Version 9 October 2026
Privacy notice
How Crashform handles information, access, availability and your privacy rights.
1. Who handles your information?
Crashform is provided by [JURIDISCHE NAAM], [REGISTERED ADDRESS]. Contact [CONTACTMAIL] for privacy questions and access or deletion requests. The legal name, address, contact email and registration number still need to be supplied.
For direct use of Crashform, [JURIDISCHE NAAM] is the controller. For an organisation’s report, your employer, fleet operator or rental company may control the report and its use. Crashform then processes it on that organisation’s instructions where that role and the required processing terms have been established. [JURIDISCHE NAAM] has its own responsibility for security, billing and enquiries.
2. Information we process
A report can include vehicle and insurance details, registration plates, names, addresses, contact and driving-licence details, accident place and time, circumstances, notes, sketches, photographs and a drawn signature. We also keep review comments, timestamps, report codes and integrity hashes. Information may come from the other party or an organisation.
Business accounts also include an email address, organisation details, settings, and vehicle or driver profiles. A business enquiry contains company, name, email, sector, countries, volume and message. Stripe handles payment details; we receive status, amount, currency and payment or subscription references, not a full card number.
Hosting and security providers process technical information such as IP addresses, browser information and request logs. We use the IP country to show regional pricing and currency, rather than a personal profile. Rate limiting stores a signed, pseudonymised IP identity.
3. Purposes and legal bases
We use information to prepare the requested report, enable review and signatures, generate a PDF, handle payments, authenticate users and send relevant emails. For users requesting the service, the basis is performance of a contract or requested pre-contract steps under GDPR Article 6(1)(b).
Where appropriate, necessary information about other people, security, abuse prevention and handling legal claims relies on legitimate interests under Article 6(1)(f). These interests are a reliable accident record and a safe service, balanced against the rights and interests of those concerned. Required financial records rely on legal obligations under Article 6(1)(c).
Optional access to device location, photographs and other device features requires browser permission. A business enquiry is used to answer the request, not as general consent for newsletters.
4. Injury and sensitive information
An injury indication, free text or photograph may reveal health information. Include only what is necessary for the accident and a concrete legal claim. Do not upload medical records, diagnoses or unnecessary identity documents.
Where special-category information is strictly necessary to establish, exercise or defend legal claims, GDPR Article 9(2)(f) may apply. This is not general permission to collect health information. Without that necessity, such information must not be included for this purpose.
5. Access and disclosure
Submitted report information, or information completed on the other party’s behalf, is shared with that party for review and signing. The personal back page requires its own private link or authorised device access and is not shared through the joint report.
An authorised organisation administrator may inspect business reports, photographs and PDFs; configured recipients may receive notifications. Business enquiries are emailed to the internal contact address for handling.
Anyone with a report code can view certain verification details, including signers’ names, signature timestamps and the document hash. The verification page does not display the full report. Possession of an issued download link or personal link can provide access to the corresponding document. Share these only with authorised recipients.
Crashform does not automatically submit a claim to an insurer or the police. You or your organisation chooses where to send the PDF. Subsequent processing by an insurer or another recipient follows that recipient’s own privacy policy.
6. Providers and international processing
Convex supplies the database, files and backend in an EU region. Cloudflare handles website delivery, security and country detection; Resend handles email; Stripe handles payments and billing. Each processes information necessary for its task. Stripe may be an independent controller for certain payment and fraud functions.
An activated Dutch vehicle lookup sends the plate to the public RDW register. An activated reverse-location lookup sends necessary coordinates to BigDataCloud.
EU backend storage does not mean that all processing takes place exclusively in the EEA. Providers may process or support services elsewhere. Appropriate transfer safeguards are required, such as an applicable adequacy decision or standard contractual clauses. Contact us for information about applicable arrangements and safeguards.
7. Availability and retention
A report and its personal back pages are available until seven days after the report is created. An automated cleanup job then deletes the report, photos, PDFs, personal back pages and linked report records. It runs every fifteen minutes and processes large volumes in batches. Download your PDF before the deadline.
Automatic deletion covers the report and its linked payment status in Crashform. Financial records and information a payment provider must legally retain follow applicable retention requirements. Business enquiries are retained as needed to handle the request and a demonstrably necessary follow-up. The final retention schedule for business enquiries still needs to be established.
Temporary rate-limit counters expire with their windows and are cleaned hourly. Keep your own downloaded PDF. Request deletion at [CONTACTMAIL]; we assess each request, including whether another party’s information is involved.
8. Cookies, browser storage and email
A functional cookie remembers your country/language page for up to one year. Browser storage keeps language, form progress and report device keys until you clear it. Business login data and sessions protect portal access. Clearing browser storage may remove your access from that device.
The current website does not include an advertising or external analytics service. Hosting and security logs remain. Emails may load brand images and Google Fonts when your email application permits them; these requests can disclose technical information to the relevant provider.
9. Security
We use encrypted connections, server-side access checks, hashed device secrets, temporary verification codes and rate limits. Hashes help detect changes to sealed documents; they do not themselves verify a person’s identity. Storage is not designed as end-to-end encrypted: authorised systems process report content to provide the service and produce PDFs.
10. Your rights and complaints
Where applicable you may request access, correction, erasure, restriction, portability or object to processing. You can withdraw consent without affecting earlier lawful processing. Not every right applies in every situation.
Email [CONTACTMAIL] with your request and report code if available. Do not immediately send an identity-document copy. We may request limited additional information to check identity and authority. We normally respond within one month, explaining any legally permitted extension.
You may complain to the Dutch Autoriteit Persoonsgegevens or the competent authority where you live or work. If an organisation controls your report, you may also contact that organisation.
11. Choices and changes
Some functions require essential information. Optional photos, device location and the paid personal back page can be omitted. We do not use the report to make automated decisions about liability, insurance or compensation.
Changes are published with a new version date. Where necessary, material changes affecting existing use will be communicated through an appropriate channel.
Sources and provider policies
Contact details still need to be supplied.