Legal
Data Processing Terms
How KROMSE processes personal data in the scan inputs, documents and workspace content you provide.
Draft pending legal review
This document was drafted by the KROMSE team from the behaviour of the running product. It has not yet been reviewed by a qualified lawyer and is published so that design partners can read what actually happens to their data before they connect a repository. Fields KROMSE cannot answer today are left as explicitly marked blanks rather than filled with a commitment the product does not keep.
- Drafted on
- 2026-08-29
- Reviewing counsel
- [ TO BE COMPLETED — name and firm of the reviewing lawyer ]
- Review completed on
- [ TO BE COMPLETED — date of legal review ]
Status of this document
These terms are a draft of the Article 28 processor terms KROMSE intends to offer. They are published so that a design partner's legal reviewer can see the shape of the arrangement and the gaps in it early, rather than after a procurement process has started.
This draft is not an executed data processing agreement and does not become one by being read or by anyone accepting the Terms of Service. Signature, effective date, and the relationship between this document and any negotiated agreement are [ TO BE CONFIRMED BY LEGAL COUNSEL — KROMSE cannot determine this ].
1. Roles
For personal data contained in the scan inputs, documents, and workspace content you connect to KROMSE, you are the controller and KROMSE is the processor.
For the account data of the individuals who log in to KROMSE, KROMSE is a controller in its own right. The Privacy Policy covers that.
Kromse S.L.
Proposed company name. Company registration is pending. The legal operator and registration details remain to be confirmed.
Contact: info@kromse.com
2. Subject matter, nature and purpose
KROMSE analyzes repository code, SBOMs, firmware and container images, records the resulting evidence, and presents it in the workflows you use. Automated analysis includes external vulnerability lookups using component and advisory identifiers, as described in section 5 of the Privacy Policy. AI processing occurs when you select optional code review, send a chat message, or separately confirm document reading by optical character recognition.
Temporary repository copies, retained firmware inputs, scan evidence and workspace records have different lifecycles, described in section 4 of the Privacy Policy. This draft does not establish an account-closure deletion deadline.
3. Categories of data and data subjects
KROMSE does not choose what personal data is in your inputs; you do. Personal data may reach KROMSE through:
- Source code and repository contents, which routinely contain author names and email addresses, and may contain test fixtures, seed data, comments, or configuration containing personal data of your employees, customers, or end users.
- Uploaded SBOMs and firmware, and selected container images, which may include author information, configuration, files or other personal data.
- Scan evidence, which can quote fragments of that code.
- Documents you upload during onboarding, and which you may choose to send for optical character recognition.
- Workspace content your team types into products, cases, and report drafts.
- Account data of your personnel who use KROMSE.
Data subjects are therefore your personnel and any individual whose personal data happens to be present in the inputs or documents you connect.
Whether special-category data may be processed, and on what conditions, is [ TO BE CONFIRMED BY LEGAL COUNSEL — KROMSE cannot determine this ]. KROMSE applies no technical control that prevents special-category data from being present in a scanned repository, and should not imply one.
4. Instructions
Product actions give processing instructions: attaching a Git source or container reference, uploading an SBOM or firmware, starting a scan, selecting optional AI code review, sending a chat message, and separately confirming external document reading. Section 5 of the Privacy Policy describes what each external processing path sends.
KROMSE does not use your data for its own purposes, does not sell it, and does not use your source code or workspace content to train machine learning models.
5. Confidentiality
Personnel authorized to process customer data are bound by confidentiality obligations.
[ TO BE COMPLETED BY KROMSE — not established today ] — the form of that obligation (employment terms, contractor agreements) should be stated once the team is larger than its founder, and background-check or training commitments should not be asserted here unless they are actually carried out.
6. Security measures
The technical measures KROMSE implements today are listed below. This is a description of the running system, not a target state.
- Workspace scoping: every record carries its organization identifier and data access is filtered by it, so one customer's data is not reachable from another's workspace.
- Role-based access control within a workspace, with permissions enforced on the server.
- Scan evidence written to private object storage with server-side encryption, verified for both encryption and content digest at the moment of writing. Local-disk evidence storage is rejected in the production configuration.
- Repository working copies held in a temporary per-scan workspace and deleted when the scan finishes; retained evidence may contain code fragments, and uploaded firmware has its own retention lifecycle.
- Secret redaction applied to any code selected for AI review, and exclusion of files in which the secret scanner found a secret.
- GitHub installation credentials confined to API calls, never forwarded to the archive download host and never written to storage, logs, or error messages.
- Archive extraction hardened against path traversal, symlinks, oversized members, and archive bombs.
- A tamper-evident audit trail: entries are chained with SHA-256 over the preceding entry so that alteration is detectable.
- Scanners executed as a non-root user in an isolated container image built from checksum-pinned binaries.
- The optional error-monitoring integration disables default personal-data collection when enabled; it is not currently configured.
KROMSE holds no SOC 2 report and no ISO 27001 certification, and has not undergone a third-party penetration test. A security questionnaire must be answered accordingly. Any commitment to obtain, maintain, or evidence such a certification is [ TO BE COMPLETED BY KROMSE — not established today ].
7. Sub-processors
Section 6 of the Privacy Policy lists the current service providers and external data services, with their technical purposes. Contractual roles, applicable agreements and transfer arrangements remain to be reviewed for this draft.
Clerk manages sign-in, workspace membership and invitation emails. When you invite a colleague, Clerk receives their email address and workspace details and sends the invitation on your instruction.
OpenAI provides the default chat options when you send a message. Mistral provides explicitly selected 🇪🇺 KROMSE chat and separately confirmed document OCR. Optional AI code review sends a bounded, redacted code selection only when enabled for the scan. Deterministic scans still make external advisory requests; disabling AI does not disable those requests.
General authorization, notice of changes, and the right to object: [ TO BE COMPLETED BY KROMSE — not established today ]. No notification mechanism exists today, so no notice period or objection window can be committed to here. This is the clause a procurement reviewer will ask about first, and it should be built before it is drafted.
8. Assistance to the controller
KROMSE will assist you, so far as the product allows, with data subject requests, with your own data protection impact assessments, and with your security obligations. Requests outside the available product controls need an assigned owner and a verified manual process. This draft does not establish that every request can already be completed.
The request owner, verified manual procedure and response policy remain [ TO BE COMPLETED BY KROMSE — not established today ]. Existing SBOM, audit and report downloads cover their stated scope; they do not export every workspace record. There is no complete self-service workspace export or workspace-erasure action, and no committed assistance turnaround in this draft.
9. Personal data breaches
[ TO BE COMPLETED BY KROMSE — not established today ]. The incident-response procedure, notification contacts and any response window remain to be confirmed for this draft. The responsible people and their advisers assess the circumstances and any applicable notification requirements. This draft does not make that legal determination or commit to a notification deadline.
10. Deletion and return
A periodic job attempts to delete expired scan-evidence objects in bounded batches and retries failures. Successful deletion replaces the stored object location with a deletion marker and records the time. The database row retains its digest and other metadata; findings, reports, audit records and database backups are not erased by that object-expiry job. Normal scan cleanup removes the temporary source copy; a forcibly stopped worker can leave temporary files until cleanup or service replacement. Uploaded firmware remains stored while its product input is active; archiving that input starts its plan-based retention period rather than deleting the bytes immediately.
Deletion or return of the remaining workspace data at the end of the arrangement is [ TO BE COMPLETED BY KROMSE — not established today ]. There is no implemented export-on-exit and no committed deletion turnaround. The standard Article 28(3)(g) choice — return or delete, at the controller's election — should be offered here only once the product can actually do both.
11. Audits
[ TO BE CONFIRMED BY LEGAL COUNSEL — KROMSE cannot determine this ]. Audit and inspection rights under Article 28(3)(h), including their frequency, notice, cost, and whether they may be satisfied by documentation rather than an on-site visit, need to be negotiated rather than asserted. KROMSE has no audit report to offer in place of an inspection.
12. International transfers
[ TO BE CONFIRMED BY LEGAL COUNSEL — KROMSE cannot determine this ]. Several sub-processors process data outside the EEA. The transfer mechanism for each — standard contractual clauses, an adequacy decision, or otherwise — together with any transfer impact assessment, must be established by counsel. The module and annexes of any incorporated standard contractual clauses belong here.
The other documents
KROMSE provides workflow software, not legal advice, certification, or automatic regulatory submission.
Version 2026-09-09