Last updated: 11 September 2026
This policy explains how Klark SAS handles personal data when operating its website, managing business relationships and providing its customer service platform.
For website enquiries, demo requests, business contacts and account administration, Klark acts as a data controller. For customer support data processed through the platform on an organisation's behalf, that organisation is the data controller and Klark acts as its processor under its documented instructions and the applicable data processing agreement. This policy does not amend those agreements or authorise additional uses or international transfers.
Depending on the services and integrations used, we process:
Information can come directly from you, from your organisation or from systems that your organisation connects to Klark. Free-text messages and attachments can contain additional personal information. Customers should provide only information needed for the relevant service and avoid unnecessary sensitive information.
For our customers, we use support data to understand enquiries, retrieve relevant information, classify and route requests, generate responses and perform the assistance or automation configured by the customer. Service data may also be processed for troubleshooting, quality evaluation, security and the operation of those services, within the customer's instructions and applicable agreement.
For our own business, we process contact and account data to respond to enquiries, arrange demonstrations, administer contracts and accounts, provide support and manage billing. We process operational records to maintain security, investigate incidents and meet legal obligations. With the required consent, website measurement helps us understand visits and attribute demo bookings to advertising.
Customer support content is not supplied to advertising pixels for campaign measurement. Automated replies, routing and other service actions depend on the customer's configuration. Customers remain responsible for the purposes, legal basis and appropriate oversight of their use of the service.
For processing where Klark acts as controller, the applicable basis depends on the purpose:
For support data processed on behalf of a customer, the customer determines the legal basis. Klark's service contract with that customer is not, by itself, a legal basis for every use of the customer's end-users' data.
We use techniques such as masking, replacement of identifiers and encryption to reduce exposure of personal data. Their coverage depends on the data field, format and processing flow. These measures do not guarantee that all identifying information is removed from free text, attachments or contextual information.
Data that can still identify a person, including by combining it with other information or using a separate key, remains personal data. We distinguish such pseudonymised or encrypted information from data that has been irreversibly anonymised. Diagnostic and analytical records are not assumed to be anonymous merely because they have passed through an automated masking process.
Retention depends on the category of information, its purpose, the customer's instructions and applicable legal requirements. The shortest applicable retention limit takes precedence. Keeping a ticket open does not extend the limits applicable to its stored content or processing logs. We are updating the retention process for the mappings that associate personal information, such as a customer's name, with replacement identifiers used during processing. The rule provides for deletion of these mappings when the ticket closes or, if it remains open, after 30 days without ticket activity. Using a suggested reply does not trigger deletion. This rule is being implemented; it is distinct from the retention of conversation content and logs described below.
Our policy sets a maximum of 30 days for AI processing inputs and outputs and operational logs containing those contents. Stored conversation content and other service data follow separate rules. Following our 2026 security review, a 90-day limit for stored questions, responses, suggestions and associated conversation content is being implemented. A separate 12-month limit is planned for other personal data of active customers where no shorter rule applies. The 90-day and 12-month limits are implementation targets; deletion of all historical records under these limits is not yet complete. Account credentials and configuration required for an active service are managed separately.
Ending the service requires stopping the relevant data flows, revoking or disabling integrations, and returning or deleting service data in accordance with the customer's agreement and instructions. Pausing suggestions alone does not complete those steps. Any information retained for billing, security investigations or legal obligations must have a defined purpose and appropriate access restrictions. A technical identifier that remains linkable to a person continues to be treated as personal data.
We retain business contact information while handling the enquiry or maintaining the relevant business relationship, and review whether continued retention remains necessary. Contract and billing records are retained for the applicable statutory period. Evidence needed to investigate an incident or establish, exercise or defend legal claims is retained for that purpose, with restricted access. Backup retention and expiry are handled separately from deletion in active systems; deletion from active systems is not represented as immediate removal from every backup.
Contact dpo@klark.ai for the retention information applicable to your data or organisation.
Personal data may be accessed by authorised personnel for their work and by providers needed to deliver the relevant service. These include hosting and infrastructure providers, AI processing providers, customer relationship and meeting-booking services, and website or measurement providers.
For example, the service uses OpenAI and Amazon Web Services, including Amazon Bedrock, for relevant AI processing flows. The website uses Webflow for hosting, Weglot for translation and HubSpot for demo scheduling. Google Analytics supports audience measurement, and Lemlist supports website visitor identification for business prospecting, subject to the applicable consent choices. When enabled and consented to, OpenAI Ads measures website visits and confirmed demo bookings. These are different processing activities: use of an AI provider for customer support does not imply permission to use support content for advertising.
Subprocessing of customer data is governed by the applicable agreement and authorisations. The list of subprocessors and information about their roles and locations can be requested from dpo@klark.ai. We do not sell or rent personal data. We may disclose information where legally required, limiting disclosure to the relevant requirement.
European hosting of a primary database does not mean that all associated processing takes place in the European Union. Some AI processing flows use OpenAI in the United States. Amazon Bedrock is also used for AI processing; the applicable region depends on the configured service and processing flow. Migration of all AI flows to the European Union remains an objective and is not presented here as complete.
International processing of personal data remains subject to the customer's instructions and contractual restrictions. For OpenAI API processing, section 4.1 of the OpenAI Data Processing Addendum provides for transfers by OpenAI Ireland under agreements containing the European Commission's standard contractual clauses or an applicable adequacy decision. AWS includes standard contractual clauses in its data processing terms for transfers to which those clauses apply; see the AWS GDPR safeguards. These safeguards are separate from the region configured for each service and do not override any requirement for prior customer authorisation. Masking or pseudonymisation alone does not remove transfer requirements. Contact dpo@klark.ai for the recipients, locations and contractual safeguards applicable to your service and to obtain a copy of the relevant safeguards.
The website uses essential technologies to operate and remember privacy choices, and optional technologies for audience measurement and marketing. Google Analytics is used for audience measurement; OpenAI Ads for advertising attribution; and Lemlist for visitor identification and business prospecting. The website provides cookie preferences for non-essential purposes. You can refuse marketing cookies and change your choice using the site's cookie preference controls.
When OpenAI Ads tracking is activated, it is configured to load after marketing consent. It measures page views and successful demo reservations through the embedded HubSpot booking flow. Measurement can involve browser, device and page information and advertising attribution identifiers processed by OpenAI. The integration does not send the content of your demo form or customer support conversations as conversion event data.
Withdrawing marketing consent stops future OpenAI measurement through this integration. Withdrawal does not erase information already lawfully collected; deletion requests can be addressed through the rights described below. See also the OpenAI Privacy Policy.
We apply technical and organisational measures appropriate to the processing, including access restrictions, authentication, network protection, encryption of relevant secrets, monitoring and security reviews. We conduct a security audit annually. These measures reduce the risk of unauthorised access, disclosure, alteration or loss and are reviewed in light of identified risks and incidents.
Following the security incident identified in August 2026, we restricted access to the affected internal analytics environment by strengthening network access controls and authentication, corrected the affected vulnerability, invalidated compromised access and renewed the relevant API keys. The incident also identified limitations in data minimisation, retention and automated masking. Our remediation programme addresses these limitations through tighter retention rules, improved detection and masking of identifiers, and stronger controls over service termination and deletion.
Where a personal data breach occurs, we investigate, take containment measures and notify affected customers without undue delay when acting as their processor. We assist customers with their assessment and notification obligations. Where Klark acts as controller, we notify the competent authority and affected individuals when required by applicable law. An update to this policy does not replace an individual breach notification.
Subject to the conditions in applicable law, you may request access, correction, erasure, restriction of processing and portability of your personal data, object to processing based on legitimate interests, and withdraw consent. You may object to direct marketing at any time.
Contact dpo@klark.ai. We may request proportionate information to verify your identity. We normally respond within one month; where a lawful extension is needed, we will explain it within that period. Requests are normally handled free of charge.
If your data is processed for one of our customers, that organisation is responsible for handling your request as controller. We will direct the request appropriately and assist that organisation under our agreement. You may also complain to the CNIL or another competent supervisory authority without first contacting Klark.
Klark SAS's data protection contact is Nicolas Pellissier, at dpo@klark.ai. We update this policy when our processing practices or applicable requirements change. The date above identifies the version, and material changes will be communicated as appropriate. An update does not retroactively change the purposes or legal basis of earlier processing or override commitments in a customer's agreement.