Privacy Policy
Last updated: 9 September 2026
This privacy policy explains how we collect, use, and protect personal data when you use our application for restoration project management, on-site damage assessment, and the commercial processing of orders, in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws. Which of these areas are available to you depends on the modules enabled for your organisation's account.
1. Controller and Processor Roles
Krahasso is a software-as-a-service application for business customers. For account and registration data, the contact and login details of the people who use the application, and technical log data, the controller within the meaning of Art. 4(7) GDPR is:
Valdrin Kuchi
(operating under the name "Krahasso")
Düsseldorfer Straße 175
51063 Cologne
Germany
Email: privacy@krahasso.com
For the project, drying-protocol, equipment, assessment-form, signature, commercial document, uploaded receipt, voice recording, and end-customer data that our business customers enter into the application, those business customers determine the purposes and means of processing. They are therefore the controllers, and Krahasso acts solely as a processor (Art. 28 GDPR) on their documented instructions under a data processing agreement (Auftragsverarbeitungsvertrag). If you are an end customer of one of our business customers, please address requests regarding that data to the business customer responsible for it.
A data protection officer is not required under Sec. 38 of the German Federal Data Protection Act (BDSG), as Krahasso is operated as a sole proprietorship that does not meet the statutory threshold. You can reach us on all data protection matters at privacy@krahasso.com.
2. What Data We Collect
We collect the following categories of personal data to provide our services:
- Account information name, email address, and securely hashed password
- Project data project addresses, status, completion dates, notes, and the name and email address recorded for the occupant of the property or other on-site contact
- Equipment usage allocation records, return dates, and equipment details
- Drying protocol data measurement readings, moisture levels, visit records, and photographs taken during on-site inspections
- Assessment data: the answers given to on-site assessment forms including free text and photographs, and floor plans with room dimensions and notes
- Signature data: the signature drawn on the device, the name and role of the signatory and, where entered, their email address and telephone number, the time of signing, the version of the consent text shown, checksums of the signed content, and the IP address and browser or device identification of the device used at the time of signing
- Commercial document data: quotations, orders, invoices, credit notes and reminders including line items, prices, payment terms and payment status, recorded payments, the master data of our business customer's own customers and suppliers, and dispatch data such as recipient addresses, subject and message body
- Receipts and incoming invoices uploaded as image or PDF files, together with the values read from them by automated extraction. Such files regularly contain personal data of third parties, in particular the name, address, bank details and tax numbers of the issuer; the choice of what is uploaded lies with the business customer
- Contract acceptance data: where a data processing agreement is accepted for a business customer, the name and role of the signatory, the confirmation of their authority to sign, the time of acceptance, the version and checksum of the document shown, and the IP address and browser identification of the device used
- Help centre feedback: the rating given to a help article and any free-text comment, together with the article, its version and the user who submitted it
- Sign-up and invitation requests: first and last name, email address, mobile telephone number, company name, country and commercial-register number of the prospective customer, and the decision taken on the request including any reason given for a rejection
- Push notification identifiers: the notification token issued by the operating system for each of your registered devices and the platform it belongs to, used solely to deliver notifications to that device
- Assistant conversations: the conversation title, the messages you exchange with the in-app assistant, and the record data the assistant read or wrote while answering a question. Voice recordings made through the assistant are described separately below
- Voice data audio recordings made through the in-app voice assistant. Recordings are transcribed; the audio file is automatically deleted from the active system at the latest 30 days after it was made, while the resulting transcript remains as part of the conversation history. Copies held in our standard backup regime age out under the lifecycle rules disclosed in Section 5.
- Organization details company name, logo, address, contact details, tax identification, and bank details used for billing
- Technical data log data (such as IP address and device/app information) necessary for security and troubleshooting, and strictly necessary cookies, including a persistent login cookie that keeps you signed in and an optional trusted-device cookie that lasts thirty days from its last use. We do not use third-party analytics, tracking, or advertising cookies.
3. Legal Basis for Processing (Art. 6 GDPR)
We process your personal data on the following legal grounds:
- Performance of a contract (Art. 6(1)(b) GDPR) processing is necessary to provide the services you have subscribed to
- Legitimate interests (Art. 6(1)(f) GDPR) for security, abuse prevention, and improvement of the Service, based on data for which Krahasso is the controller (account, login and contact details, technical log data). This basis does not extend to project, drying-protocol, equipment, assessment-form, signature, commercial document, uploaded receipt, voice recording, or end-customer data processed on behalf of business customers; that data is processed solely on the controller's instructions under Art. 28 GDPR (see Section 1).
- Consent (Art. 6(1)(a) GDPR) where you have given explicit consent (e.g. for optional communications)
- Legal obligation (Art. 6(1)(c) GDPR) where processing is required by law
Where Krahasso acts as a processor (see Section 1), the legal basis for processing the data concerned is determined by the respective business customer as controller, not by Krahasso.
4. Purpose of Data Processing
Your data is used exclusively for the following purposes:
- Managing construction and drying projects
- Tracking equipment allocations and returns
- Recording and reporting drying protocol measurements
- Generating project reports
- Recording damage assessments on site, including forms, floor plans, and the signature captured on handover
- Preparing, issuing, dispatching, and tracking payment of business documents such as quotations, orders, invoices, and reminders
- Compiling figures for tax reporting and preparing receipt and posting exports for handover to a tax accountant
- Providing AI-powered voice assistant features (transcription and natural language commands) and automated reading of uploaded receipts
- Authenticating your identity and securing your account
Automated reading of an uploaded receipt only pre-fills input fields. The result is a proposal that a user must check and accept before it is applied to a record. We do not carry out automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR.
5. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described above.
Where Krahasso is the controller (account data, login and contact details, technical logs), this data is permanently deleted within 30 days of account cancellation, unless statutory retention obligations require otherwise.
Where Krahasso acts as a processor, project, drying-protocol, equipment, assessment-form, signature, commercial document, uploaded receipt, voice recording, and end-customer data is processed according to the business customer's instructions as controller. The business customer determines the retention period; where the business customer is subject to statutory retention obligations (for example § 257 HGB for commercial documents or § 147 AO for tax-relevant records), it is for the business customer to apply those obligations to a deletion request. Krahasso deletes or returns the data on the business customer's instruction. Within 30 days after the end of the data processing agreement, we provide a complete export of the data on the business customer's request, in the content and format specified in clause 8.5 of the Service Description (see DPA § 13); after that period, the data is deleted from the active system in accordance with the data processing agreement. Backup copies held as part of our standard backup regime are permanently removed by automated lifecycle rules within at most 38 days.
Non-personal, aggregated statistics (for example, total project counts) may be retained for internal reporting purposes. These statistics do not contain information that can identify individuals.
6. Data Sharing & Transfers
Your data is only accessible to authorized users within your organization's account.
We do not sell or rent personal data.
To operate the Service, we use trusted data processors under Article 28 GDPR:
- Hetzner Online GmbH (Germany/EU) hosting infrastructure and storage services
- Amazon Web Services (AWS, eu-central-1 region) delivery of the emails sent from the application. Besides notifications to users, this covers the dispatch of business documents to recipients named by our business customer, including the recipient address, the subject and body of the message, and the attached document files.
- OpenAI Ireland Ltd (Ireland/EU) AI-powered voice transcription, natural language processing, and automated reading of uploaded receipts, incoming invoices, and documents. Audio recordings, and the page images rendered from an uploaded file, are sent to OpenAI for processing. When the assistant answers a question about the records held in your account, the records it reads in order to answer are sent as well, in particular project data including the site address and the name recorded for the occupant of the property, equipment and drying-protocol data, together with the name and role of the user asking and the name of the account. The content of uploaded files may contain personal data of third parties. The data sent is not used by OpenAI to train their models. OpenAI Ireland may use OpenAI, L.L.C. (USA) as a sub-processor; that onward transfer is safeguarded by the EU Standard Contractual Clauses. OpenAI's data usage policy applies (see openai.com/policies/usage-policies).
- Google Ireland Limited (Ireland/EU) our mobile app uses the Google Maps SDK to display project locations on a map, and Firebase Cloud Messaging to deliver push notifications. For the map, Google may collect technical data such as your IP address, device information, and map interaction data. For push notifications, the device token and the title and body of the notification are transmitted; depending on the occasion these contain content from the records held in the application, in particular project addresses and the names of the users involved. Notifications for iOS devices are handed on by Google to the Apple Push Notification Service. We do not collect or transmit your device's location; only project addresses stored in our system are displayed. Google Ireland may use Google LLC (USA) as a sub-processor; Google LLC is certified under the EU-U.S. Data Privacy Framework. For more information, see Google's privacy policy (policies.google.com/privacy).
- MapTiler AG (Switzerland) provides the basemap tiles displayed in the web application's map view. When you view a map page, your IP address and the map viewport coordinates are transmitted to MapTiler. Processing takes place in Switzerland, for which the European Commission has issued an adequacy decision under Article 45 GDPR.
- Apple Distribution International Ltd (Ireland/EU) delivers push notifications to iOS devices via the Apple Push Notification Service (APNs). The notification data required for delivery (such as the notification title and body and a device identifier) is transmitted to Apple. Any onward processing by Apple Inc. (USA) is safeguarded under the EU-U.S. Data Privacy Framework.
- Cloudflare, Inc. (USA) content delivery network and upstream reverse proxy for all of our domains, and the Turnstile bot-protection check on our public forms. All traffic between your device and our production environment is routed through Cloudflare's network and terminated there for TLS, so your IP address, connection and request data, and the content transmitted are processed by Cloudflare. Turnstile is cookieless and does not track you across websites. Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework.
- New Relic, Inc. (USA) application performance monitoring, used for troubleshooting and to keep the Service running. Performance and error telemetry, request paths and request parameters, and forwarded application logs are transmitted; these may contain personal data from the records held in the application. Credentials and parameters marked as confidential are filtered out server-side before transmission. The transfer to New Relic, Inc. in the United States is safeguarded by the EU Standard Contractual Clauses.
Most personal data is processed within the European Union. All traffic to the application passes through Cloudflare, Inc. in the United States as our content delivery network and reverse proxy; Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework. For AI voice processing, the automated reading of uploaded receipts and documents, and the drying calculator on our website, the data concerned may ultimately be processed by OpenAI, L.L.C. in the United States via OpenAI Ireland Ltd; that onward transfer is safeguarded by the EU Standard Contractual Clauses. Operational monitoring data, including request parameters and forwarded application logs, is transmitted to New Relic, Inc. in the United States under the EU Standard Contractual Clauses. For map and push notification features, the data described above may ultimately be processed by Google LLC in the United States via Google Ireland Limited; Google LLC is certified under the EU-U.S. Data Privacy Framework. For push notifications on iOS, notification delivery data is handed on to Apple Distribution International Ltd in Ireland and may be onward-processed by Apple Inc. in the United States; Apple Inc. is certified under the EU-U.S. Data Privacy Framework. For basemap tiles in the web application, your IP address and map viewport coordinates are transmitted to MapTiler AG in Switzerland; the European Commission has adopted an adequacy decision for Switzerland under Article 45 GDPR. No other personal data is transferred outside the EU/EEA or to countries without an adequacy decision.
7. Your Rights (Art. 15–21 GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) obtain a copy of your personal data
- Right to rectification (Art. 16) correct inaccurate or incomplete data
- Right to erasure (Art. 17) request deletion of your data
- Right to restriction (Art. 18) restrict processing under certain conditions
- Right to data portability (Art. 20) receive your data in a portable format
- Right to object (Art. 21) object to processing based on legitimate interests
- Right to withdraw consent where processing is based on consent, you may withdraw it at any time
You also have the right to lodge a complaint with a data protection supervisory authority if you believe your data is being processed unlawfully. Where Krahasso acts as a processor, requests to exercise your rights regarding the data concerned should be directed to the relevant business customer as controller.
The supervisory authority responsible for the controller is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encrypted data transmission (HTTPS/TLS)
- Secure password hashing and automated checks against known data-breach corpora. The check is performed against the Have I Been Pwned service (Cloudflare, Inc.) using k-anonymity: only the first five characters of the irreversible hash of the password are transmitted, never the password itself, your email address or any other identifier. If the service cannot be reached, the check is skipped and the remaining password requirements still apply
- Optional two-factor authentication via a one-time email code, available per user
- Network-level protection (firewalls and restricted database access)
- Access controls within customer accounts
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals without undue delay in accordance with Art. 33 and 34 GDPR. Where Krahasso acts as a processor, we will inform the responsible business customer without undue delay so that they can meet their notification obligations.
9. Our Website and Contact Forms
For the forms on our public website, Krahasso is the controller. This data is separate from the application and is never added to a customer account.
- Contact form and demo request: the name, email address, company and any message you enter. We use it only to answer your enquiry and, where you asked for one, to arrange a demonstration. Legal basis: Art. 6(1)(b) GDPR for steps taken at your request before entering into a contract, otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
- Drying calculator: the description of the water damage you type into the assistant is sent to OpenAI Ireland Ltd to produce the recommendation (see Section 6). If you then ask for the result by email, we process the name, email address, company and telephone number you enter in order to send it (Art. 6(1)(b) GDPR). Marketing email is sent only if you tick the separate consent box; we record the IP address and time of that consent as evidence of it, and you can withdraw it at any time (Art. 6(1)(a) GDPR).
All of these forms are protected by the Cloudflare Turnstile bot check described in Section 6.
Submissions from these forms are not stored in the application. They reach us as email and are deleted once the enquiry has been dealt with, unless a statutory retention obligation requires otherwise.
10. Changes to This Policy
We may update this privacy policy from time to time. The latest version will always be available within the application. The date of the last update is shown at the top of this page.
11. Contact
For any privacy-related inquiries or to exercise your rights, please contact:
privacy@krahasso.com
You may also request deletion of your account or personal data at any time by emailing us at privacy@krahasso.com.