Privacy
Privacy Policy
Understand how information is handled, the choices you have, and how to exercise your privacy rights.
Start readingAccount information and customer form content have different purposes.
Find privacy requests, retention information and sharing controls.
EU-only data residency is not currently available.
01Who we are and when this policy applies
This policy explains personal-information handling in connection with Klarstig. Our role depends on the activity. For account administration and our own business operations, we determine the relevant purposes and means of processing. When we handle form submissions or other customer content on an organization’s instructions, that organization generally determines those purposes and we act as its processor or service provider, as applicable.
If you submit a form belonging to a Klarstig customer, also read that organization’s privacy notice. Its notice explains why it requests the information and how it uses the responses.
02Information we collect
Information associated with the service can include account and organization details, form submissions and uploaded files, support communications, and records of actions taken within an account.
Security-related records may include IP addresses, sign-in and session events, permission changes, policy changes and request metadata. The information used by an optional feature depends on the feature and the data supplied to it.
03How information is used
Information is used to provide requested features, administer accounts, respond to requests, protect the service and meet applicable obligations. Customer-content processing remains subject to the applicable customer instructions and processing terms.
For activities where Klarstig determines the processing purposes, the applicable legal basis depends on the specific activity. Consent is not the legal basis for every use of information. Where processing relies on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal.
04Service providers and other disclosures
Hosting, support, communications, payment, AI and other service providers can have different roles and receive different information. An integration selected by a customer can also send information to that customer’s chosen service.
Current service-provider categories include cloud infrastructure and hosting, transactional email delivery, subscription billing and payment processing, and AI model providers when an AI feature is invoked. A current subprocessor list is available on request through [email protected]. A supplier’s security assessment does not establish Klarstig’s own certification.
We do not sell personal information to advertisers.
05Built-in AI and connected services
When you use built-in AI or Concierge functions that process information, the information supplied to the feature and relevant context may be processed to provide the requested assistance. Only supply information appropriate for that feature and your organization’s permissions.
Built-in AI and Concierge features are processed by Klarstig’s configured AI provider to produce the requested output, using the information you supply and the relevant context. Klarstig does not make a blanket promise about third-party model training or retention beyond the applicable provider terms. Review these points before supplying sensitive information to an AI feature.
06European privacy and international transfers
An EU-only data-residency option is not currently available. A French or Spanish interface, an EU customer address, or a visitor’s location does not mean that storage, processing, support access or backups remain within the EU.
Where GDPR applies, a transfer outside the European Economic Area requires an applicable transfer mechanism and the relevant safeguards. Specific processing-location and transfer details are available on request through [email protected]. We do not claim participation in a transfer framework or execution of contractual safeguards merely by referring to them.
07Retention, deletion and backups
Retention depends on the category of information, its purpose, applicable instructions and legal obligations. The applicable criteria distinguish customer content, account records, security logs, support information and backups.
Deleting active information and expiring backup copies are different processes. A downloadable backup link’s 24-hour expiry limits access through that link; it is not a promise that the archive or every source record is deleted after 24 hours. Copies downloaded or sent to customer-selected integrations require separate handling.
Organization owners can create a backup archive scoped to their organization. The archive is privately stored and delivered through a time-limited signed link, with a SHA-256 checksum for checking integrity. Customer archives are separate from platform recovery backups.
08How information is protected
Klarstig uses HTTPS, storage encryption, private file access, account authentication, roles, security logging and controls against automated abuse. Organization administrators can manage supported session and IP-access policies within platform safeguards.
These controls address different risks and do not eliminate all risk. Storage encryption is separate from customer-held decryption keys, which are not currently available. The Security and Compliance pages describe the scope and availability of the protections.
09Your rights and privacy requests
Depending on the law that applies, you may have rights to access, correct, delete, restrict or object to processing of personal information, receive a portable copy, withdraw consent, and complain to a data-protection authority. Where relevant, you may also have rights relating to decisions based solely on automated processing that have legal or similarly significant effects.
To make a request, use the privacy contact: email [email protected]. We may need proportionate information to verify your identity or authority. For information processed on a customer’s instructions, we will direct the request to the responsible organization or assist it as appropriate.
For GDPR requests, the normal response period is one month from receipt. Where legally permitted, this can be extended by two further months; notice of the extension and reasons must be provided within the initial month. Exceptions and other jurisdictions’ deadlines are handled under the applicable law.
10California privacy information
Where CCPA/CPRA applies to the relevant processing, rights can include knowing or accessing information, correction, deletion, opting out of sale or sharing, limiting specified uses of sensitive personal information, and protection from unlawful discrimination for exercising rights. Exceptions and verification requirements can apply.
For California-specific disclosures, or to exercise a right, contact [email protected]. Providing privacy-request tools alone does not determine whether the law applies to a business.
11Cookies, embedded content and location information
Cookies, local storage, analytics, video embeds and anti-abuse services can involve different collection and consent requirements. Klarstig uses cookies and local storage that are necessary to operate the service, including remembering your interface language; where an embedded video or anti-abuse service is used, it may set cookies under its own provider’s terms.
Precise browser location, approximate IP-derived location and the region where information is hosted are different things. A browser permission prompt does not replace the privacy information needed for a location-based feature.
12Children’s information and regulated uses
Follow the age and children’s-information provisions that apply to your collection. A form owner is responsible for considering the requirements that apply to its intended respondents and collection.
HIPAA-enabled forms and a customer Business Associate Agreement are not currently available. Do not use Klarstig for protected health information where that arrangement is required. Education-record or other regulated uses require the appropriate review, terms and safeguards; ordinary form features do not establish suitability for every regulated workflow.
13Changes and contact information
Changes to this policy will be identified through its effective date and the applicable notice process. Where additional notice or consent is required, the relevant requirements apply.
For privacy questions or to reach us, contact [email protected].
