Privacy Policy
Effective Date: 01.07.2026
Last Updated: 21.09.2026
Controller: Behman & Bergman Ltd, a company registered in the Republic of Latvia, operator of Krot (krot.io), Riga, Republic of Latvia.
Privacy contact: [email protected]
Opt-Out Form: https://krot.io/privacy/remove
1. Introduction
This Privacy Policy describes how Krot (“Krot,” “we,” “our,” or “us”) collects, uses, discloses, and otherwise processes information in connection with our websites, platform, applications, APIs, and related services (collectively, the “Services”).
This policy applies to information we process:
- when you visit our websites or use the Services as an end user or administrator;
- when our customers use the Services to upload, verify, enrich, organize, and act on business contact data; and
- when we process business contact data about individuals in a professional context (for example, work email addresses and business profile information).
Our role. For account, billing, website, and security data we act as the controller. When a customer uploads or manages their own contact lists, campaigns, and mailboxes in the Services, that customer is the controller and we act as a processor on their instructions under our Data Processing Addendum (Section 16). Where we independently source business contact data from public and third-party sources, we act as a controller for that sourcing.
2. Information We Collect
We collect information from and about you and others in a business context, including the categories below.
2.1 Information users provide
Information you (or your organization) may provide includes:
- Account and profile information (e.g., name, business email address, password or authentication credentials, role, and workspace settings).
- Billing and subscription information (e.g., billing contact details, payment-related data processed by our payment providers, subscription plan details, invoices, and tax information where applicable).
- Support and communications (e.g., messages to support, feedback, requests, and other communications).
- Configuration and content you submit to the Services (e.g., lists, campaign settings, suppression preferences, and workflow configuration).
2.2 Business contact data processed
Our Services may process business contact data in connection with email verification, lead enrichment, prospecting workflows, and related features. Depending on the feature used and data provided, this may include:
- Identifiers and professional details (e.g., name, work email address, job title, employer/company, department, seniority, and business phone number).
- Business profile information (e.g., company domain, industry, location, and publicly available professional profile URLs).
- Enrichment and verification metadata (e.g., validation results, deliverability indicators, risk signals, and associated timestamps).
2.3 Mailbox data from connected accounts
When a user connects a mailbox (Google Workspace/Gmail or Microsoft 365/Outlook), we process the outbound messages that user composes and schedules in Krot, and inbound replies to those messages, in order to detect replies, stop follow-ups, and surface unsubscribe requests. See Sections 7 and 8.
2.4 Usage, log, and device data
When you access or use the Services, we collect information such as:
- Usage data (e.g., features used, actions taken, pages viewed, and the dates/times of access).
- Log data (e.g., IP address, request identifiers, error logs, and diagnostic information).
- Device and browser data (e.g., device type, operating system, browser type, and language settings).
2.5 Cookies and tracking technologies
We and our service providers use cookies and similar technologies (such as local storage and pixels) to provide, secure, personalize, and analyze the Services. See Section 10 (Cookies Policy) for details.
2.6 Krot browser extension
If you install the Krot browser extension, we additionally process:
- The address of the professional profile page you are viewing. The extension is active only on LinkedIn profile and company pages, and sends us the page address only for a profile you explicitly open the Krot panel on, so that we can look that person up in your Krot workspace. We do not receive your browsing history.
- A device token stored locally in your browser so that you stay signed in to the extension. It is not your password, is scoped to the extension alone, and can be revoked at any time from your Krot account.
What the extension does not do. It reads the page address only. It does not read, copy, or transmit the content of pages you visit, and it does not use your LinkedIn account or session to retrieve anything. The profile and contact details shown in the extension come from Krot's own database and the sources described in Section 5.
3. How We Use Information
We use information we collect for purposes that include:
3.1 Service delivery
To operate, maintain, and provide the Services, including:
- creating and managing accounts and workspaces;
- processing requests and transactions;
- enabling core functionality such as list management, workflows, integrations, and APIs; and
- providing customer support and responding to inquiries.
3.2 Email verification
To provide email verification capabilities, including:
- validating formatting and deliverability signals;
- identifying risk patterns and potential abuse; and
- providing verification results to customers through the Services and APIs.
3.3 Lead enrichment and prospecting workflows
To provide enrichment and workflow features, including:
- appending and normalizing business contact attributes;
- improving data quality, deduplication, and matching; and
- supporting customer-managed prospecting workflows.
3.4 Fraud prevention and security
To protect the Services, users, and third parties, including:
- detecting and preventing fraud, abuse, and suspicious activity;
- enforcing usage policies and contractual terms; and
- securing accounts, infrastructure, and communications.
3.5 Analytics and product improvement
To understand usage and improve the Services, including:
- measuring performance and reliability;
- developing new features;
- debugging and quality assurance; and
- generating aggregated or de-identified analytics.
We do not use mailbox content from connected Google or Microsoft accounts for analytics or product improvement.
3.6 Legal compliance
To comply with legal obligations and respond to lawful requests, including:
- maintaining appropriate records;
- handling privacy rights requests; and
- establishing, exercising, or defending legal claims.
4. Legal Bases for Processing (GDPR)
Where the GDPR or similar laws apply, our legal bases for processing are:
- Performance of a contract (Art. 6(1)(b)): to provide the Services as agreed with our customers or with you, including account management and billing.
- Legitimate interests (Art. 6(1)(f)): to operate, secure, and improve the Services; prevent fraud; maintain reliability; and support B2B verification, enrichment, and prospecting capabilities requested by customers. We balance these interests against your rights and freedoms, and you may object at any time (Section 9).
- Compliance with a legal obligation (Art. 6(1)(c)): to meet applicable legal, tax, and accounting requirements.
- Consent (Art. 6(1)(a)): where required by law for specific processing activities (for example, non-essential cookies or marketing communications). You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Where a customer uses the Services to process contact data, that customer is responsible for establishing a lawful basis for their own outreach.
5. Sources of Data
We may obtain information from the following sources:
- Direct collection from users and customers (including administrators and authorized users).
- Public sources that make business information available (e.g., company websites and publicly available professional information).
- Third-party providers that supply business contact, enrichment, or verification-related data.
- Customer-uploaded data (e.g., lists and CSV uploads).
- Integrations enabled by customers or users (e.g., connected mailboxes, identity providers, and third-party tools).
Where we obtain your business contact information from a source other than you, Section 17 (GDPR Article 14 notice) explains what we collect, why, and how to exercise your rights.
6. Sharing of Information
We may disclose information in the following circumstances:
6.1 Service providers and subprocessors
We share information with vendors and service providers that process information on our behalf to help us provide the Services (for example, hosting, storage, email delivery, payments, and security monitoring). Each is bound by a written data processing agreement and may process data only on our documented instructions. Our current subprocessors are listed in Section 14.
6.2 Customers using the platform
When our customers use the Services, we may process and make available information (including business contact data and verification/enrichment outputs) as directed by the customer, including to the customer’s authorized users.
6.3 Legal disclosures
We may disclose information if we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request, or is necessary to protect the rights, property, or safety of Krot, our users, or others.
6.4 Corporate transactions
We may share information in connection with a corporate transaction, such as a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets. Any disclosure will be subject to appropriate confidentiality and security measures.
6.5 No sale of personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
7. Google User Data and Limited Use
When you connect a Google (Gmail) account, Krot requests only the permissions below, each tied to a specific user-facing feature:
- Send email on your behalf (
gmail.send) — to send the outreach emails and follow-ups you compose and schedule in Krot, from your own address. - Read your mailbox (
gmail.readonly) — solely to detect replies to those emails, so that automated follow-ups stop and the reply is surfaced in your dashboard (including unsubscribe requests). - Basic account information (
openid,email,profile) — to identify which Google account you connected and show it in your Krot workspace.
If you choose to sign in to Krot with Google, we also receive your name, email address, and Google account identifier, which we use only to create and authenticate your Krot account.
7.1 Google user data we access
- Your Google account identity: email address, name, and account identifier.
- Headers of new inbox messages: for each new message, we read only the sender address and the
In-Reply-ToandReferencesheaders, to check whether it is a reply to an email you sent through Krot. The message body is not requested, and unrelated correspondence is never read beyond these headers. - Replies to emails you sent through Krot: only when a message is such a reply do we read its content, and we keep its sender, subject, and up to 4,000 characters of its text.
Krot never modifies, labels, archives, deletes, or otherwise organizes messages in your mailbox.
7.2 How we use Google user data
- To send the emails you schedule, from your own address.
- To detect replies, stop the follow-ups that would otherwise go to that contact, and show the reply in your dashboard.
- To recognize unsubscribe requests and bounces in those replies, so that we stop contacting that person.
Reply detection and classification run entirely within Krot's own infrastructure using deterministic keyword rules; the content of your emails is never sent to any third-party AI system.
7.3 How we store and protect Google user data
Your Google OAuth access and refresh tokens are encrypted at rest (AES-256-GCM) and are used only by Krot's servers. Google user data is stored on our servers in the European Union (see Section 14), protected by the measures described in Section 12, and is accessible only to the users of your Krot workspace.
7.4 How we share Google user data
We do not sell Google user data and do not use it for advertising. We share it only with the service providers that host our infrastructure on our behalf (Section 14), when required by law, or as part of a merger or acquisition with appropriate safeguards. We never share it with data brokers, advertisers, or AI model providers.
7.5 Retention and deletion of Google user data
- Disconnecting a mailbox in Krot deletes its stored Google tokens.
- Reply content is kept with the campaign records it belongs to and is deleted with them, including within 90 days of account closure (Section 11).
- You can revoke Krot's access at any time at https://myaccount.google.com/connections, and you can request deletion of any Google user data we hold by writing to [email protected].
7.6 Limited Use
Krot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing features described above.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models, and we do not send it to any third-party AI system.
- We do not transfer Google user data to others except as necessary to provide these features (for example, secure cloud hosting acting on our behalf), to comply with applicable law, or as part of a merger or acquisition with appropriate safeguards.
- We do not allow humans to read Google user data except with your consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized.
8. Microsoft 365 Mailbox Data
When you connect a Microsoft 365 / Outlook account, Krot requests the minimum Microsoft Graph permissions needed for the same two features:
- Mail.Send — to send the outreach emails and follow-ups you compose and schedule in Krot, from your own address.
- Mail.Read — solely to detect replies to those emails, so that automated follow-ups stop and the reply is surfaced in your dashboard (including unsubscribe requests).
- User.Read, openid, email, profile, offline_access — to identify the connected mailbox and keep the connection active.
Krot does not request write, delete, or mailbox-management permissions and never modifies, moves, or deletes messages in your mailbox. Microsoft mailbox content is handled under the same rules stated in Section 7: deterministic reply classification inside our own infrastructure, no transfer to any third-party AI system, no use for model training, no advertising use, tokens encrypted at rest, and deletion of stored tokens when you disconnect the mailbox. You can also revoke access at any time from your Microsoft account's My Account → Privacy → Apps and services settings.
9. Privacy Rights
Depending on your location and applicable law, you have rights regarding your personal data. These include:
- Access: request access to personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of certain data, subject to legal and operational exceptions.
- Objection: object to certain processing, including processing based on legitimate interests and direct marketing.
- Restriction: request restriction of processing in certain circumstances.
- Portability: request a portable copy of certain data.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact [email protected] or use the opt-out form at https://krot.io/privacy/remove. We respond within 30 days, and may extend by a further two months for complex requests, telling you why. We may need to verify your identity and/or authority (for example, if you are acting on behalf of an organization) before responding. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
If you are a data subject whose information a customer uploaded into the Services, we act as a processor for that data. We will forward your request to the relevant customer and assist them in responding.
9.1 Right to lodge a complaint
If you are in the EEA or UK, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Data State Inspectorate of Latvia (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, Latvia — https://www.dvi.gov.lv. You may also complain to the authority in your country of residence or workplace.
9.2 California privacy rights (CCPA/CPRA)
If you are a California resident, you may have the right to request information about our collection, use, and disclosure of personal information; request deletion; request correction; and opt out of certain processing as defined by applicable law. We do not sell or share personal information as those terms are defined by the CPRA. We will not discriminate against you for exercising your rights.
9.3 Business contact opt-out rights
If your business contact information appears in or is processed by our Services, you may request to opt out at https://krot.io/privacy/remove.
Upon a verified opt-out request, we remove your profile from our Services and retain your email address only in a suppression list, so that we can honor your opt-out and prevent your data from being re-added.
10. Cookies Policy
We use cookies and similar technologies for:
- Strictly necessary purposes (e.g., authentication, session management, security, and load balancing). These are set without consent because the Services cannot function without them.
- Preferences (e.g., language and settings).
- Analytics (e.g., understanding how the Services are used and improving performance). Where required by law, these are set only with your consent, which you may withdraw at any time.
You can control cookies through your browser settings. If you disable cookies, parts of the Services may not function properly.
11. Data Retention
We retain information only as long as necessary for the purposes it was collected for. In practice:
- Account, workspace, and configuration data — for the life of the account, then deleted or anonymized within 90 days of account closure, except where longer retention is legally required.
- Billing and tax records — for the period required by Latvian and EU accounting law (generally 5 years).
- Mailbox OAuth tokens — deleted when you disconnect the mailbox or close the account.
- Reply content stored for reply detection — retained for the life of the associated campaign records and deleted with them on account closure.
- Opt-out / suppression records — retained indefinitely, because deleting them would allow the contact to be re-added; we keep only the identifiers needed to honor the opt-out.
- Logs and security telemetry — retained for up to 12 months for security, debugging, and abuse prevention.
- Signals feed data — purged automatically on a daily cycle.
- Browser extension device tokens — expire 90 days after they are issued, and are deleted immediately when you disconnect the extension or revoke the device from your Krot account.
Where a customer is the controller, retention follows that customer's instructions and their agreement with us.
12. Security Measures
We maintain administrative, technical, and organizational measures designed to protect information, including access controls and role-based permissions, encryption in transit (TLS), encryption at rest for mailbox OAuth tokens and mailbox credentials, multi-factor authentication for accounts, a strict Content Security Policy, CSRF protections, audit logging of security-relevant events, and monitoring for suspicious activity. No method of transmission or storage is completely secure, and security measures cannot guarantee absolute protection. We assess and, where applicable, notify supervisory authorities and affected individuals of personal data breaches in accordance with GDPR Articles 33 and 34.
13. International Transfers
Our primary infrastructure is hosted in the European Union. Some subprocessors listed in Section 14 process data outside the EEA (including in the United States). Where we transfer personal data outside the EEA or UK, we rely on lawful transfer mechanisms, principally the European Commission's Standard Contractual Clauses (SCCs) together with supplementary technical and organizational measures, or an adequacy decision where one applies. You can request further information about these safeguards at [email protected].
14. Subprocessors
We currently use the following subprocessors to provide the Services:
| Subprocessor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application and database hosting | Germany (EU) |
| Google LLC / Google Ireland Ltd | Gmail API for connected mailboxes, Cloud Pub/Sub for reply notifications, Firebase Authentication for sign-in | EU / US |
| Microsoft Corporation | Microsoft Graph API for connected Microsoft 365 mailboxes | EU / US |
| Stripe, Inc. | Payment and subscription processing | US / EU |
| OpenRouter, Inc. | Routing of company-level lookup queries to language-model providers (see Section 15) | US |
We will update this list when subprocessors change. Customers with a signed DPA may request advance notice of changes by writing to [email protected].
15. AI and Automated Processing
We use language models for one narrow purpose: resolving a company name to its official website domain and its industry classification, so that company records are complete and correctly categorized. These queries are routed via OpenRouter to third-party models (currently Perplexity Sonar and DeepSeek models).
- Only the company name is sent in these queries. No personal data, no contact records, and no email content are included.
- Mailbox content is never sent to any AI system. Reply detection and classification are deterministic keyword rules that run entirely inside our own infrastructure.
- We do not use customer data, contact data, or mailbox data to train AI or machine-learning models, and we do not permit our providers to do so.
- No solely automated decision-making with legal or similarly significant effects under GDPR Article 22 takes place in the Services. Enrichment and verification outputs are suggestions that customers review and act on.
16. Data Processing Addendum (DPA)
Where we process personal data on a customer's behalf, our Data Processing Addendum applies. It incorporates the GDPR Article 28 terms and, where relevant, the Standard Contractual Clauses. Request a copy at [email protected].
17. GDPR Article 14 Notice (Sourced Business Contacts)
Where we obtain your business contact information from a source other than you, this section is our Article 14 notice:
- Controller: Behman & Bergman Ltd, Riga, Latvia — [email protected].
- Categories of data: name, work email address, job title, employer, department, seniority, business phone number, company domain, industry, location, and publicly available professional profile URLs, plus verification and enrichment metadata.
- Sources: publicly available business information (such as company websites and public professional profiles), third-party business data providers, and data uploaded by our customers.
- Purposes and legal basis: to provide B2B email verification, enrichment, and prospecting features to our customers, based on our and our customers' legitimate interests in business-to-business commercial communication (Art. 6(1)(f)).
- Recipients: our customers who use the Services, and the subprocessors listed in Section 14.
- Retention: as set out in Section 11.
- Your rights: access, correction, deletion, objection, restriction, and portability, as set out in Section 9, plus the right to complain to a supervisory authority. You can opt out at any time at https://krot.io/privacy/remove.
18. Third-Party Integrations
The Services may allow you to connect third-party integrations (for example, mailbox providers, identity providers, and other tools). When enabled, information may be shared with or obtained from those third parties as part of the integration. Third-party services process information according to their own policies and terms.
LinkedIn. The Krot browser extension runs on LinkedIn profile pages that you visit. Krot is not affiliated with, endorsed by, or sponsored by LinkedIn. We do not access your LinkedIn account, credentials, or session, and we do not extract content from LinkedIn pages; the extension reads only the address of the profile page you choose to look up.
19. Children's Privacy
The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children.
20. Additional Disclosures for Email Verification Services
Email addresses submitted to the Services for verification are processed solely for verification purposes (including deliverability and risk assessment) and are not used for marketing by Krot unless separately authorized by the submitting customer or user through a distinct lawful basis.
21. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy and update the “Last Updated” date above. Where changes are material, we will provide additional notice through the Services or by email.
22. Contact Information
If you have questions or wish to exercise your privacy rights, contact us at [email protected], or write to Behman & Bergman Ltd, Riga, Republic of Latvia.