Legal
Privacy Policy
Last updated: 16 September 2026
1. Controller Identity and Contact
Data Controller:
“Martin Solutions” Ltd
A sole-owner limited liability company (ЕООД / EOOD) incorporated in Bulgaria
UIC/EIK: 208473110
VAT Status: Martin Solutions Ltd is not currently registered for VAT in Bulgaria
Registered Office: 36 Matey Preobrazhenski Street, Dryanovo 5370, Gabrovo Region, Bulgaria
Contact Email: martin.solutions.ltd@gmail.com
Website: https://www.kronoscube.com
2. What is Kronoscube?
Kronoscube is a B2B Software-as-a-Service (SaaS) platform for overdue invoice collection. We provide email sequence automation, optional QuickBooks Online synchronization, optional Stripe Connect payment links, and AI tone adjustment features. SMS services are not offered during the beta period.
3. Data Controller vs. Data Processor
Kronoscube operates in two distinct roles:
Controller Role
We act as data controller for your account information, billing data, and support communications. This includes your email address, organization name, subscription details, and any correspondence with our support team.
Processor Role
We act as data processor on your behalf for debtor contact information and invoice data you upload to run collection campaigns. You remain the controller of this data and determine the purposes and means of processing. See our Data Processing Addendum for details.
4. Categories of Personal Data We Process
As Controller (Account & Billing Data):
- Identity Data: Name, email address, organization name
- Billing Data: Payment information processed via Stripe (we do not store card details)
- Usage Data: Login timestamps, feature usage, IP addresses, browser type
- Support Data: Communications with customer support, bug reports
- OAuth Data: QuickBooks account identifiers (if you connect QuickBooks)
As Processor (Customer Invoice Data You Upload):
- Debtor Contact Data: Names, email addresses, phone numbers (optional), company names
- Invoice Data: Invoice numbers, amounts, due dates, descriptions
- Collection Events: Email delivery status, open/click events, payment confirmations
5. Legal Bases for Processing
We process personal data under the following GDPR legal bases (Article 6(1)):
Contract Performance (Art. 6(1)(b))
Processing necessary to provide the Kronoscube service under our Terms of Service
Legitimate Interests (Art. 6(1)(f))
Security monitoring, fraud prevention, product improvement, and analytics
Legal Obligation (Art. 6(1)(c))
Tax compliance, accounting obligations, and legal record-keeping under Bulgarian law
Consent (Art. 6(1)(a))
Optional marketing communications (you may withdraw consent at any time)
6. Recipients and Sub-Processors
We share data with the following categories of recipients. For customer invoice data (where we are processor), these entities are sub-processors. See our full Sub-processor List.
Supabase (Auth + Database)
EU region (eu-central-1, Frankfurt)
Vercel (Web Hosting & CDN)
Global CDN (may process in US) — transfer safeguards in place
Fly.io (API & Worker)
Currently US region (iad) — Standard Contractual Clauses apply
Stripe (Billing & Payments)
Payment processing and Stripe Connect (if enabled)
Resend (Transactional Email)
EU region (eu-west-1, Ireland)
Sentry (Error Monitoring)
EU ingest (Germany) — production errors only
OpenRouter (Optional AI Tone)
Only if you enable AI tone adjustment — invoice content processed
Intuit QuickBooks Online
Only if you connect your QuickBooks account
7. International Transfers
Some of our sub-processors are located outside the European Economic Area. Where personal data is transferred to countries without an adequacy decision, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Fly.io, Vercel where applicable)
- Processor's own GDPR compliance frameworks (Stripe, Supabase, Resend)
- Your explicit consent when enabling optional integrations (QuickBooks, OpenRouter AI)
8. Data Retention
Account Data
Retained while your account is active, plus 30 days after cancellation for recovery. Billing and accounting records retained for 10 years per Article 12 of the Bulgarian Accountancy Act (Закон за счетоводството).
Invoice & Debtor Data (Processor Role)
Deleted 30 days after account cancellation, or immediately upon your request. You control retention of this data as the controller.
Logs & Error Reports
Retained for 90 days for security and debugging purposes
9. Cookies and Tracking
We use strictly necessary cookies:
- Session Cookie: Supabase authentication (essential for login)
- No Tracking: We do not use advertising or analytics cookies without consent
10. Your Rights Under GDPR
You have the following rights regarding your personal data:
Right of Access (Art. 15)
Request a copy of your personal data
Right to Rectification (Art. 16)
Correct inaccurate data
Right to Erasure (Art. 17)
Request deletion (“right to be forgotten”)
Right to Restriction (Art. 18)
Limit processing under certain conditions
Right to Data Portability (Art. 20)
Receive data in machine-readable format
Right to Object (Art. 21)
Object to processing based on legitimate interests
How to Exercise Your Rights:
Email us at martin.solutions.ltd@gmail.com with your request. We will respond within 30 days.
11. Supervisory Authority
You have the right to lodge a complaint with the Bulgarian data protection authority:
Commission for Personal Data Protection (CPDP / КПДЗ)
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Website: https://www.cpdp.bg
12. Automated Decision-Making
Kronoscube does not use automated decision-making or profiling as defined under Article 22 GDPR. AI tone adjustment (if enabled) is a content rewriting tool and does not make decisions about individuals.
13. Children
Kronoscube is a B2B service intended for business users aged 18 and over. We do not knowingly collect data from children under 18.
14. Security
We implement appropriate technical and organizational measures:
- Encryption in transit (HTTPS/TLS) and at rest (database encryption)
- Row-level security policies on all database tables
- Regular security audits and vulnerability scanning
- Access controls and authentication via Supabase Auth
- Error monitoring with automatic PII redaction (Sentry)
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address. The “Last updated” date at the top of this page reflects the most recent version.
16. Contact Us
For any privacy-related questions or to exercise your rights, contact us at: martin.solutions.ltd@gmail.com
Disclaimer: This Privacy Policy is a professionally structured template designed to comply with GDPR and Bulgarian data protection law. It is not a substitute for legal advice from a licensed lawyer. If you have specific legal questions, please consult a qualified attorney.