Legal

Privacy Policy

Last updated: 16 September 2026

1. Controller Identity and Contact

Data Controller:

“Martin Solutions” Ltd

A sole-owner limited liability company (ЕООД / EOOD) incorporated in Bulgaria

UIC/EIK: 208473110

VAT Status: Martin Solutions Ltd is not currently registered for VAT in Bulgaria

Registered Office: 36 Matey Preobrazhenski Street, Dryanovo 5370, Gabrovo Region, Bulgaria

Contact Email: martin.solutions.ltd@gmail.com

Website: https://www.kronoscube.com

2. What is Kronoscube?

Kronoscube is a B2B Software-as-a-Service (SaaS) platform for overdue invoice collection. We provide email sequence automation, optional QuickBooks Online synchronization, optional Stripe Connect payment links, and AI tone adjustment features. SMS services are not offered during the beta period.

3. Data Controller vs. Data Processor

Kronoscube operates in two distinct roles:

Controller Role

We act as data controller for your account information, billing data, and support communications. This includes your email address, organization name, subscription details, and any correspondence with our support team.

Processor Role

We act as data processor on your behalf for debtor contact information and invoice data you upload to run collection campaigns. You remain the controller of this data and determine the purposes and means of processing. See our Data Processing Addendum for details.

4. Categories of Personal Data We Process

As Controller (Account & Billing Data):

  • Identity Data: Name, email address, organization name
  • Billing Data: Payment information processed via Stripe (we do not store card details)
  • Usage Data: Login timestamps, feature usage, IP addresses, browser type
  • Support Data: Communications with customer support, bug reports
  • OAuth Data: QuickBooks account identifiers (if you connect QuickBooks)

As Processor (Customer Invoice Data You Upload):

  • Debtor Contact Data: Names, email addresses, phone numbers (optional), company names
  • Invoice Data: Invoice numbers, amounts, due dates, descriptions
  • Collection Events: Email delivery status, open/click events, payment confirmations

5. Legal Bases for Processing

We process personal data under the following GDPR legal bases (Article 6(1)):

Contract Performance (Art. 6(1)(b))

Processing necessary to provide the Kronoscube service under our Terms of Service

Legitimate Interests (Art. 6(1)(f))

Security monitoring, fraud prevention, product improvement, and analytics

Legal Obligation (Art. 6(1)(c))

Tax compliance, accounting obligations, and legal record-keeping under Bulgarian law

Consent (Art. 6(1)(a))

Optional marketing communications (you may withdraw consent at any time)

6. Recipients and Sub-Processors

We share data with the following categories of recipients. For customer invoice data (where we are processor), these entities are sub-processors. See our full Sub-processor List.

Supabase (Auth + Database)

EU region (eu-central-1, Frankfurt)

Vercel (Web Hosting & CDN)

Global CDN (may process in US) — transfer safeguards in place

Fly.io (API & Worker)

Currently US region (iad) — Standard Contractual Clauses apply

Stripe (Billing & Payments)

Payment processing and Stripe Connect (if enabled)

Resend (Transactional Email)

EU region (eu-west-1, Ireland)

Sentry (Error Monitoring)

EU ingest (Germany) — production errors only

OpenRouter (Optional AI Tone)

Only if you enable AI tone adjustment — invoice content processed

Intuit QuickBooks Online

Only if you connect your QuickBooks account

7. International Transfers

Some of our sub-processors are located outside the European Economic Area. Where personal data is transferred to countries without an adequacy decision, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (Fly.io, Vercel where applicable)
  • Processor's own GDPR compliance frameworks (Stripe, Supabase, Resend)
  • Your explicit consent when enabling optional integrations (QuickBooks, OpenRouter AI)

8. Data Retention

Account Data

Retained while your account is active, plus 30 days after cancellation for recovery. Billing and accounting records retained for 10 years per Article 12 of the Bulgarian Accountancy Act (Закон за счетоводството).

Invoice & Debtor Data (Processor Role)

Deleted 30 days after account cancellation, or immediately upon your request. You control retention of this data as the controller.

Logs & Error Reports

Retained for 90 days for security and debugging purposes

9. Cookies and Tracking

We use strictly necessary cookies:

  • Session Cookie: Supabase authentication (essential for login)
  • No Tracking: We do not use advertising or analytics cookies without consent

10. Your Rights Under GDPR

You have the following rights regarding your personal data:

Right of Access (Art. 15)

Request a copy of your personal data

Right to Rectification (Art. 16)

Correct inaccurate data

Right to Erasure (Art. 17)

Request deletion (“right to be forgotten”)

Right to Restriction (Art. 18)

Limit processing under certain conditions

Right to Data Portability (Art. 20)

Receive data in machine-readable format

Right to Object (Art. 21)

Object to processing based on legitimate interests

How to Exercise Your Rights:

Email us at martin.solutions.ltd@gmail.com with your request. We will respond within 30 days.

11. Supervisory Authority

You have the right to lodge a complaint with the Bulgarian data protection authority:

Commission for Personal Data Protection (CPDP / КПДЗ)

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Website: https://www.cpdp.bg

12. Automated Decision-Making

Kronoscube does not use automated decision-making or profiling as defined under Article 22 GDPR. AI tone adjustment (if enabled) is a content rewriting tool and does not make decisions about individuals.

13. Children

Kronoscube is a B2B service intended for business users aged 18 and over. We do not knowingly collect data from children under 18.

14. Security

We implement appropriate technical and organizational measures:

  • Encryption in transit (HTTPS/TLS) and at rest (database encryption)
  • Row-level security policies on all database tables
  • Regular security audits and vulnerability scanning
  • Access controls and authentication via Supabase Auth
  • Error monitoring with automatic PII redaction (Sentry)

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address. The “Last updated” date at the top of this page reflects the most recent version.

16. Contact Us

For any privacy-related questions or to exercise your rights, contact us at: martin.solutions.ltd@gmail.com

Disclaimer: This Privacy Policy is a professionally structured template designed to comply with GDPR and Bulgarian data protection law. It is not a substitute for legal advice from a licensed lawyer. If you have specific legal questions, please consult a qualified attorney.