Security & Data Processing
Last updated: May 6, 2026
This page summarizes how Kropee (“we”, “us”) approaches security and data processing for customers and visitors. It is provided for transparency and convenience only and does not replace our [Privacy Policy](/privacy) or [Terms of Service](/terms).
1. Roles
Depending on the context, we may act as a controller of personal data (for example, account and billing information) or as a processor where we process personal data on behalf of customers to provide the Service. The [Privacy Policy](/privacy) describes categories of data and purposes in more detail.
2. Security measures
We implement administrative, technical, and organizational measures appropriate to the nature of the Service, which may include:
- Encryption of data in transit (such as HTTPS/TLS) between your browser and our systems.
- Access controls and authentication for production systems and administrative operations.
- Vendor diligence for subprocessors that host infrastructure or process payments.
- Monitoring and logging appropriate to detect and respond to incidents.
No method of transmission or storage is completely secure; we cannot guarantee absolute security.
3. Subprocessors
We rely on trusted third-party providers (for example, hosting, authentication, payment processing, and email delivery). A current list may be provided upon request for enterprise customers or as required by contract.
4. Data Processing Agreement (DPA)
Business customers who require a Data Processing Agreement or Standard Contractual Clauses for transfers of personal data subject to the GDPR or similar regimes should email [false](mailto:false) with your company name, role, and jurisdiction. We will respond regarding availability and execution.
5. International transfers
If personal data is transferred across borders, we rely on appropriate safeguards permitted by applicable law (such as SCCs or adequacy decisions, where applicable).
6. Incident notification
If we become aware of a breach that materially affects personal data and requires notification under applicable law, we will take steps to notify authorities and affected individuals as required.
7. Your rights
Individuals may have rights to access, rectify, delete, restrict, or object to certain processing, and to lodge a complaint with a supervisory authority. See our [Privacy Policy](/privacy) for how to exercise these rights.
8. Contact
Security inquiries (non-billing): use [Contact](/contact-us) or [false](mailto:false) where appropriate for privacy and DPA requests.
