Back to home

Privacy policy

Last updated: 3 September 2026

This policy explains what personal data Krokanti Games SL processes when you use Brymio (www.brymio.com), why we process it and what you can do about it. It is written to be understood without help: if anything is unclear, write to us and we will clarify it.

Who processes your data

Krokanti Games SL, a Spanish company, is the data controller for the people who sign up to Brymio. Write to info@krokanti.com about anything to do with data protection; that is also the address for exercising your rights.

What Brymio is

Brymio is a single platform with five modules that each organisation turns on and off as it likes: Invoicing (invoices, quotes, expenses, taxes and bank reconciliation in Spain), Team (the Spanish time register plus basic HR: absences, payslips, calendar), Commerce (store operations for Shopify and WooCommerce: products, orders, stock and customers), Projects (tasks, notes and documentation) and Store Health (performance, SEO and accessibility audits of a website). Every plan includes all five modules, so the data we process depends on what you switch on, not on what you pay.

When we are the controller and when we are a processor

For the data of whoever opens an account — name, email, subscription billing — we are the controller. For the data your organisation uploads or connects — your employees', your clients', your store's shoppers', your suppliers' — you are the controller and we act as a processor: we handle it only to provide the service and on your instructions, never for purposes of our own. If you need a signed data processing agreement, ask us at info@krokanti.com.

Data we process

Depending on the modules you have enabled, we process these categories:

  • Account: name, email address, profile picture if you upload one, language, your password stored irreversibly and, if you enable them, your authenticator app secret and its backup codes.
  • Organisation: name, URL identifier, tax number, address, time zone, logo, members with their role, and pending invitations.
  • Invoicing: your tax details and those of your clients and suppliers, including their tax numbers and addresses; invoices and their lines, quotes, expenses with their receipts, bank movements you import and tax summaries. An issued invoice can no longer be changed and is chained by a cryptographic hash.
  • Team: each employee's punches with the server clock, hash-chained so they cannot be altered (a correction never erases the original — it is stored separately with its author and reason); absences and holidays; contracts and expected hours; payslips and documents the company publishes, with their read receipts; date of birth if the employee gives it; and how they sign in (password, email link, passkey or kiosk PIN).
  • Commerce: what we pull from your own Shopify or WooCommerce store — products, stock, orders and customers, including the name, email, phone and addresses of the people who buy from you — plus the store connection credentials, which we store encrypted.
  • Projects: projects, tasks, comments, mentions, notes and their versions, labels and attachments. Secure notes are encrypted in your browser before they leave it: we only store the ciphertext and cannot read it.
  • Store Health: the URLs you ask us to audit, the result of each analysis and the screenshots of those pages.
  • Usage: pages viewed, features used and errors, so we know what gets used and what breaks.
  • Payment: the organisation's plan, subscription status and Stripe identifiers. Card details are handled by Stripe directly and never reach our servers.
  • Device and security: IP address, browser, sign-in and administrative action logs, and failed login attempts, which we use to stop brute-force attacks.

Location, biometrics and other sensitive data

The Team module touches employment data, so let us be explicit:

  • Location: it is stored only at the instant of a punch, and only if the company enabled it in settings and the employee also gave consent. There is no continuous tracking and no trace between punches. The employee can withdraw consent at any time from their settings, and from that point their punches are stored without coordinates.
  • Biometrics: Brymio processes no biometric data. There is no fingerprint or facial recognition anywhere in the product. Passkeys use your own device's sensor: the biometric data never leaves it and all we receive is a cryptographic signature.
  • Kiosk photo: kiosk mode can store a photo taken at the moment of the punch. It is off by default, the company turns it on if it wants to, and the photos are deleted automatically after 90 days.
  • Mood pulse: answers are anonymous and only shown in aggregate. If there are fewer than three answers in the period, nothing is shown at all, so nobody can be identified by elimination.

What we use it for

We process the data above for the following purposes, and nothing else:

  • Providing the service: issuing invoices, recording working time, syncing your store, running projects and auditing websites.
  • Identifying you and protecting the account: sign-in, two-factor authentication, session management and immediate revocation of access.
  • Meeting legal obligations, yours and ours: keeping the time register and the tax documentation with the safeguards Spanish law requires.
  • Charging the subscription and invoicing the platform itself, through Stripe.
  • Sending you service email: account verification, sign-in links, absence notifications, punch reminders, monthly reports and important service notices.
  • Running the AI features you choose to use: reading a receipt or an invoice to fill in an expense, answering questions about your tax data, enriching product records or explaining an audit. Only the content needed for that specific task is sent, and only when you trigger it.
  • Measuring site usage and performance so we can improve it. Google Analytics only loads if you accept analytics cookies.
  • Helping you when you write to support and resolving incidents.

On what legal basis

Under the General Data Protection Regulation, we process your data on these bases:

  • Performance of the contract: everything needed to give you the service you signed up for and to charge for it.
  • Consent: analytics cookies, punch geolocation, push notifications and Telegram linking. You can withdraw it whenever you like, without affecting what was processed before.
  • Legitimate interest: platform security, abuse prevention and product improvement.
  • Legal obligation: retention of the time register (art. 34.9 of the Spanish Workers' Statute) and of tax and accounting records.

Who we share data with

We rely on these providers to run the service; they process data on our behalf under contract. We do not sell data to anyone, we do not share it for advertising, and we do not use it to train AI models.

  • Vercel — hosting and running the application. A US company.
  • Neon — the PostgreSQL database where everything the platform stores lives. A US company.
  • Cloudflare R2 — file storage: payslips and team documents, expense receipts, project attachments, audit screenshots and logos.
  • Brevo — transactional email delivery (verification, sign-in links, notices and reminders). A French company, processing in the European Union.
  • Stripe — subscription payment and management. It handles card details directly, which we neither see nor store.
  • Google (Gemini) — optional AI analysis of Store Health reports. It only receives the content of the audited site when you ask for that analysis.
  • OpenRouter — the AI gateway used by the Invoicing assistants: reading receipts and invoices, importing documents, answering questions about your tax data and drafting payment reminders. It routes the request to the chosen model and only receives the content of that request.
  • Anthropic (Claude) — optional enrichment of product records in Commerce, only when you trigger it.
  • Inngest — orchestration of Store Health background jobs (scheduled audits, retries).
  • Telegram — only if an employee links their account to punch through the bot. In that case Telegram handles their messages with the bot and their user id. If they do not link it, Telegram is not involved.
  • Your Shopify or WooCommerce store — not our provider but yours, though data flows both ways: we read and write using the credentials you give us, and only for what you ask.
  • Google Analytics 4 — analytics for the public site, only if you accept analytics cookies.

Several of these providers are US companies, so there may be international data transfers. These rely on the standard contractual clauses approved by the European Commission and, where applicable, on the EU-US Data Privacy Framework.

Security

Data always travels encrypted over TLS and is stored encrypted at rest. Passwords are never stored in the clear: they are stored with functions designed for that (bcrypt for members, scrypt for employees). API tokens are stored as SHA-256 hashes and your store credentials are encrypted. Changing a password, using "sign out everywhere" or deactivating an account invalidates every open session immediately. Sign-in attempts are rate-limited and the account locks temporarily after several failures in a row. And one honest note: we hold no ISO 27001 or SOC 2 certification, and we are not going to pretend otherwise.

How long we keep it

Each kind of data lives as long as it has to:

  • Account and organization: for as long as the account is active. Deleting an organization makes it inaccessible immediately and we can restore it for 30 days. After that it stays deactivated, and we erase it for good when you ask us to, except for what the law requires us to keep (invoices and the time register).
  • Invoicing: issued invoices and their hash chain are not deleted on request, because Spanish tax and commercial law requires them to be kept. They are held for the statutory retention periods — four years for tax purposes and six years for accounting books and records — and deleted afterwards.
  • Time register: the law requires punches to be kept for four years (art. 34.9 of the Workers' Statute). They cannot be deleted before that, not even when the employee leaves, and they cannot be edited: corrections are stored separately and leave a trail. Kiosk photos, by contrast, are deleted after 90 days.
  • Commerce: imported products, orders and customers are kept while the project exists. Deleting the project or the connection deletes them, and we also act on the deletion requests Shopify sends us on a shopper's behalf.
  • Projects: tasks and notes live as long as the organisation keeps them. The trash can be emptied at any time.
  • Store Health: reports are kept until you delete them; those that stall or fail are removed automatically after 30 days.
  • Backups: we take encrypted backups of the database. Deleted data disappears from the application at once, but it may remain in a backup until that backup is rotated and overwritten.

When you delete your account, your user is marked as deleted, all your sessions are closed and the Commerce data of organisations that were yours alone is erased. What the law requires us to keep — issued invoices and the time register — survives that deletion for the statutory period and is used for nothing else. Download your JSON copy from settings first.

Your rights

You can exercise these rights over your personal data:

  • Access: find out what data we hold about you and ask for a copy. Settings offer an immediate JSON download, with nobody to wait for.
  • Rectification: correct anything that is wrong or incomplete.
  • Erasure: ask us to delete your data, except what the law requires us to keep.
  • Portability: take your data with you in a structured, machine-readable format.
  • Restriction: ask us to stop processing certain data while a disagreement is resolved.
  • Objection: object to the processing we carry out on the basis of legitimate interest.
  • Withdrawal of consent: turn off analytics cookies, punch geolocation, push notifications or Telegram linking whenever you want.

To exercise them, write to info@krokanti.com from your account's address. We answer within one month. If our answer does not satisfy you, you can complain to the Spanish Data Protection Agency (www.aepd.es).

If you are an employee using Brymio because your company subscribed to it, exercise your rights with your company: it decides what is processed and why. We will help it answer you, and if you get no response you can write to us and we will point you in the right direction.

Minors

Brymio is a work tool and is not aimed at anyone under 16; we do not open accounts for minors. If a company registers a legally employed minor as an employee, it is that company that answers for the lawfulness of the processing.

Changes to this policy

We may update this policy if our practices, our providers or the law change. If the change is significant we will tell you by email or inside the application. The date at the top shows the latest revision.

Contact

For any question about this policy or your data, write to info@krokanti.com or to Krokanti Games SL, Spain.