Legal
Privacy Policy
Last updated 11 September 2026. Operated by Krog Digital.
This Privacy Policy explains how Krög Digital ("we", "us") collects, uses, shares and protects personal data when you visit the Website at krog.digital, contact us, request access to our Services or work with us as a Client. We provide agency advertising accounts and related account infrastructure to media buyers and agencies, and we handle personal data in that context as a business-to-business service provider organised in the United States and serving clients worldwide.
We are committed to processing personal data lawfully, transparently and securely under the laws that apply to us and to you, including U.S. federal and state privacy laws and, for visitors in the European Economic Area, the United Kingdom and Switzerland, the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR and the Swiss Federal Act on Data Protection. This Policy was last updated on 11 September 2026. Please read it together with our Terms of Service (the "Terms") and our Cookie Policy.
1.Who We Are
The business responsible for the processing described in this Policy (the "controller" where that term applies) is Krog Digital, trading as Krög Digital, a company organised under the laws of the State of Alaska, United States (registration no. 35-482154841), with its registered address at 1101 N Muldoon Rd, Anchorage, AK 99504, United States. You can reach us for any privacy matter by email at hello@krog.digital, or through the Telegram channel published on the Website.
We have not appointed a Data Protection Officer because we are not legally required to do so. Privacy questions and requests are handled by our management team, and we treat them as a priority.
2.Scope
This Policy applies to personal data we process about Visitors of the Website, people who contact us by email or Telegram ("Contacts"), prospective clients who submit the "request access" form or subscribe to our newsletter ("Leads"), and Clients who use our Services, including their representatives, employees and authorised contacts.
This Policy does not cover the processing carried out independently by the advertising platforms on which Accounts are opened (Meta, Google, TikTok, Taboola, Outbrain, MediaGO, DV360 and others, together the "Platforms"). Each Platform is a separate controller for the data it collects through its own products, and its own privacy terms apply. It also does not cover data that Clients collect from their own audiences through their advertising campaigns and landing pages; Clients are independent controllers of that data.
3.Personal Data We Collect
We collect only the personal data we need to operate the Website, respond to enquiries and deliver the Services. The categories below describe what we collect for each type of person we deal with.
Providing the data marked as required in the request access form and the information we ask for during onboarding is necessary to enter into and perform our contract with you and to meet the partner, verification and sanctions requirements of the Platforms. Without it we cannot respond to your request, onboard you as a Client or open and maintain Accounts. Other data, such as an optional message in the form, a newsletter subscription or analytics and marketing cookies, is entirely voluntary and you can decline to provide it without affecting your access to the Services.
- Visitors: technical and log data generated when you load the Website, such as IP address, browser type and version, device type, operating system, language, referring page, pages viewed, timestamps and error logs; and your cookie consent preferences stored in the "krog.consent" entry in your browser.
- Contacts: your email address, Telegram username, display name, profile details visible through that messaging app, the content of the messages you send us and any attachments you choose to share.
- Leads (request access form): the details you enter in the form, such as your name, work email address, messaging handle, information about your advertising activity and any optional message you add. Newsletter subscribers: email address and the date and source of your subscription.
- Clients: business details (company name, registration number, VAT or tax identification number, registered address, website and business description); the names, roles and contact details of your representatives and authorised contacts; billing information (invoicing address, transaction references and payment confirmations; payment details themselves are handled by our payment or banking provider and we retain only transaction references and confirmations); compliance and know-your-customer information required to open and maintain Accounts, where a Platform or applicable law requires it (identity and business verification documents, ownership information, licences or authorisations for regulated verticals, and the outcome of sanctions or business verification checks); and Platform account data (Account identifiers, Business Manager or advertiser IDs, campaign names, spend figures, invoicing records, policy notices and appeal correspondence).
- Records of our dealings with you: contract documents, support tickets, dispute and refund requests, and notes of calls or meetings.
4.How We Collect It
Most of the personal data we hold is provided directly by you: when you fill in a form on the Website, message us on Telegram, send us an email, sign an agreement or upload compliance documents during onboarding. Where a Client provides us with personal data about its representatives, employees or contacts, we receive that data from the Client rather than from the individual concerned.
Some data is collected automatically. Our hosting provider records technical log data when your browser requests pages from the Website, and the Website stores your cookie choices in your browser. If you consent to analytics or marketing cookies, the corresponding tags will collect usage data as described in our Cookie Policy.
We also receive data from third parties. The Platforms provide us with Account status, spend, billing and policy information for the Accounts we manage on your behalf. Our payment or banking provider provides us with transaction references and confirmations. Where a Platform or applicable law requires sanctions or business verification checks, we may consult public registers and screening databases.
5.Purposes and Legal Bases
We use personal data for the purposes listed below and for no purpose that is incompatible with them. Where the GDPR, the UK GDPR or Swiss data protection law applies to you, we must also have a legal basis for each processing activity, and the list maps each purpose to the basis we rely on. Where we rely on legitimate interests, we have assessed that the processing is necessary and proportionate and that your interests and rights do not override ours.
Where the personal data concerns representatives, employees or contacts of a Client rather than the Client itself, we rely on our legitimate interests (Article 6(1)(f) GDPR) in managing the client relationship, communicating with the Client and performing our contract with it. The Client must bring this Policy to the attention of any individual whose personal data it provides to us.
- Responding to enquiries and pre-contract requests, including reviewing your request for access and discussing pricing: performance of a contract or steps taken at your request before entering into one (Article 6(1)(b) GDPR) where you are the prospective Client, and legitimate interests (Article 6(1)(f)) where you contact us on behalf of a business.
- Onboarding you as a Client, opening and maintaining Accounts on the Platforms, managing top-ups, calculating and invoicing our commission, providing support and handling refund requests: performance of a contract (Article 6(1)(b)) with the Client, and legitimate interests (Article 6(1)(f)) in respect of the Client's representatives and contacts, as explained above.
- Verifying the identity and legitimacy of Clients, screening for prohibited verticals, fraud, sanctions exposure and reputational risk, and meeting Platform partner requirements: legitimate interests (Article 6(1)(f)) in protecting our business, our agency relationships and the integrity of the Platforms, and legal obligation (Article 6(1)(c)) where sanctions or anti-fraud rules apply.
- Keeping accounting, tax and corporate records, and responding to lawful requests from authorities: legal obligation (Article 6(1)(c)).
- Operating, securing and improving the Website, including server logs, error monitoring and abuse prevention: legitimate interests (Article 6(1)(f)) in running a reliable and secure service.
- Remembering your cookie choices through the "krog.consent" entry: legitimate interests (Article 6(1)(f)) and our obligation to honour your consent decisions.
- Analytics and marketing cookies, including Google Analytics 4, Google Ads conversion tracking and Meta Pixel: consent (Article 6(1)(a) GDPR and the ePrivacy rules for visitors in the EEA and UK), collected through the cookie banner and revocable at any time via "Cookie settings" in the footer.
- Sending our newsletter and product updates: consent (Article 6(1)(a)). For existing Clients, we may send service-related communications about their Accounts on the basis of the contract, and occasional information about similar services on the basis of legitimate interests, always with an easy way to opt out.
- Establishing, exercising or defending legal claims, and enforcing our Terms: legitimate interests (Article 6(1)(f)).
6.Sharing and Recipients
We do not sell personal data, and we do not share it for cross-context behavioural advertising except through the marketing cookies you accept in the cookie banner, as described in our Cookie Policy. We share personal data only with recipients who need it to help us deliver the Services or when the law requires it. Our hosting provider, our payment and banking providers and the professional tools we use to run the business process data on our behalf under written data processing agreements, including the terms required by Article 28 GDPR where the GDPR applies.
Telegram is different. It is a consumer communications service that we use under its own published terms, and it does not enter into a data processing agreement with us. We treat it as an independent provider of the communications channel, not as our processor. To limit the risk, form submissions are forwarded to a restricted internal Telegram chat that only authorised team members can access, we forward only the data the form contains, and we delete forwarded submissions at the end of the retention period for Leads described below.
- Platforms: to open, verify, fund and maintain Accounts, we share the business details, representative contact details, compliance documents and campaign-related information that each Platform requires under its partner and advertiser policies. The Platforms act as independent controllers for this data.
- Vercel Inc. (United States): hosts the Website and processes technical log data and form submissions as our processor.
- Telegram FZ-LLC and Telegram Messenger Inc.: submissions from the request access form and the newsletter signup are forwarded to our internal Telegram chat, and much of our day-to-day communication with Contacts and Clients takes place over Telegram. Telegram acts as a communications provider under its own terms and may process message data in data centres in various countries.
- Payment and banking providers: to receive payments, issue refunds and reconcile transactions.
- Professional advisers: accountants, auditors, lawyers and insurers, bound by professional secrecy or contractual confidentiality.
- Public authorities, courts, regulators and law enforcement: where we are legally required to disclose data, or where disclosure is necessary to protect our rights or the safety of others.
- A buyer or successor in the event of a merger, acquisition or sale of assets, subject to this Policy continuing to apply to the transferred data.
7.International Transfers
We are organised in the United States, and our core business records are stored and processed in the United States, including by our hosting provider Vercel Inc. Our messaging provider, the Telegram entities, and several Platforms process data globally. If you access the Website or contact us from outside the United States, your personal data will therefore be transferred to and processed in the United States and possibly other countries whose data protection laws differ from those of your home country.
For visitors and Clients in the EEA, the UK and Switzerland, we transfer personal data outside those regions only with appropriate safeguards. Where a recipient in the United States is certified under the EU-US Data Privacy Framework, the UK Extension to it or the Swiss-US Data Privacy Framework, we rely on that certification; otherwise we rely on the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum or the Swiss adaptations where relevant, together with supplementary technical and organisational measures. With Vercel, we have concluded the Standard Contractual Clauses. For the Platforms, payment providers and other business recipients, we rely on an adequacy decision where one exists or on Standard Contractual Clauses.
Telegram is different. Telegram FZ-LLC and Telegram Messenger Inc. are not covered by an adequacy decision or a Data Privacy Framework certification, and Telegram does not offer Standard Contractual Clauses or other Chapter V GDPR safeguards to business users like us. When you choose to contact us over Telegram, the transfer of your messages to those providers takes place at your request and is necessary to take steps before entering into a contract with you or to perform that contract, so we rely on the derogation in Article 49(1)(b) GDPR and its UK and Swiss equivalents. Form submissions forwarded to our internal Telegram chat are transferred on the same basis, because they are how we act on your request for access or your newsletter subscription, and we limit the data forwarded to what the form contains. If you would rather not use Telegram, you can contact us by email at hello@krog.digital and we will handle your enquiry through that channel instead.
You can request a copy of the safeguards we rely on, or more information about a specific transfer, by contacting us at hello@krog.digital.
8.Retention Periods
We keep personal data only as long as necessary for the purposes described above, after which we delete or anonymise it. The periods below are our standard practice; we may retain data for longer where a dispute, investigation or legal hold requires it.
- Website technical logs: for the short period retained by our hosting provider, currently no more than 30 days, unless needed to investigate a security incident.
- Cookie consent record ("krog.consent"): 12 months in your browser, after which the banner will ask for your choice again.
- Analytics and marketing cookie data: for the lifetimes stated in the Cookie Policy (up to 2 years for Google Analytics identifiers, 90 days for Google Ads and Meta Pixel identifiers), and only after consent.
- Enquiries and Leads that do not become Clients: 12 months after our last contact with you, then deleted, including any form submissions forwarded to our internal Telegram chat.
- Newsletter subscriptions: until you unsubscribe or we discontinue the newsletter, plus a short suppression record so that we do not email you again.
- Client records, including contracts, invoices, payment records, compliance documents and Account data: 7 years after the end of the client relationship, in line with U.S. federal and Alaska tax and record-keeping requirements and the limitation period for contractual claims.
- Correspondence over Telegram and email: for the duration of the relationship and up to 3 years afterwards, unless it forms part of a Client record subject to the longer period above.
- Records of data subject and consumer requests: 3 years from the date we close the request, to demonstrate compliance.
9.Security Measures
We apply technical and organisational measures appropriate to the risk, taking into account the nature of the data we hold and the size of our business. These include encryption of data in transit (TLS) across the Website and our provider integrations, access controls on the accounts and tools we use, including, where available, two-factor authentication, restriction of access to compliance documents to the people who need them, and regular review of the providers we work with.
Internal messaging channels used to forward form submissions are limited to authorised team members. Compliance documents are kept only for the retention period stated above and deleted at the end of it. No system is perfectly secure, and transmission over the internet always carries some risk; if we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the affected individuals and the competent regulators as required by applicable law, including U.S. state breach notification laws and, where the GDPR or UK GDPR applies, Articles 33 and 34 of those regulations.
10.Your Rights and Choices
Wherever you live, you can ask us what personal data we hold about you, ask us to correct or delete it, and opt out of marketing communications. You can withdraw cookie consent at any time via "Cookie settings" in the footer and unsubscribe from the newsletter using the link in every email.
The two sections below describe the additional rights that apply depending on where you live, and the section "How to Exercise Your Rights" explains how to contact us and what to expect. Nothing in this Policy removes rights that mandatory law grants you in the country or state where you live.
11.Rights for Visitors in the EEA, UK and Switzerland
If you are located in the European Economic Area, the United Kingdom or Switzerland, the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection gives you the following rights in relation to your personal data. Some rights are subject to conditions and exceptions set out in the law, and we will explain any limitation that applies when we respond.
The legal bases we rely on for each purpose are set out in the section "Purposes and Legal Bases" above, and the safeguards we use when transferring your data to the United States are described under "International Transfers".
- Access: to obtain confirmation that we process your data and receive a copy of it, together with information about how we use it.
- Rectification: to have inaccurate data corrected and incomplete data completed.
- Erasure: to have your data deleted where it is no longer needed, where you withdraw consent, or where it has been processed unlawfully, unless we must keep it to comply with a legal obligation or to defend legal claims.
- Restriction: to ask us to limit the processing of your data in certain circumstances, for example while we verify its accuracy.
- Portability: to receive the data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection: to object to processing based on legitimate interests, and at any time to processing for direct marketing purposes.
- Withdrawal of consent: to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before the withdrawal. You can withdraw cookie consent via "Cookie settings" in the footer and unsubscribe from the newsletter using the link in every email.
- Complaint: to lodge a complaint with your local data protection authority, in particular the supervisory authority in the EEA country where you live or work or where the alleged infringement took place, the Information Commissioner's Office in the UK, or the Federal Data Protection and Information Commissioner in Switzerland.
12.Your U.S. State Privacy Rights
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (together the "CCPA") gives you the rights described in this section, to the extent the CCPA applies to us and to the data in question. In the 12 months preceding the date of this Policy we have collected the categories of personal information listed below, from the sources and for the business purposes described in the sections "How We Collect It" and "Purposes and Legal Bases", and we have disclosed them to the recipients described under "Sharing and Recipients". We use sensitive personal information only to open and maintain Accounts and to meet Platform and legal verification requirements, and not to infer characteristics about you.
We do not sell personal information and have not sold it in the preceding 12 months. We do not "share" personal information for cross-context behavioural advertising except through the Google Ads and Meta Pixel marketing cookies described in our Cookie Policy, which are set only if you accept marketing cookies in the cookie banner. You can opt out at any time via "Cookie settings" in the footer, and we treat a Global Privacy Control signal sent by your browser as a valid request to opt out of sale or sharing for the browser it is sent from. We do not knowingly sell or share the personal information of anyone under 16.
As a California resident you have the right to know what personal information we collect, use, disclose and share, including the categories of sources and recipients; the right to delete personal information we have collected from you; the right to correct inaccurate personal information; the right to opt out of sale or sharing; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising any of these rights. You can exercise these rights through the contact details in the section "How to Exercise Your Rights", directly or through an authorised agent who provides proof of authority. We verify requests by matching the details you provide against the information we hold, and we respond to verifiable requests within 45 days, extendable once by a further 45 days with notice.
Residents of other states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Texas and others, have similar rights to access, correct, delete and obtain a copy of their personal data, to opt out of targeted advertising and of the sale of personal data, and to appeal a decision we make on a request. You can exercise those rights, and appeal any refusal, through the same contact details, and we will handle your request under the law of your state.
- Identifiers: name, email address, Telegram handle, phone number, IP address and online identifiers such as cookie IDs.
- Customer records and commercial information: business and billing details, transaction references, payment confirmations and records of the Services purchased.
- Internet or other electronic network activity: pages viewed, referring page, browser and device data, and analytics and advertising cookie data collected with your consent.
- Approximate geolocation: country or region derived from your IP address.
- Professional or employment-related information: your role and the business you represent.
- Sensitive personal information: government identification documents, collected only from Client representatives and only where a Platform or applicable law requires identity verification.
13.How to Exercise Your Rights
To exercise any of these rights, contact us at hello@krog.digital or through the Telegram channel on the Website, and tell us which right you wish to exercise and, where relevant, where you live. We may ask you to confirm your identity or provide additional details so that we can locate your data and make sure we do not disclose it to the wrong person.
We will respond within one month of receiving your request where the GDPR, the UK GDPR or Swiss law applies, and within 45 days where a U.S. state privacy law applies. Where a request is complex or we receive several requests from you, we may extend this period as the applicable law permits (by up to two further months under the GDPR, or by a further 45 days under U.S. state laws), in which case we will tell you within the initial period and explain why. Exercising your rights is free of charge, except where requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, as permitted by applicable law.
14.Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Decisions about whether to accept a Client, open an Account or pause or terminate the Services are taken by our team, even where we use screening tools or Platform signals to inform them.
The Platforms may apply their own automated systems to review advertisers, ads and Accounts. Those systems are operated by the Platforms under their own terms, and we cannot control their outcomes, although we will assist Clients with appeals where a Platform allows it.
15.Children
Our Services are designed for businesses and professional media buyers and are available only to persons aged 18 or over. We do not knowingly collect personal data from anyone under 18, and in particular we do not knowingly collect personal information from children under 13 within the meaning of the U.S. Children's Online Privacy Protection Act (COPPA). If you believe that a minor has provided us with personal data, please contact us at hello@krog.digital and we will delete it promptly.
16.Links to Third Parties
The Website and our communications may contain links to the Platforms, to our messaging channels and to other third-party websites and services. We do not control those sites and are not responsible for their content or their privacy practices. We encourage you to read the privacy notice of any third-party service you use, including Telegram and each Platform on which your Accounts are opened.
17.Changes to This Policy
We may update this Policy from time to time to reflect changes in our Services, our providers or the law. In particular, we expect to update it when we launch the planned client dashboard and introduce user accounts, since that will involve new categories of data such as login credentials and dashboard activity. The current version is always published on the Website with its "last updated" date.
Where a change materially affects how we process your data, we will take reasonable steps to bring it to your attention, for example by notifying Clients through our usual communication channels or displaying a notice on the Website. The updated Policy applies from its "last updated" date. Where a change requires your consent (for example a new use of data that relies on consent), we will ask for it separately before the change takes effect.
18.Contact
If you have questions about this Policy or how we handle your personal data, please contact Krog Digital (Krög Digital) at hello@krog.digital, or through the Telegram channel listed on the Website at krog.digital. Postal correspondence can be sent to Krog Digital, 1101 N Muldoon Rd, Anchorage, AK 99504, United States.
If you are in the EEA, the UK or Switzerland and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. If you are a resident of a U.S. state whose privacy law provides a right of appeal, you can appeal our decision by replying to our response, and we will tell you how to contact your state Attorney General if you remain dissatisfied.
Questions about this document: hello@krog.digital. Krog Digital, 1101 N Muldoon Rd, Anchorage, AK 99504, United States.