What happens to the data.
Two different people's data is in this product. This page says which is which before it says anything else.
Last reviewed August 2026
What this page is
A factual description of what the software does with data, written by the people who built it and checked line by line against the code. It is not legal advice, and no lawyer has reviewed it — what you are reading is engineering candour, not a vetted notice, and it is worth knowing which of the two you have.
Two roles, and they are not the same
Almost every person whose data is in this product never signed up for it. They walked up to a stand and handed over a card.
For your visitors’ data, you are the controller and we are the processor. You decide what your staff collect, what they ask, on what basis, and where it goes afterwards. Klaaristores it, keeps it separated from every other customer’s, does the work you asked for, and hands it back. We do not decide what you collect, do not use it for our own purposes, do not sell it, do not use it to train models, never combine it with another customer’s data, and never contact the people in it.
For your own account data, we are the controller. Your email address, your workspace, your colleagues, and what your team used.
One consequence, stated plainly: if a booth visitor writes to us asking to see or erase their record, we will not act on it ourselves. We will identify the customer holding it, pass the request to them, and tell the person we did that. Deciding is yours, because the data is yours.
Someone who applied for early access. If you filled in the application form, we hold what you typed: your company, your name, your work email, and what you said you wanted to try. We use it to reply and to decide who to let in next. It is not used for anything else, not shared, and not added to a mailing list. We keep it until early access closes or you ask us to delete it — write to info@klaari.ee and it goes.
What a captured lead contains
What a lead holds comes from three places, plus what the product works out from them.
The photograph your staff took — the card image itself, and the name, company, role, email, phone, website and address read out of it.
The conversation at the stand — the answers to your own questions, any notes typed in, and, where your team recorded one, the basis for following up. Alongside it we store the wording that was current at that moment, and superseded wordings are kept forever, so the record can still be read years later. To be exact about what that is and is not: it records the wording in force when the basis was set. It is not proof the person was shown it, and the product does not capture agreement. Whether and how your staff show it at the stand is yours.
The public web — if research is switched on for your workspace, we search for the person and their company using their name, role and employer, and keep the addresses of the pages actually read. A field is left empty rather than guessed. This means their name reaches a search provider, and that some of what a lead holds came from the web rather than from the conversation. No notice is sent to that person by us. Whether one is owed is your decision as controller, not ours.
The product also records automatically: which of your staff captured the lead, at which event, and when.
And it forms a view.From the above it writes a score, a short summary of the person’s role and seniority, how confident it is that a matched profile is really them, and a suggested next step. That is the product’s opinion about a named individual rather than something they told anyone, which is worth knowing before you export it or act on it.
What we hold about you and your team
Your email address, the workspace you created, your role in it, and the record of your sign-ins. What your workspace used — leads captured and model calls made — because usage is metered and capped. Sign-ins and account changes are recorded with the time, the account and the address they came from.
We hold it to run the service, to meter and cap it, to keep accounts secure, and to answer you when you write. Not for advertising, not for profiling, not for sale.
Our staff can reach workspace content when operating or supporting the product. When one of us reads a customer’s lead content, that read is written to the audit trail with a reason.
Who else receives it
Hetzner holds the server, in Germany. They provide the machine; they are not given access to what is on it.
OpenAIreceives the card photograph in order to read it, the sparse lead record in order to run the research, and the lead together with its recorded answers when somebody asks for a follow-up draft. It does not receive your other leads, your analytics or your team’s details. It processes all of it outside the EU. Under their published terms for the interface we use, that data is not used to train their models and is held for up to 30 days for abuse monitoring before deletion. A zero-retention option exists and is not switched on for this account. We take that from their published policy rather than from terms we negotiated, and we have not yet executed their data-processing addendum — the document that puts standard contractual clauses behind a transfer like this one. Doing so is on the list below.
Brevodelivers our email — sign-in links, invitations to join a workspace, and notices about what a workspace has spent. So it receives your team’s addresses, the addresses of anyone you invite, and your workspace name. Your visitors’ addresses are never sent to it; the product never emails the people in your leads. We have not verified in which countries Brevo stores that mail, so we do not claim EU-only for it.
Wherever you send leads yourself.When you connect a CRM or your own endpoint, the leads you choose go there. From that point the data is under that system’s terms and your agreement with its provider, not ours.
There is nobody else. No analytics provider, no advertising network, no data broker, no third-party backup service. The security page says how the data is kept apart.
Where it is stored
The application, the database and the card photographs all live on one server at Hetzner in Falkenstein, Germany. There is no CDN or proxy in front of it, no US region, and no replication to another region. The single exception is what OpenAI receives, above.
There are no off-site backups running today. If that machine were lost, the data on it would be lost with it. When backups exist they will be held in the EU, and this page will say so on the day it is true rather than before.
How long it is kept
Leads stay for as long as you keep them. There is no retention schedule and nothing expires on its own.
What “delete” does today, precisely, because the word is doing less work than it looks like: deleting a lead hides it — it leaves your lists, your search and your exports immediately, and no longer appears to anyone in your workspace. The underlying record and the card photograph remain on the server until a person removes them. Nothing sweeps them later.
Two further copies survive it. If the lead was sent to a webhook, the delivery log keeps the exact body that was posted and it stays readable. If it was sent to your CRM, it is in your CRM and deleting it here recalls nothing. Both matter if you are answering an erasure request, because neither is somewhere this product will clear for you.
Permanent removal is a request to info@klaari.ee, carried out by hand.
The rest, in short. The card photograph at OpenAI: up to 30 days, then deleted by them. Your sign-in session: seven days. Sign-in and account-change records: kept, with no schedule to remove them.
Getting it out, and getting it deleted
Export is a feature, not a request. Every lead your workspace holds comes out as a spreadsheet with the columns you choose, or as JSON through a read-only key. Neither export includes the card photographs; those are visible on the lead itself.
There is no self-service “delete my workspace and everything in it” button. Deletion is a request to info@klaari.ee and a person carries it out. We will confirm when it is done, but we cannot yet give you a deletion report produced by the system, because nothing produces one.
Rights, and where to take them
If you are a visitor whose card was scanned: the organisation whose stand you visited is responsible for your data — ask them for access, correction, erasure, restriction, objection or a copy. They can act on it; we cannot act on it for them.
If you cannot reach them, write to info@klaari.ee with what you remember — the stand, roughly when, the email address you gave. We will try to trace it and put you in touch. Being straight about this: we have no way to search leads across customers, so a person doing it by hand needs enough to go on and may not find it. If we do, we pass your request to the customer and tell you we have.
If you are a customer or on a customer’s team: write to the same address for access to your account data, a correction, a copy or its deletion. We aim to answer within 30 days and will tell you if something will take longer.
You can also complain to the data protection authority in the country you live in, whether or not you have raised it with us first.
Cookies
No analytics, no advertising pixel, no third-party tag, anywhere. Four cookies exist on klaari.ee and nothing else does: the sealed session cookie set when you sign in; a short-lived one while a single-sign-on hand-off is in flight; a short-lived one while you are connecting HubSpot; and one for our own staff console, which only our staff can obtain. The light or dark theme you pick is stored in your browser, not on our server.
What is not in place yet
Named rather than omitted, because this is the section a review asks about anyway.
- No data-processing agreement you can sign, and no subprocessor annex.
- OpenAI's data-processing addendum is not executed, so there are no standard contractual clauses behind the transfer described above.
- No off-site backups.
- No retention schedule, no automated erasure, and no self-service deletion of a workspace.
- No data protection officer is appointed, and whether one is required has not been assessed.
- Some older integration signing secrets are stored on the server without encryption. Anyone with the database could sign deliveries to your endpoint as if they came from us. Newer connections do not have this problem.
- No external penetration test or third-party security review.
- The registered company name, address and registry number are not printed here yet. Ask and we will send them.
- If we discover a breach affecting your data we will tell you as soon as we know, with what we know at the time. There is no rehearsed procedure behind that commitment yet.
If your organisation needs one of these before it can use Klaari, write and say which. Knowing that is genuinely useful, and it moves it up the list.
Asking a person
info@klaari.ee reaches the people who built and run this, not a ticket queue. The date at the top is when this page was last read against what the software actually does.