Privacy Policy

Privacy Policy

Last updated: 28 June 2026

1. Who We Are

YKRAFT ("we", "us", "our") provides a self-hosted operations platform available at

ykraft.tech. YKRAFT is currently run as an individual undertaking and is **not yet

registered as a business; a business registration in Poland (EU)** is in progress. It

is pre-launch and does not take payments yet.

For the purposes of the EU/UK General Data Protection Regulation (GDPR), the **data

controller** for the personal data described in this policy is:

  • YKRAFT — currently an individual undertaking, registering as a business in Poland (EU)
  • Contact: privacy@ykraft.tech

_Once YKRAFT is registered in Poland, this section will be updated with the registered

company name and address. In the meantime, contact us at the email above to ask about or

exercise any of your rights._

If you have any questions about this policy or how we handle your data, email us at

the address above.

2. Our Data-Ownership Model (Please Read First)

YKRAFT runs on a deliberate hybrid model, and we want to be precise about it because

it's the whole point of the product:

  • Your operational business data lives in _your_ database and _your_ storage — a

PostgreSQL database and S3-compatible object storage that you own and control.

  • YKRAFT never persists that operational data on our servers. We do not keep a

copy of it.

  • The application processes your data in memory to function — to render your

pages, run your tickets, manage your devices, search your documents, and so on,

exactly like any application you would self-host. This processing is transient: it

happens in memory while the app serves your request, and is not written to

YKRAFT-controlled storage.

  • You can revoke access or move providers at any time. Because the data layer is

yours, you are never locked in and nobody can hold your data hostage.

This policy covers the personal data YKRAFT itself acts as controller for — your

account, billing, support, and lead/enquiry information (Sections 3–8). It does not

turn your own database and storage contents into data we control; for that operational

data, you remain the controller and YKRAFT acts only as a transient processor on

your instructions.

3. What We Collect

3.1 Account data

  • Email address — authentication and essential service communication.
  • Name — account identification.
  • Workspace / configuration settings — how you've set up your instance.
  • Authentication metadata — login timestamps and session information, handled via

our identity provider (Keycloak).

3.2 Lead / enquiry data (the "Apply to work together" form)

When you submit the early-access / contact form on ykraft.tech, we collect what you

provide: **name, email, country, role, number of devices or clients managed, current

tools, the problem you're trying to solve, and how you heard about us**. We use this

solely to evaluate and follow up on a potential working relationship.

3.3 Billing data

If and when paid plans apply to your account, payment is processed by Stripe. We do

not store full card details; Stripe processes them as an independent processor. _(If you

are not on a paid plan, no billing data is collected.)_

3.4 Technical data

  • Session cookie (connect.sid) — strictly necessary to keep you logged in.
  • Basic server logs — IP address, browser/user-agent, and request metadata, kept

for security and to operate the service.

3.5 What we do not collect

We do not collect, persist, or mine your operational business data — your

documents, tickets, device inventory, files, or records. That data lives in your own

database and storage as described in Section 2.

4. How We Use Your Data and Our Legal Basis

We do not use your data for advertising and we do not sell it.

5. Sub-processors

We rely on a small number of service providers to operate YKRAFT. Each processes

personal data only on our instructions:

  • OVHcloud — application hosting / infrastructure (VPS in France, EU)
  • Keycloak — authentication (self-hosted by us)
  • Namecheap Private Email — transactional email and notifications
  • Stripe — payment processing (only once paid plans are offered)
  • AI provider (optional) — AI search and assistant features, when enabled, use the AI

provider configured for your workspace. If no AI provider is configured, no data is sent

to any AI service.

Device management (Device Desk): remote-device data and remote sessions flow

through a MeshCentral server that you operate, not through YKRAFT-hosted storage.

6. International Data Transfers

Your application data is hosted within the EU (OVHcloud, France). Some providers — for

example email delivery, or a payment or AI provider you enable — may be located outside

the EEA/UK. Where they are, transfers are made under appropriate safeguards (Standard

Contractual Clauses / a UK IDTA, or an adequacy decision).

7. Data Retention

  • Account data — kept while your account is active and for 30 days after closure,

then deleted or anonymised.

  • Lead / enquiry data — kept for up to 24 months unless we begin working together

(in which case it becomes account data), or you ask us to delete it sooner.

  • Billing records — kept as required by tax/accounting law (typically 5 years in

Poland / 6 years in the UK).

  • Server logs — kept for up to 90 days for security.

8. Your Rights (GDPR)

You have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten")
  • Restrict or object to our processing
  • Port your data (receive it in a structured, machine-readable format)
  • Withdraw consent at any time, where processing is based on consent
  • Lodge a complaint with your supervisory authority — in Poland, the **President of

the Personal Data Protection Office (UODO); in the UK, the Information

Commissioner's Office (ICO)**

To exercise any of these rights, email privacy@ykraft.tech. We respond within the

timeframes required by law (generally one month).

9. Cookies

YKRAFT uses a small set of strictly necessary and functional cookies — for

authentication (connect.sid) and to remember your language, theme, and layout

preferences. We use no analytics, advertising, or cross-site tracking cookies. As

these are essential or preference cookies set in response to your own actions, they do

not require prior consent under GDPR/ePrivacy. See the Cookie Policy

for the full list.

10. Security

We protect personal data with industry-standard measures including encryption in

transit (HTTPS), authenticated access (OIDC/Keycloak), and least-privilege access

controls. No system is perfectly secure, but we work to keep your account data safe and

to keep your operational data where it belongs — in your own infrastructure.

11. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top reflects

the latest version, and we will notify you of material changes by email or in-app.

12. Contact

Questions, requests, or complaints about your personal data:

privacy@ykraft.tech