Privacy Policy
Last updated: 25 August 2026
This policy explains what Pybex Technology Private Limited collects when you use Krrim, why we collect it, and what you can ask us to do with it.
1. Who we are
Krrim is operated by Pybex Technology Private Limited (“Pybex”, “we”, “us”). In this policy, “the Service” means the Krrim application and the websites at krrim.com and its subdomains.
For privacy questions or to exercise any right described here, contact privacy@krrim.com.
2. Two roles, and why the distinction matters
We handle personal data in two different capacities, and your rights differ between them:
- As a controller — for account data, billing details and how you use our website. We decide why and how this is processed.
- As a processor — for the content you put inside your workspace: tasks, comments, documents, attachments and the personal data they may contain. Your organization is the controller of that content, and we act on its instructions.
If you are an employee of a customer and want workspace content corrected or deleted, your organization’s administrator is the right first contact — they control that data, not us. See our data processing addendum for the terms governing our role as processor.
3. What we collect
3.1 Information you give us
- Account details — name, email address, password hash (never the password itself), and profile preferences.
- Organization details — workspace name, subdomain, timezone and settings.
- Workspace content — tasks, comments, documents, attachments, time entries and custom field values.
- Billing information — company name, billing address and tax identifiers. Card details are handled by our payment processor and never reach our servers.
- Correspondence — what you send us by email.
3.2 Information collected automatically
- Audit records — for each change made in a workspace: who made it, when, the source IP, the user agent and a request identifier.
- Technical logs — request paths, status codes and timings, used to operate and debug the Service.
- Error reports — stack traces and the context needed to diagnose a fault.
- Essential cookies — a session cookie and your interface preferences. See section 8.
3.3 What we do not collect
- We do not collect payment card numbers.
- We do not run third-party advertising or cross-site tracking on the Service.
- We do not read your workspace content except where you ask us to as part of support, or where we are legally compelled to.
4. Why we process it
| Purpose | Lawful basis |
|---|---|
| Providing the Service to you and your organization | Performance of a contract |
| Sending notifications you have not turned off | Performance of a contract |
| Billing and tax compliance | Contract, and legal obligation |
| Keeping audit records, and detecting abuse | Legitimate interests, and our customers’ security |
| Diagnosing faults and improving reliability | Legitimate interests |
| Product announcements you opted into | Consent |
We do not sell personal data, and we do not use workspace content to train machine learning models.
5. How it is separated and secured
Each organization’s data lives in its own PostgreSQL schema, so separation between customers is enforced by the database rather than by application code. Data is encrypted in transit, and stored credentials — webhook signing secrets and SSO client secrets — are encrypted at rest with a key held outside the database. API tokens are stored only as a hash and cannot be recovered.
Our security page describes these controls in more detail, including what we do not yet claim.
6. Who we share it with
We share personal data only with sub-processors that help us operate the Service, and only as much as each needs. The current list — what each provides, and where it processes data — is published at krrim.com/legal/subprocessors.
We also disclose data where:
- You or your organization instruct us to.
- We are legally compelled to. Where we are permitted to tell you, we will.
- It is necessary to establish or defend a legal claim, or to prevent harm.
If Pybex is involved in a merger or acquisition, personal data may transfer as part of it. You will be told before that happens, and before any change to how the data is handled.
7. How long we keep it
| Data | Retention |
|---|---|
| Workspace content | Until deleted by your organization, or 30 days after the workspace is closed |
| Account data | Until the account is deleted |
| Audit records | For the life of the workspace, unless your plan sets a longer term |
| Technical logs | Up to 30 days |
| Error reports | Up to 90 days |
| Billing records | As required by tax law, typically 7 years |
Backups are retained on their own cycle and expire within 30 days. Deleted content may persist in a backup until that expires, but is not restored to the Service.
8. Cookies
Krrim uses cookies for two things only:
- Session — keeps you signed in. Strictly necessary; the Service does not work without it.
- Preferences — remembers your theme, density and interface settings.
We do not use advertising or cross-site tracking cookies, which is why there is no consent banner asking you to accept any.
9. International transfers
Krrim is operated from India, and some sub-processors operate elsewhere. Where personal data is transferred out of the region it was collected in, we rely on the appropriate safeguards for that transfer — typically Standard Contractual Clauses. The sub-processor list names the processing location for each.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a portable copy, and to withdraw consent where consent was the basis.
Write to privacy@krrim.com. We respond within 30 days, and may need to verify your identity first.
For workspace content, please contact your organization’s administrator — we act on their instructions for that data and will forward your request to them. You can also delete your own account directly.
If you believe we have handled your data improperly, you may complain to your local data protection authority. We would rather you told us first.
11. Children
Krrim is a workplace tool and is not directed at children under 16. We do not knowingly collect their personal data, and will delete it if we learn we have.
12. Changes to this policy
We will update this page when this policy changes and revise the date at the top. For material changes we will notify account holders by email or in the application before the change takes effect.
13. Contact
Pybex Technology Private Limited
privacy@krrim.com
Our postal address and registration details are available on request.