1. Who we are
CRUNCH, a service of CIDAH (cidah.ai), operates the client portal at crunchdd.com/portal ("Portal"). For the personal data described below we act as controller for account and security data, and as processor on behalf of the client organisation for the content of uploaded documents.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | work email address, organisation, role in the Portal (client / operator / reviewer) | invitation by your organisation; you |
| Authentication data | one-time sign-in codes (transient), authenticator (TOTP) enrolment for staff, session tokens | you; our authentication provider |
| Activity data | request created / submitted, file uploaded, message posted, deliverable released, download issued; timestamps; user id | generated by the Portal |
| Technical data | IP address, browser type, request logs (short-lived) | your device; hosting provider logs |
| Content data | documents and messages you upload for a matter, which may contain personal data of third parties | you, on behalf of your organisation |
We do not use tracking cookies or advertising analytics anywhere on crunchdd.com or in the Portal. Cookies and local storage are limited to what the service needs to function:
| Name | Purpose | Type | Lifetime |
|---|---|---|---|
| Authentication cookies (Portal) | keep you signed in and protect your session | strictly necessary | session / until sign-out |
NEXT_LOCALE | remember your interface language (Hebrew / English) | functional preference, set only when you choose a language | 1 year |
theme (local storage) | remember your light / dark mode choice | functional preference, set only when you use the toggle | until cleared |
Because no cookie is used for tracking, profiling or advertising, and preference cookies are set only on your explicit action, no consent banner is shown. You can clear these at any time through your browser settings.
3. Why we process it and on what basis
| Purpose | Legal basis (GDPR, where applicable) |
|---|---|
| Providing the Portal and delivering the engaged work | performance of a contract (Art. 6(1)(b)) |
| Account security, malware scanning, audit trail | legitimate interests (Art. 6(1)(f)) — security and integrity |
| Professional-conduct and record-keeping duties | legal obligation (Art. 6(1)(c)) |
| Processing document content for the client organisation | on the organisation's documented instructions (Art. 28) |
4. Who receives it (sub-processors)
| Provider | Role | Location |
|---|---|---|
| Supabase | database, authentication, private file storage | EU (Frankfurt, eu-central-1) |
| Vercel | application hosting | global edge network; server functions in the EU (Frankfurt, fra1) |
| Resend | transactional email (sign-in codes only) | EU (Ireland, eu-west-1) |
| Cloudmersive | malware scanning of uploaded files (file content transmitted for scanning; not retained by the provider per its terms) | US (provider default API region) |
No personal data is sold. We disclose data to authorities only where legally required.
5. International transfers
Primary storage is in the EU. Where a sub-processor processes data outside the EU/Israel, transfers rely on the provider's standard contractual clauses / adequacy (Israel holds an EU adequacy decision).
6. How long we keep it
See the Retention Policy. Summary: matter content and released deliverables — 7 years from matter close (GN decision 11/09/2026); quarantined files — deleted within 30 days; sign-in codes — 10 minutes; request/session logs — 30 days; account data — for the life of the engagement plus the retention period.
7. Security
Invite-only access; one-time email codes; mandatory authenticator (TOTP) for CRUNCH staff; row-level access controls per organisation; private storage with short-lived signed links; malware scanning of every upload before any staff access; full activity audit trail.
8. Your rights
Depending on applicable law you may request access, rectification, erasure, restriction, portability or object to processing, and complain to a supervisory authority (Israel: Privacy Protection Authority; EU: your local authority). Where we process document content as a processor, please address requests to your organisation; we will assist it.
9. Contact
Privacy requests and general questions: info@crunchdd.com (subject line "Privacy").
Responsible officer: Guy Ne'eman, Adv. (guyn@cidah.ai). No statutory DPO appointment is required at the current scale of processing; this is reviewed annually.
10. Changes
We will post the updated notice in the Portal and, for material changes, notify the organisation's administrator by email.
This document combines the firm's advanced AI system with experienced legal expertise, under the close supervision and approval of a senior attorney.