A note on why we built Cruma
Legal

Data Processing Addendum

The data processing terms for business customers.

Last updated: 2026-07-02 · Version: draft-1

Variables

  • Roles: customer is controller; Cruma is processor for workspace content.
  • Subprocessors: docs/legal/subprocessors.md, updated before any new subprocessor touches customer data.
  • Security measures: tenant isolation with fail-closed policy checks, credential-free model context, append-only audit ledgers, approval-gated consequential actions, RLS at the database boundary.
  • Retention: run-record bodies inline 30 days then archived; deletion on verified request; cancellation does not auto-delete.
  • Training: no customer content used for model training absent explicit opt-in (Privacy Policy); enforcement is technical (fail-closed export gate), not procedural.

The work moves
while you sleep.

Point Cruma at the business. It works across the tools you already use and speaks up before you ask. Your mornings can start somewhere else.

  • Works across the tools you already use
  • Advises, unasked, with its sources
  • Nothing consequential without you
Request your invite

Two fields. You'll hear from a real person within two days.

We onboard in small waves, with real help getting set up. Read why we built this.

Already have an invite? Open Cruma