Privacy Policy

Effective Date: 01.07.2026

Last Updated: 21.09.2026

Controller: Behman & Bergman Ltd, a company registered in the Republic of Latvia, operator of Krot (krot.io), Riga, Republic of Latvia.

Privacy contact: [email protected]

Opt-Out Form: https://krot.io/privacy/remove

1. Introduction

This Privacy Policy describes how Krot (“Krot,” “we,” “our,” or “us”) collects, uses, discloses, and otherwise processes information in connection with our websites, platform, applications, APIs, and related services (collectively, the “Services”).

This policy applies to information we process:

Our role. For account, billing, website, and security data we act as the controller. When a customer uploads or manages their own contact lists, campaigns, and mailboxes in the Services, that customer is the controller and we act as a processor on their instructions under our Data Processing Addendum (Section 16). Where we independently source business contact data from public and third-party sources, we act as a controller for that sourcing.

2. Information We Collect

We collect information from and about you and others in a business context, including the categories below.

2.1 Information users provide

Information you (or your organization) may provide includes:

2.2 Business contact data processed

Our Services may process business contact data in connection with email verification, lead enrichment, prospecting workflows, and related features. Depending on the feature used and data provided, this may include:

2.3 Mailbox data from connected accounts

When a user connects a mailbox (Google Workspace/Gmail or Microsoft 365/Outlook), we process the outbound messages that user composes and schedules in Krot, and inbound replies to those messages, in order to detect replies, stop follow-ups, and surface unsubscribe requests. See Sections 7 and 8.

2.4 Usage, log, and device data

When you access or use the Services, we collect information such as:

2.5 Cookies and tracking technologies

We and our service providers use cookies and similar technologies (such as local storage and pixels) to provide, secure, personalize, and analyze the Services. See Section 10 (Cookies Policy) for details.

2.6 Krot browser extension

If you install the Krot browser extension, we additionally process:

What the extension does not do. It reads the page address only. It does not read, copy, or transmit the content of pages you visit, and it does not use your LinkedIn account or session to retrieve anything. The profile and contact details shown in the extension come from Krot's own database and the sources described in Section 5.

3. How We Use Information

We use information we collect for purposes that include:

3.1 Service delivery

To operate, maintain, and provide the Services, including:

3.2 Email verification

To provide email verification capabilities, including:

3.3 Lead enrichment and prospecting workflows

To provide enrichment and workflow features, including:

3.4 Fraud prevention and security

To protect the Services, users, and third parties, including:

3.5 Analytics and product improvement

To understand usage and improve the Services, including:

We do not use mailbox content from connected Google or Microsoft accounts for analytics or product improvement.

3.6 Legal compliance

To comply with legal obligations and respond to lawful requests, including:

4. Legal Bases for Processing (GDPR)

Where the GDPR or similar laws apply, our legal bases for processing are:

Where a customer uses the Services to process contact data, that customer is responsible for establishing a lawful basis for their own outreach.

5. Sources of Data

We may obtain information from the following sources:

Where we obtain your business contact information from a source other than you, Section 17 (GDPR Article 14 notice) explains what we collect, why, and how to exercise your rights.

6. Sharing of Information

We may disclose information in the following circumstances:

6.1 Service providers and subprocessors

We share information with vendors and service providers that process information on our behalf to help us provide the Services (for example, hosting, storage, email delivery, payments, and security monitoring). Each is bound by a written data processing agreement and may process data only on our documented instructions. Our current subprocessors are listed in Section 14.

6.2 Customers using the platform

When our customers use the Services, we may process and make available information (including business contact data and verification/enrichment outputs) as directed by the customer, including to the customer’s authorized users.

6.3 Legal disclosures

We may disclose information if we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request, or is necessary to protect the rights, property, or safety of Krot, our users, or others.

6.4 Corporate transactions

We may share information in connection with a corporate transaction, such as a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. Any disclosure will be subject to appropriate confidentiality and security measures.

6.5 No sale of personal information

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

7. Google User Data and Limited Use

When you connect a Google (Gmail) account, Krot requests only the permissions below, each tied to a specific user-facing feature:

If you choose to sign in to Krot with Google, we also receive your name, email address, and Google account identifier, which we use only to create and authenticate your Krot account.

7.1 Google user data we access

Krot never modifies, labels, archives, deletes, or otherwise organizes messages in your mailbox.

7.2 How we use Google user data

Reply detection and classification run entirely within Krot's own infrastructure using deterministic keyword rules; the content of your emails is never sent to any third-party AI system.

7.3 How we store and protect Google user data

Your Google OAuth access and refresh tokens are encrypted at rest (AES-256-GCM) and are used only by Krot's servers. Google user data is stored on our servers in the European Union (see Section 14), protected by the measures described in Section 12, and is accessible only to the users of your Krot workspace.

7.4 How we share Google user data

We do not sell Google user data and do not use it for advertising. We share it only with the service providers that host our infrastructure on our behalf (Section 14), when required by law, or as part of a merger or acquisition with appropriate safeguards. We never share it with data brokers, advertisers, or AI model providers.

7.5 Retention and deletion of Google user data

7.6 Limited Use

Krot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

8. Microsoft 365 Mailbox Data

When you connect a Microsoft 365 / Outlook account, Krot requests the minimum Microsoft Graph permissions needed for the same two features:

Krot does not request write, delete, or mailbox-management permissions and never modifies, moves, or deletes messages in your mailbox. Microsoft mailbox content is handled under the same rules stated in Section 7: deterministic reply classification inside our own infrastructure, no transfer to any third-party AI system, no use for model training, no advertising use, tokens encrypted at rest, and deletion of stored tokens when you disconnect the mailbox. You can also revoke access at any time from your Microsoft account's My Account → Privacy → Apps and services settings.

9. Privacy Rights

Depending on your location and applicable law, you have rights regarding your personal data. These include:

To exercise any of these rights, contact [email protected] or use the opt-out form at https://krot.io/privacy/remove. We respond within 30 days, and may extend by a further two months for complex requests, telling you why. We may need to verify your identity and/or authority (for example, if you are acting on behalf of an organization) before responding. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

If you are a data subject whose information a customer uploaded into the Services, we act as a processor for that data. We will forward your request to the relevant customer and assist them in responding.

9.1 Right to lodge a complaint

If you are in the EEA or UK, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Data State Inspectorate of Latvia (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, Latvia — https://www.dvi.gov.lv. You may also complain to the authority in your country of residence or workplace.

9.2 California privacy rights (CCPA/CPRA)

If you are a California resident, you may have the right to request information about our collection, use, and disclosure of personal information; request deletion; request correction; and opt out of certain processing as defined by applicable law. We do not sell or share personal information as those terms are defined by the CPRA. We will not discriminate against you for exercising your rights.

9.3 Business contact opt-out rights

If your business contact information appears in or is processed by our Services, you may request to opt out at https://krot.io/privacy/remove.

Upon a verified opt-out request, we remove your profile from our Services and retain your email address only in a suppression list, so that we can honor your opt-out and prevent your data from being re-added.

10. Cookies Policy

We use cookies and similar technologies for:

You can control cookies through your browser settings. If you disable cookies, parts of the Services may not function properly.

11. Data Retention

We retain information only as long as necessary for the purposes it was collected for. In practice:

Where a customer is the controller, retention follows that customer's instructions and their agreement with us.

12. Security Measures

We maintain administrative, technical, and organizational measures designed to protect information, including access controls and role-based permissions, encryption in transit (TLS), encryption at rest for mailbox OAuth tokens and mailbox credentials, multi-factor authentication for accounts, a strict Content Security Policy, CSRF protections, audit logging of security-relevant events, and monitoring for suspicious activity. No method of transmission or storage is completely secure, and security measures cannot guarantee absolute protection. We assess and, where applicable, notify supervisory authorities and affected individuals of personal data breaches in accordance with GDPR Articles 33 and 34.

13. International Transfers

Our primary infrastructure is hosted in the European Union. Some subprocessors listed in Section 14 process data outside the EEA (including in the United States). Where we transfer personal data outside the EEA or UK, we rely on lawful transfer mechanisms, principally the European Commission's Standard Contractual Clauses (SCCs) together with supplementary technical and organizational measures, or an adequacy decision where one applies. You can request further information about these safeguards at [email protected].

14. Subprocessors

We currently use the following subprocessors to provide the Services:

SubprocessorPurposeLocation
Hetzner Online GmbHApplication and database hostingGermany (EU)
Google LLC / Google Ireland LtdGmail API for connected mailboxes, Cloud Pub/Sub for reply notifications, Firebase Authentication for sign-inEU / US
Microsoft CorporationMicrosoft Graph API for connected Microsoft 365 mailboxesEU / US
Stripe, Inc.Payment and subscription processingUS / EU
OpenRouter, Inc.Routing of company-level lookup queries to language-model providers (see Section 15)US

We will update this list when subprocessors change. Customers with a signed DPA may request advance notice of changes by writing to [email protected].

15. AI and Automated Processing

We use language models for one narrow purpose: resolving a company name to its official website domain and its industry classification, so that company records are complete and correctly categorized. These queries are routed via OpenRouter to third-party models (currently Perplexity Sonar and DeepSeek models).

16. Data Processing Addendum (DPA)

Where we process personal data on a customer's behalf, our Data Processing Addendum applies. It incorporates the GDPR Article 28 terms and, where relevant, the Standard Contractual Clauses. Request a copy at [email protected].

17. GDPR Article 14 Notice (Sourced Business Contacts)

Where we obtain your business contact information from a source other than you, this section is our Article 14 notice:

18. Third-Party Integrations

The Services may allow you to connect third-party integrations (for example, mailbox providers, identity providers, and other tools). When enabled, information may be shared with or obtained from those third parties as part of the integration. Third-party services process information according to their own policies and terms.

LinkedIn. The Krot browser extension runs on LinkedIn profile pages that you visit. Krot is not affiliated with, endorsed by, or sponsored by LinkedIn. We do not access your LinkedIn account, credentials, or session, and we do not extract content from LinkedIn pages; the extension reads only the address of the profile page you choose to look up.

19. Children's Privacy

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children.

20. Additional Disclosures for Email Verification Services

Email addresses submitted to the Services for verification are processed solely for verification purposes (including deliverability and risk assessment) and are not used for marketing by Krot unless separately authorized by the submitting customer or user through a distinct lawful basis.

21. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy and update the “Last Updated” date above. Where changes are material, we will provide additional notice through the Services or by email.

22. Contact Information

If you have questions or wish to exercise your privacy rights, contact us at [email protected], or write to Behman & Bergman Ltd, Riga, Republic of Latvia.