Privacy Policy
Last updated: August 2026
Your HR data stays with you
1. Scope
Krip provides an application and licensed backend images that run on infrastructure controlled by the customer. This policy covers only the krip.app website, customer contact, billing, licensing, and license activation services operated by Krip.
2. Data Krip Does Not Receive
Krip does not receive or store employee profiles, leave records, expense claims, receipts, resumes, candidate records, equipment records, timesheets, performance reviews, or other HR content held in your Nextcloud instance.
Licensed backend images, including AI processing components, run on infrastructure controlled by the customer. Documents and AI inputs are not sent to Krip. If an administrator configures an external model provider, that connection is controlled by the customer and governed by the provider's terms.
3. Limited Data Krip Receives
Krip may receive the minimum information required to sell, support, and validate a license:
- Organization name and account contact details
- Billing and transaction references
- License identifier, edition, validity period, and status
- Instance identifier and applicable employee range used for license validation
- Support messages and information you choose to provide
- Technical request metadata recorded by the license service for security and reliability
Krip does not use license validation to collect product content or employee identities.
4. How Krip Uses This Data
- Issue, validate, renew, and revoke licenses
- Provide billing, account administration, and customer support
- Protect the license service from misuse and security threats
- Meet applicable accounting and legal obligations
5. Storage and Retention
HR data retention is controlled entirely by the customer through Nextcloud and the licensed backend deployment. Krip retains account, billing, license, support, and security records only for as long as they are needed for the purposes above or required by applicable law.
6. Your Rights
Privacy rights apply only to the limited account, contact, billing, license, and support information held by Krip. Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. These requests do not affect HR data because Krip does not hold that data.
To submit a privacy request, contact contact@krip.app.
7. Customer Responsibilities
The customer controls the Nextcloud instance, licensed backend deployment, HR data, retention settings, user access, backups, and any external AI provider configuration. The customer is responsible for its own privacy notices and legal obligations for HR data processed on its infrastructure.
8. Changes and Contact
We may update this policy when our licensing or account services change. For privacy questions, contact contact@krip.app.