Privacy Policy — Version 2.1 — Effective 2026-08-01
In plain language: Kelavon does not receive the task data stored in your local Excel files through normal App use. Kelavon does process purchase, website-log, support, recovery, and activation information. At activation, normalized device identifiers are transmitted over TLS, used in memory, and converted into per-anchor salted hashes; raw hardware values are not intentionally stored or logged.
1. Controller identity
Controller: Denys Nalbat, trading as Kelavon, Mattackerstrasse 9, 8052 Zürich, Switzerland. Privacy contact: privacy@kelavon.com, which is monitored by the proprietor; support@kelavon.com reaches the same person and is forwarded if used for a privacy request. The merchant of record identified at checkout may independently control transaction data under its own notice.
2. Scope
This Policy covers the Website, downloads, activation service, license-help service, support, communications, and business administration. It does not make Kelavon controller of Customer Data stored locally merely because the Software can process it.
3. Applicable laws
Kelavon complies with the Swiss Federal Act on Data Protection. Because the Software is offered to customers in the EU/EEA, Kelavon also treats the EU General Data Protection Regulation as applicable to EU/EEA-directed sales, and this Policy is written on that basis.
Kelavon has not appointed a representative under Article 27 GDPR or the UK GDPR. Data-protection enquiries and data-subject requests should be sent directly to privacy@kelavon.com, or by post to Denys Nalbat, Mattackerstrasse 9, 8052 Zürich, Switzerland. If a representative is appointed in future, their name, address and contact details will be published in this section.
4. Data minimisation
Only data reasonably needed for the stated purposes is collected. No telemetry, analytics, advertising, crash reporting, or background license checks will be added without first updating the product, this Policy, the Cookie Policy, consent design, and internal records.
5. Website technical data
Production logs may include IP address, date/time, requested URL, response status, browser/user-agent, referrer, and security events. Hosting and edge delivery are provided by Vercel; these logs are retained by Vercel under its own retention schedule and are used only for operating and securing the Website. No separate CDN or web-analytics vendor is used.
6. Contact and support data
When you contact Kelavon, data may include name, organisation, email, message, attachments, purchase details, App/Windows versions, screenshots, and troubleshooting information. Redact unnecessary sensitive or regulated data before sending.
7. Purchase and transaction data
Kelavon may receive order ID, purchaser name, email, organisation, product, amount, currency, tax location/status, payment status, refund/dispute status, and invoice/receipt references. Full card details are handled by the merchant of record and payment providers and are not received by Kelavon.
8. Activation data
Activation may process the license key, purchase email where required, App version, random installation ID, normalized raw system/product UUID, primary disk serial, and processor identifier, activation result, timestamp, and ordinary network/security data. Raw hardware identifiers are transmitted over TLS only when activation is requested, used in memory to compare candidate anchors and generate per-anchor salted hashes, and are not intentionally persisted or written to application logs, analytics, tracing, or support observations. Stored activation data may include the binding mode, immutable random salt, fingerprint-format version, salted original hashes, salted installation-ID hash, degraded/confidence status, anchor ID, and salted observation hashes. Hashing reduces exposure but does not guarantee that low-entropy identifiers can never be guessed or correlated; unique salts make straightforward cross-license correlation harder, not provably impossible. Task names, workbook contents, attachments, and Customer Data are not transmitted by activation.
9. License-help data
The view-only license-help page may process a submitted email, magic-link token/status, license and capacity information, activation dates, and recovery/security logs. It does not provide self-service seat release or deactivation. Magic-link tokens expire 30 minutes after issue. Recovery requests are rate-limited per email address and per IP address, and rate-limit records are pruned within 24 hours. The page displays only the license number, purchased capacity, seat count and activation dates — never device identifiers, hashes or salts.
10. Trial data
The trial is email-free but contacts the licensing service when started, processing the same categories of device-binding data as activation (installation ID and normalized hardware identifiers, stored only as per-anchor salted hashes) plus trial start/expiry timestamps. The trial can recognise a device; it is anonymous in the sense that no name, email, or account is required — not in the sense that no technical identifier is processed.
11. Local Customer Data
Normal App use stores Customer Data in local Excel files selected and controlled by the Customer. The App does not automatically upload those contents to Kelavon. A sample file voluntarily sent for support is processed as support data.
12. No passwords or application accounts
The App does not create user accounts or passwords. License-help magic links are time-limited and must be protected like any emailed access link.
13. Purposes
Providing downloads and activation; matching a request to an existing immutable activation anchor; enforcing permanent-seat capacity; fulfilling orders; license recovery; support; fraud and abuse prevention; request rate limiting; security; legal compliance; accounting; refunds/disputes; defending claims; and improving documentation and reliability.
14. Legal bases
For GDPR-covered processing, possible bases include contract necessity, legal obligation, legitimate interests, and consent where required. Specifically: performing the purchase contract and delivering and activating the licence rests on contract necessity; retaining purchase and accounting records rests on legal obligation; rate limiting, abuse prevention and seat-capacity enforcement rest on legitimate interests; and any optional communication you request rests on consent, which you may withdraw at any time.
15. Mandatory and optional data
A working email address is required to complete a purchase and receive the license; device-binding data is required to activate. Optional marketing consent is never bundled with purchase or support.
16. Recipients and processors
Categories and key providers: merchant of record/payment (Stripe); hosting (Vercel); license database/API hosting (Supabase); email delivery (Resend); accounting/legal advisers; public authorities where legally required. Web fonts are additionally requested from Google Fonts as described in the Cookie Policy. This is the complete list of processors used by Kelavon; it is updated here before any new processor is introduced.
17. Stripe Managed Payments
The checkout uses Stripe Managed Payments and the merchant of record identified at checkout. Stripe, Link, banking/payment participants, tax partners, and fraud/dispute providers may process transaction data under their own roles and notices. Kelavon does not control all such processing.
18. International transfers
Processor infrastructure may be located outside Switzerland/the EEA. In particular, processing may occur in the European Union and the United States. Transfers to processors outside Switzerland and the EEA are made under the European Commission's and the Swiss Federal Council's Standard Contractual Clauses, or under an applicable adequacy decision, together with each processor's own data-processing agreement.
19. Retention
Retention periods: rate-limit entries are pruned within 24 hours; magic-link tokens expire after 30 minutes and their records are removed within 30 days; support tickets and attachments are kept for 24 months after the request is closed; purchase and accounting records are kept for 10 years as Swiss bookkeeping law requires; security-incident records are kept for 24 months. Activation anchors, activation observations and installation-ID hashes are kept for the life of the licence plus 12 months, because a permanent seat must remain attributable to its device for as long as the licence can be used or disputed.
20. Security measures
Proportionate measures include TLS, request-body redaction at the logging boundary, exclusion of raw hardware values from logs and tracing, access control, secrets management, database-level immutable-anchor controls, least privilege, database transactions/locking for capacity, backups, patching, and vendor review. No method is completely secure.
21. Data breaches
An incident process covers assessment, containment, documentation, notification to authorities, and communication to affected persons where legally required.
22. Individual rights
Depending on your jurisdiction: information, access, correction, deletion, restriction, objection, portability where applicable, consent withdrawal, and complaint to the competent authority. Identity and authority may be verified before acting; legal exceptions may apply.
23. Swiss supervisory authority
The Swiss Federal Data Protection and Information Commissioner (FDPIC) is the relevant federal authority where Swiss data protection law applies; other authorities may also be competent.
24. EU/EEA rights and representative
If GDPR applies, you have the right to complain to a supervisory authority. Kelavon has not appointed a Data Protection Officer, as it does not carry out large-scale monitoring or large-scale processing of special-category data. Its position on an Article 27 representative is stated in section 3.
25. Children
The Software is a professional business tool and not directed to children. Kelavon does not knowingly collect children's data.
26. Automated decision-making
Kelavon itself performs no legally significant automated decision-making or profiling. Capacity enforcement is a deterministic rule (seat count vs. purchased capacity). The merchant of record's fraud tooling may produce risk signals under its own notice. No decision producing legal or similarly significant effects is made about you by automated means alone.
27. Marketing
Kelavon does not currently send optional marketing newsletters. Transactional, legal, security, and support messages are not marketing. If you opted in at checkout, product news may be sent with an unsubscribe control; consent can be withdrawn any time via privacy@kelavon.com.
28. Cookies and similar technologies
See the Cookie Policy. Non-essential technology will not be enabled before consent where required.
29. Third-party links
External sites and merchant-of-record pages have separate privacy practices. Kelavon is not responsible for them.
30. Changes
The version and effective date are shown at the top of this page. This Policy is updated before, not after, introducing new analytics, telemetry, cloud features, or categories of recipients.
31. Contact and requests
Privacy requests: support@kelavon.com or privacy@kelavon.com, with postal correspondence to Mattackerstrasse 9, 8052 Zürich, Switzerland. Identity and authority may be verified before acting.
32. Consistency with production
A non-public data inventory, processing records where required, vendor agreements, transfer assessments, retention schedule, and request-response procedure are maintained internally; this public Policy is kept consistent with actual production behavior.