KROG
KROG · Privacy noticeISO/IEC 29184 · TS 27560 · GDPR

Privacy notice

What KROG does with your personal data, in the order most likely to surprise you. Publishing a page to the open web comes first; account plumbing comes last.

Every section states the same thirteen facts in the same order, each one carrying the ISO/IEC 29184:2020 clause that requires it. Where something is not settled, this notice says so in place rather than filling the gap with reassuring text.

Version
2.0
Issued
not yet published
Renderings
en · nb-NO
Identifier
krog:privacy-notice-1@v2.0
Who is answerable · §5.3.4
Krog Data Privacy & Governance
Via Mariöl 31, 7524 Zuoz, Switzerland
Stated once here, and the same for all seven sections — so it is not repeated thirteen times below.
How to reach us
hello@signatu.com
One month to answer any request below.
Version archive · §5.2.8
Every superseded version
Kept as long as any record citing it.
No automated decisions

Matching ranks and explains; a person decides whether to contact you. Nothing here produces an Art. 22 decision.

No special category data

We do not ask for Art. 9 data. Please do not put it in free-text fields — they are published as written.

No ads, no third-party analytics

Browser storage is limited to what sign-in and your language choice need.

⚠︎
Seventeen items are not settled, and this notice will not pretend otherwise

A data protection officer; the supervisory authority you complain to; whether an Art. 27 representative in the EEA is required of a Swiss controller; the publication date; two balancing-test references; five retention periods; the full sub-processor list with regions and transfer mechanisms; the controller arrangement with Gumroad; three assistant questions — the model provider’s region, retention at the gateway, and whether prompts are used for training; and whether the krog: vocabulary namespace is published and resolvable at the address this notice gives. Each is marked in place below. None is filled with drafted text — a notice that guesses at its own complaint route is worse than one that admits the gap.

Sections are ordered by surprise multiplied by how much say you have — not by how much data each touches. Publishing a page to the open web and issuing a credential that outlives your account are the two things people do not expect, so they come first. Sign-in is fourth because it holds no surprises and offers no choices: it is the precondition for everything else.

# SECTION BASIS §5.4? WHAT YOU CAN DO
01 Publishing your profile
Highest surprise — world-readable, indexable, cached.
A6-1-f
A6-1-a
In full, for the consent fields Publish · per-field consent · erase
02 Issuing and verifying credentials
Signed, portable, built to outlive the account.
A6-1-b No — reason recorded See the evidence · revoke · export
03 Matching and discovery
You are ranked against needs others describe.
A6-1-f No — reason recorded Object · turn off availability
04 Account, sign-in and security
No surprise and no say — the precondition.
A6-1-b
A6-1-f
No — reason recorded Access · correct · delete
05 Records layer
No opt-out, deliberately — and we say so.
A6-1-c
A6-1-f
No — reason recorded Access only
06 Course sign-up and payment
Sold through Gumroad, an independent US controller — the one activity whose data sits outside the EEA.
A6-1-b No — reason recorded Access · correct · Gumroad’s own controls
07 Operating the platform
Hosting, error reports, page-speed timings.
A6-1-f No — reason recorded Object
08 The assistant
Your prompts leave our infrastructure.
A6-1-f No — reason recorded Do not use it
Each summary is complete and true on its own. If you read only the summaries you have not been misled — you have read less. Open a section for all thirteen facts, each with the clause that requires it.
8 sections · 104 facts
01Publishing your profile

Nothing is public until you publish. When you do, your page is served to anyone who asks for it, can be crawled, and is rendered into share cards. Your photo, contact details and social links are published only on your consent, field by field. Unpublishing removes the page from KROG — it cannot recall copies others already hold.

Off until you publishA6-1-f · A6-1-a
Purpose§5.3.2–3
To publish a professional directory page for you, as a person or an institution, so others can find and verify who you are.
Legal basis§5.3.15
Legitimate interest for the fields inherent to professional presence. Consent for your photo, contact details and social links — separately, per field. ⚠︎ Balancing-test reference not yet assigned.
Personal data§5.3.5
Classified field by field in the map below. Photos sit in a private store, served through short-lived signed links.
How and when we get it§5.3.6–7 · Art. 13
Typed by you into the profile editor, when you choose to. Organisation identity details are checked against a public register at verification — the only route here that is not from you.
What we do with it§5.3.8
Store it, render it as a public page, include it in the network and expertise indexes and the sitemap, and generate share cards from it. No enrichment, no scoring, no inference.
Who else receives it§5.3.10
The open internet — and therefore search engines, social platforms fetching share cards, and web archives. Lovable Labs AB as hosting processor.
Storage, processing, governing law§5.3.9 · Art. 13(1)(f)
Stored in the EEA. Processed in the EEA, and accessed from Switzerland by the controller. Governed by Swiss law and, where it applies to you, the GDPR. Once published, the page itself is readable worldwide — that is the point of publishing, and it is not a transfer we can restrict.
How long§5.3.11
While your profile is active. On deletion, removed from public surfaces and operational stores, except where law requires retention or we need it to defend a legal claim.
Risks worth knowing§5.3.16
A published page can be copied, cached and archived beyond our reach; unpublishing cannot undo that. Free-text fields are published verbatim, so anything you write about a client or a colleague is published too.
Your controls§5.3.12 · Art. 7(3)
Publish or unpublish. Edit any field. Withdraw any of the three consents on its own, at any time, in one action. Delete the profile.
Where your choices live§5.3.14
Profile settings → Visibility. Each consent shows its current state, when you gave it, and which version of the consent notice you saw.
Complaints§5.3.13 · Art. 77
⚠︎ Supervisory authority not yet named — see the rights section for why.
If you decline§5.4.6
Decline the three consents and you still get a full public profile — they are optional, and nothing else depends on them. Decline publication entirely and there is no profile, no discovery and no matching. Your account still works.
02Issuing and verifying credentials

A credential says you hold a competence, and it is signed, timestamped and portable. It is built on purpose to stay checkable by others after you leave KROG. Revoking one is recorded rather than erased, so a credential you have already shown can be shown to have been withdrawn.

Outlives the accountA6-1-b
Purpose§5.3.2–3
To issue you a verifiable competence credential, and to let a third party check it without contacting us.
Legal basis§5.3.15
Performance of the service you asked for. You asked for a credential; a credential is only worth holding if it can be checked.
Personal data§5.3.5
You as the credential subject, the competence claimed, the EQF level, your assessment answers and scores, references to the evidence, issue and revocation timestamps, and which issuing administrator acted.
How and when we get it§5.3.6–7 · Art. 13 · Art. 14
From you, when you sit an assessment. Or from an institution, when a verified issuer attests a competence on your behalf — data not collected from you, so you are told within one month of us receiving it, or at our first communication with you, whichever is sooner.
What we do with it§5.3.8
Assess the evidence, sign a verifiable-credential document, store it, and publish it on your profile if you publish. The database refuses to issue a credential from an issuer not competent to issue it.
Who else receives it§5.3.10
Anyone you show it to. A verifier checks it against the issuer’s published key document without contacting you or us — which is the point, and also means we cannot see who checked it.
Storage, processing, governing law§5.3.9
Stored and processed in the EEA; accessed from Switzerland by the controller. Governed by Swiss law and, where it applies to you, the GDPR. A credential you have shared travels wherever you shared it.
How long§5.3.11
Until revoked or erased. A revocation is recorded rather than deleted. ⚠︎ Retention period for revoked credentials not yet set.
Risks worth knowing§5.3.16
A credential you have shown cannot be un-shown; revocation is visible to anyone who checks, which is what makes revocation meaningful and also public. Erasure and verifiability pull against each other here — we keep the revocation, not the claim.
Your controls§5.3.12 · Art. 20
See your credentials and the evidence behind them. Ask for a revocation. Export your profile and credentials in a machine-readable file.
Where your choices live§5.3.14
Profile settings → Credentials, showing each credential, its issuer, its evidence and its current state.
Complaints§5.3.13 · Art. 77
⚠︎ Supervisory authority not yet named.
If you decline—
No credential, and no verified standing in the network. Everything else works.
03Matching and discovery

Someone describes what they need and your published profile is scored against it, with the reason for the match shown. Only what you have already published is read. A person then decides whether to contact you — the engine ranks and explains, it does not decide.

No Art. 22 decisionA6-1-f
Purpose§5.3.2–3
To connect a stated need with verified capability, and to show why each match was made.
Legal basis§5.3.15
Legitimate interest in connecting demand with verified capability. ⚠︎ Balancing-test reference not yet assigned.
Personal data§5.3.5
Only what is already on your published profile — the capability group above — plus your availability setting. Nothing private is read.
How and when we get it§5.3.6–7
Nothing new is collected from you. Matching reads your profile as it stands at the moment someone runs a search.
What we do with it§5.3.8 · Art. 22
Score your profile against a stated need — jurisdiction, area, competence, language, EQF level, AI Act actor context — and return a ranked list with the reason for each match. This is profiling in the Art. 4(4) sense and not an Art. 22 decision: ranking is not deciding, and no result of it has legal or similarly significant effect on you. No profiling for advertising.
Who else receives it§5.3.10
The person who described the need. Your profile was already public to them.
Storage, processing, governing law§5.3.9
Computed in the EEA against data stored in the EEA. Governed by Swiss law and, where it applies to you, the GDPR.
How long§5.3.11
The match is computed and shown; nothing additional about you is stored by it.
Risks worth knowing§5.3.16
Ranking low is invisible to you — you cannot see the opportunities you did not appear in. How you describe your own capability therefore affects who finds you, and we cannot correct for that on your behalf.
Your controls§5.3.12 · Art. 21
Turn off availability. Object to matching while staying published. Unpublish.
Where your choices live§5.3.14
Profile settings → Discovery, with the availability switch and the objection control on the same surface.
Complaints§5.3.13 · Art. 77
⚠︎ Supervisory authority not yet named.
If you decline—
You keep a public profile that nobody is matched to.
04Account, sign-in and security

You register with an email address and a password, or with Google. Our backend provider hashes your password and we never see it. Breached and common passwords are refused. Sessions are held as tokens in your browser.

Required for the serviceA6-1-b · A6-1-f
Purpose§5.3.2–3
To give you an account, let you sign in to it, and keep it from being taken over.
Legal basis§5.3.15
Performance of the contract for the account itself. Legitimate interest for security, abuse prevention and rate limiting.
Personal data§5.3.5
Your email address, your hashed password, the provider identifier, and — with Google sign-in — the basics it returns: name, email address, avatar. Plus timestamps for sign-up, sign-in and confirmation, and your role assignments.
How and when we get it§5.3.6–7 · Art. 13
Typed by you at registration, or returned by Google if you choose that route. Timestamps are recorded as you act.
What we do with it§5.3.8
Authenticate you, hold your session, send transactional email for password reset and address confirmation, and rate-limit abuse.
Who else receives it§5.3.10
Our authentication provider, as a processor. Nobody else.
Storage, processing, governing law§5.3.9
Stored and processed in the EEA; accessed from Switzerland by the controller. Governed by Swiss law and, where it applies to you, the GDPR.
How long§5.3.11
The life of the account; the authentication record goes when you delete it. ⚠︎ Grace period before hard deletion not yet set.
Risks worth knowing§5.3.16
Your email address is both your login and a contact route, so a breach at the authentication provider would expose it. We do not hold your password in any form we could disclose.
Your controls§5.3.12 · Art. 15–17
Change your email address or password. Delete the account.
Where your choices live§5.3.14
Account settings → Security.
Complaints§5.3.13 · Art. 77
⚠︎ Supervisory authority not yet named.
If you decline—
There is no service without an account. This is the one section with no alternative, and we say so rather than offering a switch that would not work.
05Records layer

Sensitive changes are recorded — who acted, what changed, when — and there is no opt-out. It is what lets KROG say a credential was issued by a competent issuer rather than merely assert it. You can see these records; you cannot delete them while the claim they support is still relied on.

No opt-outA6-1-c · A6-1-f
Purpose§5.3.2–3
To be able to demonstrate, after the fact, who did what to a profile, an organisation, an admission or a credential.
Legal basis§5.3.15
A legal obligation — accountability under Art. 5(2) — with legitimate interest in the integrity of the credential system.
Personal data§5.3.5
Who made a change, what changed, and when. Where an administrator acted, their identity too.
How and when we get it§5.3.6–7
Generated by your own actions in the product, and ours, at the moment they happen.
What we do with it§5.3.8
Append an entry. Entries are added, never rewritten, and never used to profile you or to make a decision about you.
Who else receives it§5.3.10
Nobody outside KROG, unless a verifier or a regulator has a right to see a specific decision.
Storage, processing, governing law§5.3.9
Stored and processed in the EEA; accessed from Switzerland by the controller. Governed by Swiss law and, where it applies to you, the GDPR.
How long§5.3.11
As long as the claim the entry evidences is still relied on. ⚠︎ Retention period for audit entries not yet set.
Risks worth knowing§5.3.16
These entries name you as the actor and cannot be erased on request while the claim stands. That is a real limit on your Art. 17 right, and it is the price of the credential being checkable at all.
Your controls§5.3.12 · Art. 15
Access. Deliberately nothing more, while the underlying claim is relied on — a record you can delete is not a record.
Where your choices live§5.3.14
Profile settings → History. There is no switch here, and no greyed-out switch either — a disabled control would imply an opt-out that was taken away.
Complaints§5.3.13 · Art. 77
⚠︎ Supervisory authority not yet named.
If you decline—
You cannot decline this one. We are telling you rather than pretending otherwise.
06Course sign-up and payment

The structured-consent course is sold on Gumroad’s own page. Gumroad collects your name, email address and payment details as an independent controller in the United States, under its own notice. We receive your name and email address from it to enrol you, run your sittings, and issue what you earn. We never see your payment details.

Sold through Gumroad · USA6-1-b
Purpose§5.3.2–3
To enrol you in the course you bought, deliver it, arrange your examination sittings, and issue your certificate, badge and credential on a pass.
Legal basis§5.3.15
Performance of the contract you entered when you bought the course. No consent is sought on top of a purchase.
Personal data§5.3.5
Your name and email address. Your payment details go to Gumroad and its payment processors — they never reach us.
How and when we get it§5.3.6–7 · Art. 14
From Gumroad, when you buy at georgian117.gumroad.com/l/structured-consent — not collected from you by us, so we tell you what we hold at our first communication: the enrolment email.
What we do with it§5.3.8
Enrol you, send course and examination email, record your sittings and results, and issue the credential under section 02.
Who else receives it§5.3.10
Nobody, from our side. The flow runs the other way: you give your data to Gumroad when you buy, and Gumroad gives us your name and email address. Your results and credentials are not shared back to it. ⚠︎ The controller-to-controller arrangement with Gumroad is not yet documented.
Storage, processing, governing law§5.3.9 · Art. 44–49
Our copy is stored and processed in the EEA and accessed from Switzerland. Gumroad holds its own copy in the United States as an independent controller — that transfer happens directly between you and Gumroad when you buy, under Gumroad’s notice, not this one.
How long§5.3.11
⚠︎ Retention for course and examination records is not yet set. Credential evidence, once issued, follows section 02.
Risks worth knowing§5.3.16
Your purchase sits with a US company under US law, and this notice cannot govern it — read Gumroad’s notice too. Examination results are kept as evidence behind a credential, so deleting your account does not erase a result a credential relies on.
Your controls§5.3.12
Access and correct our copy by writing to us. For Gumroad’s copy, use Gumroad’s own account controls.
Where your choices live§5.3.14
Write to us for our copy. Gumroad’s account settings govern theirs.
Complaints§5.3.13 · Art. 77
⚠︎ Supervisory authority not yet named.
If you decline§5.4.6
Do not buy the course. The purchase is the choice — there is no separate consent to give or withhold on top of it.
07Operating the platform

Hosting, error reports, and page-speed timings. Error reports carry no user identifiers, no cookies and no IP addresses, and email addresses and tokens are stripped before anything is stored. No advertising, no third-party analytics.

No trackingA6-1-f
Purpose§5.3.2–3
To keep the site up, find out when it breaks, and keep it fast.
Legal basis§5.3.15
Legitimate interest in running a secure, working service.
Personal data§5.3.5
Intended to be none. Error text and timing measurements only; identifiers, cookies and IP addresses are not collected, and addresses and tokens are stripped server-side before storage.
How and when we get it§5.3.6–7
Posted by your browser to our own endpoint when a page errors or finishes loading. Capped at ten error reports per page visit.
What we do with it§5.3.8
Store it, read it when something is broken, and use it to fix the software. Browser storage is limited to what signing in and remembering your language need.
Who else receives it§5.3.10
Lovable Labs AB, Regeringsgatan 25, 111 53 Stockholm, Sweden, as processor, with a database, authentication and storage provider and an edge delivery network as sub-processors. ⚠︎ Full sub-processor list, each one’s region, and the transfer mechanism per processor not yet published — naming a processor without its region is not a transfer disclosure.
Storage, processing, governing law§5.3.9 · Art. 44–49
The controller is in Switzerland; the processors are in the EU and EEA. Edge delivery serves cached public pages from the region nearest the reader. Governed by Swiss law and, where it applies to you, the GDPR.
How long§5.3.11
⚠︎ Retention period for error reports and timings not yet set.
Risks worth knowing§5.3.16
An error message can incidentally quote something you typed. Stripping is a filter, not a guarantee, and we would rather say that than claim the reports are certainly anonymous.
Your controls§5.3.12 · Art. 21
Object to this processing.
Where your choices live§5.3.14
Write to us — there is no switch for this one, because turning off error reporting would mean shipping a site we cannot repair.
Complaints§5.3.13 · Art. 77
⚠︎ Supervisory authority not yet named.
If you decline—
This one runs for everyone who loads a page. Objecting is your route, not a toggle.
08The assistant

If you use the chat, your prompt and the conversation around it are sent to a model provider to produce an answer. Whatever you type goes with it. Nothing else on KROG depends on the assistant, so not using it costs you nothing.

Leaves our infrastructureA6-1-f
Purpose§5.3.2–3
To answer the question you asked the assistant.
Legal basis§5.3.15
Legitimate interest in providing an assistant you chose to invoke.
Personal data§5.3.5
Whatever you type. Please do not paste client-confidential material, or personal data about other people.
How and when we get it§5.3.6–7
Typed by you into the chat, at the moment you send it. Nothing is collected unless you use it.
What we do with it§5.3.8
Send your prompt and the conversation context server-side to the Lovable AI Gateway and on to the underlying model, currently Google Gemini Flash, and return the response to you.
Who else receives it§5.3.10
The gateway and the model provider, as processors.
Storage, processing, governing law§5.3.9 · Art. 44–49
⚠︎ The model provider’s processing region and the transfer mechanism are not yet confirmed. This is the one section where data may leave the EEA, and we will not state a region we have not verified.
How long§5.3.11
⚠︎ Retention at the gateway not yet confirmed.
Risks worth knowing§5.3.16
A prompt that has left our infrastructure cannot be recalled. ⚠︎ We do not yet have written confirmation that prompts are not used for training, so we cannot promise it. Treat the assistant as you would any third-party chat tool.
Your controls§5.3.12 · Art. 21
Do not use it. It is not required for any other function.
Where your choices live§5.3.14
The chat itself — using it is the choice, and closing it is the withdrawal.
Complaints§5.3.13 · Art. 77
⚠︎ Supervisory authority not yet named.
If you decline—
Nothing. Every other part of KROG works exactly the same.

Three fields in section 01 rest on your consent: your photo, your contact details, and your social links. The wording you are shown when you switch one on is a notice in its own right, with its own identifier and its own version — it is section 01 itself, not a copy of it. Your consent record cites that version, so we can always show what you were told at the moment you agreed.

CLAUSE §5.4 CONTROL HOW IT IS MET, FOR THE THREE CONSENTS
§5.4.2 Consent is the appropriate basis These three fields are genuinely optional — a profile works fully without them. Nothing about the service depends on them, so a real choice exists and consent is the honest basis.
§5.4.3 Informed and freely given The switch is off until you turn it on. Nothing is pre-selected, agreeing and declining carry equal weight, and closing the panel records no consent.
§5.4.4 Account identification The consent attaches to your KROG account, not to a browser or a cookie.
§5.4.5 Independent of other consents Not bundled with the terms of service, and not bundled with each other — three switches, three records.
§5.4.6 Necessary and optional kept apart The field map marks which fields rest on interest and which on consent, and refusing the optional ones changes nothing else.
§5.4.7 Frequency of re-confirmation — optional control We do not time-limit these consents; they stand until you withdraw them. Stated because §5.4.7 is optional and we are choosing not to apply it — not because it was overlooked.
§5.4.8 Timeliness The consent is recorded at the moment you give it, with the timestamp, the notice version, and the withdrawal route as it stood then.
Seven of the eight sections do not rest on consent, so the seven consent controls do not apply to them. A control that does not apply is not silence — it is a line with a reason. This is the table an auditor asks for, and the commonest place a notice falls down.
SECTION BASIS WHY §5.4.2–5.4.8 DO NOT APPLY
02 · Credentials A6-1-b No consent is sought. The processing is what you asked us to do, and consent would be the wrong basis — withdrawing it would have to un-issue a credential someone has already verified. Offering a consent control here would misdescribe the relationship.
03 · Matching A6-1-f No consent is sought, so §5.4 is not engaged. The right that applies instead is objection under Art. 21, and it is available in place on the discovery panel rather than by email.
04 · Account and security A6-1-b
A6-1-f
No consent is sought. There is no version of the service without an account, so a consent request would be a choice that does not exist — the definition of a consent that is not freely given.
05 · Records layer A6-1-c
A6-1-f
No consent is sought and none could be: the records exist to satisfy an accountability obligation we cannot waive on request. No opt-out exists, and none is implied — there is no disabled switch on this surface.
06 · Course sign-up A6-1-b No consent is sought. The purchase is the contract, and the only consent-shaped choice is whether to buy. Gumroad’s own collection is governed by Gumroad’s notice, which we cannot write for it.
07 · Operating the platform A6-1-f No consent is sought. Browser storage is limited to what sign-in and your language choice require, which is why no consent banner appears — asking for consent we do not need would be theatre.
08 · The assistant A6-1-f No consent is sought; invoking the assistant is itself the choice, and not invoking it is the refusal. ⚠︎ If the open transfer and training questions resolve badly, consent may become the appropriate basis and §5.4 would then apply in full here.
Content is only half of 29184. The other half is provision — whether the notice actually arrives, in time, in a form you can use. These are claims about our own process, and they are the ones a regulator tests against the product rather than the page.
§5.2.2It is provided. Linked from every page footer, from the profile editor, and from each consent switch.
§5.2.3Plainly expressed. Short sentences, no defined-terms table, no cross-references to other documents.
§5.2.4Both renderings from one source. English and Norwegian are generated from the same structured notice and versioned together, so neither lags.
§5.2.5Before collection. Shown at registration before an account exists, and at each consent switch before it can be turned on.
§5.2.6Where the data is asked for. The relevant section is reachable from the field that collects it, not only from the footer — and the search above means a question finds its section without knowing our structure.
§5.2.7Layered, honestly. Each summary is true on its own; the thirteen facts are one action away. Not a long page with jump links.
§5.2.8Citable and archived. Every version keeps its identifier and stays retrievable for as long as any record cites it.
§5.2.9Accessible. Semantic headings, real tables, native disclosure controls, visible focus, and no reliance on colour alone. ⚠︎ Comprehension not yet tested with readers — Art. 25(1) evidence is a claim until it is.
Rights here are product controls first and a request route second. Where you can do it yourself, the switch is in the product and takes effect immediately. Writing to us is the fallback, not the mechanism.
RIGHT HOW YOU USE IT WHERE
See your data Art. 15 Your profile, your credentials and the evidence behind them, and the records of changes to them. In the product
Correct it Art. 16 Edit any profile field. Changes to a published profile take effect on the public page. In the product
Erase it Art. 17 Delete your profile, or the whole account. Records evidencing a credential still relied upon are the stated exception — see section 05, where the limit and its reason are set out. In the product
Take it with you Art. 20 Export your profile and credentials as a machine-readable file. Portability is built in, not a request queue. In the product
Withdraw consent Art. 7(3) Turn off the phone opt-in, remove your photo, remove a social link — each on its own, in one action, on the same surface where you gave it. Withdrawing does not make what happened before it unlawful. In the product
Object Art. 21 To matching, to publication, or to platform operation — the three things resting on legitimate interest. Product, or write to us
Restrict processing Art. 18 Ask us to hold processing while a dispute about accuracy or grounds is resolved. Write to us
Not be subject to an automated decision Art. 22 Nothing here produces one. Matching profiles you in the Art. 4(4) sense, but a person decides whether to make contact — so this right has nothing to bite on, and we say so rather than omitting the row. Not engaged
Complain Art. 77 To a supervisory authority, without going through us first. Authority not yet named
⚠︎
Open before publication

Which supervisory authority hears a complaint — Datatilsynet in Norway, the FDPIC in Switzerland, or both — turns on the Art. 3 territorial analysis and on whether an Art. 27 representative in the EEA is required of a Swiss controller offering services there. That analysis is not finished, so the authority is not named. A guessed complaint route is worse than an admitted gap, and this is the single most-used line in any privacy notice.

Using any of these

Write to hello@signatu.com. We answer within one month. If we need longer because a request is complex, we will tell you inside that month and say why.

The same notice, machine-readable

KROG vocabulary

Everything above as structured data, in the KROG vocabulary at krognetwork.com/ns — one namespace, mapped term for term onto W3C DPV 2.3, so a consent record can cite it and a tool that has never seen KROG can still read it. Published here to be read, not injected invisibly: a machine-readable claim you cannot inspect is not transparency.

{ "@context": { "krog": "https://krognetwork.com/ns#", "gdpr": "https://krognetwork.com/ns/gdpr#", "dct": "http://purl.org/dc/terms/" }, "@id": "krog:privacy-notice-1", "@type": "krog:PrivacyNotice", "dct:hasVersion": "2.0", "dct:issued": "«REVIEW»", "dct:language": ["en", "nb-NO"], "krog:hasDataController": { "@id": "krog:KrogDataPrivacyAndGovernance", "krog:hasName": "Krog Data Privacy & Governance", "krog:hasAddress": "Via Mariöl 31, 7524 Zuoz, Switzerland", "krog:hasContact": "mailto:hello@signatu.com" }, "krog:hasDataProtectionOfficer": "«REVIEW»", "krog:hasAuthority": "«REVIEW: Datatilsynet | FDPIC | both»", "krog:hasRepresentative": "«REVIEW: Art. 27 required for a CH controller?»", "krog:hasProcess": [ { "@id": "krog:publish-profile", "krog:order": 1, "krog:hasPurpose": "krog:ServiceProvision", "krog:hasLegalBasis": ["gdpr:A6-1-f", "gdpr:A6-1-a"], "krog:hasLegitimateInterestAssessment": "«REVIEW»", "krog:hasPersonalData": ["krog:Name", "krog:Photo", "krog:EmailAddress", "krog:TelephoneNumber", "krog:SocialMediaAccount", "krog:JobTitle", "krog:City", "krog:Qualification"], "krog:hasDataSource": ["krog:DataSubjectSource", "krog:PublicSource"], "krog:hasProcessing": ["krog:Collect", "krog:Store", "krog:MakeAvailable", "krog:Disseminate"], "krog:hasRecipient": ["krog:LovableLabsAB", "krog:ThirdParty"], "krog:hasStorageCondition": { "krog:hasLocation": "krog:EEA" }, "krog:hasLocation": ["krog:EEA", "krog:Switzerland"], "krog:hasJurisdiction": ["krog:Switzerland", "krog:EEA"], "krog:hasNotice": "krog:consent-notice-1", "krog:hasRight": ["gdpr:A7-3", "gdpr:A15", "gdpr:A16", "gdpr:A17", "gdpr:A20", "gdpr:A21"], "krog:hasConsentControl": "krog:WithdrawConsent" }, { "@id": "krog:issue-credential", "krog:order": 2, "krog:hasPurpose": "krog:ServiceProvision", "krog:hasLegalBasis": "gdpr:A6-1-b", "krog:hasDataSource": ["krog:DataSubjectSource", "krog:ThirdPartySource"], "krog:hasProcessing": ["krog:Assess", "krog:Store", "krog:MakeAvailable"], "krog:hasStorageCondition": { "krog:hasDuration": "«REVIEW: revoked»" }, "krog:hasJurisdiction": ["krog:Switzerland", "krog:EEA"], "krog:art14Applies": true }, { "@id": "krog:match-profile", "krog:order": 3, "krog:hasPurpose": "krog:SearchFunctionalities", "krog:hasLegalBasis": "gdpr:A6-1-f", "krog:hasLegitimateInterestAssessment": "«REVIEW»", "krog:hasProcessing": ["krog:Analyse", "krog:Profiling", "krog:Match"], "krog:hasAutomatedDecisionMaking": false, "krog:hasRight": "gdpr:A21" }, { "@id": "krog:account", "krog:order": 4, "krog:hasPurpose": ["krog:AccountManagement", "krog:EnforceSecurity"], "krog:hasLegalBasis": ["gdpr:A6-1-b", "gdpr:A6-1-f"], "krog:hasPersonalData": ["krog:EmailAddress", "krog:Password"], "krog:hasStorageCondition": { "krog:hasDuration": "«REVIEW: grace period»" } }, { "@id": "krog:records-layer", "krog:order": 5, "krog:hasPurpose": "krog:RecordManagement", "krog:hasLegalBasis": ["gdpr:A6-1-c", "gdpr:A6-1-f"], "krog:hasOrganisationalMeasure": "krog:AuditLog", "krog:hasStorageCondition": { "krog:hasDuration": "«REVIEW»" }, "krog:hasRight": "gdpr:A15", "krog:hasOptOut": false }, { "@id": "krog:course-enrolment", "krog:order": 6, "krog:hasPurpose": ["krog:ServiceProvision", "krog:PaymentManagement"], "krog:hasLegalBasis": "gdpr:A6-1-b", "krog:hasPersonalData": ["krog:Name", "krog:EmailAddress"], "krog:hasDataSource": "krog:ThirdPartySource", "krog:hasRecipient": "krog:GumroadInc", "krog:hasLocation": ["krog:EEA", "krog:UnitedStatesOfAmerica"], "krog:hasStorageCondition": { "krog:hasDuration": "«REVIEW: course records»" }, "krog:art14Applies": true, "krog:c2cArrangement": "«REVIEW: Gumroad»" }, { "@id": "krog:operate-platform", "krog:order": 7, "krog:hasPurpose": "krog:TechnicalServiceProvision", "krog:hasLegalBasis": "gdpr:A6-1-f", "krog:hasDataProcessor": "krog:LovableLabsAB", "krog:hasDataSubProcessor": "«REVIEW: list + region each»", "krog:hasJurisdiction": ["krog:Switzerland", "krog:EU", "krog:EEA"], "krog:transferMechanism": "«REVIEW: per processor»" }, { "@id": "krog:assistant", "krog:order": 8, "krog:hasPurpose": "krog:ServiceProvision", "krog:hasLegalBasis": "gdpr:A6-1-f", "krog:hasRecipient": "krog:LovableAIGateway", "krog:hasLocation": "«REVIEW: model provider region»", "krog:usedForTraining": "«REVIEW: written confirmation pending»" } ], "krog:consentControlsApplicability": [ { "krog:hasProcess": "krog:publish-profile", "krog:iso29184-5.4": "applies in full", "krog:appliesTo": ["krog:Photo", "krog:EmailAddress", "krog:TelephoneNumber", "krog:SocialMediaAccount"] }, { "krog:hasProcess": "krog:issue-credential", "krog:iso29184-5.4": "not applicable", "krog:reason": "No consent sought; contract basis. Withdrawal could not un-issue a verified credential." }, { "krog:hasProcess": "krog:match-profile", "krog:iso29184-5.4": "not applicable", "krog:reason": "No consent sought; Art. 21 objection applies instead, available in place." }, { "krog:hasProcess": "krog:account", "krog:iso29184-5.4": "not applicable", "krog:reason": "No consent sought; no service exists without an account, so no free choice could be offered." }, { "krog:hasProcess": "krog:records-layer", "krog:iso29184-5.4": "not applicable", "krog:reason": "No consent sought and none possible; Art. 5(2) accountability cannot be waived on request." }, { "krog:hasProcess": "krog:course-enrolment", "krog:iso29184-5.4": "not applicable", "krog:reason": "No consent sought; contract. The purchase is the choice. Gumroad's collection is governed by Gumroad's own notice." }, { "krog:hasProcess": "krog:operate-platform", "krog:iso29184-5.4": "not applicable", "krog:reason": "No consent sought; storage limited to sign-in and language, so no consent is required." }, { "krog:hasProcess": "krog:assistant", "krog:iso29184-5.4": "not applicable", "krog:reason": "No consent sought; invoking the assistant is the choice. May change if transfer questions resolve badly." } ], "krog:nestedNotice": { "@id": "krog:consent-notice-1", "@type": "krog:ConsentNotice", "dct:hasVersion": "1.0", "dct:isPartOf": "krog:privacy-notice-1", "krog:hasIndicationMethod": "krog:CheckboxAgreement", "krog:citedByRecordsAs": "krog:consent-notice-1@v1.0" } }
Download the profile field map Download the organisation field map

When this notice changes

§5.5 · VERSION ARCHIVE
Every change gets a version

Editorial corrections included. Superseded versions keep their identifiers and stay retrievable, because consent records cite this notice by version number.

A material change asks again

Where processing rests on your consent and the meaning of a section changes, we ask for consent again before the change takes effect. Telling you is not the same as asking you.

The archive outlives the notice

A version stays available for as long as any record cites it — not until the next release. A record citing a version you cannot produce is not evidence.

Both languages move together

English and Norwegian render from one source and are versioned together. Neither is a translation that lags behind the other.

How this notice is written — in development
CODE → DPV MODEL → NOTICE

We are building agents that read the platform’s source code, populate a DPV 2.3 data model from what the code actually does, and draft this notice — and the other compliance documents — from that model. When the code changes what it collects or why, the agent proposes a new version; we can also prompt it to change. A generated version is still a version: numbered, archived, diffable, and citable by consent records. Until that pipeline is in production, every version is written by hand.

VERSION ISSUED CHANGE WHAT CHANGED
v2.0 unpublished Material Thirteen facts per section against the §5.3 clauses; jurisdiction, processing operations, risks and choice location added; the consent notice nested with its own version; the §5.4 applicability table added; the machine layer moved to DPV 2.3; the notice made searchable; the course sign-up activity added, with its Art. 14 route.
v1.0 unpublished Draft First draft. Never published, so no consent record cites it.
Krog Data Privacy & Governance · Via Mariöl 31, 7524 Zuoz, Switzerland
krog:privacy-notice-1@v2.0 · en · nb-NO
ISO/IEC 29184:2020 §5.2–5.5 · ISO/IEC TS 27560:2023
GDPR Art. 13–14 supplement · W3C DPV 2.3
krog-notice.jsonldkrog:privacy-notice-1 · v2.0