ChromaChecker Corporation ("ChromaChecker," "We," "Us," or "Our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
ChromaChecker is a B2B color management platform designed for organizations in the printing and color reproduction industry. We process primarily technical measurement data, with minimal personal data collection necessary for service delivery.
1. What Data Does ChromaChecker Collect?
1.1 Technical/Measurement Data
The primary data we collect describes technological processes: spectral measurement data; optical, physical, and chemical parameters; device calibration data; production quality metrics. This data is not personal data and relates to machines, devices, and processes.
1.2 Personal Data
We collect personal data in the following categories:
Main User (Account Owner): First name, last name, business email, business phone, company address — for contract execution, account management, support.
Staff/Operators (Optional): Nickname or name, email, login credentials — for access control, notifications, accountability.
Billing Information: Payment details, billing address — for payment processing.
Usage Data: IP address, browser type, access times, pages viewed — for security, analytics, service improvement.
Machine identifier: An identifier derived from a computer's hardware characteristics, used to distinguish licensed seats (including Plugin licences assigned to a specific computer). It is not used to identify an individual person.
Cookies: Session identifiers, preferences — for functionality, analytics (see Cookie Policy).
1.3 Data We Do NOT Collect
- Social Security or national ID numbers
- Biometric data
- Health information
- Data from children under 16
- Sensitive personal data (racial/ethnic origin, political opinions, religious beliefs, etc.)
2. How Is My Data Collected?
We collect personal data through: direct from you (registration forms, account settings, support requests); automated collection (cookies, server logs, usage analytics); from your organization (when Main User adds staff members); third parties (payment processors, for transaction verification only).
3. Why Is My Data Collected? (Legal Basis)
Under GDPR, we process personal data based on the following legal grounds:
- Providing the Service — Contract performance (Art. 6(1)(b))
- Account management — Contract performance (Art. 6(1)(b))
- Billing and payments — Contract performance (Art. 6(1)(b))
- Customer support — Legitimate interest (Art. 6(1)(f))
- Security and fraud prevention — Legitimate interest (Art. 6(1)(f))
- Legal compliance — Legal obligation (Art. 6(1)(c))
- Service improvements — Legitimate interest (Art. 6(1)(f))
- Marketing communications — Consent (Art. 6(1)(a))
- Analytics (cookies) — Consent (Art. 6(1)(a))
You may withdraw consent at any time without affecting the lawfulness of prior processing.
4. Who Processes My Data?
4.1 Data Controller
ChromaChecker Corporation, 4324 Sanddollar Court, New Port Richey, FL 34652, USA. Phone: 651.717.0590. Email: privacy@chromachecker.com.
4.2 Data Processors (Sub-processors)
We use the following categories of service providers:
| Provider | Purpose | Locations |
|---|---|---|
| Cloud hosting (OVH) | Data storage and processing | USA, Canada, France, Poland |
| Payment processors | Transaction processing | USA, EU |
| Analytics (Google Analytics) | Usage analytics | USA |
| Email services | Transactional emails | USA |
We maintain Data Processing Agreements with all sub-processors. Current sub-processor list available upon request: privacy@chromachecker.com.
5. Data handled by Plugins
Plugins are optional extensions that you choose to install. Some of them move data that the base applications never touch, and the following applies only to Plugins you have installed and enabled.
Your own accounts with third parties. Where a Plugin connects to a third-party service — for example cloud storage — it uses your organisation's account and, in the ChromaChecker desktop applications, your organisation's own registered application credentials. Files transferred that way move between your computer and your provider. ChromaChecker does not receive, store or process copies of them, and is not the controller of the data held in those accounts.
Production data from equipment on your site. A Plugin that reads production systems on your network may make selected values available to ChromaChecker as context attached to your colour measurements — but only for the values you have explicitly enabled. Some of those values can constitute personal data (for example the employees assigned to a press) or data confidential to your own customers (for example the name of the customer whose job is running). Your organisation is the controller for that data and decides whether it is sent at all; every such parameter is off by default, and each Plugin's Plugin Terms states which ones exist and where they go.
Credentials. Credentials a Plugin needs for a third-party service or a machine on your network are stored in the operating system's own credential store on that computer (macOS Keychain, Windows Credential Manager). They are not transmitted to ChromaChecker.
Local caches. A Plugin may cache downloaded files on the computer it runs on, so that reopening a file does not re-download it. Those caches are local to that computer and can be deleted at any time.
Machine identification. To assign a Plugin licence to a specific computer, ChromaChecker records an identifier derived from that computer's hardware characteristics. It is used to distinguish one licensed seat from another and is not used to identify an individual person.
6. Diagnostics and support reports
CC Capture includes Run Diagnostics, a tool that examines the workstation to explain why something is not working — most often an instrument that will not connect. It runs only when a person starts it. It is never scheduled, never automatic, and nothing is sent anywhere by running it.
What it examines, on the machine it runs on:
| Area | What is examined |
|---|---|
| The computer | operating system and version, processor, memory, disk space, locale, and the application's own runtime |
| Instruments | measuring devices connected or detected, including their model and serial number, together with the vendor drivers and services they need |
| Connections | USB and Bluetooth devices present, whether our servers can be reached, DNS, proxy settings, and the reachability of instruments on your network |
| The application | recent errors, warnings and crashes from CC Capture's own log files, and — on macOS — which system permissions the application has been granted |
It does not read your documents, your images or your measurement data, and it does not search the disk. It looks at the machine, its devices and our own logs.
Nothing leaves the workstation unless you send it. The result is shown to you first. If you then choose to send a support report, the diagnostic text is attached to it, and you may additionally attach CC Capture's recent session logs by ticking a box. The report goes to ChromaChecker support and is handled under this Policy.
Before anything is shown or sent, it is filtered. Home-directory paths are shortened so your account name does not travel; anything shaped like a password, token or API key is replaced with [REDACTED]; e-mail addresses other than your own reply-to address are removed; identifiers in paths and addresses are masked; and addresses on your own network — printers, instruments, servers — are replaced with [PRIVATE_IP], so the layout of your network does not travel with the report.
Support reports are retained for as long as the enquiry and our records require, and you may ask for one to be deleted (see the contact section below).
6.1 The Network Link Monitor
CC Capture also includes a Network Link Monitor, for the fault that only shows itself over hours — a connection that drops once an afternoon. Like Run Diagnostics it starts only when a person starts it, and there is no obligation to use it at all.
Once started it keeps running until it is stopped, including while its window is closed — that is the point of it, and the application warns you if you try to quit with a run still going. While it runs it repeatedly contacts two addresses, both discovered when you press Start: the ChromaChecker server your installation is configured to use, and the measuring instrument on your network if you have a network-connected one. It sends ordinary reachability traffic — a ping, a connection attempt, a web request — and records how long each took and whether it succeeded. On macOS it also notes the strength and quality of the WiFi signal, so a fault can be told apart from a weak aerial.
It reads nothing else, and it contacts nothing else — no third party, and no address you have not configured.
The results are written to a file on the workstation. Nothing is sent anywhere by the monitor itself; if you want us to look at a run, you attach its report to a support report, and everything above about filtering applies to it.
7. How Long Is My Data Stored?
- Active account data: Duration of service agreement
- Inactive account data: 180 days after last login, then deleted
- Billing records: 7 years (legal requirement)
- Support tickets: 3 years after resolution
- Server logs: 90 days
- Backup data: 60 days (rolling)
After 166 days of inactivity: warning email sent. After 180 days: account and all data permanently deleted. Data removed from backups within 60 days.
8. How Is My Data Protected?
8.1 Technical Measures
- Encryption in transit: TLS 1.2+ for all connections
- Encryption at rest: AES-256 for stored data
- Access controls: Role-based access, multi-factor authentication available
- Network security: Firewalls, intrusion detection, DDoS protection
- Data isolation: Multi-tenant architecture with logical separation
8.2 Organizational Measures
Employee background checks and confidentiality agreements; regular security training; access limited to personnel who need it; incident response procedures; regular security assessments.
8.3 Infrastructure
Our servers are hosted in certified data centers (OVH) with: ISO 27001 certification; SOC 2 compliance; physical security controls; redundant power and cooling; 24/7 monitoring.
8.4 Credentials on the workstation
Credentials used by the ChromaChecker desktop applications and Plugins for third-party services or equipment on your network are stored in the operating system's credential store (macOS Keychain, Windows Credential Manager), not on ChromaChecker servers.
9. What Are My Rights?
Depending on your location, you have the following rights:
- Access: Obtain a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure ("Right to be Forgotten"): Delete your data
- Restriction: Limit processing of your data
- Portability: Receive data in machine-readable format
- Object: Object to processing based on legitimate interest
- Withdraw Consent: Revoke previously given consent
- Non-Discrimination: Equal service regardless of privacy choices
- Opt-Out of Sale: Prevent sale of personal data
We do not sell your personal data.
To exercise rights: log in → "Manage Account" → edit/export/delete; or email privacy@chromachecker.com; or call 651.717.0590. GDPR requests: within 30 days. CCPA requests: within 45 days.
10. Does ChromaChecker Transfer My Data?
10.1 International Transfers
Your data may be transferred to and processed in: United States (primary); Canada; European Union (France, Poland).
10.2 Transfer Safeguards
For transfers outside the EEA/UK, we use Standard Contractual Clauses (SCCs) approved by the European Commission; Data Processing Agreements with all recipients; supplementary measures where required.
10.3 Adequacy Decisions
We rely on adequacy decisions where available (e.g., EU-US Data Privacy Framework for certified recipients).
11. Accountability Inspector (Staff Management)
11.1 Purpose
ChromaChecker offers an optional Staff Management feature allowing organizations to assign roles and permissions to employees.
11.2 Data Collected
Nickname or name (real name not required); email address (business email recommended); login credentials; role/permissions.
11.3 Responsibilities
Organization (Main User): Data Controller for employee data; responsible for legal basis, employee notification, and compliance with local labor laws. ChromaChecker: Data Processor; processes data only as instructed by the organization.
11.4 Recommendations
- Use job titles instead of real names where possible
- Use business email addresses only
- Regularly audit and remove inactive staff
- Inform employees about data processing per local law
12. AI Assistant (Peter)
12.1 Overview
ChromaChecker provides an AI-powered assistant ("Peter") to help users navigate the platform, answer questions, and optimize workflows.
12.2 Data Accessed by Peter
Peter has access to aggregated, statistical account data to provide contextual assistance: usage statistics; module usage; instrument inventory; feature utilization (~40 quantitative parameters).
12.3 Data NOT Accessed by Peter
Individual measurement values or spectral data; color specifications or formulas; project content or customer files; personal data (names, emails, contact information); billing or payment information; passwords or authentication credentials.
12.4 AI Service Providers
Peter is powered by: Google (Gemini) — current; Anthropic (Claude) — planned. These providers process user queries in real-time, do not retain conversation data for model training (per our agreements), and are bound by Data Processing Agreements.
12.5 Purpose Limitation
AI-processed data is used solely to answer questions, provide contextual help, suggest relevant features, and assist with troubleshooting.
12.6 No Automated Decision-Making
ChromaChecker does not use AI to make decisions affecting user account status, pricing, or any decisions with legal or significant effects. Peter is an assistance tool only.
13. Cookies and Tracking
We use cookies and similar technologies. See our Cookie Policy for details. Essential cookies: required for service function (no consent needed). Analytics cookies: Google Analytics (consent required). Preference cookies: remember your settings (consent required).
14. Children's Privacy
ChromaChecker is a B2B service not directed at children. We do not knowingly collect data from anyone under 16 years of age.
15. Do Not Track
ChromaChecker does not respond to DNT signals. Cookie use is governed by explicit user consent provided through the cookie consent banner.
16. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights: Right to Know; Right to Delete; Right to Correct; Right to Opt-Out; Right to Limit; Non-Discrimination. We do not sell or share personal data for cross-context behavioral advertising. Contact: privacy@chromachecker.com or 1-800-917-4568.
17. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email, prominent notice on our website, or in-app notification. Changes take effect 30 days after posting.
18. Contact Us
ChromaChecker Corporation, Attn: Privacy Team, 4324 Sanddollar Court, New Port Richey, FL 34652, USA.
Email: privacy@chromachecker.com | Phone: 651.717.0590 | North America Toll-Free: 1-800-917-4568 | Europe: +48.607.628.995
EU Representative (GDPR Art. 27): Appointed. Contact details available upon request at privacy@chromachecker.com.
UK Representative (UK GDPR): Appointed. Contact details available upon request at privacy@chromachecker.com.
19. Supervisory Authority
If you are in the EU/EEA, you have the right to lodge a complaint with your local data protection authority. List: https://edpb.europa.eu/about-edpb/about-edpb/members_en
© 2026 ChromaChecker Corporation. All rights reserved.