Kleos Privacy Policy
This page describes what data the Kleos service collects and stores: the redirect infrastructure for physical carriers (NFC stands, QR codes), the admin panel and — with the profile owner's separate consent — the Google Business Profile integration.
- Who is responsible for the data. The service operator and data controller is Roman Romanenko, Kyiv, Ukraine. Contact for questions about this policy and data requests: hello@yevrox.tech.
- Carrier scans. When someone taps an NFC tag or scans a QR code, only four values are stored: the carrier code (which stand), the device platform (ios / android / other), the source of the visit (nfc / qr / other) and the time of the scan (UTC). No IP address, no User-Agent, no device identifiers, no geolocation and no cookies are collected or stored — this is a requirement of the service built into its architecture. These records cannot identify a person, are not personal data and are kept indefinitely as carrier statistics.
- Client data. Kleos works for businesses — venues that order profile setup and management. About such businesses the panel stores: the venue name and address, its Google Maps profile identifier, the name, phone, email or Telegram of a contact person, the interaction history (meetings, agreements, notes) and work status. Contact details of client representatives are personal data; the legal basis for processing is the performance of the agreement with the client or the client's consent. This data is kept for the duration of the agreement and 12 months after it ends, then deleted or anonymised. The panel does not collect data about venue visitors or guests.
- Panel users. For service staff and client representatives who receive panel access, the email, role and password hash are stored. Records of actions in the panel (audit log) are kept for security and change tracking.
- Google Business Profile data. If a profile owner grants Kleos access through Google OAuth, the service receives only the data required for its functions: reviews and replies to them, profile performance metrics (views, calls, directions, website clicks) and basic profile details. This data is used solely to work with reviews and to prepare reports for the same client; it is not sold, not shared with third parties and not used for advertising. Access can be revoked at any time on the Google Account permissions page (myaccount.google.com → Security → Third-party apps) or by emailing hello@yevrox.tech — after revocation the received data is deleted on request or after the agreement ends under the general retention period. Kleos' use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. As of the date of this policy, this integration is in preparation and not active.
- Where data is stored and who helps process it. Carrier redirects and this website run on Cloudflare infrastructure; scan records are stored in Cloudflare (D1, KV). The admin panel database is hosted on a server in the Germany (Frankfurt) region. Notifications to service staff are sent via Telegram and contain no data about venue guests. No other third-party services have access to the data.
- Cookies and analytics. This website sets no cookies and uses no analytics or tracking services. The admin panel stores a sign-in token only in the panel user's browser.
- Your rights. You may request access to your personal data, its correction or deletion, withdraw consent or object to processing. Send requests to hello@yevrox.tech; we respond within 30 days.
- Changes to this policy. Updates are published on this page with the date. Last updated: 20 September 2026.
Home.