Privacy Policy
This policy explains how KALIROX AS handles personal information when you use the 6ops app, website and business subscription service.
Who is responsible
KALIROX AS is responsible for personal information used to administer accounts, subscriptions, support and the security of our service. Your company determines the purposes of its shared business records and the people permitted to access them. Where we process those records on your company's behalf, the company is the controller and we act as its processor. Contact privacy@6ops.com for privacy requests or information about processing arrangements.
Information we process
We process your account identifier, name, work email, company membership, role and permissions; account and currency records, expenses, amounts, dates, notes, receipts, cash handovers and audit history; photos or voice notes you choose to attach; assistant conversations; and recent activity within the app. We also process request identifiers, error information and network access logs to operate and protect the service. Information may come from you, your company administrator or colleagues who create records involving you.
For subscriptions, we process company and billing contact details, billing address, tax details where provided, Stripe customer and subscription identifiers, invoices and payment status. Card details are entered directly into Stripe. 6ops does not receive your full card number or card security code.
Website enquiries
When you submit the contact form, we process your name, work email, company, team size, enquiry type, language and optional message to answer your request. The message is sent through Cloudflare Email Service to sales@6ops.com and delivered to our Google Workspace mailbox. Replying uses the work email you provide. Please do not include sensitive personal information or financial documents.
Cloudflare Turnstile processes browser and connection signals, including your IP address, to prevent automated abuse. The security check loads when you approach or interact with the form, and its result is verified on the server before email is sent. We use these details to answer enquiries and protect the service; correspondence is retained as needed to handle the enquiry and any resulting business relationship. See Cloudflare’s Privacy Policy for information about its processing.
Purposes and legal bases
We use information to authenticate users, control access, provide shared records and synchronisation, manage trials and subscriptions, answer support requests and deliver assistant responses you request. Depending on the context, the legal basis is performing a contract with the customer, legitimate interests in providing a secure business service and preventing abuse, compliance with legal record-keeping obligations, or consent for optional processing. Where we rely on legitimate interests, individuals may object as described below. Device permissions and optional assistant consent can be withdrawn through the relevant settings; withdrawal does not affect processing that was lawful before withdrawal.
When your company controls the business records, it is responsible for establishing and explaining the appropriate legal basis. Records are visible to authorised company users according to their role and workspace permissions.
Service providers and international processing
We use Google Firebase for authentication; Microsoft Azure for the app API, database, private file storage and assistant processing; Cloudflare for website delivery, network security, contact-form verification and email delivery; Stripe for subscription payments and invoices; and Google Workspace for support correspondence. These providers receive information needed to perform their services. Information may also be disclosed where required by law or necessary to protect legal rights.
The database and file resources are hosted in Sweden. Assistant text processing uses a European data zone; audio transcription may use global processing infrastructure. Firebase, support, billing and network services may involve processing in other countries. Contact privacy@6ops.com for details of the applicable providers, processing locations and transfer safeguards, or to request information about relevant arrangements.
The workspace assistant
When you consent and submit a question, your message and relevant records you are authorised to access are sent to the model service on Microsoft Azure. Relevant receipts or voice notes may also be read or transcribed. Private conversations are not shown to other team members. The assistant does not independently create or change financial records, and its answers may be wrong. Check the original linked record before relying on an answer.
Permissions, storage and cookies
Photo-library, camera and microphone access is requested when you use the corresponding feature. The app does not request location, contacts or advertising-tracking permissions. Mobile session credentials use the operating system's secure storage, and the local record cache is encrypted. Selected photos and recordings may be stored in the app's local storage. Information is transmitted over HTTPS.
This website does not use advertising or visitor-analytics cookies. The subscription area uses a secure, HttpOnly session cookie that expires after one hour, created after Google sign-in. A one-way hash of the account email is retained to prevent a free trial from being restarted through account deletion and recreation. It is not used for advertising.
Retention and account deletion
Account and operational information is retained as needed to provide the service, protect its security and meet applicable record-keeping obligations. You can request deletion from the app or through our account deletion page. Deletion removes the sign-in account, private assistant conversations and server files not attached to a shared financial record. The app clears that user's local session and records when deletion completes.
Shared financial records, audit history and attached documents may be retained to preserve the company's record integrity. The visible profile name is changed to "Deleted user". Information already included in documents or record descriptions is not automatically rewritten; contact us about further correction or deletion requests. Billing records may be retained where legally required.
Deleted information may remain in backups until the provider's retention cycle completes. Database backups are retained for 7 days in the test environment and 14 days in production. Old file versions and snapshots are covered by a 14-day cleanup rule, with a further 14-day recovery period for deleted copies; final cleanup follows the provider's processing cycle.
Your rights and contact
Subject to applicable conditions, you may request access, correction, deletion, restriction, portability or object to processing. You may withdraw consent where processing relies on it. We may need to verify your identity and coordinate requests about company-controlled records with your company. Contact privacy@6ops.com. You may also complain to the Norwegian Data Protection Authority or your competent supervisory authority.
Service provider: KALIROX AS. General support: support@6ops.com. We will update this policy when the service's processing changes and make the current version available here.