. We keep candidate records only for the length of the hiring round and a short period afterwards, unless you ask us to hold them for a future opening.

Current staff and engaged contractors have a fuller set of records held for payroll, benefits and legal compliance. Those records are kept securely, seen only by the people who need them, and retained for the periods that law requires. This policy covers those records as well; a member of staff can always ask for the same access and deletion rights described earlier, subject to the legal duties that hang over an employment file.

21 · Marketing Communications

We would love to tell you when a new capability or a helpful guide is ready, but we will only do so if you have told us that you want the mail. Where we send marketing, you will find a clear way to stop it in every single message, and unsubscribing is fast and permanent until you choose to return. A business enquiry about a project is not automatic permission to send you a weekly blast; we treat sales and marketing as separate channels with separate consent.

The studio leads who book a production scoping call with us will receive the materials that call makes useful, and we will not then add them to a general list without an extra yes. We regard the marketing inbox as a place a person welcomes us, not a place we argue for room. If it ever feels crowded, the quietest one-word reply will clear it.

22 · Analytics and Usage Data

We use simple analytics to understand which pages help visitors and which leave them confused. The tool tells us page counts, rough regions, device types and how long a reader stays. It does not tell us who you are, and we have set it not to join your visit to your name or email. This keeps the measurement honest while still letting us improve the service.

The analytics insight we value most is simple: does the site explain our work well enough that a studio lead reaches the contact page? We improve against that question, not against a goal of collecting the most data. When we review analytics, we talk about the wall of our work and what you read next, never about any single person and the private details of that person or a particular browsing trail.

23 · No Data Products or Resale

Some companies quietly build a second income by selling the details their users hand them. CRAVEWORKS LLC does not and will not. We do not sell contact lists, we do not sell browsing behaviour, and we do not build products whose raw material is the personal information of our clients or visitors. Our only income is honest work for honest fees, and joining that work to a data trade would poison the trust every project depends on.

So the position above is not a boast but a written rule with real teeth. No part of this document authorises a sale, and no contract with us creates the right to build a separate merchandise from the details you share. If you ever see wording that suggests otherwise, tell us at once at the contact address below, and we will correct it without delay.

24 · Mergers and Transfers

CRAVEWORKS LLC is a small company, but small companies change hands too. If we are ever sold, merged or otherwise reorganised, the personal data we hold may move to the successor operation as part of the assets needed to keep the service alive. Should that happen, we will make sure the new owner is bound to this policy or to one that is at least as protective, and we will announce the change clearly on this page well before it takes effect.

A transfer of data in a sale is not permission to repurpose it. The buyer inherits the purposes described here, not a licence to invent new ones. If the buyer intends to change how your data is used, it must ask you again just as we would, and you keep the same rights to say no. The yard may change hands, but the bricks stay yours.

25 · Government and Legal Demands

We will not hand your personal information to a government simply because it asks. When an authority presents a demand, we will check that it is lawful, that it comes through a proper channel, and that it asks only for what it truly needs. Where we can, we will tell you that a request for your data has been made before we comply, so that you are not surprised by a silence around your own record.

We will resist over-broad demands and object to secrecy orders that have no lawful basis. When we do comply, we comply narrowly and we keep a record so that the whole exchange is open to later review by the right authority. Our aim is neither to be a heroic refuge for wrongdoers nor a compliant accomplice to over-reach, but a careful middle: we follow real law, and we make the government prove that it is real law.

26 · Changes to This Policy

We may revise this Privacy Policy as our service, the law or the tools we use change. When the revision is material, we will place a clear notice on the website and, if we hold your contact details for that purpose, we will mention the change in a note to you. The effective date at the top of this page will always tell you which version is in force, and we keep earlier versions on record so a request can be judged against the rules that were true at the time.

A change that weakens your protections will not be slipped in beneath a long list of new words. If we ever have to remove a safeguard, we will say what we are removing, why, and what we put in its place. Reading a revised policy is quick, because the parts that matter to you, the contact details and your rights, sit in the same familiar places at the end of the page.

27 · Complaints and Escalation

If you believe we have not handled your information fairly, we want to hear from you first. Our small team can often put a worry right faster than any regulator, and we would rather mend the joint than defend the crack. Write to the address below with the words Privacy Concern and we will reply without delay, telling you what we found and what we changed. We keep a log of every privacy complaint and we review it with the same care as a project defect.

If you are not satisfied with our answer, you are free to complain to the supervisory authority or regulator that has power over your region. In the United States that may include the relevant state authority or the federal trade contact, and in Europe the data protection authority of your own country. We will never punish you for complaining, and we will cooperate honestly with any authority that takes an interest. A genuine complaint is a gift of feedback, and we treat it as such.

28 · Contact Information

Questions, requests and concerns about this policy, or about your personal information in general, are welcome at any time. The named developer behind this service is CraveWorks, operating the site on behalf of the company set out below, and the details we would like you to use are plain and open.

When you write to us about privacy, please tell us how you prefer to be reached and grant us the detail we need to identify your record safely. We answer every genuine message and we never treat a person who asks questions about privacy as a nuisance. Thank you for reading, and for trusting CRAVEWORKS LLC with your attention and your data.