Privacy Policy — Version 2.0 — Effective 2026-07-19
In plain language: Kelavon does not receive the task data stored in your local Excel files through normal App use. Kelavon does process purchase, website-log, support, recovery, and activation information. At activation, normalized device identifiers are transmitted over TLS, used in memory, and converted into per-anchor salted hashes; raw hardware values are not intentionally stored or logged.
1. Controller identity
Controller: Denys Nalbat, trading as Kelavon, Mattackerstrasse 9, 8052 Zürich, Switzerland. Privacy contact: support@kelavon.com or privacy@kelavon.com [DEDICATED PRIVACY INBOX TO BE CONFIRMED AS ACTIVE]. The merchant of record identified at checkout may independently control transaction data under its own notice.
2. Scope
This Policy covers the Website, downloads, activation service, license-help service, support, communications, and business administration. It does not make Kelavon controller of Customer Data stored locally merely because the Software can process it.
3. Applicable laws
Kelavon intends to comply with the Swiss Federal Act on Data Protection and other applicable laws. GDPR applicability, representative requirements, and country-specific supplements are [TO BE CONFIRMED based on actual targeting and processing].
4. Data minimisation
Only data reasonably needed for the stated purposes is collected. No telemetry, analytics, advertising, crash reporting, or background license checks will be added without first updating the product, this Policy, the Cookie Policy, consent design, and internal records.
5. Website technical data
Production logs may include IP address, date/time, requested URL, response status, browser/user-agent, referrer, and security events. [HOSTING/CDN VENDOR, PRECISE FIELDS, LOCATIONS, AND RETENTION TO BE CONFIRMED.]
6. Contact and support data
When you contact Kelavon, data may include name, organisation, email, message, attachments, purchase details, App/Windows versions, screenshots, and troubleshooting information. Redact unnecessary sensitive or regulated data before sending.
7. Purchase and transaction data
Kelavon may receive order ID, purchaser name, email, organisation, product, amount, currency, tax location/status, payment status, refund/dispute status, and invoice/receipt references. Full card details are handled by the merchant of record and payment providers and are not received by Kelavon.
8. Activation data
Activation may process the license key, purchase email where required, App version, random installation ID, normalized raw system/product UUID, primary disk serial, and processor identifier, activation result, timestamp, and ordinary network/security data. Raw hardware identifiers are transmitted over TLS only when activation is requested, used in memory to compare candidate anchors and generate per-anchor salted hashes, and are not intentionally persisted or written to application logs, analytics, tracing, or support observations. Stored activation data may include the binding mode, immutable random salt, fingerprint-format version, salted original hashes, salted installation-ID hash, degraded/confidence status, anchor ID, and salted observation hashes. Hashing reduces exposure but does not guarantee that low-entropy identifiers can never be guessed or correlated; unique salts make straightforward cross-license correlation harder, not provably impossible. Task names, workbook contents, attachments, and Customer Data are not transmitted by activation.
9. License-help data
The view-only license-help page may process a submitted email, magic-link token/status, license and capacity information, activation dates, and recovery/security logs. It does not provide self-service seat release or deactivation. [TOKEN EXPIRY (currently 30 minutes), RATE LIMITS, DISPLAYED FIELDS, AND RETENTION TO BE KEPT CONSISTENT WITH PRODUCTION.]
10. Trial data
The trial is email-free but contacts the licensing service when started, processing the same categories of device-binding data as activation (installation ID and normalized hardware identifiers, stored only as per-anchor salted hashes) plus trial start/expiry timestamps. The trial can recognise a device; it is anonymous in the sense that no name, email, or account is required — not in the sense that no technical identifier is processed.
11. Local Customer Data
Normal App use stores Customer Data in local Excel files selected and controlled by the Customer. The App does not automatically upload those contents to Kelavon. A sample file voluntarily sent for support is processed as support data.
12. No passwords or application accounts
The App does not create user accounts or passwords. License-help magic links are time-limited and must be protected like any emailed access link.
13. Purposes
Providing downloads and activation; matching a request to an existing immutable activation anchor; enforcing permanent-seat capacity; fulfilling orders; license recovery; support; fraud and abuse prevention; request rate limiting; security; legal compliance; accounting; refunds/disputes; defending claims; and improving documentation and reliability.
14. Legal bases
For GDPR-covered processing, possible bases include contract necessity, legal obligation, legitimate interests, and consent where required. [FINAL MAPPING OF EACH ACTIVITY TO ITS BASIS TO BE CONFIRMED WITH COUNSEL.]
15. Mandatory and optional data
A working email address is required to complete a purchase and receive the license; device-binding data is required to activate. Optional marketing consent is never bundled with purchase or support.
16. Recipients and processors
Categories and key providers: merchant of record/payment (Stripe); hosting (Vercel); license database/API hosting (Supabase); email delivery (Resend); accounting/legal advisers; public authorities where legally required. [FINAL VENDOR LIST TO BE CONFIRMED AT LAUNCH.]
17. Stripe Managed Payments
The checkout uses Stripe Managed Payments and the merchant of record identified at checkout. Stripe, Link, banking/payment participants, tax partners, and fraud/dispute providers may process transaction data under their own roles and notices. Kelavon does not control all such processing.
18. International transfers
Processor infrastructure may be located outside Switzerland/the EEA. [DATA LOCATIONS, ADEQUACY, AND CONTRACTUAL SAFEGUARDS TO BE CONFIRMED AFTER VENDOR MAPPING.]
19. Retention
[RETENTION SCHEDULE TO BE CONFIRMED covering: website and rate-limit logs (rate-limit entries are pruned within 24 hours by design), activation anchors and observations, installation-ID hashes, purchase/accounting records, support tickets and attachments, magic-link records, security incidents, and legal claims. Permanent-seat records may need retention for the duration of the license plus an appropriate claims/security period.]
20. Security measures
Proportionate measures include TLS, request-body redaction at the logging boundary, exclusion of raw hardware values from logs and tracing, access control, secrets management, database-level immutable-anchor controls, least privilege, database transactions/locking for capacity, backups, patching, and vendor review. No method is completely secure.
21. Data breaches
An incident process covers assessment, containment, documentation, notification to authorities, and communication to affected persons where legally required.
22. Individual rights
Depending on your jurisdiction: information, access, correction, deletion, restriction, objection, portability where applicable, consent withdrawal, and complaint to the competent authority. Identity and authority may be verified before acting; legal exceptions may apply.
23. Swiss supervisory authority
The Swiss Federal Data Protection and Information Commissioner (FDPIC) is the relevant federal authority where Swiss data protection law applies; other authorities may also be competent.
24. EU/EEA rights and representative
If GDPR applies, you have the right to complain to a supervisory authority. [WHETHER AN EU REPRESENTATIVE OR DPO IS REQUIRED TO BE CONFIRMED.]
25. Children
The Software is a professional business tool and not directed to children. Kelavon does not knowingly collect children's data.
26. Automated decision-making
Kelavon itself performs no legally significant automated decision-making or profiling. Capacity enforcement is a deterministic rule (seat count vs. purchased capacity). The merchant of record's fraud tooling may produce risk signals under its own notice. [FINAL WORDING TO BE CONFIRMED.]
27. Marketing
Kelavon does not currently send optional marketing newsletters. Transactional, legal, security, and support messages are not marketing. If you opted in at checkout, product news may be sent with an unsubscribe control; consent can be withdrawn any time via privacy@kelavon.com.
28. Cookies and similar technologies
See the Cookie Policy. Non-essential technology will not be enabled before consent where required.
29. Third-party links
External sites and merchant-of-record pages have separate privacy practices. Kelavon is not responsible for them.
30. Changes
The version and effective date are shown at the top of this page. This Policy is updated before, not after, introducing new analytics, telemetry, cloud features, or categories of recipients.
31. Contact and requests
Privacy requests: support@kelavon.com or privacy@kelavon.com, with postal correspondence to Mattackerstrasse 9, 8052 Zürich, Switzerland. Identity and authority may be verified before acting.
32. Consistency with production
A non-public data inventory, processing records where required, vendor agreements, transfer assessments, retention schedule, and request-response procedure are maintained internally; this public Policy is kept consistent with actual production behavior.