Privacy Policy
Last updated 4 October 2026
This Privacy Policy explains how KKH Ventures, Helsinki, Finland, handles personal data in connection with Chronaro.
1. Who is responsible for your data
KKH Ventures is the controller for account administration, direct customer relationships, billing, security and service operations.
When an organization provides its users with Chronaro, that organization generally acts as controller for workspace content, including time entries, descriptions, clients and tasks. KKH Ventures processes that content on the organization’s behalf to provide the service.
2. Data we process
- Account data, such as name, email address, authentication identifiers and company membership.
- Workspace data, such as company, team, clients, tasks, groups, time entries, descriptions and billing classifications.
- Subscription and billing data, such as plan, seat count, payment status, invoices and payment-provider references. We do not store complete card details.
- Technical and security data, such as device, browser, IP address, timestamps, error records and authentication events.
- Communications you send to us, including support and billing messages.
3. Why we process data
- To create accounts, provide workspaces and deliver requested features.
- To authenticate users, prevent abuse and keep the service secure.
- To administer trials, subscriptions, invoices and customer support.
- To maintain and improve reliability using aggregated or limited technical information.
- To comply with accounting, legal and regulatory obligations and establish or defend legal claims.
Our legal bases may include performance of a contract, legitimate interests in operating and securing Chronaro, compliance with legal obligations and consent where the law requires it.
4. Visibility and access
Workspace information is separated by company and is available only to authorized members according to their role. KKH Ventures’ platform administration uses company identity, user counts and aggregate usage for operations and billing; it is not designed to display customers’ client names, task names, descriptions or individual time-entry details.
Authorized service providers may process limited data when necessary to host, secure, support or bill for Chronaro and are required to protect it.
5. Service providers and transfers
We use providers for cloud hosting and authentication, payment processing, email delivery and technical operations. Card details are handled by the payment provider under its own privacy terms.
Some providers may process data outside Finland or the European Economic Area. Where required, we use recognized safeguards such as adequacy decisions or the European Commission’s standard contractual clauses.
6. Retention
We keep account and workspace data while the relevant account or customer relationship is active and for a limited period afterwards for recovery, dispute handling and legal compliance. Billing and accounting records are retained for the period required by Finnish law. Security logs are kept only as long as reasonably necessary for security and troubleshooting.
When data is no longer needed, we delete or anonymize it, subject to backup cycles and legal retention duties.
7. Security
We use access controls, company-level separation, encrypted connections, restricted administrative access and other reasonable technical and organizational measures. No online system can guarantee absolute security.
8. Cookies and local storage
Chronaro uses essential browser storage and similar technologies to keep you signed in, protect sessions and remember necessary preferences, such as dismissing a notice for the day. These are required for the service to function. If we introduce non-essential analytics or advertising technologies, we will provide any consent choices required by law.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection to processing. Where processing relies on consent, you may withdraw it. You may also complain to the Office of the Data Protection Ombudsman in Finland or your local supervisory authority.
If your account is supplied by an employer or another organization, direct requests about workspace content to that organization first. We will assist it where required.
10. Children
Chronaro is intended for working-age users and is not directed to children. Users must have the legal capacity to agree to the service or use it under an organization that is authorized to provide access.
11. Changes and contact
We may update this policy as the service or law changes. The latest version and update date will be posted here.
For privacy questions or requests, contact:
KKH Ventures
Helsinki, Finland
admin@chronaro.com