The short version
- We collect what we need to run Berel OS and our websites.
- Data in your workspace belongs to your company. We process it on its behalf.
- We do not sell personal data, and we do not use customer data to train general-purpose AI models.
- You can ask to access, correct or delete your data at legal@berelos.com.
This summary is for convenience. The full text below is what applies.
1.Who we are
Berel OS is operated by Cravto, LLC, registered in the Republic of Armenia at 64/5 Anastas Mikoyan, Yerevan 0054, Armenia (“Cravto”, “we”, “us”).
- For website visitors, prospects and account administration, Cravto is the controller of personal data.
- For personal data inside a customer’s workspace, the customer is the controller and Cravto is a processor acting on its instructions.
We handle personal data in line with the Law of the Republic of Armenia on Protection of Personal Data and, where they apply, the EU and UK General Data Protection Regulations and other applicable privacy laws.
2.Information we collect
Information you give us
- Account details: name, work email, company, role and login credentials.
- Demo and sales requests: name, work email, company, team size, freight modes and your message.
- Billing details: billing contact, address and tax ID. Card details are handled by our payment processor; we do not store full card numbers.
- Support requests and other messages you send us.
Information in your workspace
Emails from mailboxes you connect, shipment, rate, quote and booking records, documents such as bills of lading, invoices, packing lists and customs forms, and contact details of your customers and carriers. We process this only to provide the Services to your company.
Information collected automatically
Device and log data such as IP address, browser, pages viewed and timestamps, product usage events, and data from cookies as described in our Cookie policy.
Information from third parties
Data from integrations you connect, confirmations from our payment processor, and business contact details from public or partner sources for sales outreach.
3.How we use information
| Purpose | Legal basis |
|---|---|
| Provide, operate and maintain the Services | Contract |
| Run AI agents on workspace data at your instruction | Contract and customer instructions |
| Secure the Services and prevent fraud and abuse | Legitimate interests, legal obligation |
| Billing, invoicing and tax records | Contract, legal obligation |
| Support and service messages | Contract |
| Improve the product using aggregated usage data | Legitimate interests |
| Marketing emails to business contacts | Legitimate interests or consent; you can opt out at any time |
| Comply with law and respond to lawful requests | Legal obligation |
4.AI processing
AI Agents use large language models from AI providers that act as our subprocessors. Workspace content is sent to them only to perform the task you asked for.
- We do not use Customer Data to train general-purpose AI models, and our contracts require our AI providers not to either.
- We may use de-identified, aggregated measures, such as how often agent drafts are approved, to improve the Services.
- People at Cravto review workspace content only when you ask for support, or to investigate security or abuse. That access is logged.
6.International transfers
Cravto is based in Armenia and our providers may process data in the European Union, the United States and other countries. Where required, we use safeguards such as Standard Contractual Clauses for these transfers.
7.How long we keep data
- Account data: for as long as your account is active, then as needed for the purposes above.
- Customer Data: deleted within 90 days after the 30-day export window that follows the end of a Subscription.
- Billing records: for the period tax and accounting laws require.
- Security logs: usually up to 12 months.
- Marketing data: until you opt out or ask us to delete it.
8.Security
We encrypt data in transit and at rest, limit access on a least-privilege basis, log administrative access, keep backups and bind our staff to confidentiality. No system is perfectly secure. If a personal data breach affects you, we will notify affected customers and authorities without undue delay as the law requires.
9.Your rights
Depending on where you are, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive it in a portable format and to withdraw consent. You can also complain to a supervisory authority: in Armenia, the Personal Data Protection Agency; in the EU or UK, your local data protection authority.
To exercise a right, email legal@berelos.com. We will verify your identity and respond within the time the law requires, usually 30 days. If your data sits in a customer’s workspace, we will pass your request to that customer.
10.Children
The Services are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children.
11.Changes to this policy
We may update this policy. The date at the top shows the latest version, and we will notify customers of material changes by email or in the product.