Your data
Data processing agreement
The particulars are below. A data processing agreement is available on request.
Last updated 8 September 2026
What this is for
If your organisation puts personal data into Kromdraw, and a name on a sticky note counts, then under the GDPR you are the controller and Kromdraw is a processor acting on your instructions. Article 28 says that relationship has to be written down. A data processing agreement is that document.
A DPA is available on request. It is not a public download yet. Write to me and I will provide it directly.
The particulars, as they stand today
Who is who
You, or your organisation, are the controller. The processor is Ronkatil B.V., Plataanstraat 7, 6573 XP Beek, Gelderland, the Netherlands. KvK 96968176 · BTW NL867854571B01. Ronkatil B.V. has no parent company and no investors.
Subject matter and duration
Processing lasts as long as your account does, and ends when the account is deleted. The retention periods that apply while it runs are on the privacy page.
Nature and purpose
Storing boards, comments and uploaded files so you and the people you share them with can open them, sending the three kinds of account email Kromdraw sends, and taking payment.
Categories of personal data
- Account data. Your email address, the name you chose, and a hash of your password. The password itself is never stored.
- Session data. The IP address and browser string of each signed-in session, and when it was last used.
- Content. Whatever you put on a canvas, subject to the Terms. Special-category and criminal-offence data are prohibited. Kromdraw doesn't inspect content. Comment text carries the name shown against it, and sticky notes carry the name of whoever wrote them.
- Guest data. The display name a guest types when joining a live link, and a hashed token identifying that guest's browser for the length of the session.
- Page records. One row per request: the IP address, the browser and operating system it reported, the referrer and the page. Kromdraw's own, on Kromdraw's own server.
- Audit records. A row for each change to a name, email address or password, and for disabling an account or an organisation, naming who made it.
- Billing data. The billing contact's name and email address and the member count, held by Creem as the merchant of record. Card details go to Creem and never reach Kromdraw.
Categories of data subject
People with accounts in your organisation, guests you invite to a board through a link, and anybody whose personal data your own people choose to write onto a canvas.
Subprocessors
Four of them, named with what each one sees, on the subprocessor list. That page carries the date it last changed.
Security measures
- Traffic is encrypted in transit, everywhere.
- Database backups are encrypted before upload to Scaleway in Amsterdam, with a key the storage provider doesn't hold.
- Passwords are stored as bcrypt hashes.
- Sign-in and password reset are rate limited, by IP address and by the email submitted.
- A session expires 30 days after it was last used, and expired sessions are deleted nightly.
- One person has access to the production server.
What isn't in place: no ISO 27001 certification, no third-party penetration test, no formal incident response drill. Where your data lives lists the rest.
Transfers outside the EU
None. Every subprocessor is European and every machine holding your data is in the EU, so there is no transfer to a third country to find a mechanism for.
Deletion, and getting your data back
You can export everything at any time without asking, in a format other tools open. What export gives you describes what actually comes out. To request deletion, email me from the address registered to the account. I verify the request through that address and delete the account or organisation from the live service within 30 days, including archived boards, imports and completed exports. Encrypted backup copies age out within a further 90 days.
Breaches, audits and data subject requests
The obligations here are the ones Article 28 sets out. Assistance with requests from your own users, notification without undue delay when something goes wrong, and making the information needed to demonstrate compliance available on request. The specific deadlines and audit arrangement in the agreement remain pending legal review.
If you need one now
Write to me and ask for the DPA. I will provide it directly.