Privacy Policy
Privacy Policy
Last updated: 28 June 2026
1. Who We Are
YKRAFT ("we", "us", "our") provides a self-hosted operations platform available at
ykraft.tech. YKRAFT is currently run as an individual undertaking and is **not yet
registered as a business; a business registration in Poland (EU)** is in progress. It
is pre-launch and does not take payments yet.
For the purposes of the EU/UK General Data Protection Regulation (GDPR), the **data
controller** for the personal data described in this policy is:
- YKRAFT — currently an individual undertaking, registering as a business in Poland (EU)
- Contact: privacy@ykraft.tech
_Once YKRAFT is registered in Poland, this section will be updated with the registered
company name and address. In the meantime, contact us at the email above to ask about or
exercise any of your rights._
If you have any questions about this policy or how we handle your data, email us at
the address above.
2. Our Data-Ownership Model (Please Read First)
YKRAFT runs on a deliberate hybrid model, and we want to be precise about it because
it's the whole point of the product:
- Your operational business data lives in _your_ database and _your_ storage — a
PostgreSQL database and S3-compatible object storage that you own and control.
- YKRAFT never persists that operational data on our servers. We do not keep a
copy of it.
- The application processes your data in memory to function — to render your
pages, run your tickets, manage your devices, search your documents, and so on,
exactly like any application you would self-host. This processing is transient: it
happens in memory while the app serves your request, and is not written to
YKRAFT-controlled storage.
- You can revoke access or move providers at any time. Because the data layer is
yours, you are never locked in and nobody can hold your data hostage.
This policy covers the personal data YKRAFT itself acts as controller for — your
account, billing, support, and lead/enquiry information (Sections 3–8). It does not
turn your own database and storage contents into data we control; for that operational
data, you remain the controller and YKRAFT acts only as a transient processor on
your instructions.
3. What We Collect
3.1 Account data
- Email address — authentication and essential service communication.
- Name — account identification.
- Workspace / configuration settings — how you've set up your instance.
- Authentication metadata — login timestamps and session information, handled via
our identity provider (Keycloak).
3.2 Lead / enquiry data (the "Apply to work together" form)
When you submit the early-access / contact form on ykraft.tech, we collect what you
provide: **name, email, country, role, number of devices or clients managed, current
tools, the problem you're trying to solve, and how you heard about us**. We use this
solely to evaluate and follow up on a potential working relationship.
3.3 Billing data
If and when paid plans apply to your account, payment is processed by Stripe. We do
not store full card details; Stripe processes them as an independent processor. _(If you
are not on a paid plan, no billing data is collected.)_
3.4 Technical data
- Session cookie (
connect.sid) — strictly necessary to keep you logged in. - Basic server logs — IP address, browser/user-agent, and request metadata, kept
for security and to operate the service.
3.5 What we do not collect
We do not collect, persist, or mine your operational business data — your
documents, tickets, device inventory, files, or records. That data lives in your own
database and storage as described in Section 2.
4. How We Use Your Data and Our Legal Basis
We do not use your data for advertising and we do not sell it.
5. Sub-processors
We rely on a small number of service providers to operate YKRAFT. Each processes
personal data only on our instructions:
- OVHcloud — application hosting / infrastructure (VPS in France, EU)
- Keycloak — authentication (self-hosted by us)
- Namecheap Private Email — transactional email and notifications
- Stripe — payment processing (only once paid plans are offered)
- AI provider (optional) — AI search and assistant features, when enabled, use the AI
provider configured for your workspace. If no AI provider is configured, no data is sent
to any AI service.
Device management (Device Desk): remote-device data and remote sessions flow
through a MeshCentral server that you operate, not through YKRAFT-hosted storage.
6. International Data Transfers
Your application data is hosted within the EU (OVHcloud, France). Some providers — for
example email delivery, or a payment or AI provider you enable — may be located outside
the EEA/UK. Where they are, transfers are made under appropriate safeguards (Standard
Contractual Clauses / a UK IDTA, or an adequacy decision).
7. Data Retention
- Account data — kept while your account is active and for 30 days after closure,
then deleted or anonymised.
- Lead / enquiry data — kept for up to 24 months unless we begin working together
(in which case it becomes account data), or you ask us to delete it sooner.
- Billing records — kept as required by tax/accounting law (typically 5 years in
Poland / 6 years in the UK).
- Server logs — kept for up to 90 days for security.
8. Your Rights (GDPR)
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict or object to our processing
- Port your data (receive it in a structured, machine-readable format)
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your supervisory authority — in Poland, the **President of
the Personal Data Protection Office (UODO); in the UK, the Information
Commissioner's Office (ICO)**
To exercise any of these rights, email privacy@ykraft.tech. We respond within the
timeframes required by law (generally one month).
9. Cookies
YKRAFT uses a small set of strictly necessary and functional cookies — for
authentication (connect.sid) and to remember your language, theme, and layout
preferences. We use no analytics, advertising, or cross-site tracking cookies. As
these are essential or preference cookies set in response to your own actions, they do
not require prior consent under GDPR/ePrivacy. See the Cookie Policy
for the full list.
10. Security
We protect personal data with industry-standard measures including encryption in
transit (HTTPS), authenticated access (OIDC/Keycloak), and least-privilege access
controls. No system is perfectly secure, but we work to keep your account data safe and
to keep your operational data where it belongs — in your own infrastructure.
11. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top reflects
the latest version, and we will notify you of material changes by email or in-app.
12. Contact
Questions, requests, or complaints about your personal data:
privacy@ykraft.tech