Privacy Policy

Welcome to Kronometric’s Privacy Policy!

Please note that this Privacy Policy applies to personal data that is collected and processed by Kronometrics. (“Kronometrics”“we”“our” or “us”).

Kronometrics, as a data controller, collects and processes personal data relating to interactions on the Website (as defined in Section 1 of Terms of Use). Sections 2 -7 of this here Privacy Policy apply to Kronometrics’ processing of data when it functions as a data controller.

Additionally, Kronometrics processes personal data on behalf of you, as a data processor, when you use our services. You can find more details on how Kronometrics functions as a data processor     8.DATA PROCESSING AGREEMENT – KRONOMETRICS AS A DATA PROCESSOR:

This Privacy Policy describes how Kronometrics uses and protects any information that you give us.

Kronometrics also as a data controller, recognizes and attaches particular importance to the obligation to comply with the applicable regulatory and legislative framework according to the provisions of the General Data Protection Regulation 2016/679 (GDPR) and its implementation on the protection of individuals from processing of personal data.

We respect the confidentiality of your personal data and aim to protect them. Our privacy policy complies with European Regulation (EC) 2016/679, the laws 4624/2019, 3471/2006 and the Presidential Decree 207/1998 on the protection of personal data, as in force.

At Kronometrics, we are committed to protecting your privacy, and we have created this Privacy Policy to explain what information we collect, how your information is collected, and how we may use it.

We believe in full transparency, which is why we keep our Privacy Policy simple and easy to understand.

We strongly urge you to read this Privacy Policy and make sure that you fully understand and agree with it. If you do not agree to this Privacy Policy, please do not access or otherwise use the Website.

The purpose of the private policy is to provide information to you as a potential and/or existing customer regarding the processing of your personal data, in the Kronometrics platform.

This document will provide you with information about the following:

  1. DEFINITIONS
  2. WHAT DATA WE COLLECT
  3. WHAT PERSONAL DATA CAN BE PROCESSED AND FOR HOW LONG
  4. PERSONAL DATA SECURITY
  5. WITH WHOM WE SHARE YOUR PERSONAL DATA
  6. HOW LONG WE KEEP YOUR DATA
  7. YOUR RIGHTS AND HOW TO EXERCISE THEM
  8. DATA PROCESSING AGREEMENT – KRONOMETRICS AS A DATA PROCESSOR
  9. CHANGES TO PRIVACY POLICY

DEFINITIONS

When we say “you”“your” or “Data Subject” we mean any natural person that shares personal data with us via Website.

When we say “processing” we mean any operation that includes activities such as collection, recording, organization, structuring, storage, adaptation, consultation, use of personal data.

When we say “personal data” or “data” we mean any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, either directly or indirectly. Therefore, data about a company or any legal entity is not considered to be personal data but registering on behalf of a legal entity may include sharing personal data. For example, the information in relation to one-person companies may constitute personal data where it allows the identification of a natural person. The rules also apply to all personal data relating to natural persons in the course of professional activity, such as the employees of a company or organization, business e-mail addresses https://www.kronometrics.com

This Privacy Policy does not apply to information from which no individual can reasonably be identified (anonymized information).

When we say “Data Processor” or “processor” we mean any natural or legal person who processes the data on behalf of the Data Controller.

When we say “cookies” we mean small pieces of data stored on your device (computer or mobile device), that enable access and use of specific pages and/or website pages for statistical reasons.

2. WHAT DATA WE COLLECT

We may collect and receive information about you in various ways.

We receive data about you each time you use the computer, mobile phone or other device in order to access the website of “Kronometrics”, such as the pages you visit, the IP address, location, type of browser.

  • (i) Information you provide through the use of the Service (for example, by creating the account on Cloud Kronometrics).
  • (ii) Information you decide to provide through getting in touch with us via support@kronometrics.com
  • (iii) Information we collect through the use of cookies in accordance with our Cookie Policy (for example, your time zone).

3. PERSONAL DATA WE PROCESS AND FOR HOW LONG

You may access, delete or rectify your personal information at any time or limit the data processing, by sending an e-mail at: info@kronometrics.com. For more detailed information on your rights as a data subject please see the relevant Section 7: YOUR RIGHTS AND HOW TO EXERCISE THEM

The personal data we process as Data Controllers are the following:

  • Email address, password, time zone and sometimes profile photo, name personal API key (if the User decides to provide such personal data). The purpose is to create and maintain a User Account on the Website according to the terms of use. Processing is necessary for the performance of the Agreement (as defined in Section 1 of the terms of use). Without providing an email address, password and time zone, the User may not create the User Account. We keep your data until the account is deleted in accordance with the terms of use.
  • Financial Data The payer may not be the User subscribing to the Paid Plan, so it is possible to receive the information from another User. When subscribing to any of the Paid Plans or when changing any Paid Plan in accordance with the terms of use, this information is being collected by a third party processor. Processing is necessary for the User’s performance of the Agreement which includes providing Additional Features based on the selected Paid Plan.
  • Additional Data., data you decide to share with us. If you send us an inquiry at support@kronometrics.com or otherwise request support, we will collect data you decide to share with us. Processing of personal data is either necessary to provide a Service or part thereof, or the processing is based on your consent. In principle, if the processing is based on your consent, we keep the information for five years. It is possible that we maintain certain data sets for a longer period of time, as necessary pursuant to the statutes of limitation of the Greek civil code for the exercise or defense of legal claims related to contracts or if we are obliged to do so by law (for example in the case of audits by administrative authorities).
  • Email address (collected directly by you) If you decide to sign up for our newsletter, we use your e-mail address. This newsletter allows us to inform you of the new features of the Service, updates, as well as other news relevant to the company. Processing is based on your consent. You have the right to withdraw your consent at any time, without affecting the lawfulness of the processing based on consent prior to such withdrawal. You may unsubscribe from receiving a newsletter from us. An easy to follow procedure is included at the end of each email through a hyperlink for your convenience. Bear in mind that after you unsubscribe you will be removed from the mailing list for our promotional newsletters, however the personal data we are collecting and processing further to other relationships (e.g. if you have signed up for a User account) will be maintained independently on the other legal bases outlined in this policy.
  • Email address (when provided by other Users). Users may invite non-users via Kronometrics to join the Workspace, in which case they provide the non-user’s email address. Processing is necessary for the performance of the Agreement between us and the User who provided the information and it is also in the User’s legitimate interest. We will always ask for you input when a third user has shared your email with us. Unless you verify your subscription within 30 days, we will delete your data from our list of potential recipients.
  • Information necessary for identification. To allow Data Subjects to exercise their rights in accordance with this Privacy Policy. Processing is necessary for compliance with a legal obligation which Controller is subject to. We keep this information for a period of one year.

4. PERSONAL DATA SECURITY

We take administrative, technical, organizational and other measures to ensure the appropriate level of security of personal data we process. Upon assessing whether a measure is adequate and which level of security is appropriate, we consider the nature of the personal data we are processing and the nature of the processing operations we perform, the risks to which you are exposed by our processing activities and other relevant matters in the particular circumstances.

Some of the measures we apply include access authorization control, information classification (and handling thereof), protection of integrity and confidentiality, data backup, firewalls, data encryption and other appropriate measures. We equip our staff with the appropriate knowledge and understanding of the importance and confidentiality of your personal data security Kronometrics will never:

  • — Sell any kind of personal information or data
  • — Disclose this information to marketers or third parties
  • — Process your data in any way other than stated in this Privacy Policy.

5. WITH WHOM WE SHARE YOUR DATA

We only disclose your data to certified and reliable service providers and exclusively for the purposes of delivering and ameliorating our services to you. In certain cases these service providers as recipients of data may be located outside the EU/EEA. We have ensured the signing of the most updated Standard Contractual Clauses (certified by the EU Commission) for transferring data with all our service providers located in third countries and taken sophisticated security measures and safeguards to ensure that all recipients of data will maintain the same level of protection of your data as we do, regardless of their location.

Additionally, we obtain company documents, certifications, references and ensure that the processor is adequate, appropriate and effective for the task we are employing them for.

This is the list of processors and sub-processors with whom we share your personal data:

PROCESSOR ROLE SEAT
The Rocket Science Group, LLC (MailChimp) Email services based on Cloud USA
Google, Inc. Analytics USA
Amazon Web Services, Inc. Cloud Infrastructure (IaaS) USA
Stripe, Inc. Payment provider USA

We may also share your personal data with our outside accountants, legal counsels and auditors. In some cases, if we are required to do so by law, we may disclose your data to public administrative or judicial authorities.

Please keep in mind that, subject to your instructions to us while using the Service, your data may be shared with third parties in the following situations:

  • — If you join another User’s Workspace;
  • — If you invite another User to join you Workspace;
  • — If you invite a non-user to join Kronometrics;

6. HOW LONG WE KEEP YOUR DATA

The period for which we store your personal data depends on a particular purpose for the processing of personal data. We retain personal data for as long as we reasonably require it for legal or business purposes. In determining data retention periods, we take into consideration the applicable law, contractual obligations, and the expectations and requirements of our Users. When we no longer need personal information, or when you request us to delete your information, where this is legal, we will securely delete or destroy it.
However, as an exception to the retention periods the data may be processed to determine, pursue or defend claims and counterclaims.

7. YOUR RIGHTS AND HOW TO EXERCISE THEM

Further to the data protection legislative framework as applicable, you have the right to access, rectify, delete, restrict or object to the processing of your data as well as the right to data portability. You may exercise any of your rights by signing in to Kronometrics and making the change or by emailing to support@kronometrics.com

. We will respond to your request within 30 days. We may decline to process unreasonable requests or requests that are not otherwise required by local law.

We retain your information and data that we process on your behalf as long as your account is active, as needed to provide our Services, and as necessary to comply with our legal obligations and resolve disputes.

We have no direct relationship with third parties with whom our users may interact using the Services. Any such party who would like to amend or delete data which may be stored in the Services should direct his or her request to the applicable Kronometrics user acting as the “data controller” for such information. You also have the right to file a complaint with the Hellenic DPA at www.dpa.gr if you believe that we have violated the data protection legislation in the context of processing your data.

8. DATA PROCESSING AGREEMENT – KRONOMETRICS AS A DATA PROCESSOR

As also outlined in the beginning of the Privacy Policy, Kronometrics also functions as a data processor when providing our services to you. This essentially means that we process the data that our users input in the Workspace, not for our own interest and business, but only to the extent necessary to provide you with the service that you request. Therefore, in the context of the Services, a User that creates the Workspace (regardless of whether they are a legal or natural person) is considered to be the Data Controller, and they are primarily responsible to use the Services in accordance with the Terms of Use and only input personal data that they lawfully permitted to collect and process. Kronometrics is not responsible for personal data unlawfully added or otherwise stored by Users in the Workspace or any other platform that is linked to the provision of the Services. By using the Services you acknowledge that you appoint Kronometrics as a data processor under the Data Processing Agreement in this here Section 8, in respect to the provision of the Services.

  • 8.1 Obligations of the Data Controller: By using the Services, the Data Controller warrants that they comply with the data protection laws that they are subject to, including providing all necessary information to data subjects and acquiring valid consent for the processing whenever necessary and applicable.
  • 8.2 Obligations of Kronometrics
    • 8.2.1 General Obligations: Kronometrics shall (i) process the personal Data in conformity with the data protection laws, and (ii) shall not use the personal data for own advantage and benefit, including use for promotional activities, sale and/or access of the personal data by third parties. Kronometrics may use statistical and historical data or user metadata on an anonymized basis in order to monitor and improve the services we provide to you.
    • 8.2.2 Security of the data: Kronometrics ensures the confidentiality of the data and has taken all appropriate technical and organizational measures necessary to protect the Data Controller’s data from unlawful destruction, deletion and loss.
    • 8.2.3 Appointment of subcontractors: The Data Controller grants its general authorization to Kronometrics for the appointment of sub-contractors/sub-processors. Kronometrics ensures that any sub-contractors /sub-processors who have access to any personal data of the Data Controller maintain a standard of protection of personal data equal to that of Kronometrics as described in this here Data Processing Agreement.
    • 8.2.4 Data transfers outside the EU/EEA: Kronometrics does not transfer the Data Controller’s data outside the EU/EEA. If such transfer occurs, Kronometrics shall inform the Data Controller and shall ensure that appropriate safeguards are effected to protect the Data Controller’s data to an equal standard of protection as provided by Kronometrics under this here Data Processing Agreement.
    • 8.2.5 Personal Data Breaches: In case of a data breach which affects the integrity, availability or accuracy of the Data Controller’s personal data, Kronometrics shall inform the Data Controller without undue delay. At the written request of the latter, Kronometrics shall assist the Data Controller in the containment of the breach and any necessary actions before supervisory authorities, taking into account the nature of the breach and the information available to Kronometrics.
    • 8.2.6 Assistance of compliance with the GDPR: If the Data Controller has an obligation to comply with the GDPR, Kronometrics shall assist with the compliance by maintaining records of the processing activities carried out on behalf of the Data Controller, notify the Data Controller about any data subject requests concerning the personal data processed and forward such requests, provide the Data Controller, at the latter’s request, with any information related to the processing carried out by Kronometrics on its behalf.
    • 8.2.7 Return or deletion of the data: After the end of the provision of the Services, at the Data Controller’s request, Kronometrics shall return or permanently delete the personal data that they process on behalf of the Data Controller, to the extent permitted by law and to the extent that Kronometrics is not obliged to maintain the data for the establishment and defense of legal claims.
  • 8.3 Other Clauses
    • 8.3.1 Duration: The term of this Data Processing Agreement shall commence when the User accepts the Terms of Use and begins use of the Services and shall continue until the termination of the provision of the Services.
    • 8.3.2 Liability: Kronometrics shall be liable towards the Data Controller only for direct damages arising from malice or gross negligence of Kronometrics in the course of the processing of personal data on behalf of the Data Controller. The Data Controller shall be liable towards Kronometrics for any damages to Kronometrics or to its sub-contractors/sub-processors arising from or in connection to the Data Controller’s non-compliance with this here Data Processing Agreement or the data protection legislation as applicable.
    • 8.3.3 Conflict Resolution: Any dispute arising from or in connection with this here Data Processing Agreement shall be governed by the laws of Greece and shall be subject to the exclusive jurisdiction of the Courts of Athens.

Personal data being processed: When you use our Workspace and/or our cloud services we naturally process the data that you input in the system and only insofar as is necessary to deliver the best possible functionality of our services to you according to the instructions you input to the system. We do not manually monitor or control the data you input into the Workspace.

9. CHANGES TO PRIVACY POLICY

We reserve our right to change the terms of this privacy policy at any time, with prior notification to you at the e-mail address that you may have notified to us during the subscription, according to the procedures provided by the existing legal frame. In that case, a relevant consent for the personal data, that we keep or/and process will be anew required.

Where you have previously consented to our Privacy Policy, your continued use of the Website after we make changes is deemed to be acceptance of the updated rules.

Last updated January 2021