GDPR & Data Privacy in CRED
Last updated: August 15, 2025
CRED Data Privacy FAQs
CRED values your right to privacy and endeavors to provide complete transparency as it relates to how we collect and process information as part of our service offering. With this in mind we have compiled a list of frequently asked questions about personal data, your rights relating to your data, and our obligations. More information can also be found in our Privacy Policy.
What type of personal data does CRED process?
Professional profiles in CRED’s database contain some or all of the following categories of personal data:
Full name
Email addresses
City location
Job title and department
Company/employer name and address
Employment history
Educational background
Social media profiles related to work
We only process contact information that would typically be found on a business card.
Does CRED process any sensitive personal data?
CRED does not process any sensitive personal data (including but not limited to private financial data, internet browsing history, racial or ethnic origin, political opinions, religious beliefs, health or medical records), nor do we process any information concerning minors.
How is your data obtained?
The information contained in our database originates from various sources, including publicly available information, licensed data from other companies, market research, and data shared by our users and customers in accordance with our policies. CRED provides a majority of data as modeled outputs using artificial intelligence and proprietary modeling.
How often does CRED update its data?
Our data is updated continuously. The frequency depends on the type of data and what is required to maintain up to date information for our users and their needs ranging from hourly to weekly.
Who does CRED share the personal data with?
Personal data is included in company profiles and professional profiles which are accessible to customers who use our Services. CRED adheres to strict privacy regulations and further requires all its customers to sign legal agreements mandating their observance to applicable privacy laws to ensure that any and all personal data is protected at all times. We further encourage and expect our customers to follow all applicable consent requirements applicable to them in their use of personal data.
What is the legal basis of CRED’s processing data?
We collect and process data under the lawful basis of legitimate interest, as allowed under Article 6(1)(f) of GDPR. Legitimate Interest allows CRED to gather and handle professional contact information which is essential to its service offering. In exercising its right to legitimate interest, CRED takes strict measures to minimally affect an individual's private life, their personal interests, rights, and freedoms. See further details in our Privacy Policy regarding how legitimate interest applies as it relates to personal data.
How do I exercise my privacy rights if you have my contact data?
To access your personal data or exercise any other privacy right, please contact CRED
on privacy@credinvestments.com, using the subject line “PRIVACY” in your email.
How do I opt-out of sharing my personal data?
If you no longer wish for your personal data to be included in our database, please contact CRED on privacy@credinvestments.com, using the subject line “PRIVACY” in your email.
Is CRED the Processor or the Controller of personal data according to GDPR?
For the purposes of classifications under the EU General Data Protection Regulation 2016/679 (GDPR) and the UK GDPR, CRED is the processor of personal information and its customers are classified as the controller. As such, CRED and its customers are individually responsible for complying with all requirements that apply to its own and independent purposes under applicable Data Protection Laws, where CRED processes personal data to provide its services, while customers may use the data for its own purposes, including sales and marketing outside of CRED’s control and visibility.
What privacy policies does CRED adhere to in its processing practices?
CRED is registered with the Information Commissioner's Office (ICO) and adheres to the Privacy and Electronic Communications Directive 2002/58/EC, the General Data Protection Regulation 2026/679, the UK General Data Protection Regulation, the Data Protection Act 2018, and is certified in accordance with Service Organization Control Type 2 (SOC2) as set out by the American Institute of Certified Public Accountants
(AICPA).
What are CRED’s customers’ privacy obligations?
CRED’s customers are subject to General Data Protection Regulation 2026/679 (GDPR) obligations as controllers when using data processed by CRED for the independent business purposes, as well as any other applicable obligations that apply to their use of data, including but not limited to those found under the ePrivacy Directive when utilizing contact data for sales and marketing purposes.
How does CRED track and manage any occurrences of data breaches?
CRED actively maintains various security protocols to ensure that data security is maintained promptly in instances of a breach, including but not limited to business continuity, disaster recovery, vendor security, and recurring training for staff and employees. In case of a security breach or incident, clients are notified immediately, and in no event later than 72 hours as from the time of the breach or incident.