Confidentiality & Legal Privilege Assurance

Privacy & Data Security Policy

Last Updated: October 2026 • Version 2.4 (Compliant with GDPR & UK Data Protection Act)

This Privacy Policy explains how NAVIR LTD (“we”, “us”, or “our”) processes information, contract files, and transactional records across the KROTKA platform at krotka.app.

01. Data Controller & System Operator

The KROTKA platform is operated and delivered by:

NAVIR LTD

Company Registration Number: 09112128 (England and Wales)

Registered Address: 137 County Road, Walton, Liverpool, L4 3QF, United Kingdom

Direct Privacy Enquiries: privacy@krotka.app

02. Zero-Training Guarantee (No Customer Data in Public AI Models)

Law Firm Confidentiality & Trade Secret Safeguards

No uploaded contracts, amendments, Non-Disclosure Agreements (NDAs), transactional filings, or extracted financial terms are ever used to train public, open-source, or proprietary third-party AI models.

KROTKA is powered by a deterministic cognitive memory engine. Unlike consumer conversational chatbots, the audit process consists of structural logic parsing, editorial section indexing, and exact verbatim source quote verification within strict closed-world boundaries.

03. Ephemeral Processing & Data Retention

  • Ephemeral Execution Sandbox: Uploaded PDF and DOCX files are processed in isolated memory environments. Once parameter extraction is complete and the audit report is returned, original files are purged from active server memory.
  • No Permanent Document Archives: The service does not maintain public or persistent databases storing the full text of your confidential agreements. Audit reports in PDF or Excel formats are generated on demand and downloaded directly to your local workstation.
  • No Data Monetization: Under no circumstances do we sell, rent, or commercialize customer files or legal findings.

04. Scope of Information & Legal Basis

We collect only the minimum information necessary to provide the service and fulfill billing requirements:

  • Account & Subscription Data: Professional email address, organisation name, VAT/tax identifier, and chosen plan (Starter / Professional / Team).
  • Audit Metrics & Provenance: Processed page volume, cryptographic document hash (SHA-256) for audit integrity verification, and execution runtime.
  • Secure Payments: Subscription processing is handled by a certified Level 1 PCI-DSS payment partner. We never store payment card details on our servers.

Legal Basis: Article 6(1)(b) GDPR (necessary for the performance of a contract or preliminary steps) and Article 6(1)(f) GDPR (legitimate interests in ensuring platform infrastructure security and fraud prevention).

05. Security by Architecture

Transport Security (TLS 1.3)

All traffic is encrypted in transit using TLS 1.3 with mandatory HTTP Strict Transport Security (HSTS).

Rest Encryption (AES-256)

Temporary working volumes utilize block-level AES-256 encryption.

06. Cookies & Tracking

We do not use advertising trackers or third-party marketing cookies. We use only strictly necessary session cookies for authentication, and local browser storage (localStorage) to preserve your language preference and active audit view.

07. Your Rights (GDPR & UK DPA)

Under European and UK data protection law, you have the right to access, rectify, or erase your account data, restrict or object to processing, and lodge a complaint with your supervisory authority (such as the UK Information Commissioner's Office – ICO at ico.org.uk, or your competent EU Data Protection Authority).

For privacy enquiries or to exercise your statutory rights, contact our legal counsel team directly at: privacy@krotka.app.