At KrakDBench ("Company," "we," "us," or "our"), we take your privacy seriously.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information
when you use our software-as-a-service data analytics platform (the "Service").
This policy complies with the General Data Protection Regulation (GDPR) (EU)
and the California Consumer Privacy Act (CCPA) (US).
Please read this policy carefully. By using our Service, you consent to the practices described herein.
1. Data Controller & Data Protection Officer (DPO)
KrakDBench Inc. acts as the Data Controller for personal data collected
directly from you (e.g., account information). For data you upload to the Service
("Your Data"), we act as a Data Processor on your behalf.
If you have any questions about this Privacy Policy or wish to exercise your data rights,
please contact our Data Protection Officer at:
dpo@krakdbench.com
123 Data Street, Suite 100, Wilmington, DE 19801, USA
2. What Data We Collect
2.1 Personal Data You Provide:
- Account Information: Full name, email address, company name, industry, and password (hashed).
- Billing Information: Payment method details (processed securely by our third-party payment processor, Stripe).
- Communication Data: Any information you provide when contacting support, requesting a demo, or responding to surveys.
2.2 Data You Upload (Your Data):
- When you upload datasets, files, or other content to the Service, we process this data solely on your behalf to provide analytics, structuring, and reporting services.
- We do not: Sell, rent, or share Your Data with any third party for their own purposes.
- We do not: Use Your Data to train our own AI or machine learning models without your explicit written consent (as explicitly stated in our Terms of Service).
2.3 Automatically Collected Data (Usage & Cookies):
- Log Data: IP address, browser type, operating system, referring URLs, pages visited, and timestamps.
- Cookies & Tracking: We use essential cookies for authentication and session management. We may also use analytics cookies (e.g., Google Analytics or Plausible) to understand how users interact with our Service.
- Stripe Cookies: If you make a payment, Stripe may set cookies for fraud prevention and checkout processing.
3. Legal Basis for Processing (GDPR)
Under the GDPR, we process your personal data based on the following legal grounds:
- Contractual Necessity: To create and manage your account, provide the Service, and fulfill our obligations to you.
- Legitimate Interests: To improve our Service, prevent fraud, ensure security, and send you relevant communications (e.g., product updates).
- Legal Obligation: To comply with applicable laws, tax regulations, and court orders.
- Consent: For marketing communications and non-essential cookies, where you have actively given consent.
4. How We Use Your Data
- Service Delivery: To operate, maintain, and improve the Service, including processing Your Data to generate analytics and reports.
- Account Management: To authenticate users, manage subscriptions, and send administrative notifications.
- Customer Support: To respond to your inquiries, troubleshoot issues, and provide technical assistance.
- Security: To detect, prevent, and investigate security breaches, fraud, or other malicious activity.
- Compliance: To comply with legal and regulatory obligations (e.g., tax reporting, anti-money laundering).
- Analytics & Improvement: To analyze usage patterns and gather feedback to enhance features, performance, and user experience.
5. Data Sharing & Third-Party Sub-Processors
We never sell your personal data. However, we engage trusted third-party service providers
("Sub-Processors") to help us deliver the Service. These include:
- Cloud Hosting: AWS / Google Cloud / Azure (for data storage and compute).
- Database & Caching: PostgreSQL, Redis (for application state and performance).
- Payment Processing: Stripe (for billing and subscription management).
- Analytics: Plausible / Google Analytics (anonymized or aggregated usage data).
- Support: Helpdesk tools (e.g., Zendesk, Intercom) for customer service.
All Sub-Processors are contractually bound to process your data only for the purposes outlined in this policy and in compliance with applicable data protection laws.
6. International Data Transfers
Your information may be transferred to and processed in countries other than your own,
including the United States. For users in the European Union, we ensure that such transfers
are protected by appropriate safeguards, such as the EU-US Data Privacy Framework
or Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Data Retention
- Account Data: We retain your personal data for as long as your account is active or as needed to provide the Service to you.
- Your Data (Uploaded Datasets): Retained while your account is active. You may delete datasets at any time. Upon account termination, we will delete or anonymize Your Data within 30 days, unless we are required to retain it for legal or regulatory reasons.
- Usage Logs: Aggregated, anonymized logs may be retained indefinitely for analytical purposes, but cannot be used to identify you.
- Backup Retention: Encrypted backups are retained for disaster recovery purposes for up to 90 days.
8. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Access Controls: Strict role-based access control (RBAC) to our production environment, with multi-factor authentication (MFA) required for all employees.
- Regular Audits: Periodic security assessments, vulnerability scanning, and penetration testing.
- Incident Response: A dedicated incident response plan to address any potential data breaches promptly.
While we take all reasonable precautions, no method of transmission over the internet is 100% secure. You use the Service at your own risk.
9. Your Data Privacy Rights
If you are a resident of the European Union (GDPR), you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data.
- Right to Restrict Processing: Request that we limit how we process your data.
- Right to Data Portability: Request a machine-readable copy of your data to transfer to another provider.
- Right to Object: Object to processing based on legitimate interests, including direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time for processing based on consent.
If you are a resident of California (CCPA), you have the following rights:
- Right to Know: Request details about the categories and specific pieces of personal data we have collected about you.
- Right to Delete: Request deletion of your personal data (subject to certain exceptions).
- Right to Opt-Out of Sale: We do not sell your personal data. However, if you wish to opt-out of any future sale (should our policy change), you may contact us.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise any of these rights, please contact our DPO at dpo@krakdbench.com.
We will respond within 30 days (GDPR) or 45 days (CCPA) as required by law.
10. Cookies & Tracking Technologies
We use the following types of cookies:
- Essential Cookies: Required for authentication, session management, and security (e.g.,
access_token, session). These cannot be disabled.
- Preference Cookies: Remember your settings and preferences (e.g., theme, language).
- Analytics Cookies: Used to understand how users interact with our platform (e.g., Google Analytics). We anonymize IP addresses where possible.
- Stripe Cookies: Set by our payment processor for fraud prevention and checkout.
You can manage cookie preferences in your browser settings. Disabling essential cookies will prevent you from using the Service.
11. Children's Privacy
The Service is not intended for children under the age of 16 (or 13 in the US). We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
12. Changes to This Privacy Policy
We may update this policy periodically. We will notify you of material changes by:
- Posting the updated policy on this page with a new "Last Updated" date.
- Sending an email notification (if you have an account) at least 30 days prior to the effective date.
- Displaying a prominent in-app banner requiring your acknowledgment of the changes.
Your continued use of the Service after the effective date constitutes your acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy,
please contact our Data Protection Officer:
dpo@krakdbench.com
+1 (302) 123-4567
123 Data Street, Suite 100, Wilmington, DE 19801, USA
© 2026 KrakDBench. All rights reserved.