Skip to content

Legal

Privacy Policy

Version 2026-09-C Effective

Controller and contact

KRONENWERK

230 boul. HarwoodVaudreuil-Dorion (Québec) J7V 0L4Canada

Contact support@kronenwerk.org

Person in charge of the protection of personal information Tyler Pernitsch support@kronenwerk.org

This policy explains what personal information KRONENWERK processes, why, for how long, with whom it is shared, and what rights you have. It is written to describe what the software actually does. Where something is not done, this policy does not claim it.

1. Who is responsible

KRONENWERK is operated by the provider identified in the Legal Notice, which is the controller of the personal information described here. KRONENWERK is operated from Québec, Canada. The application and its database are hosted in Frankfurt, Germany.

For any question or request concerning personal information, use the contact email given in the Legal Notice. As required by Québec's Act respecting the protection of personal information in the private sector, the Legal Notice states the title and contact details of the person in charge of the protection of personal information; requests are answered through the KRONENWERK contact address, not through personal channels.

KRONENWERK has not appointed a representative in the European Union under Article 27 of the GDPR. Whether that article requires one for KRONENWERK's activities is under professional review; this policy will be updated if a representative is appointed.

2. Two kinds of information, two roles

KRONENWERK is accounting and invoicing software used by businesses. That produces two distinct situations, and your rights differ between them.

Information about you as a user. Your account, your sign-in credentials, your company's settings and your subscription. For this information KRONENWERK decides the purposes and means of processing and is the controller.

Information a business enters about other people. When a business using KRONENWERK records its customers, suppliers, contacts, invoices and receipts, that information belongs to the business and is processed on its instructions. For that information the business is the controller and KRONENWERK is its processor. If you are a customer or supplier of a business that uses KRONENWERK, and you have a question about how that business handles your information, the business is the right party to ask; KRONENWERK will not disclose a business's records to third parties on request.

3. What information is processed

3.1 Account and sign-in

  • Your name, email address and interface language.
  • If you register with a password: a one-way hash of that password (Argon2id). The password itself is not stored and cannot be recovered from the hash.
  • If you sign in with Google: Google's stable account identifier for you (the sub claim), the email address Google reports as verified, and your display name. KRONENWERK requests only the openid, email and profile scopes and does not receive or store Google access or refresh tokens, and has no access to your Gmail, Drive, Calendar, Contacts or any other Google service.
  • Email verification and sign-in codes, stored only as one-way hashes, valid for fifteen minutes and for a single use.
  • Trusted-device tokens where you choose "trust this device", stored only as a one-way hash. These are random tokens KRONENWERK issues; KRONENWERK does not fingerprint your browser or device.
  • Password-reset tokens, stored only as one-way hashes, valid for one hour and for a single use.
  • The time of account creation and, for security records, the time of sign-in events.

3.2 Company and business information

  • Your company's legal name, trading details, address, country and, where applicable, province or region.
  • Business and tax identifiers you enter for your company (for example a VAT identification number, a tax number, or Canadian GST/HST and QST registration numbers). These are your company's identifiers; they are never treated as KRONENWERK's own registrations.
  • Bank account details you enter so that they can be printed on your invoices (IBAN, BIC, account holder). KRONENWERK does not use these to move money.
  • Team members you invite: their email address and role.

3.3 Records you create in the software

  • Customers, suppliers and contacts, including any personal information you enter about them.
  • Quotes, invoices, credit notes, bills, expenses, payments and accounting entries.
  • Documents and receipts you upload.
  • Issued invoices are preserved exactly as issued, including a snapshot of the supplier and buyer details at the time of issue and the rendered PDF and, where applicable, structured e-invoice file. This is deliberate: an issued legal document must not change when settings change later.

3.4 Subscription and payment

  • Your plan, billing period, currency, subscription status and period end.
  • Payment card details are entered directly with Stripe and are never transmitted to or stored by KRONENWERK.
  • For each paid subscription invoice, KRONENWERK records what Stripe reported: amounts, currency, the country and region used for tax, any tax identifier you provided at checkout, and the tax breakdown. This is KRONENWERK's own tax record and is kept because tax law requires the provider to be able to account for tax it has collected.

3.5 Developer and integration features

  • API keys, stored only as one-way hashes; the key itself is shown once at creation.
  • Webhook endpoint addresses you configure, and delivery records for messages sent to them.
  • Credentials for third-party integrations you connect (for example banking or automation services), stored encrypted. KRONENWERK never stores your online-banking password; bank connections use a provider reference, not your credentials.

3.6 Technical and security information

  • Server logs containing the IP address, request path, timestamp and browser identification string of requests. These are used to operate and secure the service and to investigate abuse and errors.
  • An audit trail of security-relevant actions on your account and, for the operator, of privileged actions taken in the operator console.
  • Rate-limiting counters for sign-in, registration and password reset, keyed by account and by request origin, held briefly in memory.

4. Cookies and similar technologies

KRONENWERK uses no advertising cookies, no third-party analytics and no tracking scripts. The cookies it sets are:

NamePurposeLifetime
Session cookieKeeps you signed in during a browser session. Marked Secure, HttpOnly and SameSite=Lax.Browser session
kw_spracheRemembers the language you chose on the public website.Persistent
kw_geraetSet only if you choose "trust this device" when entering a sign-in code. Identifies this browser to your account so that a code is not asked for again. Secure, HttpOnly, SameSite=Lax.60 days

Because none of these cookies are used for advertising, analytics or tracking across sites, no cookie banner is shown. If that changes, this policy will change first.

5. Why information is processed, and on what basis

PurposeInformationBasis (where the GDPR applies)
Providing the service you signed up for: accounts, companies, invoicing, accounting, documents3.1, 3.2, 3.3, 3.5Performance of a contract (Art. 6(1)(b))
Billing your subscription and accounting for the tax collected on it3.4Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Securing accounts and the service: sign-in codes, device recognition, rate limiting, audit trail, logs3.1, 3.6Legitimate interest in security and abuse prevention (Art. 6(1)(f))
Sending transactional email: verification and sign-in codes, password reset, invoices and reminders you choose to send3.1, 3.3Contract (Art. 6(1)(b))
Preserving issued invoices unchanged3.3Legal obligation of the business (Art. 6(1)(c)), performed on its instructions
Responding to your requests and legal obligationsas neededLegal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f))

KRONENWERK does not use your information for advertising, does not sell it, and does not build profiles of you.

6. Who receives information

KRONENWERK uses a small number of service providers to operate. Each processes information only to provide its service to KRONENWERK.

ProviderWhat it doesInformationLocation
RenderHosts the application and the databaseAll data held in KRONENWERKFrankfurt, Germany (EU)
CloudflareContent delivery, DNS, TLS termination and protection against malicious trafficRequest metadata including IP address; content in transitGlobal network; company based in the United States
StripeSubscription payments and calculation of tax on KRONENWERK subscriptionsBilling details, payment method (held by Stripe only), billing address, tax identifiers you provide at checkoutUnited States and Ireland
ResendDelivers transactional emailRecipient address, subject and message content of emails KRONENWERK sendsUnited States
GoogleSign in with Google, only if you use itAuthentication of your Google account; KRONENWERK receives identifier, verified email and nameUnited States
StorecoveAccess point to the Peppol e-invoicing network and, where contracted, French approved platform — only for businesses that connect their company in Settings → DeliveryInvoices and credit notes sent or received over the network; the business's registration on itNetherlands (EU)
Enable BankingBank account connection for European banks — only for businesses that connect a bank account in Settings → Banking; named on the screen before you connectAccount identifiers, balances and transactions of the connected account; the connection reference. KRONENWERK never sees your online-banking passwordFinland (EU)
PlaidBank account connection for banks in Canada and the United States — only for businesses that connect a bank account in Settings → Banking; named on the screen before you connectAccount identifiers, balances and transactions of the connected account; the connection reference. KRONENWERK never sees your online-banking passwordUnited States

Where a business's country runs a national invoicing system operated by its tax administration (for example Poland's KSeF), and the business connects to it in Settings → Delivery, KRONENWERK transmits that business's invoices to the system and collects invoices from it on the business's instruction, using the business's own credentials. The tax administration is an independent controller under its own law, not a service provider of KRONENWERK.

KRONENWERK asks the European Commission's VIES service whether a customer's VAT identification number is valid when an invoice relies on it (reverse charge, intra-Community supply). Only the number is sent; the answer and its time are recorded with the invoice.

If you connect a banking or other integration from within the software, information is exchanged with that provider on your instruction; the integration screen names the provider before you connect it. The banking providers above are only involved once you connect an account; until then no information reaches them.

KRONENWERK does not share information with advertisers, data brokers or other third parties for their own purposes. Information may be disclosed where the law requires it.

7. Where information is processed and international transfers

The application and database run in Frankfurt, Germany. The operator is located in Québec, Canada, and may access the service from there to operate and support it. Several of the providers listed above are based in the United States. Information may therefore be transferred outside the country in which you are located, including outside the European Economic Area and outside Canada.

Where the GDPR applies, transfers to those providers rely on the transfer mechanisms those providers offer, such as the European Commission's standard contractual clauses. KRONENWERK does not claim any certification or adequacy status of its own.

8. How long information is kept

  • Account and company information: for as long as the account exists.
  • Records created in the software: for as long as the business keeps its account. Businesses are subject to their own statutory retention periods for accounting records, which they must observe; KRONENWERK does not delete accounting records on its own initiative.
  • Issued invoices: preserved as issued for the life of the account. Correction is by credit note, not by alteration.
  • Subscription tax records: retained for the period tax law requires the provider to keep them.
  • Sign-in and verification codes, reset tokens: expire within fifteen minutes to one hour; the expired records are not used afterwards.
  • Trusted-device tokens: 60 days.
  • Server logs: retained by the hosting provider for a limited operational period.

9. Deletion, and what must be kept

After a subscription ends, you keep sign-in access for a retrieval period of at least 30 days to export your records (Settings → Data export produces a complete archive of your company's records at any time). After that, information KRONENWERK no longer needs and is not required to keep may be deleted or anonymised. KRONENWERK does not guarantee erasure from every backup on a specific day; backups expire on their own schedule, and deleted information is not used in the meantime.

What is kept regardless. KRONENWERK's own tax and billing record of your subscription, for the period tax law requires the provider to keep it; security and audit records, which are append-only; and whatever our service providers retain under their own terms. Stripe keeps its own records of payments it processed.

Accounts that were never used. An account with no issued documents, no payments and no additional members can be removed entirely, including its company and membership, on request.

Accounts with accounting history. Issued invoices and accounting entries are records the business is legally required to retain and that KRONENWERK cannot alter or destroy on request. Where the law grants you a right to erasure, KRONENWERK removes the personal references it can — for example, the link between you as a person and KRONENWERK's internal security and analytics events, which then remain as anonymous events — while preserving the accounting records themselves.

10. Your rights

Depending on where you are located, you may have the right to: access the personal information KRONENWERK holds about you; have it corrected; have it deleted; restrict or object to its processing; receive it in a portable form; and withdraw consent where processing is based on consent. Where the GDPR applies, you also have the right to lodge a complaint with a supervisory authority. Where Québec's Act respecting the protection of personal information in the private sector applies, you may address a complaint to the Commission d'accès à l'information du Québec.

To exercise these rights, contact the provider using the details in the Legal Notice. Requests concerning information a business has entered about you as its customer or supplier should be directed to that business.

11. Security

Described factually and without guarantees: passwords are hashed with Argon2id; sign-in codes, reset tokens, device tokens and API keys are stored only as one-way hashes; integration credentials are stored encrypted; all traffic is served over TLS with HTTP Strict Transport Security and a Content Security Policy that loads nothing from third-party hosts; a code sent to your email address is required when you sign in with a password from a device that has not been confirmed before, and a confirmed device is remembered for 60 days unless the password changes; a password change ends every other session; issued documents, subscription tax records, legal-acceptance records and security and operator audit records are append-only, enforced by the database. No system is immune to compromise, and KRONENWERK does not represent otherwise. KRONENWERK holds no security certification and this policy makes no claim of compliance with any certification scheme.

12. Children

KRONENWERK is business software and is not directed at children. It does not knowingly collect information from anyone under the age at which they can lawfully enter into a business contract in their jurisdiction.

13. Changes to this policy

Each version of this policy carries a version identifier and an effective date at the top of the page. A materially changed version will be published here before it takes effect. The English text is the authoritative version; translations, where provided, are for convenience.