Privacy Policy

Last updated: September 22, 2025

Who We Are

This Privacy Policy explains how Yezholov Kyrylo, sole proprietor operating as Korrero ('we', 'us', or 'our'), collects, uses, and protects your personal information.

Information We Collect & Purpose

We only collect information about you that help us identify you, to communicate with you, or make our Service better.

We collect information from several sources: information that you provided to us, information we collected automatically from your interactions with the Service, and from third parties.

Information You Provide Directly

Account & Profile Information

When you register for a Korrero account, we require your full name and email address. We also require you to create a password, which we store in a secure, hashed format (meaning we can never see your actual password). You may also voluntarily choose to upload a Profile Picture (Avatar) to personalize your account. We collect this information to create your account, identify you within the Service, and communicate important service-related notices to you (like password resets or billing notifications).

Project & Team Member Information

Our Service allows you to create projects to manage your notifications. We store the project names you create and the secure API keys we generate for those projects. If you invite other team members to a project, we process the email address you provide to send the invitation. To facilitate collaboration, once a team member has joined your project, their name, email address, and Profile Picture (Avatar) will be visible to you and other members within that project's team management view.

Notification Content

As a core part of our service, we process the data you send through our API. This includes the content of the notifications themselves and any associated media files you upload or link to. We process this data solely on your behalf and according to your instructions, which are to deliver it to your specified channels. You are the Data Controller for this information and are responsible for its content.

Information We Collect Automatically

Usage & Analytics Data

When you use our service, we collect data about your activity. This includes analytics on your notifications, such as impressions, clicks, and Click-Through Rate (CTR). We collect this information to display it to you on your analytics dashboard and to help us understand how our Service is performing, allowing us to improve it.

Technical Log Data

Like most websites and services, our servers automatically collect technical information when you access or use our console or API. This includes your IP address, browser type and version, operating system, and the date and time of your interactions. We use this log data for the legitimate interests of securing our Service, preventing abuse, diagnosing technical problems, and ensuring stability. These logs are retained for a fixed period of 90 days.

Information We Receive from Third Parties

Payment Information

We use Paddle as our official Merchant of Record to handle all subscription payments and invoicing. When you choose to upgrade to a paid plan, we securely pass your email address and a unique Korrero user identifier to Paddle to initiate the checkout process. You provide your payment details directly to Paddle's secure checkout page. We do not receive or store this sensitive payment information. After a successful payment, Paddle provides us with confirmation details, such as your name, country of residence, and which plan you purchased.

Third-Party Authentication Information

We offer the ability to sign up and log in using third-party authentication services ("OAuth"), such as Google or other providers we may support in the future. If you choose to use one of these services, you authorize that service to share certain information with us. We will receive information like your identifier, name, email address, and profile picture from the provider to create and authenticate your Korrero account. We do not receive your password from these third-party services.

How and Why We Use Your Information

Under the General Data Protection Regulation (GDPR), we must have a valid legal reason, known as a lawful basis," to use and process your personal information. We rely on the following lawful bases to run the Korrero service:

a) To Provide Our Service (Based on "Performance of a Contract")

This is our primary reason for processing your data. When you sign up for Korrero, you are entering into a contract with us to provide you with a notification service. We use your data to fulfill this contract, which includes:

  • Creating and Managing Your Account: We use your Account Information (name, email, password) to create your account, secure it, and allow you to log in.
  • Delivering the Core Service: We process your Project Data and Notification Content to send, manage, and track notifications as you instruct through our API and Console.
  • Managing Your Subscription: We use information from our payment processor, Paddle, to apply the correct subscription plan to your account and manage your access to paid features.
  • Providing Essential Communications: We use your email address to send you critical service-related messages, such as password resets, security alerts, and subscription status updates.

b) For Legitimate Business Interests (Based on "Legitimate Interest")

We use some data for legitimate business purposes to maintain, secure, and improve our service. We only do this when our interest is not overridden by your fundamental rights and freedoms. These purposes include:

  • Security and Fraud Prevention: We process Technical Log Data to protect the security of our Service.
  • Debugging and Service Improvement: We use Technical Log Data and aggregated Usage Analytics to diagnose problems, troubleshoot errors, and understand how our service is being used.
  • Customer Support: If you contact us for help, we will use your Account Information and any other information you provide to investigate and resolve your issue.

c) With Your Explicit Permission (Based on "Consent")

For any activities that are not essential to providing the core service, we will always ask for your consent first. This includes:

  • Marketing Communications: We will only send you promotional emails or newsletters about new features or offers if you have explicitly opted in to receive them.
  • Analytics and Performance Cookies: As described in our Cookie Policy, we use services like Google Analytics to understand how users interact with our website.

Who We Share Your Data With (Our Sub-Processors)

We are committed to keeping your personal data safe and private. We do not sell your personal information to anyone.

However, to provide, secure, and operate the Korrero service, we rely on a small number of trusted third-party companies that act as our "sub-processors." These companies are contractually bound to protect the data we share with them and are prohibited from using it for any other purpose.

Service ProviderPurposeLocation
Hetzner Online GmbHHosting of our servers, database, and file storageGermany / Finland, EU
CloudflareSecurity (Web Firewall, DDoS Protection) & Performance (CDN)Global / US
PaddlePayment Processing (as our Merchant of Record)Ireland / US
Google (OAuth, SMTP)Client Authentication & Transactional Email DeliveryUS
Google AnalyticsWebsite & Service Usage AnalyticsUS

Data Transfers: Some of our sub-processors are based outside of the European Union (EU), primarily in the United States. When you use our Service, this may involve transferring your personal data to these locations. We ensure these transfers are legal and that your data remains protected to the same high standard as required by GDPR.

How Long We Keep Your Data (Data Retention)

We are committed to the principle of storage limitation and will only keep your personal data for as long as it is necessary to fulfill the purposes we collected it for, as described in this policy, or to comply with legal and regulatory obligations.

Account and Notification Data

Your Account Information, Project Data, and Notification Content are retained for as long as your Korrero account is active. The indefinite storage and archiving of your notification history is a core feature of the Service that we provide to you.

As our client, you are the Data Controller for this information and are responsible for its lifecycle. You can and should use our built-in features to manually delete any or all your notification data at any time.

If you choose to delete your account, all personal data associated with it (including your profile, projects, and notification history) will be permanently deleted from our active systems within a reasonable period.

Technical and Log Data

We retain Technical Log Data, which includes your IP address and information about your interactions with our service, for a fixed period of 90 days. This data is used for security analysis and debugging purposes. After 90 days, these logs are automatically and permanently deleted.

Legal Obligations

Please note that we may be required to retain some information for a longer period to comply with our legal or regulatory responsibilities. For example, we may need to keep basic transactional records provided by Paddle for several years to comply with financial and tax laws in the EU.

Your Rights Under GDPR

If you are a resident of the European Economic Area (EEA), you have important rights over your personal data under the General Data Protection Regulation (GDPR). We are committed to upholding these rights.

Your Rights

  • The Right to Access: You have the right to request a copy of the personal data we hold about you.
  • The Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
  • The Right to Erasure (The 'Right to be Forgotten'): You have the right to request that we delete your personal data from our systems. We will do so if we are not legally required to retain it.
  • The Right to Restrict Processing: You have the right to request that we temporarily or permanently stop processing all or some of your personal data.
  • The Right to Data Portability: You have the right to request a copy of your personal data in a structured, commonly used, and machine-readable format (like a JSON file). You also have the right to transmit this data to another service without hindrance.
  • The Right to Object: You have the right to object to us processing your personal data, specifically for direct marketing purposes or when our processing is based on "legitimate interest."
  • Rights in Relation to Automated Decision Making and Profiling: We do not use automated decision-making or profiling that would have a legal or similarly significant effect on you.

How to Exercise Your Rights

We have built tools to help you easily exercise your rights:

  • Access, Rectification, and Deletion: You can access and update most of your Account Information directly from your account settings page. You can also delete your data by using the project and notification deletion features, or by using the "Delete Account" function in your settings.
  • Data Portability: You can download a machine-readable file of your account and project data using the "Export My Data" function in your account settings.

For any other requests, or if you need assistance, please contact us directly by emailing [email protected]. We will respond to your request within 30 days, as required by law.

Right to Lodge a Complaint

While we hope to resolve any concerns you have directly, you have the right to lodge a complaint with your local data protection authority if you believe your privacy rights have been infringed.

As we are based in Lithuania, our lead supervisory authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija). You can find their contact details on their website.

Security of Your Information

We take our responsibility to protect your data very seriously and have implemented a range of appropriate technical and organizational measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, or disclosure.

Important Note: While we have implemented robust security measures, please be aware that no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

Technical Security Measures

  • Encryption in Transit: All data transferred between your device and our servers is encrypted using strong Transport Layer Security (TLS 1.2 or higher), commonly known as HTTPS.
  • Encryption at Rest: The virtual disk volumes on Hetzner Online GmbH that store our database, and uploaded files are fully encrypted at the infrastructure level.
  • Password Security: We never store your account password in plaintext. All passwords are put through a strong, industry-standard, one-way hashing algorithm before being stored in our database.
  • Secure Infrastructure: Our service is built upon the robust and secure infrastructure of Hetzner Online GmbH, hosted in an EU data center in Germany and Finland.
  • Network Protection: We use services from Cloudflare to provide a Web Application Firewall (WAF), protection against Distributed Denial of Service (DDoS) attacks, and other measures to shield our service from malicious internet traffic.

Organizational Security Measures

  • Access Control: Access to sensitive production data is strictly limited to authorized personnel on a "need-to-know" basis. As a sole proprietor, this access is limited to the founder for the purposes of maintaining, debugging, and securing the service.
  • Secure Development: We integrate security considerations into our software development lifecycle to identify and mitigate potential vulnerabilities before they are deployed.

Your Role in Security

The security of your account also depends on you. You are responsible for keeping your account password confidential by using a strong, unique password.

Regarding API Keys: Our service provides public API keys for each project. This key is designed to be used in public-facing applications (such as websites or mobile apps) to retrieve notification data for that specific project. These keys are read-only and are scoped to a single project.

It is your sole responsibility as our client to ensure that any notifications you make accessible via this public API key do not contain any sensitive, private, or confidential information. By design, any data retrievable by this key should be considered publicly accessible. You are in full control of the data you choose to expose through this mechanism.

Cookie Policy

We use cookies and similar tracking technologies to help operate and improve our Service, perform analytics, and remember your preferences. For more detailed information about the cookies we use, why we use them, and how you can manage your cookie settings, please see our dedicated Cookie Policy.

Your consent for non-essential cookies is managed through the cookie consent banner presented to you when you visit our site.

Changes to This Privacy Policy and How to Contact Us

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.

We will notify you of any changes by posting the new Privacy Policy on this page. We will also update the "Last Updated" date at the top of this policy. For any significant changes, we will provide a more prominent notice, such as by sending you an email notification to the address associated with your account. You are advised to review this Privacy Policy periodically for any changes.

How to Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your data rights, or our data protection practices, please do not hesitate to contact us.

Email: [email protected]

Data Controller: Kyrylo Yezholov (sole proprietor)

Location: Lithuania

© 2025 Korrero. All rights reserved.