Privacy Policy

Effective date: 29 September 2026

1. Who We Are

Krono (“Krono”, “we”, “us”, or “our”) is the trade name of a sole proprietorship based in Chennai, India, and operates krono-labs.com. We publish video courses and e-books on hardware regulatory compliance, operate CertifiOS, a free compliance platform, and provide compliance consulting engagements.

We decide how and why your personal data is processed, which makes us the controller under the EU and UK GDPR and the data fiduciary under India's Digital Personal Data Protection Act, 2023. Questions about this policy, and requests about your data, can be sent to [email protected].

2. Data We Collect

Account data: When you create an account (including accounts created automatically on purchase), we store your email address and a hashed password. We never store plaintext passwords.

Course and book purchases: These are processed by Paddle. We receive your email address, the transaction status and a transaction reference. We never receive or store card numbers or bank details.

Course and book access records: Which courses you are enrolled in, which books you own, and your lesson and reading progress, so we can grant access and resume where you left off.

CertifiOS platform data: The platform does not require an account. If you use it, we store the product details you provide (product name, product type, target markets and your answers to decision questions) to generate your compliance plan, plus the text of any document you draft in the built-in editor. The platform does not accept file uploads. This data is linked to a browser session unless you are signed in.

Email capture: If you give us your email address to receive a compliance plan, or enter it in a checkout you don't complete, we store it together with the product or item concerned. If you start a search and leave without finishing, we may store the search text, which is not linked to you.

Service inquiries: If you request a consulting engagement, we store the contact, company and product details you submit so we can reply, scope and quote the work.

Consulting clients: For engagements you accept, we hold your contact and billing details (including company name, address and tax details for invoicing), payment confirmations from our payment provider, and the correspondence and files you send us. Files may contain personal data, such as names and signatures on your documents.

Analytics: We measure how the site is used with Umami, which we host ourselves, and Google Analytics. See Section 8.

Log data: Our servers record standard access logs (IP address, browser type, pages visited, timestamps) for security and debugging.

3. How We Use Your Data

We use your data to:

  • Provide and operate courses, books and the free compliance platform, and grant access to content you have purchased
  • Generate your compliance plan from the information you provide
  • Reply to service inquiries, and scope, deliver and invoice consulting engagements
  • Send transactional emails, such as purchase confirmations, account credentials and password resets
  • Send product emails about Krono, such as a short series after you sign up, request a plan or leave a checkout. Every product email has an unsubscribe link, and unsubscribing stops them permanently.
  • Understand how the site is used, so we can improve it
  • Detect and prevent fraud and abuse, and comply with legal and tax obligations

We do not sell your data, use it for advertising, or share it with advertisers.

4. Legal Basis for Processing

Where the EU or UK GDPR applies, we rely on:

  • Contract: to deliver courses, books and consulting engagements you have bought or requested, and to generate the plans you ask for.
  • Legitimate interests: security logging, fraud prevention, aggregate site analytics, and product emails to people who have signed up, requested a plan or started a purchase with us. You can object at any time, and unsubscribing always works.
  • Legal obligation: keeping invoicing and payment records as tax law requires.

Under India's Digital Personal Data Protection Act, we process your data for the purposes you provided it for, or with your consent where the Act requires it. You can withdraw consent at any time by emailing us, which does not affect processing that happened before.

5. Data Sharing

We share personal data only with the providers we need to run the Service, and only as much as they need:

  • Paddle: processes course and book payments as merchant of record. Privacy policy
  • Resend: delivers our emails. Privacy policy
  • Hetzner: hosts our servers and databases in Germany.
  • Cloudflare (R2): stores course videos, course resources and book files in the EU, served through short-lived links after we verify your access.
  • Google Analytics: receives anonymous, cookieless measurements of page use (see Section 8).
  • Payment providers and our bank: process payments for consulting invoices.
  • Third parties you authorise: in a consulting engagement, such as a test laboratory or certification body you have asked us to coordinate with.

We do not share your data with anyone else unless the law requires it.

6. Where Your Data Is Stored

Our servers and databases are in Germany, and our file storage is in the EU. Krono is operated from India, so your data is accessed from India to run the Service. Some of our providers, such as Paddle, Resend and Google, may process data in other countries, including the United States, under their own safeguards for international transfers. Files sent to us in a consulting engagement are stored on our encrypted devices, not on our servers.

7. Data Retention

  • Account data: while your account is active. You can ask us to delete it at any time.
  • Course enrollment, book ownership and progress records: while your account is active, so you keep access to what you bought.
  • CertifiOS platform data: for as long as the project exists. You can ask us to delete it at any time, even without an account.
  • Email capture and product emails: until you unsubscribe or ask us to delete it. After you unsubscribe we keep your address on a suppression list, only so we never email you again.
  • Service inquiries: for as long as needed to reply and scope the work. If no engagement follows, we delete them within 24 months.
  • Files you send in a consulting engagement: deleted within 30 days of the engagement being completed, or of the end of a Compliance Partner term.
  • Our consulting deliverables and engagement correspondence: up to three years, as a record of the advice given.
  • Invoices and payment records: for the period Indian tax law requires.
  • Server access logs: 30 days.
  • Aggregate analytics: indefinitely. They contain no personal data.

8. Cookies and Analytics

Session cookie: We use one strictly necessary cookie to keep you signed in.

Umami: Our main analytics tool, hosted on our own servers. It sets no cookies, does not track you across sites, and records page views only in aggregate.

Google Analytics: Runs in consent mode with every consent category set to denied, and we never ask for or grant consent. In that mode it sets no cookies and stores no identifiers on your device. It sends only anonymous, cookieless measurements that Google uses to estimate aggregate traffic.

We do not use advertising cookies or tracking pixels.

9. Your Rights

Depending on where you live, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Have your data deleted
  • Object to or restrict certain processing, including product emails
  • Receive your data in a portable format
  • Withdraw consent you have given
  • Nominate someone to exercise your rights if you die or become incapacitated (India)
  • Complain to a data protection authority, such as your local authority in the EU or UK, or the Data Protection Board of India

To exercise any of these rights, or to raise a grievance about how we handle your data, email [email protected]. We respond within 30 days.

10. Security

We protect your data with encrypted connections (TLS), hashed passwords (bcrypt), access controls on every database, and encrypted storage on the devices we use for consulting work. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and the relevant authorities of a breach where the law requires.

11. Children

Krono is intended for businesses and professionals. We do not knowingly collect personal data from anyone under 18.

12. Changes to This Policy

We may update this policy from time to time. The effective date at the top shows when it last changed, and material changes are communicated by email to registered users.

13. Contact

For any privacy question, request or grievance:
Krono, Chennai, India
[email protected]

See also our Terms of Service.