ChromaChecker Legal

Privacy Policy

How we collect, use and protect your personal data.

Effective Date: January 15, 2026

ChromaChecker Corporation ("ChromaChecker," "We," "Us," or "Our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

ChromaChecker is a B2B color management platform designed for organizations in the printing and color reproduction industry. We process primarily technical measurement data, with minimal personal data collection necessary for service delivery.

1. What Data Does ChromaChecker Collect?

1.1 Technical/Measurement Data

The primary data we collect describes technological processes: spectral measurement data; optical, physical, and chemical parameters; device calibration data; production quality metrics. This data is not personal data and relates to machines, devices, and processes.

1.2 Personal Data

We collect personal data in the following categories:

Main User (Account Owner): First name, last name, business email, business phone, company address — for contract execution, account management, support.

Staff/Operators (Optional): Nickname or name, email, login credentials — for access control, notifications, accountability.

Billing Information: Payment details, billing address — for payment processing.

Usage Data: IP address, browser type, access times, pages viewed — for security, analytics, service improvement.

Machine identifier: An identifier derived from a computer's hardware characteristics, used to distinguish licensed seats (including Plugin licences assigned to a specific computer). It is not used to identify an individual person.

Cookies: Session identifiers, preferences — for functionality, analytics (see Cookie Policy).

1.3 Data We Do NOT Collect

2. How Is My Data Collected?

We collect personal data through: direct from you (registration forms, account settings, support requests); automated collection (cookies, server logs, usage analytics); from your organization (when Main User adds staff members); third parties (payment processors, for transaction verification only).

Under GDPR, we process personal data based on the following legal grounds:

You may withdraw consent at any time without affecting the lawfulness of prior processing.

4. Who Processes My Data?

4.1 Data Controller

ChromaChecker Corporation, 4324 Sanddollar Court, New Port Richey, FL 34652, USA. Phone: 651.717.0590. Email: privacy@chromachecker.com.

4.2 Data Processors (Sub-processors)

We use the following categories of service providers:

ProviderPurposeLocations
Cloud hosting (OVH)Data storage and processingUSA, Canada, France, Poland
Payment processorsTransaction processingUSA, EU
Analytics (Google Analytics)Usage analyticsUSA
Email servicesTransactional emailsUSA

We maintain Data Processing Agreements with all sub-processors. Current sub-processor list available upon request: privacy@chromachecker.com.

5. Data handled by Plugins

Plugins are optional extensions that you choose to install. Some of them move data that the base applications never touch, and the following applies only to Plugins you have installed and enabled.

Your own accounts with third parties. Where a Plugin connects to a third-party service — for example cloud storage — it uses your organisation's account and, in the ChromaChecker desktop applications, your organisation's own registered application credentials. Files transferred that way move between your computer and your provider. ChromaChecker does not receive, store or process copies of them, and is not the controller of the data held in those accounts.

Production data from equipment on your site. A Plugin that reads production systems on your network may make selected values available to ChromaChecker as context attached to your colour measurements — but only for the values you have explicitly enabled. Some of those values can constitute personal data (for example the employees assigned to a press) or data confidential to your own customers (for example the name of the customer whose job is running). Your organisation is the controller for that data and decides whether it is sent at all; every such parameter is off by default, and each Plugin's Plugin Terms states which ones exist and where they go.

Credentials. Credentials a Plugin needs for a third-party service or a machine on your network are stored in the operating system's own credential store on that computer (macOS Keychain, Windows Credential Manager). They are not transmitted to ChromaChecker.

Local caches. A Plugin may cache downloaded files on the computer it runs on, so that reopening a file does not re-download it. Those caches are local to that computer and can be deleted at any time.

Machine identification. To assign a Plugin licence to a specific computer, ChromaChecker records an identifier derived from that computer's hardware characteristics. It is used to distinguish one licensed seat from another and is not used to identify an individual person.

6. Diagnostics and support reports

CC Capture includes Run Diagnostics, a tool that examines the workstation to explain why something is not working — most often an instrument that will not connect. It runs only when a person starts it. It is never scheduled, never automatic, and nothing is sent anywhere by running it.

What it examines, on the machine it runs on:

AreaWhat is examined
The computeroperating system and version, processor, memory, disk space, locale, and the application's own runtime
Instrumentsmeasuring devices connected or detected, including their model and serial number, together with the vendor drivers and services they need
ConnectionsUSB and Bluetooth devices present, whether our servers can be reached, DNS, proxy settings, and the reachability of instruments on your network
The applicationrecent errors, warnings and crashes from CC Capture's own log files, and — on macOS — which system permissions the application has been granted

It does not read your documents, your images or your measurement data, and it does not search the disk. It looks at the machine, its devices and our own logs.

Nothing leaves the workstation unless you send it. The result is shown to you first. If you then choose to send a support report, the diagnostic text is attached to it, and you may additionally attach CC Capture's recent session logs by ticking a box. The report goes to ChromaChecker support and is handled under this Policy.

Before anything is shown or sent, it is filtered. Home-directory paths are shortened so your account name does not travel; anything shaped like a password, token or API key is replaced with [REDACTED]; e-mail addresses other than your own reply-to address are removed; identifiers in paths and addresses are masked; and addresses on your own network — printers, instruments, servers — are replaced with [PRIVATE_IP], so the layout of your network does not travel with the report.

Support reports are retained for as long as the enquiry and our records require, and you may ask for one to be deleted (see the contact section below).

6.1 The Network Link Monitor

CC Capture also includes a Network Link Monitor, for the fault that only shows itself over hours — a connection that drops once an afternoon. Like Run Diagnostics it starts only when a person starts it, and there is no obligation to use it at all.

Once started it keeps running until it is stopped, including while its window is closed — that is the point of it, and the application warns you if you try to quit with a run still going. While it runs it repeatedly contacts two addresses, both discovered when you press Start: the ChromaChecker server your installation is configured to use, and the measuring instrument on your network if you have a network-connected one. It sends ordinary reachability traffic — a ping, a connection attempt, a web request — and records how long each took and whether it succeeded. On macOS it also notes the strength and quality of the WiFi signal, so a fault can be told apart from a weak aerial.

It reads nothing else, and it contacts nothing else — no third party, and no address you have not configured.

The results are written to a file on the workstation. Nothing is sent anywhere by the monitor itself; if you want us to look at a run, you attach its report to a support report, and everything above about filtering applies to it.

7. How Long Is My Data Stored?

After 166 days of inactivity: warning email sent. After 180 days: account and all data permanently deleted. Data removed from backups within 60 days.

8. How Is My Data Protected?

8.1 Technical Measures

8.2 Organizational Measures

Employee background checks and confidentiality agreements; regular security training; access limited to personnel who need it; incident response procedures; regular security assessments.

8.3 Infrastructure

Our servers are hosted in certified data centers (OVH) with: ISO 27001 certification; SOC 2 compliance; physical security controls; redundant power and cooling; 24/7 monitoring.

8.4 Credentials on the workstation

Credentials used by the ChromaChecker desktop applications and Plugins for third-party services or equipment on your network are stored in the operating system's credential store (macOS Keychain, Windows Credential Manager), not on ChromaChecker servers.

9. What Are My Rights?

Depending on your location, you have the following rights:

We do not sell your personal data.

To exercise rights: log in → "Manage Account" → edit/export/delete; or email privacy@chromachecker.com; or call 651.717.0590. GDPR requests: within 30 days. CCPA requests: within 45 days.

10. Does ChromaChecker Transfer My Data?

10.1 International Transfers

Your data may be transferred to and processed in: United States (primary); Canada; European Union (France, Poland).

10.2 Transfer Safeguards

For transfers outside the EEA/UK, we use Standard Contractual Clauses (SCCs) approved by the European Commission; Data Processing Agreements with all recipients; supplementary measures where required.

10.3 Adequacy Decisions

We rely on adequacy decisions where available (e.g., EU-US Data Privacy Framework for certified recipients).

11. Accountability Inspector (Staff Management)

11.1 Purpose

ChromaChecker offers an optional Staff Management feature allowing organizations to assign roles and permissions to employees.

11.2 Data Collected

Nickname or name (real name not required); email address (business email recommended); login credentials; role/permissions.

11.3 Responsibilities

Organization (Main User): Data Controller for employee data; responsible for legal basis, employee notification, and compliance with local labor laws. ChromaChecker: Data Processor; processes data only as instructed by the organization.

11.4 Recommendations

12. AI Assistant (Peter)

12.1 Overview

ChromaChecker provides an AI-powered assistant ("Peter") to help users navigate the platform, answer questions, and optimize workflows.

12.2 Data Accessed by Peter

Peter has access to aggregated, statistical account data to provide contextual assistance: usage statistics; module usage; instrument inventory; feature utilization (~40 quantitative parameters).

12.3 Data NOT Accessed by Peter

Individual measurement values or spectral data; color specifications or formulas; project content or customer files; personal data (names, emails, contact information); billing or payment information; passwords or authentication credentials.

12.4 AI Service Providers

Peter is powered by: Google (Gemini) — current; Anthropic (Claude) — planned. These providers process user queries in real-time, do not retain conversation data for model training (per our agreements), and are bound by Data Processing Agreements.

12.5 Purpose Limitation

AI-processed data is used solely to answer questions, provide contextual help, suggest relevant features, and assist with troubleshooting.

12.6 No Automated Decision-Making

ChromaChecker does not use AI to make decisions affecting user account status, pricing, or any decisions with legal or significant effects. Peter is an assistance tool only.

13. Cookies and Tracking

We use cookies and similar technologies. See our Cookie Policy for details. Essential cookies: required for service function (no consent needed). Analytics cookies: Google Analytics (consent required). Preference cookies: remember your settings (consent required).

14. Children's Privacy

ChromaChecker is a B2B service not directed at children. We do not knowingly collect data from anyone under 16 years of age.

15. Do Not Track

ChromaChecker does not respond to DNT signals. Cookie use is governed by explicit user consent provided through the cookie consent banner.

16. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights: Right to Know; Right to Delete; Right to Correct; Right to Opt-Out; Right to Limit; Non-Discrimination. We do not sell or share personal data for cross-context behavioral advertising. Contact: privacy@chromachecker.com or 1-800-917-4568.

17. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by email, prominent notice on our website, or in-app notification. Changes take effect 30 days after posting.

18. Contact Us

ChromaChecker Corporation, Attn: Privacy Team, 4324 Sanddollar Court, New Port Richey, FL 34652, USA.

Email: privacy@chromachecker.com | Phone: 651.717.0590 | North America Toll-Free: 1-800-917-4568 | Europe: +48.607.628.995

EU Representative (GDPR Art. 27): Appointed. Contact details available upon request at privacy@chromachecker.com.
UK Representative (UK GDPR): Appointed. Contact details available upon request at privacy@chromachecker.com.

19. Supervisory Authority

If you are in the EU/EEA, you have the right to lodge a complaint with your local data protection authority. List: https://edpb.europa.eu/about-edpb/about-edpb/members_en

© 2026 ChromaChecker Corporation. All rights reserved.

Peter · AI Assistant
Need help choosing the right path into ChromaChecker? I can guide you based on your role and workflow.