Privacy.

Last updated: 19 August 2026

This policy explains what personal data Kalnov collects, why, how long we keep it, and how you can exercise your rights over it. If anything is unclear, email privacy@kalnov.com.

Who we are.

Kalnov is operated by TektonOperations Limited, a Hong Kong company registered at Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong. TektonOperations Limited is the data controller for all personal data described below.

Two frameworks apply to what we do. As a Hong Kong company we are a “data user” under the Personal Data (Privacy) Ordinance (Cap. 486). Because we offer services to residents of the European Union and the United Kingdom, the EU / UK GDPR also applies to our processing of their data under Article 3(2). This policy names the rights and safeguards under both.

Data we collect, by feature.

When you sign up.

Name and email, so we can identify your account and contact you about it. Password, stored only as a bcrypt hash (cost factor 12). We never see or store your password in a readable form.

Lawful basis: contract (Article 6(1)(b) GDPR, Principle 1 PDPO). We need these to provide the account you signed up for.

Retention: for as long as the account exists, plus a short technical grace period after deletion for backups to age out.

When you use the invoicing tools.

Business details you enter yourself (business name, address, currency, invoice prefix). Client records you create: the client company name, contact email, address, and registration number. Invoice content: line items, amounts, dates, notes. Payment records: the date each invoice was paid, and any voids with reasons.

Your business logo, if you upload one. Stored in our database, embedded only into the PDF invoices and invoice emails you generate for your own clients. Served over a public URL keyed by your user id so that email clients can display it in your recipients’ inboxes (email clients block authenticated image loads). Never used elsewhere in the product, never sent to any third party beyond our database processor (Neon). Deleted with your account.

Lawful basis: contract. Invoicing is the service.

Retention: while your account exists. When you delete your account, invoices and payment records are retained in anonymised form (see Payment scores below); client contact details, invoice notes, and your business logo are permanently erased.

When you view company scores.

Lookup logs: which company page you opened and when. Used for the Recently viewed list on your companies page and for rate limiting (500 lookups per hour on the paid tier to prevent bulk export).

Lawful basis: legitimate interest (running the product and preventing abuse). Balanced against your interest by keeping the logs minimal (no user agent, no IP) and clearing them when your account is deleted.

Retention: while your account exists.

Payment scores (the network score).

Company payment scores are derived from users’ invoices and payment records. The score is data about a company. Companies are not natural persons under Article 4(1) GDPR or under the PDPO, so the aggregate score itself is not personal data.

The underlying payment records that feed a score reference the user who logged them. When you delete your account we sever the direct link to you (the user row is anonymised) but the records themselves are kept so the aggregate scores you contributed to remain accurate. In GDPR terms this is pseudonymised personal data retained on the lawful basis of legitimate interest in the integrity of the dataset.

If you want the underlying records fully deleted, which will cause any affected scores to recompute and may cause them to drop, email privacy@kalnov.com and we will do it manually.

When you dispute a score.

Your name, email, the claim you write, and a salted hash of your IP address plus your user agent.

Lawful basis: legitimate interest in defending the accuracy of published data and detecting abuse. Balanced by hashing the IP rather than storing it, and by deleting IP hashes after 12 months.

Retention: dispute records for as long as the underlying score is public. IP hashes and user agents: 12 months. Per-IP rate-limit counters: 30 days.

When you subscribe.

Stripe customer ID, subscription ID, subscription status, current period end. Payment card details are handled by Stripe directly and never touch our servers.

Lawful basis: contract and legal obligation (financial record-keeping).

Retention: while your subscription exists. The Stripe records themselves are retained by Stripe under their own retention rules.

Cookies.

We set exactly one cookie: kalnov_session, a JWT session cookie required for login. This is a strictly-necessary cookie and no consent is required under the ePrivacy Directive.

We use no analytics cookies, no advertising cookies, and no third-party trackers.

Who receives your data.

We use these processors, each with its own Data Processing Agreement.

ProcessorWhat they receiveLocation
Neon
DPA
The full database: user rows, clients, invoices, payment events, dispute records, lookup logs.EU (Frankfurt, AWS eu-central-1)
Vercel
DPA
Every HTTP request, incidentally IP address and user agent. Function logs contain user IDs and Stripe references.EU + US (edge network)
Resend
DPA
Recipient email address plus the body of transactional emails (verification, password reset, dispute resolution).EU
Stripe
DPA
Only if you subscribe: email, name, billing address (required for VAT), payment method, and the subscription lifecycle.EU + US

We do not sell your data. We do not use it for advertising. We do not share it with anyone outside the list above.

International transfers.

TektonOperations Limited is based in Hong Kong. Our primary database (Neon) is in Frankfurt. Vercel and Stripe operate infrastructure in the United States as well as the EU.

Where personal data is transferred out of the UK or EEA, the transfer is protected by the European Commission’s Standard Contractual Clauses, each processor’s supplementary technical measures, and, for transfers to Hong Kong, our own commitment to process the data in accordance with GDPR-equivalent standards.

Your rights.

Under both GDPR and the Hong Kong PDPO you have the right to:

  • Access the personal data we hold about you.
  • Correction of inaccurate data.
  • Erasure. Delete your account directly from Settings → Delete account. See Payment scores above for what stays anonymised; full erasure of the underlying records requires an email to us.
  • Restriction of processing (GDPR).
  • Portability: a copy of the data you have provided (GDPR).
  • Objection to processing based on legitimate interest (GDPR).
  • Complaint. In Hong Kong, to the Office of the Privacy Commissioner for Personal Data. In the UK, to the Information Commissioner’s Office. In the EU, to your national data protection authority.

To exercise any right other than deletion, email privacy@kalnov.com. We aim to respond within one calendar month.

Security.

Passwords are stored as bcrypt hashes with a cost factor of 12. Session cookies are HTTP-only, marked Secure in production, and expire after 30 days. All traffic between your browser and our servers, and between our servers and the database, is encrypted with TLS. Database connections require both the correct credentials and TLS channel binding.

Changes to this policy.

We may update this policy. When we do, the last-updated date at the top of this page changes. Please check back periodically. If a change materially reduces your rights or expands how we use your data, we will make reasonable efforts to draw attention to it in the product before it takes effect.