Privacy Policy
Updated: 3 August 2026
This policy explains what data NORTHLODE SRL processes through the Clarito website, and what the desktop app does — and does not — send. Your accounting data stays on your computer.
1. What we collect through the site
Through the site we collect the minimum data needed for your account and payment:
Legal bases: the contract (your account and licence), a legal obligation (invoicing) and legitimate interest (site security).
Orders paid as a guest, without an account, are linked to your account automatically when the account's confirmed email address is the one used for payment; the basis is performance of the contract — GDPR art. 6(1)(b).
- Account: your email and name, to create the account and deliver the licence key.
- Account hosting and authentication: your account, authentication and licences are hosted by Supabase in the EU region (eu-west-1, Ireland), under a data processing agreement (DPA).
- Google sign-in (optional): if you choose “Continue with Google”, Google LLC (USA) shares your email address and name with us to create your account. This is a data transfer outside the EU, made under Standard Contractual Clauses.
- Payments: processed by Stripe as the payment processor. We do not store your card details.
- Transactional emails: sent through Resend (account confirmation, licence key, invoices).
- Newsletter: your email address, only if you voluntarily subscribe on the site (basis: consent — GDPR art. 6(1)(a)). You can unsubscribe anytime by writing to our support address.
2. What we do NOT collect from the app
The accounting data you enter in the app (invoices, partners, returns, records) stays 100% local, in a SQLite database on your computer. We have no access to this data and never send it to our servers.
The app does talk to our servers for two things, described in full in the next two sections: trial verification and paid-licence activation. Neither of them sends any accounting data.
3. Trial-abuse prevention
WHAT we send: when the trial period is activated, the app sends our servers your email address (lowercased), a pseudonymised device identifier (the SHA-256 hash of the machine identifier — not the raw hardware ID), the app version and the operating system. On receipt, Cloudflare's infrastructure provides us the request's IP address, country and network (ASN). This data includes NOTHING from your accounting records.
WHEN: once, at trial activation. If the network was down at that moment, the app retries once on a later start.
PURPOSE and basis: solely preventing abuse of the trial period (for example, repeatedly restarting the trial on the same device with different email addresses). The legal basis is legitimate interest — GDPR art. 6(1)(f), in line with Recital 47 on fraud prevention — not consent; transparency about it is mandatory, which is why this section exists.
WHERE: the data reaches our own backend endpoint (clarito.eu/api/trial/checkin) and is stored in our database hosted by Supabase in the EU region (eu-west-1, Ireland), under a data processing agreement (DPA).
RETENTION and minimisation: the SHA-256 hash remains pseudonymised (not anonymous) data and we treat it as personal data; it cannot be reversed to recover the device identifier. Verification data is kept for at most 180 days, then deleted automatically.
ERASURE on request: a deletion request (see the "Your rights" section) also covers these server-side verification records — we remove them together with the rest of your data. Payments remain processed by Stripe, and the site and downloads are delivered through Cloudflare.
4. Paid-licence activation and verification
WHAT we send: when a paid licence is activated, the app sends our servers the licence key, your email address (lowercased), a pseudonymised device identifier (the SHA-256 hash of the machine identifier — not the raw hardware ID), the app version and the operating system. Later verifications send only the key, the pseudonymised identifier, the version and the operating system — no email address. On receipt, Cloudflare's infrastructure provides us the request's IP address and country; the IP address is personal data and we treat it as such. Nothing from your accounting records leaves your computer.
WHEN: once at activation, then automatically, in the background, at most once every 24 hours. In the licence's last 7 days of validity — or if a verification failed — the app retries more often until it gets an answer. The checks run in the background, never interrupt your work and never ask you for anything.
PURPOSE and basis: delivering and maintaining the licence you bought — confirming it is valid, binding it to the computers you use it on, and honouring the number of computers included in your plan (see the Terms, "Licence" section). The basis is performance of the contract — GDPR art. 6(1)(b). We use the IP address and country to secure the endpoint and limit abuse, on the basis of legitimate interest — GDPR art. 6(1)(f).
WHERE: the data reaches our own backend endpoints (clarito.eu/api/license/activate and clarito.eu/api/license/refresh) and is stored in our database hosted by Supabase in the EU region (eu-west-1, Ireland), under a data processing agreement (DPA).
WHAT WE KEEP: for each activated computer we keep the pseudonymised identifier, the operating system, the app version, the first-activation date, the last-verification date and the last IP address seen. Separately, we keep a log of activations and verifications, where each record carries the date, the IP address, the country and — if a verification was refused — the reason for the refusal.
RETENTION: the activation and verification log is deleted automatically after 12 months. The records of activated computers are kept for as long as the licence is in force plus a further 12 months, so we can answer a support request or a complaint about the licence.
ERASURE on request: a deletion request (see the "Your rights" section) also covers these records — the activated-computer data and its log are deleted together with the licence.
5. Your rights (GDPR)
You have the right to access, rectify, erase and port the data linked to your site account. You can exercise these rights by emailing a request to the support address.
You also have the right to restriction of processing and to object. If you believe the processing infringes your rights, you can lodge a complaint with ANSPDCP — the Romanian National Supervisory Authority for Personal Data Processing (dataprotection.ro).
6. Cookies
We use only essential cookies, needed for authentication and for the site to work. We do not use tracking, advertising or analytics cookies.
Concretely: we use only authentication cookies (Supabase), essential to keep you signed in. Your theme preference is stored in the browser's local storage (localStorage), and language is determined by the page URL — neither uses cookies. We use no analytics, advertising or tracking cookies, so no consent banner is required.
7. How long we keep data
We keep account data for as long as the account exists. Data needed for invoicing is kept as required by Romanian tax law (10 years). Support emails are kept for at most 2 years.
Trial-verification data (the hashed device identifier and its associated metadata): at most 180 days, then deleted automatically.
Paid-licence activation data: the activation and verification log, 12 months; the records of activated computers, for as long as the licence is in force plus a further 12 months.
8. Data controller
The controller of the data collected through the site is NORTHLODE SRL. For any question about data processing, you can contact us by email at the support address.